VYPR

Maven package

org.apache.jackrabbit/jackrabbit-jcr-commons

pkg:maven/org.apache.jackrabbit/jackrabbit-jcr-commons

Vulnerabilities (1)

  • CVE-2025-58782MedSep 8, 2025
    affected >= 1.0.0, < 2.22.2fixed 2.22.2

    Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR