Bug#1109335: jackrabbit: CVE-2025-53689

2025-07-23 Thread Bastian Germann
Control: tags -1 patch I am uploading a NMU to fix this. The debdiff is attached. diff -Nru jackrabbit-2.20.11/debian/changelog jackrabbit-2.20.11/debian/changelog --- jackrabbit-2.20.11/debian/changelog 2023-07-29 15:08:48.0 +0200 +++ jackrabbit-2.20.11/debian/changelog 2025-07-23 10:05:

Bug#1109335: jackrabbit: CVE-2025-53689

2025-07-15 Thread Moritz Mühlenhoff
Package: jackrabbit X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for jackrabbit. CVE-2025-53689[0]: | Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit- | core in Apache Jackrabbit < 2.23.2 due to usage of an