CVE-2025-50151

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.
CVSS

No CVSS.

References
Link Resource
https://lists.apache.org/thread/12gks5z40gh9bszn1xk8mz34gz586xss Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*

History

29 Jul 2025, 14:22

Type Values Removed Values Added
References () https://lists.apache.org/thread/12gks5z40gh9bszn1xk8mz34gz586xss - () https://lists.apache.org/thread/12gks5z40gh9bszn1xk8mz34gz586xss - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*
First Time Apache jena
Apache

21 Jul 2025, 15:15

Type Values Removed Values Added
CWE CWE-20

21 Jul 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-21 10:15

Updated : 2025-07-29 14:22


NVD link : CVE-2025-50151

Mitre link : CVE-2025-50151


JSON object : View

Products Affected

apache

  • jena
CWE

No CWE.