Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2hvc-5c6v-f533

Опубликовано: 26 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache CXF: Untrusted JMS configuration can lead to RCE

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

Пакеты

Наименование

org.apache.cxf:cxf-rt-transports-jms

maven
Затронутые версииВерсия исправления

= 4.2.0

4.2.1

Наименование

org.apache.cxf:cxf-rt-transports-jms

maven
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.6

4.1.6

Наименование

org.apache.cxf:cxf-rt-transports-jms

maven
Затронутые версииВерсия исправления

< 3.6.11

3.6.11

EPSS

Процентиль: 36%
0.00446
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
redhat
2 месяца назад

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVSS3: 7.5
nvd
2 месяца назад

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

EPSS

Процентиль: 36%
0.00446
Низкий

7.5 High

CVSS3

Дефекты

CWE-20