QID 377806
QID 377806: Apache Jena Fuseki Deserialization of Untrusted Data Vulnerability
Apache Jena Fuseki is a SPARQL server. It can run as a operating system service, as a Java web application (WAR file), and as a standalone server.
Affected Versions:
Apache Jena SDB 3.17.0 and earlier
QID Detection Logic(Unauthenticated):
This QID checks for vulnerable version by sending a $/server query using GET request to server.
Apache Jena SDB can be subjected to RCE when connected to a malicious database server by an attacker.
Solution
Update to the latest version of Apache Jena Fuseki
Refer to Apache Jena Fuseki for information on this.
Refer to Apache Jena Fuseki for information on this.
Vendor References
- CVE-2022-45136 -
lists.apache.org/thread/mc77cdl5stgjtjoldk467gdf756qjt31
CVEs related to QID 377806
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-45136 |
|