{"id":"CVE-2015-1833","aliases":["GHSA-9284-j4c9-779q"],"url":"https://o3.security/vulnerability/CVE-2015-1833","summary":"Improper Input Validation in Apache Jackrabbit","details":"XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.","published":"2015-05-29T15:59:13Z","modified":"2026-04-16T06:24:13.100315220Z","cvss":null,"epss":{"score":0.55028,"percentile":0.98964,"asOf":"2026-09-10"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.jackrabbit:jackrabbit-core","fixedVersion":"2.0.6"},{"ecosystem":"Maven","name":"org.apache.jackrabbit:jackrabbit-core","fixedVersion":"2.2.14"},{"ecosystem":"Maven","name":"org.apache.jackrabbit:jackrabbit-core","fixedVersion":"2.4.6"},{"ecosystem":"Maven","name":"org.apache.jackrabbit:jackrabbit-core","fixedVersion":"2.6.6"},{"ecosystem":"Maven","name":"org.apache.jackrabbit:jackrabbit-core","fixedVersion":"2.8.1"},{"ecosystem":"Maven","name":"org.apache.jackrabbit:jackrabbit-core","fixedVersion":"2.10.1"}],"fix":{"url":"https://github.com/apache/jackrabbit/commit/17e9f68f5a3f05ded20569777a7b07422680612d","label":"apache/jackrabbit@17e9f68"},"references":[{"type":"ADVISORY","url":"http://mail-archives.apache.org/mod_mbox/jackrabbit-announce/201505.mbox/%3C555DA644.8080908%40greenbytes.de%3E"},{"type":"ADVISORY","url":"http://www.apache.org/dist/jackrabbit/2.10.1/RELEASE-NOTES.txt"},{"type":"ADVISORY","url":"http://www.debian.org/security/2015/dsa-3298"},{"type":"ADVISORY","url":"https://issues.apache.org/jira/browse/JCR-3883"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/37110/"},{"type":"WEB","url":"http://packetstormsecurity.com/files/132005/Jackrabbit-WebDAV-XXE-Injection.html"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/535582/100/0/threaded"},{"type":"WEB","url":"http://www.securityfocus.com/bid/74761"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1833"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/17e9f68f5a3f05ded20569777a7b07422680612d"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/26e601934d0f439f0a61d62265f52936d79df40d"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/3903739363b79deb7579802fbc27b9b7448218b2"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/6191b366c607e65325a0116097aca8a359b36486"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/89c5c4ed6ab250ad609829517f167d2dbe0abdd0"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/b7fa1ae39641936872617ff95363353b0345b777"},{"type":"WEB","url":"https://github.com/apache/jackrabbit/commit/ddf9a3cd408397d0805917299c4114b09449373d"},{"type":"PACKAGE","url":"https://github.com/apache/jackrabbit"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/37110"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-16T06:24:13.100315220Z"}}