REDHAT-BUG-2480729: High severity Apache Apache CXF vulnerability
The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead to code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.1.6 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 3.6.11
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2480729?
The severity of REDHAT-BUG-2480729 is rated as high with a score of 7.
How do I fix REDHAT-BUG-2480729?
To fix REDHAT-BUG-2480729, users should upgrade to Apache CXF versions 4.2.1 or later.
What is the main issue described in REDHAT-BUG-2480729?
REDHAT-BUG-2480729 describes a vulnerability where incomplete fixes for CVE-2025-48913 allow untrusted users to configure JMS, potentially leading to remote code execution.
What software is affected by REDHAT-BUG-2480729?
REDHAT-BUG-2480729 affects Apache CXF software.
When was REDHAT-BUG-2480729 published?
REDHAT-BUG-2480729 was published on May 22, 2026.