In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC)
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but under certain conditions, it could lead to unauthorized trust in insecure servers (see PoC) | |
| Title | Race Condition allows Bypass of Trust Restrictions | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-11-18T15:14:37.765Z
Reserved: 2025-10-28T10:21:45.989Z
Link: CVE-2025-12383
No data.
Status : Received
Published: 2025-11-18T16:15:42.867
Modified: 2025-11-18T16:15:42.867
Link: CVE-2025-12383
No data.
OpenCVE Enrichment
No data.