Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7p63-w6x9-6gr7

Опубликовано: 18 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.4

Описание

Eclipse Jersey has a Race Condition

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)

Пакеты

Наименование

org.glassfish.jersey.core:jersey-client

maven
Затронутые версииВерсия исправления

= 2.45

2.46

Наименование

org.glassfish.jersey.core:jersey-client

maven
Затронутые версииВерсия исправления

= 3.0.16

3.0.17

Наименование

org.glassfish.jersey.core:jersey-client

maven
Затронутые версииВерсия исправления

= 3.1.9

3.1.10

EPSS

Процентиль: 18%
0.00057
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-296
CWE-362

Связанные уязвимости

CVSS3: 7.4
nvd
3 месяца назад

In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)

EPSS

Процентиль: 18%
0.00057
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-296
CWE-362