Description
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
2.20.0 (maven) before 2.20.17
2.22.0 (maven) before 2.22.1
2.23.0-beta (maven) before 2.23.2-beta
Credits
Lars Krapf - Adobe
Dylan Pindur - Assetnote
Adam Kues - Assetnote
References
www.openwall.com/lists/oss-security/2025/07/14/1
lists.apache.org/thread/5pf9n76ny13pzzk765og2h3gxdxw7p24