Skip to content

Apache CXF - Improper Input Validation Vulnerability #3731

@JannisDev

Description

@JannisDev

Hey there,

I've identified an open vulnerability in the image:

  • Description: If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
  • Solution: Update to the latest version of the library. Vendor has provided fix in versions 3.6.8, 4.0.9, 4.1.3.
  • Findings: /usr/share/mc-image-helper-1.48.11/lib/cxf-core-3.5.11.jar
  • References: Apache, CVE-2025-48913

Please consider updating the affected library in the next release.

Sub-issues

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Projects

    Status

    To do

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions