Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93g8-qqv3-mrx8

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

EPSS

Процентиль: 47%
0.00646
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-502

Связанные уязвимости

CVSS3: 8.8
redhat
около 2 месяцев назад

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

CVSS3: 8.1
nvd
около 2 месяцев назад

A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.

EPSS

Процентиль: 47%
0.00646
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-502