Логотип exploitDog
bind:CVE-2025-48913
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-48913

Количество 2

Количество 2

nvd логотип

CVE-2025-48913

11 дней назад

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-g4px-6qhm-hqjm

11 дней назад

Apache CXF: Untrusted JMS configuration can lead to RCE

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.

CVSS3: 9.8
0%
Низкий
11 дней назад
github логотип
GHSA-g4px-6qhm-hqjm

Apache CXF: Untrusted JMS configuration can lead to RCE

0%
Низкий
11 дней назад

Уязвимостей на страницу