Blind XXE Vulnerability in Apache Jackrabbit Core and SPI Commons
CVE-2025-53689

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
14 July 2025

What is CVE-2025-53689?

A blind XML External Entity (XXE) vulnerability exists in the Apache Jackrabbit Core and SPI Commons components prior to version 2.23.2. This security flaw results from the use of an unsecured document build that allows for the unauthorized loading of privileges. It is essential for users to upgrade to supported versions—2.20.17 for Java 8, 2.22.1 for Java 11, or 2.23.2 for Java 11 (including beta versions)—to mitigate this issue, as earlier versions (up to 2.20.16) are no longer supported.

Affected Version(s)

Apache Jackrabbit 2.20.0 < 2.20.17

Apache Jackrabbit 2.22.0 < 2.22.1

Apache Jackrabbit 2.23.0-beta < 2.23.2-beta

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lars Krapf - Adobe
Dylan Pindur - Assetnote
Adam Kues - Assetnote
.
CVE-2025-53689 : Blind XXE Vulnerability in Apache Jackrabbit Core and SPI Commons