CVE-2025-12383: Race Condition allows Bypass of Trust Restrictions
In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12383?
CVE-2025-12383 has a medium severity rating due to its potential to compromise critical SSL configurations.
How do I fix CVE-2025-12383?
To fix CVE-2025-12383, upgrade Eclipse Jersey to a version later than 3.1.9.
What versions of Eclipse Jersey are affected by CVE-2025-12383?
CVE-2025-12383 affects Eclipse Jersey versions 2.45, 3.0.16, and 3.1.9.
What kind of issues does CVE-2025-12383 cause?
CVE-2025-12383 can lead to SSLHandshakeException due to the race condition in handling SSL configurations.
What security settings are ignored because of CVE-2025-12383?
CVE-2025-12383 can cause the ignoring of critical SSL settings such as mutual authentication and custom key/trust stores.