Логотип exploitDog
bind:CVE-2025-53689
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-53689

Количество 5

Количество 5

ubuntu логотип

CVE-2025-53689

5 месяцев назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2025-53689

5 месяцев назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2025-53689

5 месяцев назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2025-53689

5 месяцев назад

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-cor ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-44c3-38h8-9fh9

5 месяцев назад

Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 7.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

CVSS3: 8.8
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-cor ...

CVSS3: 8.8
0%
Низкий
5 месяцев назад
github логотип
GHSA-44c3-38h8-9fh9

Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build

CVSS3: 8.8
0%
Низкий
5 месяцев назад

Уязвимостей на страницу