Apache Jena File Upload Vulnerability in Configuration Management

Vulnerability

A vulnerability exists in Apache Jena in versions prior to 5.4.0, where file access paths in configuration files uploaded by users with administrator rights are not properly validated. This lack of validation could potentially be exploited to upload arbitrary configuration files. Users are advised to upgrade to version 5.5.0, which addresses this issue by disallowing arbitrary configuration uploads.

Impact

Exploitation of this vulnerability could lead to unauthorized configuration changes or the introduction of malicious configurations that could be executed by the application.

Remediation

Users should upgrade to Apache Jena version 5.5.0 or later, which does not permit arbitrary configuration file uploads.

Added: Jul 21, 2025, 10:28 AM
Updated: Jul 21, 2025, 10:28 AM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
2.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.