CVE-2022-28890: Processing external DTDs
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
Other sources
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 only. Apache Jena 4.2.x and 4.3.x do not allow external entities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.jena:jenato a version that resolves this vulnerability.Fixed in 4.5.0
Event History
Frequently Asked Questions
What is CVE-2022-28890?
CVE-2022-28890 is a vulnerability in the RDF/XML parser of Apache Jena that allows an attacker to retrieve external DTDs.
Which versions of Apache Jena are affected by CVE-2022-28890?
Apache Jena versions 4.4.0 and prior are affected by CVE-2022-28890.
How does CVE-2022-28890 impact Apache Jena?
CVE-2022-28890 allows an attacker to cause an external DTD to be retrieved, posing a potential security risk to Apache Jena.
How severe is CVE-2022-28890?
CVE-2022-28890 has a severity score of 9.8 (critical).
How can I fix CVE-2022-28890?
To fix CVE-2022-28890, upgrade to Apache Jena version 4.5.0 or later.