Blind XXE Vulnerability in Apache Jackrabbit Core and SPI Commons
CVE-2025-53689
Currently unrated
What is CVE-2025-53689?
A blind XML External Entity (XXE) vulnerability exists in the Apache Jackrabbit Core and SPI Commons components prior to version 2.23.2. This security flaw results from the use of an unsecured document build that allows for the unauthorized loading of privileges. It is essential for users to upgrade to supported versions—2.20.17 for Java 8, 2.22.1 for Java 11, or 2.23.2 for Java 11 (including beta versions)—to mitigate this issue, as earlier versions (up to 2.20.16) are no longer supported.
Affected Version(s)
Apache Jackrabbit 2.20.0 < 2.20.17
Apache Jackrabbit 2.22.0 < 2.22.1
Apache Jackrabbit 2.23.0-beta < 2.23.2-beta