CVE-2022-25312 — apache-any23
CRITICALCVE-2022-25312 is a critical-severity (CVSS 9.1) XML External Entity (XXE) vulnerability in org.apache.any23:apache-any23. A fix is available for org.apache.any23:apache-any23 — see the affected versions and patch details below.
An XML external entity (XXE) injection vulnerability exists in the Apache Any23 RDFa XSLTStylesheet extractor
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2022-25312 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
org.apache.any23:apache-any23Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access. This issue is fixed in Apache Any23 2.7.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | org.apache.any23:apache-any23 | all versions | 2.7org.apache.any23:apache-any23:2.7 |
Affected Products
any23apacheDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.apache.any23:apache-any23, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update org.apache.any23:apache-any23 to 2.7 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2022-25312 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
Frequently Asked Questions
Is CVE-2022-25312 in your dependencies?
Find it across Maven, including transitive dependencies.