CVE-2023-32200: Apache Jena

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0.

Affected products

  • Apache Jena: from 3.7.0, up to and including 4.8.0

Published 2023-07-12. Last modified 2026-06-17.