Vulnerability GHSA-g4px-6qhm-hqjm

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
August 08, 2025 at 12:32 PM UTC
Apache CXF: Untrusted JMS configuration can lead to RCE
>=2.0.6 <2.0.14, >=2.1.0 <2.1.11, >=2.2.0 <2.2.13, >=2.3.0 <2.3.12, >=2.4.0 <2.4.11, >=2.5.0 <2.5.12, >=2.6.0 <2.6.18, >=2.7.0 <2.7.19, >=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.12, >=3.6.0 <3.6.8, >=4.0.0 <4.0.9, >=4.1.0 <4.1.3
>=2.0.6 <2.0.14, >=2.1.0 <2.1.11, >=2.2.0 <2.2.13, >=2.3.0 <2.3.12, >=2.4.0 <2.4.11, >=2.5.0 <2.5.12, >=2.6.0 <2.6.18, >=2.7.0 <2.7.19, >=3.0.0 <3.0.17, >=3.1.0 <3.1.19, >=3.2.0 <3.2.15, >=3.3.0 <3.3.14, >=3.4.0 <3.4.11, >=3.5.0 <3.5.12, >=3.6.0 <3.6.8, >=4.0.0 <4.0.9, >=4.1.0 <4.1.3

Summary

Apache CXF: Untrusted JMS configuration can lead to RCE

Details

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.

Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.

Timeline

Published
1 year ago
August 08, 2025 at 12:32 PM UTC
Fixed (3.6.8)
Unknown
Unknown
Fixed (4.0.9)
Unknown
Unknown
Fixed (4.1.3)
Unknown
Unknown
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC