VDB
Sign up
MEDIUM

GHSA-g4px-6qhm-hqjm

Apache CXF: Untrusted JMS configuration can lead to RCE

Quick fix

GHSA-g4px-6qhm-hqjm — org.apache.cxf:cxf-rt-transports-jms: upgrade to the fixed version with the command below.

# pom.xml: bump <version>3.6.8</version> for org.apache.cxf:cxf-rt-transports-jms

Details

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.

Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.cxf:cxf-rt-transports-jms
Introduced in: 0Fixed in: 3.6.8
Fix# pom.xml: bump <version>3.6.8</version> for org.apache.cxf:cxf-rt-transports-jms
Maven/org.apache.cxf:cxf-rt-transports-jms
Introduced in: 4.0.0Fixed in: 4.0.9
Fix# pom.xml: bump <version>4.0.9</version> for org.apache.cxf:cxf-rt-transports-jms
Maven/org.apache.cxf:cxf-rt-transports-jms
Introduced in: 4.1.0Fixed in: 4.1.3
Fix# pom.xml: bump <version>4.1.3</version> for org.apache.cxf:cxf-rt-transports-jms

References