QID 377797
QID 377797: Apache Jena Fuseki Deserialization of Untrusted Data Vulnerability
Apache Jena Fuseki is a SPARQL server. It can run as a operating system service, as a Java web application (WAR file), and as a standalone server.
Affected Versions:
Apache Jena SDB 3.17.0 and earlier
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version by sending a $/server query using GET request to server.
QID Detection Logic(Authenticated):
This QID checks for vulnerable version from the fuseki-server binary
An application using Apache Jena SDB can be subject to RCE when connected to a malicious database server by an attacker.
Solution
Update to the latest version of Apache Jena Fuseki
Refer to Apache Jena Fuseki for information on this.
Refer to Apache Jena Fuseki for information on this.
Vendor References
- CVE-2021-33192 -
lists.apache.org/thread/mc77cdl5stgjtjoldk467gdf756qjt31
CVEs related to QID 377797
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-45136 |
|