Threats Tagged 'cve-2025-41249'
View all threats tagged with 'cve-2025-41249'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-41249'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat has issued a security advisory for HawtIO 4.3.0 as part of the Red Hat build of Apache Camel 4 GA Release. This advisory addresses two vulnerabilities: an authorization bypass in spring-security-core (CVE-2025-41248) and an annotation detection vulnerability in spring-core (CVE-2025-41249). The update aims to improve developer experience and ensure security and stability. No explicit patch or fix is detailed in the advisory, but users are advised to apply all previously released errata relevant to their systems. Join the discussion | GCVE Database | 12/04/2025, 15:07:27 UTC Added: 06/28/2026, 22:14:00 UTC |
0 Red Hat build of Apache Camel 4.10.7 for Spring Boot patch release and security update is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * spring-security-core: Spring Security authorization bypass (CVE-2025-41248) * spring-core: Spring Framework Annotation Detection Vulnerability (CVE-2025-41249) * spring-core-test: Spring Framework Annotation Detection Vulnerability (CVE-2025-41249) * org.springframework/spring-core: Spring Framework Annotation Detection Vulnerability (CVE-2025-41249) * org.eclipse.jgit: XXE vulnerability in Eclipse JGit (CVE-2025-4949) * netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2025-58056) * netty-codec-http2: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2025-58056) * minio: minio-java Client XML Tag is Vulnerable to Value Substitution (CVE-2025-59952) * io.minio/minio: minio-java Client XML Tag is Vulnerable to Value Substitution (CVE-2025-59952) Join the discussion | GCVE Database | 10/14/2025, 17:59:03 UTC Added: 06/10/2026, 11:41:49 UTC |
0 The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions. Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature. You are not affected by this if you are not using @EnableMethodSecurity or if you do not use security annotations on methods in generic superclasses or generic interfaces. This CVE is published in conjunction with CVE-2025-41248 https://spring.io/security/cve-2025-41248 . Join the discussion | CVE Database V5 | 09/16/2025, 10:15:34 UTC Added: 09/16/2025, 10:21:31 UTC |
Showing 1 to 3 of 3 results