CVE-2025-53689
Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
8.8
HIGH
CVSS 3.1
EPSS 0.47%
Description
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.
How to fix CVE-2025-53689
To remediate CVE-2025-53689, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 2.23.2-beta or later
- —upgrade to 2.20.17 or later
Is CVE-2025-53689 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0
- >= 2.23.0-beta, < 2.23.2-beta
- >= 2.20.0, < 2.20.17
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |