CVE-2025-53689 Details
Description
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
A blind XML External Entity (XXE) vulnerability has been identified in Apache Jackrabbit versions prior to 2.23.2. This vulnerability arises in the jackrabbit-spi-commons and jackrabbit-core components, due to the use of an unsecured document builder that loads privileges. As a result, it allows for blind XXE attacks, where an attacker can exploit the XML parsing to access internal resources or files.
Users are advised to upgrade to Apache Jackrabbit versions 2.20.17 (Java 8), 2.22.1 (Java 11), or 2.23.2 (Java 11, beta versions), all of which address this vulnerability. Earlier versions up to 2.20.16 are no longer supported.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/07/14/1 | CVE | |
| https://lists.apache.org/thread/5pf9n76ny13pzzk765og2h3gxdxw7p24 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache jackrabbit | >= 2.20.0, < 2.20.17 2.22.0 2.23.0 beta 2.23.1 beta |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Jul 29, 2025 | Initial Analysis | [email protected] |
| Jul 14, 2025 | CVE Modified | CISA-ADP |
| Jul 14, 2025 | New CVE Received | [email protected] |