CVE-2022-28890

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
05/05/2022
Last modified:
25/10/2023

Description

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:jena:4.4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools