Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Users not using custom scripted functions are advised to run Java17 or later with no script engine added to the deployment.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xgh5-gwq5-rpx8 | Arbitrary javascript injection in Apache Jena |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:44:03.940Z
Reserved: 2023-01-05T14:41:04.515Z
Link: CVE-2023-22665
No data.
Status : Modified
Published: 2023-04-25T07:15:08.137
Modified: 2026-06-17T05:35:53.417
Link: CVE-2023-22665
No data.
OpenCVE Enrichment
No data.
-
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Github GHSA