Loading HuntDB...

GHSA-7rp6-w7mg-h8rw

GitHub Security Advisory

XML External Entity Reference in Apache Jena

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.

Affected Packages

Maven org.apache.jena:jena-core
Affected versions: 0 (fixed in 4.2.0)

Related CVEs

Key Information

GHSA ID
GHSA-7rp6-w7mg-h8rw
Published
September 20, 2021 8:22 PM
Last Modified
September 17, 2021 6:29 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.jena:jena-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.