REDHAT-BUG-2387221: High severity Apache CXF vulnerability
If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility.
Users are recommended to upgrade to versions 3.6.8, 4.0.9 or 4.1.3, which fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2387221?
The vulnerability REDHAT-BUG-2387221 has been identified as critical due to the potential for code execution.
How do I fix REDHAT-BUG-2387221?
To resolve REDHAT-BUG-2387221, users should upgrade to Apache CXF versions 3.6.8 or later.
Who is affected by REDHAT-BUG-2387221?
Users of Apache CXF versions prior to 3.6.8, 4.0.9, and 4.1.3 are affected by REDHAT-BUG-2387221.
What causes the vulnerability in REDHAT-BUG-2387221?
The vulnerability in REDHAT-BUG-2387221 is caused by untrusted users being allowed to configure JMS using insecure RMI or LDAP protocols.
What measures have been implemented to mitigate REDHAT-BUG-2387221?
The mitigation for REDHAT-BUG-2387221 includes restricting the JMS configuration interface to reject insecure RMI and LDAP protocols.