CVE-2023-22665

CVSS V2 None CVSS V3 None
Description
There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.
Overview
  • CVE ID
  • CVE-2023-22665
  • Assigner
  • security@apache.org
  • Vulnerability Status
  • Received
  • Published Version
  • 2023-04-25T07:15:08
  • Last Modified Date
  • 2023-04-25T07:15:08
History
Created Old Value New Value Data Type Notes
2023-04-25 08:00:55 Added to TrackCVE
2023-04-25 08:00:56 Weakness Enumeration new