PT-2026-103961 · Djehuty · Djehuty
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
djehuty versions prior to 26.3.2
Description
An unauthenticated attacker can perform SPARQL injection in search and listing queries. This occurs through three separate parameters, allowing the attacker to execute read (SELECT) queries. This can lead to cross-graph data exfiltration, such as retrieving triples from graphs not scoped to the request, including private, internal, or draft data stored in the RDF store. Additionally, it can cause a denial of service by executing expensive or malformed queries that exhaust the resources of the SPARQL backend and web workers. SPARQL is a query language designed to retrieve and manipulate data stored in Resource Description Framework (RDF) format.
Recommendations
Update to version 26.3.2.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Djehuty