First published: Fri May 29 2015(Updated: )
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Jackrabbit | <=2.0.5 | |
Apache Jackrabbit | =2.2.0 | |
Apache Jackrabbit | =2.2.1 | |
Apache Jackrabbit | =2.2.2 | |
Apache Jackrabbit | =2.2.4 | |
Apache Jackrabbit | =2.2.5 | |
Apache Jackrabbit | =2.2.7 | |
Apache Jackrabbit | =2.2.8 | |
Apache Jackrabbit | =2.2.9 | |
Apache Jackrabbit | =2.2.10 | |
Apache Jackrabbit | =2.2.11 | |
Apache Jackrabbit | =2.2.12 | |
Apache Jackrabbit | =2.2.13 | |
Apache Jackrabbit | =2.4.0 | |
Apache Jackrabbit | =2.4.1 | |
Apache Jackrabbit | =2.4.2 | |
Apache Jackrabbit | =2.4.3 | |
Apache Jackrabbit | =2.4.4 | |
Apache Jackrabbit | =2.4.5 | |
Apache Jackrabbit | =2.6.0 | |
Apache Jackrabbit | =2.6.1 | |
Apache Jackrabbit | =2.6.2 | |
Apache Jackrabbit | =2.6.3 | |
Apache Jackrabbit | =2.6.4 | |
Apache Jackrabbit | =2.6.5 | |
Apache Jackrabbit | =2.8.0 | |
Apache Jackrabbit | =2.10.0 | |
maven/org.apache.jackrabbit:jackrabbit-core | =2.10.0 | 2.10.1 |
maven/org.apache.jackrabbit:jackrabbit-core | =2.8.0 | 2.8.1 |
maven/org.apache.jackrabbit:jackrabbit-core | >=2.6.0<=2.6.5 | 2.6.6 |
maven/org.apache.jackrabbit:jackrabbit-core | >=2.4.0<=2.4.5 | 2.4.6 |
maven/org.apache.jackrabbit:jackrabbit-core | >=2.2.0<=2.2.13 | 2.2.14 |
maven/org.apache.jackrabbit:jackrabbit-core | <=2.0.5 | 2.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.