CVE-2015-1833
medium · 6.4XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.
6.4
CVSS
55.0%
EPSS (exploit prob.)
99th
EPSS percentile
2015-05-29
Published
AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | jackrabbit | <= 2.0.5 |
| apache | jackrabbit | 2.2.0 |
| apache | jackrabbit | 2.2.1 |
| apache | jackrabbit | 2.2.2 |
| apache | jackrabbit | 2.2.4 |
| apache | jackrabbit | 2.2.5 |
| apache | jackrabbit | 2.2.7 |
| apache | jackrabbit | 2.2.8 |
| apache | jackrabbit | 2.2.9 |
| apache | jackrabbit | 2.2.10 |
| apache | jackrabbit | 2.2.11 |
| apache | jackrabbit | 2.2.12 |
| apache | jackrabbit | 2.2.13 |
| apache | jackrabbit | 2.4.0 |
| apache | jackrabbit | 2.4.1 |
| apache | jackrabbit | 2.4.2 |
| apache | jackrabbit | 2.4.3 |
| apache | jackrabbit | 2.4.4 |
| apache | jackrabbit | 2.4.5 |
| apache | jackrabbit | 2.6.0 |
| apache | jackrabbit | 2.6.1 |
| apache | jackrabbit | 2.6.2 |
| apache | jackrabbit | 2.6.3 |
| apache | jackrabbit | 2.6.4 |
| apache | jackrabbit | 2.6.5 |
| apache | jackrabbit | 2.8.0 |
| apache | jackrabbit | 2.10.0 |
Check a specific version with /api/v1/cve/match.
References
- http://mail-archives.apache.org/mod_mbox/jackrabbit-announce/201505.mbox/%3C555DA644.8080908%40greenbytes.de%3E
- http://packetstormsecurity.com/files/132005/Jackrabbit-WebDAV-XXE-Injection.html
- http://www.apache.org/dist/jackrabbit/2.10.1/RELEASE-NOTES.txt
- http://www.debian.org/security/2015/dsa-3298
- http://www.securityfocus.com/archive/1/535582/100/0/threaded
- http://www.securityfocus.com/bid/74761
- https://issues.apache.org/jira/browse/JCR-3883
- https://www.exploit-db.com/exploits/37110/
- http://mail-archives.apache.org/mod_mbox/jackrabbit-announce/201505.mbox/%3C555DA644.8080908%40greenbytes.de%3E
- http://packetstormsecurity.com/files/132005/Jackrabbit-WebDAV-XXE-Injection.html
- http://www.apache.org/dist/jackrabbit/2.10.1/RELEASE-NOTES.txt
- http://www.debian.org/security/2015/dsa-3298
- http://www.securityfocus.com/archive/1/535582/100/0/threaded
- http://www.securityfocus.com/bid/74761
- https://issues.apache.org/jira/browse/JCR-3883
- https://www.exploit-db.com/exploits/37110/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-1833