eserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/t4wdrost6dh17dh406g792j9wq6xmy6v | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/09/06/3 | Mailing List Third Party Advisory |
19 Nov 2025, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | ||
| References | () http://www.openwall.com/lists/oss-security/2025/09/06/3 - Mailing List, Third Party Advisory |
04 Nov 2025, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
18 Sep 2025, 15:49
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-09-08 09:15
Updated : 2025-11-19 16:17
NVD link : CVE-2025-58782
Mitre link : CVE-2025-58782
CVE.ORG link : CVE-2025-58782
JSON object : View
Deserialization of Untrusted Data