CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48913?
CVE-2025-48913 is a moderate severity vulnerability due to the potential for code execution through misconfigured JMS in Apache CXF.
How do I fix CVE-2025-48913?
To fix CVE-2025-48913, users should upgrade their Apache CXF installations to version 3.6.9 or later, or 4.0.10 or later.
What software is affected by CVE-2025-48913?
CVE-2025-48913 affects Apache CXF versions up to 3.6.8, 4.0.9, and 4.1.3.
What type of attack is possible due to CVE-2025-48913?
CVE-2025-48913 could allow untrusted users to exploit unsanctioned RMI or LDAP URLs for remote code execution.
What measures are taken in response to CVE-2025-48913?
In response to CVE-2025-48913, the interface has been updated to restrict untrusted configurations and reject RMI and LDAP protocols.