CRITICAL 9.8
GHSA-qp3f-rvj8-46c8
Apache CXF JNDI Injection vulnerability in DispatchMDBMessageListenerImpl
빠른 조치
GHSA-qp3f-rvj8-46c8 — org.apache.cxf:cxf-integration-jca: 아래 명령으로 수정 버전으로 올리세요.
# pom.xml: bump <version>4.2.2</version> for org.apache.cxf:cxf-integration-jca 상세
A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code execution, if an attacker is able to manipulate the JCA deployment descriptor (ra.xml) or runtime activation parameters. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Maven / org.apache.cxf:cxf-integration-jca
최초 영향 버전:
4.2.0 수정 버전: 4.2.2 수정
# pom.xml: bump <version>4.2.2</version> for org.apache.cxf:cxf-integration-jca Maven / org.apache.cxf:cxf-integration-jca
최초 영향 버전:
0 수정 버전: 4.1.7 수정
# pom.xml: bump <version>4.1.7</version> for org.apache.cxf:cxf-integration-jca 참고
- https://nvd.nist.gov/vuln/detail/CVE-2026-50633 [ADVISORY]
- https://access.redhat.com/errata/RHSA-2026:37390 [WEB]
- https://access.redhat.com/security/cve/CVE-2026-50633 [WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2488307 [WEB]
- https://github.com/apache/cxf [PACKAGE]
- https://lists.apache.org/thread/1czhgovkgzdkyp3t61wthn0foogh2grf [WEB]
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50633.json [WEB]
- http://www.openwall.com/lists/oss-security/2026/06/11/10 [WEB]