Repository navigation
[GHSA-93g8-qqv3-mrx8] Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory - #9597
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The summary mischaracterizes the vulnerability, and the affected ranges contain invalid combined versions and incorrect boundaries.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Updates the Apache CXF JNDI injection advisory’s affected versions, description, summary, and references.
Changes:
- Adds Apache CXF 3.6.12 remediation information.
- Revises advisory text and affected ranges.
- Replaces several references with upstream sources.
File summaries
| File | Description |
|---|---|
GHSA-93g8-qqv3-mrx8.json |
Updates advisory metadata, version ranges, and references. |
Review details
Suppressed comments (2)
advisories/github-reviewed/2026/06/GHSA-93g8-qqv3-mrx8/GHSA-93g8-qqv3-mrx8.json:37
- This metadata broadens the first entry to every version below 4.2.2 even though its range starts at 4.2.0. Include the lower bound so downstream range displays do not report older releases as part of this branch.
"last_known_affected_version_range": "< 4.2.2"
advisories/github-reviewed/2026/06/GHSA-93g8-qqv3-mrx8/GHSA-93g8-qqv3-mrx8.json:57
- This comma-separated value is not a valid single
fixedversion, and keepingintroduced: 0would incorrectly mark 3.6.12 through 3.x as affected. Model the CNA's disjoint< 3.6.12and>= 4.0.0, < 4.1.7intervals as separate affected entries, as done for the same three-branch layout inGHSA-ghvc-7hp8-2g2v.json:17-74.
"fixed": "3.6.12, 4.1.7"
}
]
}
],
- Files reviewed: 1/1 changed files
- Comments generated: 3
- Review effort level: Balanced (auto)
Note
Copilot is running an experiment and ran this review at Balanced.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| }, | ||
| { | ||
| "fixed": "4.2.2" | ||
| "fixed": "3.6.12, 4.2.2" |
| ], | ||
| "summary": "Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory", | ||
| "details": "A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.", | ||
| "summary": "Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory - false positive", |
| "summary": "Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory", | ||
| "details": "A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users are recommended to upgrade to versions 4.2.2 or 4.1.7, which fixes this issue.", | ||
| "summary": "Apache CXF has JNDI Injection Vulnerability in JMSConfigFactory - false positive", | ||
| "details": "Change the < 4.1.7 range to >= 4.0.0, < 4.1.7 and add a new < 3.6.12 range with patched version 3.6.12.", |
71a5cef
into
wojciechtrzaski/advisory-improvement-9597
|
Hi @wojciechtrzaski! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Updates
Comments
Please check these links:
https://www.cve.org/CVERecord?id=CVE-2026-50632
apache/cxf@31eb1f90d4