PT-2026-107580 · Apache · Apache Jackrabbit
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/S:N |
Name of the Vulnerable Software and Affected Versions
Apache Jackrabbit versions 2.23.0 through 2.23.5
Apache Jackrabbit versions 2.22.0 through 2.22.4
Apache Jackrabbit versions 2.20.0 through 2.20.17
Description
The WebDAV/DavEx client contains a flaw where it uses externally-controlled input to select classes or code. A malicious WebDAV/DavEx server, or an attacker intercepting the connection, can force the client to instantiate arbitrary classes from its classpath by manipulating server-controlled error bodies via
Class.forName. This unsafe reflection on wire data can lead to arbitrary file creation or truncation. This issue specifically affects applications using jackrabbit-spi2dav (directly or through jackrabbit-jcr2dav) to connect to remote repositories; servers are not affected.Recommendations
Upgrade Apache Jackrabbit versions 2.23.0 through 2.23.5 to version 2.23.6.
Upgrade Apache Jackrabbit versions 2.22.0 through 2.22.4 to version 2.22.5.
Upgrade Apache Jackrabbit versions 2.20.0 through 2.20.17 to version 2.20.18.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Jackrabbit