CVE-2025-12383 is a race condition vulnerability in Eclipse Jersey versions 2.45, 3.0.16, and 3.1.9 that can lead to critical SSL configurations, such as mutual authentication and custom key/trust stores, being ignored. This high-severity vulnerability (CVSS 7.4) could result in unauthorized trust in insecure servers under specific conditions, despite normally causing an SSLHandshakeException. The attack complexity is high, but it requires no user interaction or privileges, potentially leading to high confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.45CPE matchmatch criteria | cpe:2.3:a:eclipse:jersey:2.45:*:*:*:*:*:*:* | ||
3.0.16CPE matchmatch criteria | cpe:2.3:a:eclipse:jersey:3.0.16:*:*:*:*:*:*:* | ||
3.1.9CPE matchmatch criteria | cpe:2.3:a:eclipse:jersey:3.1.9:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.