SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-50151

Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.

HIGH 8.8EPSS 0.99%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.99%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.99% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
apache/jena
Source
security@apache.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.