GHSA-7p63-w6x9-6gr7
CRITICALCVE-2025-12383In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)
- Affected
- = 2.45
- Fixed in
- 2.46
- Weakness
- CWE-296
- Published
- 2025-11-18
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference