A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain page views. This issue affects Apache Jena Fuseki from version 2.0.0 to version 4.0.0 (inclusive).
References
Link | Resource |
---|---|
https://lists.apache.org/thread.html/r684d8943d755a96fe90f8cd8df196737b6bde3f2b74e15a9bd479975%40%3Cusers.jena.apache.org%3E | Mailing List Vendor Advisory |
https://lists.apache.org/thread.html/r684d8943d755a96fe90f8cd8df196737b6bde3f2b74e15a9bd479975%40%3Cusers.jena.apache.org%3E | Mailing List Vendor Advisory |
Configurations
History
21 Nov 2024, 06:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.apache.org/thread.html/r684d8943d755a96fe90f8cd8df196737b6bde3f2b74e15a9bd479975%40%3Cusers.jena.apache.org%3E - Mailing List, Vendor Advisory |
Information
Published : 2021-07-05 10:15
Updated : 2024-11-21 06:08
NVD link : CVE-2021-33192
Mitre link : CVE-2021-33192
CVE.ORG link : CVE-2021-33192
JSON object : View
Products Affected
apache
- jena_fuseki
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')