Apache Jena: Exposure of execution in script engine expressions.
CVE-2023-32200
8.8HIGH
What is CVE-2023-32200?
A vulnerability exists in Apache Jena versions 4.8.0 and earlier due to insufficient restrictions applied to called script functions. This flaw could allow a remote attacker to execute arbitrary JavaScript code via a crafted SPARQL query, potentially compromising the integrity and security of the affected systems. Users and administrators of Apache Jena should take immediate measures to address this issue by applying the recommended updates and patches.
Affected Version(s)
Apache Jena 3.7.0 <= 4.8.0