We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53689

Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons



Description

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

Reserved 2025-07-08 | Published 2025-07-14 | Updated 2025-07-14 | Assigner apache

Problem types

CWE-611 Improper Restriction of XML External Entity Reference

Product status

Default status
unaffected

2.20.0 before 2.20.17
affected

2.22.0 before 2.22.1
affected

2.23.0-beta before 2.23.2-beta
affected

Credits

Lars Krapf - Adobe reporter

Dylan Pindur - Assetnote finder

Adam Kues - Assetnote finder

References

lists.apache.org/thread/5pf9n76ny13pzzk765og2h3gxdxw7p24 vendor-advisory

cve.org (CVE-2025-53689)

nvd.nist.gov (CVE-2025-53689)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53689

Support options

Helpdesk Chat, Email, Knowledgebase