Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1manE1LTVqNWYtbXZ4aM4AAQY7

Deserialization of Untrusted Data in Apache commons collections

It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.

Permalink: https://github.com/advisories/GHSA-fjq5-5j5f-mvxh
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1manE1LTVqNWYtbXZ4aM4AAQY7
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 2 years ago
Updated: 6 months ago


CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-fjq5-5j5f-mvxh, CVE-2015-7501
References: Repository: https://github.com/jensdietrich/xshady-release
Blast Radius: 47.0

Affected Packages

maven:org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-generic
Dependent packages: 3
Dependent repositories: 5
Downloads:
Affected Version Ranges: >= 4.01, < 4.02
No known fixed version
All affected versions:
maven:net.sourceforge.collections:collections-generic
Dependent packages: 83
Dependent repositories: 384
Downloads:
Affected Version Ranges: = 4.01
No known fixed version
All affected versions:
maven:org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collections
Dependent packages: 11
Dependent repositories: 45
Downloads:
Affected Version Ranges: >= 3.2.1, < 3.2.2
No known fixed version
All affected versions:
maven:org.apache.commons:commons-collections4
Dependent packages: 3,801
Dependent repositories: 26,825
Downloads:
Affected Version Ranges: < 4.1
Fixed in: 4.1
All affected versions:
All unaffected versions:
maven:commons-collections:commons-collections
Dependent packages: 5,134
Dependent repositories: 63,019
Downloads:
Affected Version Ranges: < 3.2.2
Fixed in: 3.2.2
All affected versions: 2.1.1, 3.2.1
All unaffected versions: 3.2.2