First published: Thu Sep 16 2021(Updated: )
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including exposing the contents of local files to a remote server.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Jena | <=4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-39239 is high, with a severity value of 7.5.
The vulnerability in Apache Jena is an XML External Entities (XXE) vulnerability.
Versions up to 4.1.0 of Apache Jena are affected by CVE-2021-39239.
An attacker can exploit CVE-2021-39239 by executing XML External Entities (XXE) to expose the contents of local files to a remote server.
Yes, upgrading to a version beyond 4.1.0 of Apache Jena will provide a fix for CVE-2021-39239.