Impact
The vulnerability allows an unauthenticated user to hijack an existing authenticated session by using an attacker‑derived WebDAV lock token. The session is reused across users without a credential check, enabling an attacker to perform actions as another user. This results in potential compromise of confidentiality, integrity, and availability of the Jackrabbit repository.
Affected Systems
The affected product is Apache Jackrabbit from the Apache Software Foundation. Versions 2.23.0 through 2.23.5, 2.22.0 through 2.22.4, and 2.20.0 through 2.20.17 are impacted. Users should upgrade to 2.23.6, 2.22.5, or 2.20.18 to receive the fix.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of a required authentication step and the ability to derive lock tokens from public information suggest a practical exploitation path. The likely attack vector is a crafted WebDAV request that includes a Lock-Token, TransactionId, SubscriptionId, or If-Header that matches a cached session, bypassing the credential check and allowing session reuse across users.
OpenCVE Enrichment