CVE-2025-58782
published 2025-09-08CVE-2025-58782: Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from…
PriorityP343medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.29%
66.8th percentile
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1.
Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data.
Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jackrabbit | >= 1.0.0 < 2.22.2 | 2.22.2 |
| apache_software_foundation | apache_jackrabbit_core | 1.0.0 – 2.22.1 | — |
| apache_software_foundation | apache_jackrabbit_jcr_commons | 1.0.0 – 2.22.1 | — |
| debian | jackrabbit | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
ghsa·2025-09-08
CVE-2025-58782 [MEDIUM] CWE-502 Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
There is a serialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1.
Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
OSV
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
osv·2025-09-08
CVE-2025-58782 [MEDIUM] Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
There is a serialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1.
Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
OSV
CVE-2025-58782: Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons
osv·2025-09-08·CVSS 6.5
CVE-2025-58782 [MEDIUM] CVE-2025-58782: Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
Red Hat
org.apache.jackrabbit/jackrabbit-core: org.apache.jackrabbit/jackrabbit-jcr-commons: Apache Jackrabbit JNDI injection
vendor_redhat·2025-09-08·CVSS 6.5
CVE-2025-58782 [MEDIUM] CWE-502 org.apache.jackrabbit/jackrabbit-core: org.apache.jackrabbit/jackrabbit-jcr-commons: Apache Jackrabbit JNDI injection
org.apache.jackrabbit/jackrabbit-core: org.apache.jackrabbit/jackrabbit-jcr-commons: Apache Jackrabbit JNDI injection
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons.
This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1.
Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data.
Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
A
Debian
CVE-2025-58782: jackrabbit - Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Ap...
vendor_debian·2025·CVSS 6.5
CVE-2025-58782 [MEDIUM] CVE-2025-58782: jackrabbit - Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Ap...
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-08
Published