Description
There is insufficient restrictions of called script functions in Apache Jena
versions 4.8.0 and earlier. It allows a
remote user to execute javascript via a SPARQL query.
This issue affects Apache Jena: from 3.7.0 through 4.8.0.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9Attack Vector: Network
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages4 packages
🔴Vulnerability Details
4CVEListApache Jena: Exposure of execution in script engine expressions.↗2023-07-12 ▶ OSVApache Jena Expression Language Injection vulnerability↗2023-07-12 ▶ GHSAApache Jena Expression Language Injection vulnerability↗2023-07-12 ▶ OSVCVE-2023-32200: There is insufficient restrictions of called script functions in Apache Jena versions 4↗2023-07-12 ▶ 📋Vendor Advisories
1DebianCVE-2023-32200: apache-jena - There is insufficient restrictions of called script functions in Apache Jena ve...↗2023 ▶