Home

Description

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.

PUBLISHED Reserved 2025-06-09 | Published 2025-07-21 | Updated 2025-11-04 | Assigner apache

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

Any version
affected

Credits

Noriaki Iwasaki; Cyber Defense Institute, Inc reporter

References

www.openwall.com/lists/oss-security/2025/07/21/1

lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq vendor-advisory

cve.org (CVE-2025-49656)

nvd.nist.gov (CVE-2025-49656)

Download JSON