CVE-2021-39239

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
16/09/2021
Last modified:
07/11/2023

Description

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:* 4.1.0 (including)