cbcvebase.
CVE-2025-53689
published 2025-07-14

CVE-2025-53689: Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load…

PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.47%
37.2th percentile
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachejackrabbit
apachejackrabbit
apachejackrabbit
apachejackrabbit>= 0 < 2.20.11-1.12.20.11-1.1
apachejackrabbit>= 0 < 2.20.11-1.12.20.11-1.1
apachejackrabbit>= 2.20.0 < 2.20.172.20.17
apache_software_foundationapache_jackrabbit>= 2.20.0 < 2.20.172.20.17
apache_software_foundationapache_jackrabbit>= 2.22.0 < 2.22.12.22.1
apache_software_foundationapache_jackrabbit>= 2.23.0-beta < 2.23.2-beta2.23.2-beta
debianjackrabbit< jackrabbit 2.20.11-1.1 (forky)jackrabbit 2.20.11-1.1 (forky)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.