Apache Jackrabbit XML external entity information leakage (CVE-2015-1833)
Apache Jackrabbit XML external entity information leakage (CVE-2015-1833)
Release date:
Updated on:
Affected Systems:
Apache Group Jackrabbit 2.10.1
Description:
Bugtraq id: 74761
CVE (CAN) ID: CVE-2015-1833
Apache Jackrabbit is an implementation that fully complies with the Java API version's content storage specification (JCR.
In versions earlier than Apache Jackrabbit 2.10.1, the jackrabbit-webdav module has the XXE/XEE vulnerability. Attackers can exploit this vulnerability to obtain sensitive application information.
<* Source: Julian Reschke ([email protected])
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://issues.apache.org/jira/browse/JCR-3883
JackRabbit details: click here
JackRabbit: click here
This article permanently updates the link address: