Skip to content

Blackduck: Automated PR: Update commons-collections:commons-collections:3.1 to 3.2.2 - #5

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
BD-PR-commons-collections_3.1_commons-collections-1743703433
Open

Blackduck: Automated PR: Update commons-collections:commons-collections:3.1 to 3.2.2#5
github-actions[bot] wants to merge 1 commit into
mainfrom
BD-PR-commons-collections_3.1_commons-collections-1743703433

Conversation

@github-actions

@github-actions github-actions Bot commented Apr 3, 2025

Copy link
Copy Markdown

Vulnerabilities associated with commons-collections:commons-collections:3.1

BDSA-2015-0753 (CRITICAL): The apache commons collection (ACC) library, when utilized in an application that deserializes untrusted user input, is vulnerable to a remote attacker executing arbitrary code.

BDSA-2015-0001 (HIGH): Apache Commons Collections has a security flaw in the InvokeTransformer class whereby serializable collections can be built that execute arbitrary Java code. An attacker can achieve remote code execution (RCE) when untrusted user-provided objects are deserialized by applications that use Commons Collections.

BDSA-2015-0766 (HIGH): Apache Commons Collection is vulnerable to remote code execution (RCE) due to the unsafe handling of in-memory data structures. A remote attacker could execute arbitrary code on the underlying system by submitting crafted data packets to a vulnerable server.

BDSA-2017-2285 (HIGH): Apache Common Collections and Apache Synapse contain a vulnerability that allows for remote code execution (RCE) via crafted specialized objects. Failed attempts will cause a denial of service (DoS) attack.

Click Here To See More Details On Server

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants