CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.
CVE
CVE-2022-28890
Severity
CRITICAL
CVSS
9.8
EPSS
2.54%
Apache
Original NVD Description
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.
Related CVEs
Other vulnerabilities affecting the same vendor(s)