REDHAT-BUG-2488304: High severity Apache Apache CXF vulnerability
A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.2.2 - Upgrade
Upgrade
Apache CXFto a version that resolves this vulnerability.Fixed in 4.1.7
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2488304?
The severity of REDHAT-BUG-2488304 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2488304?
To fix REDHAT-BUG-2488304, upgrade to the latest versions of Apache CXF as recommended.
What is the main risk associated with REDHAT-BUG-2488304?
The main risk associated with REDHAT-BUG-2488304 is potential remote code execution if untrusted users can configure JMS.
Does REDHAT-BUG-2488304 relate to any previous vulnerabilities?
Yes, REDHAT-BUG-2488304 is related to a further incomplete fix for CVE-2026-44417.
What impact does REDHAT-BUG-2488304 have on Apache CXF?
REDHAT-BUG-2488304 allows code execution capabilities in Apache CXF when untrusted users have JMS configuration access.