Upgrade jersey libraries to address CVE-2025-12383#21395
Upgrade jersey libraries to address CVE-2025-12383#21395tengu-alt wants to merge 1 commit intoapache:3.9from
Conversation
|
@FrankYang0529 Could you please take a look or ping someone to review this? |
|
@tengu-alt Thanks for the fix. We will take a look to check whether to include this in 3.9.2. |
|
The CVE is regarding eclipse-ee4j/jersey#5749, and the patch was NOT merged into @tengu-alt @FrankYang0529 WDYT? |
| javassist: "3.29.2-GA", | ||
| jetty: "9.4.57.v20241219", | ||
| jersey: "2.39.1", | ||
| jersey: "2.46", |
There was a problem hiding this comment.
Curious why 2.46 and not 2.47 when that's the latest released 2.x version?
|
@chia7712 https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/253 mentions a reproducer for the CVE is at https://github.com/dtbaum/jerseyCveCandidate. I was able to reproduce it with |
|
@gaurav-narula thanks for the verification. I'm wondering whether it is the same issue, since PRs mentioned by the CVE is unrelated to 2.39.1 |
I'm fairly certain it's the same issue as the PoC is asserting the same CVE and it's reproducible in 2.39.1. Here's the trail I could find:
|
|
@gaurav-narula thanks for the info @FrankYang0529 it seems we need to cut another RC |
|
Does this mean that the CVE data is just wrong? I ask because CVE-2025-12383 only references 2.45, 3.0.16, 3.1.9 |
This PR upgrades
jerseylibraries family from 2.39.1 to 2.46 to address CVE-2025-12383Note: while 2.39.1 is not listed as vulnerable - security scanners still may alert it as vulnerable