{"api_version":"1","generated_at":"2026-07-23T10:04:59+00:00","cve":"CVE-2022-28890","urls":{"html":"https://cve.report/CVE-2022-28890","api":"https://cve.report/api/cve/CVE-2022-28890.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-28890","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-28890"},"summary":{"title":"CVE-2022-28890","description":"A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.","state":"PUBLIC","assigner":"security@apache.org","published_at":"2022-05-05 09:15:00","updated_at":"2023-10-25 17:01:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://lists.apache.org/thread/h88oh642455wljo0p5jgzs9phk4gj878","name":"https://lists.apache.org/thread/h88oh642455wljo0p5jgzs9phk4gj878","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-28890","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28890","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Apache Jena would like to thank Feras Daragma, Avishag Shapira & Amit Laish (GE Digital, Cyber Security Lab) for their report.","lang":""}],"nvd_cpes":[{"cve_year":"2022","cve_id":"28890","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"jena","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"28890","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"apache","cpe5":"jena","cpe6":"4.4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2022-28890","qid":"183707","title":"Debian Security Update for apache-jena (CVE-2022-28890)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@apache.org","ID":"CVE-2022-28890","STATE":"PUBLIC","TITLE":"Processing external DTDs"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Apache Jena","version":{"version_data":[{"version_affected":"<=","version_name":"Apache Jena","version_value":"4.4.0"}]}}]},"vendor_name":"Apache Software Foundation"}]}},"credit":[{"lang":"eng","value":"Apache Jena would like to thank Feras Daragma, Avishag Shapira & Amit Laish (GE Digital, Cyber Security Lab) for their report."}],"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities."}]},"generator":{"engine":"Vulnogram 0.0.9"},"impact":[{"other":"medium"}],"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"XML External DTD vulnerability"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://lists.apache.org/thread/h88oh642455wljo0p5jgzs9phk4gj878","name":"https://lists.apache.org/thread/h88oh642455wljo0p5jgzs9phk4gj878"}]},"source":{"discovery":"UNKNOWN"},"work_around":[{"lang":"eng","value":"Users are advised to upgrade to Apache Jena 4.5.0 or later."}]},"nvd":{"publishedDate":"2022-05-05 09:15:00","lastModifiedDate":"2023-10-25 17:01:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:apache:jena:4.4.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}