In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)
Metrics
Affected Vendors & Products
References
History
Tue, 18 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC) | |
| Title | Race Condition allows Bypass of Trust Restrictions | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published: 2025-11-18T15:14:37.765Z
Updated: 2025-11-18T21:34:35.027Z
Reserved: 2025-10-28T10:21:45.989Z
Link: CVE-2025-12383
Updated: 2025-11-18T21:34:32.273Z
Status : Awaiting Analysis
Published: 2025-11-18T16:15:42.867
Modified: 2025-11-19T19:14:59.327
Link: CVE-2025-12383
No data.