Vulnerability GHSA-g4px-6qhm-hqjm
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
August 08, 2025 at 12:32 PM UTC
Apache CXF: Untrusted JMS configuration can lead to RCE
>=2.0.6 <2.0.14, >=2.1.0 <2.1.11, >=2.2.0 <2.2.13, >=2.3.0 <2.3.12, >=2.4.0 <2.4.11, >=2.5.0 <2.5.12, >=2.6.0 <2.6.18, >=2.7.0 <2.7.19, >=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.12, >=3.6.0 <3.6.8, >=4.0.0 <4.0.9, >=4.1.0 <4.1.3
>=2.0.6 <2.0.14, >=2.1.0 <2.1.11, >=2.2.0 <2.2.13, >=2.3.0 <2.3.12, >=2.4.0 <2.4.11, >=2.5.0 <2.5.12, >=2.6.0 <2.6.18, >=2.7.0 <2.7.19, >=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.12, >=3.6.0 <3.6.8, >=4.0.0 <4.0.9, >=4.1.0 <4.1.3
Summary
Apache CXF: Untrusted JMS configuration can lead to RCE
Details
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
3 months ago
Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory
4.2.0 - 4.2.1 GHSA-93g8-qqv3-mrx8
4.2.0 - 4.2.1 GHSA-93g8-qqv3-mrx8
High Risk
4 months ago
Apache CXF: Untrusted JMS configuration can lead to RCE
4.2.0 GHSA-2hvc-5c6v-f533
4.2.0 GHSA-2hvc-5c6v-f533
Impacted packages
Timeline
Published
1 year ago
August 08, 2025 at 12:32 PM UTC
Fixed (3.6.8)
Unknown
Unknown
Fixed (4.0.9)
Unknown
Unknown
Fixed (4.1.3)
Unknown
Unknown
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC