CVE Published: 25/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Jena Status : PUBLISHED
CVE-2023-22665 Description
There is insufficient checking of user queries in Apache Jena versions 4.7.0 and earlier, when invoking custom scripts. It allows a remote user to execute arbitrary javascript via a SPARQL query.
CWE-ID: CWE-917 CWE Name: CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement (
Expression Language Injection
) Source: Apache Software Foundation
Common Attack Pattern Enumeration and Classification (CAPEC)