{"id":"GHSA-9284-j4c9-779q","summary":"Improper Input Validation in Apache Jackrabbit","details":"XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.","aliases":["CVE-2015-1833"],"modified":"2024-12-04T05:40:40.504899Z","published":"2022-05-14T02:49:30Z","database_specific":{"github_reviewed_at":"2022-07-06T20:22:18Z","nvd_published_at":"2015-05-29T15:59:00Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1833"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/17e9f68f5a3f05ded20569777a7b07422680612d"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/26e601934d0f439f0a61d62265f52936d79df40d"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/3903739363b79deb7579802fbc27b9b7448218b2"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/6191b366c607e65325a0116097aca8a359b36486"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/89c5c4ed6ab250ad609829517f167d2dbe0abdd0"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/b7fa1ae39641936872617ff95363353b0345b777"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/ddf9a3cd408397d0805917299c4114b09449373d"},{"type":"PACKAGE","url":"https://github.com/apache/jackrabbit"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/JCR-3883"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/37110"},{"type":"WEB","url":"http://mail-archives.apache.org/mod_mbox/jackrabbit-announce/201505.mbox/%3C555DA644.8080908%40greenbytes.de%3E"},{"type":"WEB","url":"http://packetstormsecurity.com/files/132005/Jackrabbit-WebDAV-XXE-Injection.html"},{"type":"WEB","url":"http://www.apache.org/dist/jackrabbit/2.10.1/RELEASE-NOTES.txt"},{"type":"WEB","url":"http://www.debian.org/security/2015/dsa-3298"}],"affected":[{"package":{"name":"org.apache.jackrabbit:jackrabbit-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.jackrabbit/jackrabbit-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.6"}]}],"versions":["1.0","1.0.1","1.1","1.1.1","1.2.1","1.2.2","1.2.3","1.3","1.3.1","1.3.3","1.4","1.4.1","1.4.10","1.4.11","1.4.12","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.6.0","1.6.1","1.6.2","1.6.4","1.6.5","2.0-beta1","2.0-beta3","2.0-beta4","2.0-beta5","2.0-beta6","2.0.0","2.0.3","2.0.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9284-j4c9-779q/GHSA-9284-j4c9-779q.json"}},{"package":{"name":"org.apache.jackrabbit:jackrabbit-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.jackrabbit/jackrabbit-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.14"}]}],"versions":["2.2.0","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.2","2.2.4","2.2.5","2.2.7","2.2.8","2.2.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.2.13","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9284-j4c9-779q/GHSA-9284-j4c9-779q.json"}},{"package":{"name":"org.apache.jackrabbit:jackrabbit-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.jackrabbit/jackrabbit-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.6"}]}],"versions":["2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.4.5","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9284-j4c9-779q/GHSA-9284-j4c9-779q.json"}},{"package":{"name":"org.apache.jackrabbit:jackrabbit-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.jackrabbit/jackrabbit-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.6"}]}],"versions":["2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9284-j4c9-779q/GHSA-9284-j4c9-779q.json","last_known_affected_version_range":"\u003c= 2.6.5"}},{"package":{"name":"org.apache.jackrabbit:jackrabbit-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.jackrabbit/jackrabbit-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.1"}]}],"versions":["2.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9284-j4c9-779q/GHSA-9284-j4c9-779q.json"}},{"package":{"name":"org.apache.jackrabbit:jackrabbit-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.jackrabbit/jackrabbit-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.10.0"},{"fixed":"2.10.1"}]}],"versions":["2.10.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9284-j4c9-779q/GHSA-9284-j4c9-779q.json"}}],"schema_version":"1.9.0"}