Uploaded image for project: 'Nuxeo Platform'
  1. Nuxeo Platform
  2. NXP-18385

Upgrade to commons-collections 3.2.2

    XMLWordPrintable

    Details

      Description

      The Apache Commons Collections contains Serializable classes that make it possible for a process doing unserialization without being careful to be vulnerable to user-submitted input.

      -> Upgrade to commons-collections 3.2.2 which fixes the issue.

      See COLLECTIONS-580 and http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/ for more.

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: