Home

Description

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

PUBLISHED Reserved 2025-07-08 | Published 2025-07-14 | Updated 2025-11-04 | Assigner apache

Problem types

CWE-611 Improper Restriction of XML External Entity Reference

Product status

Default status
unaffected

2.20.0 (maven) before 2.20.17
affected

2.22.0 (maven) before 2.22.1
affected

2.23.0-beta (maven) before 2.23.2-beta
affected

Credits

Lars Krapf - Adobe reporter

Dylan Pindur - Assetnote finder

Adam Kues - Assetnote finder

References

www.openwall.com/lists/oss-security/2025/07/14/1

lists.apache.org/thread/5pf9n76ny13pzzk765og2h3gxdxw7p24 vendor-advisory

cve.org (CVE-2025-53689)

nvd.nist.gov (CVE-2025-53689)

Download JSON