Skip to main content
HIGH

CVE-2025-50151

Apache Jena: Configuration files uploaded by administrative users are not check properly

CVSS v3

8.8

HIGH

EPSS Score

1.1 %

exploit probability, as of 2026-10-11

CISA KEV

No

known exploited

Exploitation

none

SSVC status

Affected and fixed versions

Packages from OSV.dev and products from the vendors' CSAF advisories.

version not verifiedVersions not verified: read as OSV.dev and the vendors publish them, not checked against each vendor's release list.

Packages

  • org.apache.jena:jenaMavenall versions · fixed in 5.5.0

Vendor advisories

  • CVE-2025-50151 Red Hat Product Security54 known affected

    org.apache.jena: Apache Jena insufficent file validation

    jena-arq as a component of Red Hat AMQ Clients · jena-base as a component of Red Hat AMQ Clients · jena-core as a component of Red Hat AMQ Clients

Full record on NVD

Description

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Published
2025-07-21
Last Modified
2025-11-04

Frequently asked questions

What is CVE-2025-50151?

File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload.

Is CVE-2025-50151 actively exploited?

Active exploitation of CVE-2025-50151 has not been confirmed. Its EPSS score was 1.1% on 2026-10-11, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-50151?

CVE-2025-50151 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

Running jena? Hear about its next vulnerability

CVE Watch matches each new CVE to the vendors and products you list (vendor and product, not the version) and puts it in your alerts with its KEV and EPSS status.

Already have an account? Open CVE Watch

No credit card required · 50 free checks/month · Free API key