Blind XXE Vulnerability in Apache Jackrabbit Core and SPI Commons
CVE-2025-53689
8.8HIGH
What is CVE-2025-53689?
A blind XML External Entity (XXE) vulnerability exists in the Apache Jackrabbit Core and SPI Commons components prior to version 2.23.2. This security flaw results from the use of an unsecured document build that allows for the unauthorized loading of privileges. It is essential for users to upgrade to supported versions—2.20.17 for Java 8, 2.22.1 for Java 11, or 2.23.2 for Java 11 (including beta versions)—to mitigate this issue, as earlier versions (up to 2.20.16) are no longer supported.
Affected Version(s)
Apache Jackrabbit 2.20.0 < 2.20.17
Apache Jackrabbit 2.22.0 < 2.22.1
Apache Jackrabbit 2.23.0-beta < 2.23.2-beta
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lars Krapf - Adobe
Dylan Pindur - Assetnote
Adam Kues - Assetnote