Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-53689

Опубликовано: 14 июл. 2025
Источник: redhat
CVSS3: 7.1

Описание

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

An XML external entity flaw was found in Apache Jackrabbit. This issue occurs when using an unsecured document builder to load privileges and is vulnerable to an attack where a malicious user can inject harmful code.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4jackrabbit-coreAffected
Red Hat build of Apache Camel for Spring Boot 4jackrabbit-spi-commonsAffected
Red Hat Fuse 7jackrabbit-coreWill not fix
Red Hat Fuse 7jackrabbit-spi-commonsWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=2379885jackrabbit-spi-commons: jackrabbit-core: Apache Jackrabbit XXE vulnerability

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
24 дня назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 8.8
nvd
24 дня назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 8.8
debian
24 дня назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-cor ...

CVSS3: 8.8
github
24 дня назад

Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build

7.1 High

CVSS3