---
title: "CVE-2015-1833\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-1833?format=md
keywords: index, follow
---

# CVE-2015-1833

Publication date 29 May 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6,
2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before
2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary
files and send requests to intranet servers via a crafted WebDAV request.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2015-1833?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| jackrabbit | 15.04 vivid | Fixed 2.3.6-1+deb8u1build0.15.04.1 |
| 14.10 utopic | Fixed 2.3.6-1+deb8u1build0.14.10.1 |
| 14.04 LTS trusty | Fixed 2.3.6-1+deb8u1build0.14.04.1 |
| 12.04 LTS precise | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

package only contains webdav module; however, vuln affects
webdav module

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1833)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-1833)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-1833)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-1833)

### Other references

* <https://issues.apache.org/jira/browse/JCR-3883>
* <http://www.openwall.com/lists/oss-security/2015/05/21/6>
* <https://www.cve.org/CVERecord?id=CVE-2015-1833>
