Description
Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version
Credits
Noriaki Iwasaki; Cyber Defense Institute, Inc
References
www.openwall.com/lists/oss-security/2025/07/21/1
lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq