8.8

CVE-2025-53689

Apache Jackrabbit: XXE vulnerability in jackrabbit-spi-commons

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.

Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Jackrabbit Version >= 2.20.0 < 2.20.17
Apache ≫ Jackrabbit Version 2.22.0
Apache ≫ Jackrabbit Version 2.23.0 Update beta
Apache ≫ Jackrabbit Version 2.23.1 Update beta
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.387
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://lists.apache.org/thread/5pf9n76ny13pzzk765og2h3gxdxw7p24
Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/07/14/1