We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-49656

Apache Jena: Administrative users can create files outside the server directory space via the admin UI



Description

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.

Reserved 2025-06-09 | Published 2025-07-21 | Updated 2025-07-21 | Assigner apache

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

Any version
affected

Credits

Noriaki Iwasaki; Cyber Defense Institute, Inc reporter

References

lists.apache.org/thread/qmm21som8zct813vx6dfd1phnfro6mwq vendor-advisory

cve.org (CVE-2025-49656)

nvd.nist.gov (CVE-2025-49656)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-49656

Support options

Helpdesk Chat, Email, Knowledgebase