{
  "threat_severity" : "Important",
  "public_date" : "2025-07-14T09:15:38Z",
  "bugzilla" : {
    "description" : "jackrabbit-spi-commons: jackrabbit-core: Apache Jackrabbit XXE vulnerability",
    "id" : "2379885",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2379885"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
    "status" : "draft"
  },
  "cwe" : "CWE-611",
  "details" : [ "Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.\nUsers are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the respective supported version.", "An XML external entity flaw was found in Apache Jackrabbit. This issue occurs when using an unsecured document builder to load privileges and is vulnerable to an attack where a malicious user can inject harmful code." ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Not affected",
    "package_name" : "jackrabbit-core",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat build of Apache Camel for Spring Boot 4",
    "fix_state" : "Not affected",
    "package_name" : "jackrabbit-spi-commons",
    "cpe" : "cpe:/a:redhat:camel_spring_boot:4"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "jackrabbit-core",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Will not fix",
    "package_name" : "jackrabbit-spi-commons",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-53689\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53689\nhttps://github.com/apache/jackrabbit/commit/410d708595750528095db1a2accc95356ddf7311\nhttps://issues.apache.org/jira/browse/JCR-5165\nhttps://lists.apache.org/thread/5pf9n76ny13pzzk765og2h3gxdxw7p24" ],
  "name" : "CVE-2025-53689",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}