Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
History

Tue, 29 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache jackrabbit
CPEs cpe:2.3:a:apache:jackrabbit:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.22.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.23.0:beta:*:*:*:*:*:*
cpe:2.3:a:apache:jackrabbit:2.23.1:beta:*:*:*:*:*:*
Vendors & Products Apache
Apache jackrabbit

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.00039}


Tue, 15 Jul 2025 00:15:00 +0000


Mon, 14 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}


Mon, 14 Jul 2025 09:30:00 +0000

Type Values Removed Values Added
Description Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
Title Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons
Weaknesses CWE-611
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-07-14T09:15:38.863Z

Updated: 2025-07-14T15:46:20.206Z

Reserved: 2025-07-08T10:21:17.361Z

Link: CVE-2025-53689

cve-icon Vulnrichment

Updated: 2025-07-14T15:45:46.499Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-14T10:15:28.587

Modified: 2025-07-29T14:52:26.610

Link: CVE-2025-53689

cve-icon Redhat

Severity : Important

Publid Date: 2025-07-14T09:15:38Z

Links: CVE-2025-53689 - Bugzilla