Apache Jackrabbit
cpe:2.3:a:apache:jackrabbit:*:*:*:*:*:*:*
- >= 2.20.0, < 2.20.17
- >= 2.22.0, < 2.22.1
- >= 2.23.0-beta, < 2.23.2-beta
A blind XML External Entity (XXE) vulnerability has been identified in Apache Jackrabbit versions prior to 2.23.2. This vulnerability arises in the jackrabbit-spi-commons and jackrabbit-core components, due to the use of an unsecured document builder that loads privileges. As a result, it allows for blind XXE attacks, where an attacker can exploit the XML parsing to access internal resources or files.
Exploitation of this vulnerability allows for blind XML External Entity attacks, where an attacker can manipulate XML data to access internal resources or files, potentially leading to further exploitation or information disclosure.
Users are advised to upgrade to Apache Jackrabbit versions 2.20.17 (Java 8), 2.22.1 (Java 11), or 2.23.2 (Java 11, beta versions), all of which address this vulnerability. Earlier versions up to 2.20.16 are no longer supported.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.