We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-50151

Apache Jena: Configuration files uploaded by administrative users are not check properly



Description

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.

Reserved 2025-06-13 | Published 2025-07-21 | Updated 2025-07-21 | Assigner apache

Problem types

CWE-20

Product status

Default status
unaffected

Any version
affected

References

lists.apache.org/thread/12gks5z40gh9bszn1xk8mz34gz586xss vendor-advisory

cve.org (CVE-2025-50151)

nvd.nist.gov (CVE-2025-50151)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-50151

Support options

Helpdesk Chat, Email, Knowledgebase