CVE-2025-53689
published 2025-07-14CVE-2025-53689: Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.47%
37.2th percentile
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.
Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | — | — |
| apache | jackrabbit | >= 0 < 2.20.11-1.1 | 2.20.11-1.1 |
| apache | jackrabbit | >= 0 < 2.20.11-1.1 | 2.20.11-1.1 |
| apache | jackrabbit | >= 2.20.0 < 2.20.17 | 2.20.17 |
| apache_software_foundation | apache_jackrabbit | >= 2.20.0 < 2.20.17 | 2.20.17 |
| apache_software_foundation | apache_jackrabbit | >= 2.22.0 < 2.22.1 | 2.22.1 |
| apache_software_foundation | apache_jackrabbit | >= 2.23.0-beta < 2.23.2-beta | 2.23.2-beta |
| debian | jackrabbit | < jackrabbit 2.20.11-1.1 (forky) | jackrabbit 2.20.11-1.1 (forky) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
ghsa·2025-07-14
CVE-2025-53689 [HIGH] CWE-611 Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
Blind XXE vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.
Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
OSV
CVE-2025-53689: Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2
osv·2025-07-14·CVSS 8.8
CVE-2025-53689 [HIGH] CVE-2025-53689: Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
OSV
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
osv·2025-07-14
CVE-2025-53689 [HIGH] Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
Blind XXE vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.
Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
Red Hat
jackrabbit-spi-commons: jackrabbit-core: Apache Jackrabbit XXE vulnerability
vendor_redhat·2025-07-14·CVSS 8.8
CVE-2025-53689 [HIGH] CWE-611 jackrabbit-spi-commons: jackrabbit-core: Apache Jackrabbit XXE vulnerability
jackrabbit-spi-commons: jackrabbit-core: Apache Jackrabbit XXE vulnerability
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.
Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
An XML external entity flaw was found in Apache Jackrabbit. This issue occurs when using an unsecured document builder to load privileges and is vulnerable to an attack where a malicious user can inject harmful code.
Mitigation: Mitigation for this issue is either not available or the currentl
Debian
CVE-2025-53689: jackrabbit - Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apach...
vendor_debian·2025·CVSS 8.8
CVE-2025-53689 [HIGH] CVE-2025-53689: jackrabbit - Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apach...
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.20.11-1.1)
sid: resolved (fixed in 2.20.11-1.1)
trixie: resolved (fixed in 2.20.11-1.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-14
Published