oss-sec mailing list archives

Assign CVE for common-collections remote code execution on deserialisation flaw


From: Jason Shepherd <jshepher () redhat com>
Date: Sun, 8 Nov 2015 19:36:20 -0500 (EST)

Hello oss-esc,

It was found that a flaw in Apache commons-collections Java library allowed remote code execution when Deserialised 
with Java Object Serialization. Full details of the vulnerability can be found in this recent blog post, [1]. A 
proposed patch for 3.2.x branch has been submitted upstream, but no release has been made with the fix at the current 
time. The issue affects version 3.x, and 4.x of Apache common-collections, [2].

   [1] 
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
   [2] https://issues.apache.org/jira/browse/COLLECTIONS-580

Regards,
Jason Shepherd
Red Hat Product Security


Current thread: