An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1qcTJjLW04Z2ctbXFjbc4ABKU-

Moderate EPSS: 0.00072% (0.22668 Percentile) EPSS:

Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server

Affected Packages Affected Versions Fixed Versions
maven:org.apache.jena:jena-fuseki < 5.5.0 5.5.0
20 Dependent packages
59 Dependent repositories

Affected Version Ranges

All affected versions

0.2.2, 0.2.3, 0.2.4, 0.2.5, 0.2.6, 0.2.7, 1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.1.1, 2.0.0, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.6.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 3.12.0, 3.13.0, 3.13.1, 3.14.0, 3.15.0, 3.16.0, 3.17.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.4.0, 4.5.0, 4.6.0, 4.6.1, 4.7.0, 4.8.0, 4.9.0, 4.10.0, 5.0.0, 5.1.0, 5.2.0, 5.3.0, 5.4.0

All unaffected versions

5.5.0

Users with administrator access can create databases files outside the files area of the Fuseki server.

This issue affects Apache Jena version up to 5.4.0.

Users are recommended to upgrade to version 5.5.0, which fixes the issue.

References: