Security Advisory

CVE-2022-28890

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-05-05 08:40:09
Last updated 2024-08-03 06:10:56
Assigner apache
State PUBLISHED

Description

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.