Skip to content

Upgrade Apache Commons Collections to v3.2.2 - #151

Closed
jart wants to merge 1 commit into
apache:masterfrom
jart:patch-1
Closed

Upgrade Apache Commons Collections to v3.2.2#151
jart wants to merge 1 commit into
apache:masterfrom
jart:patch-1

Conversation

@jart

@jartjart commented Mar 5, 2016

Copy link
Copy Markdown

Version 3.2.1 has a CVSS 10.0 vulnerability. That's the worst kind of
vulnerability that exists. By merely existing on the classpath, this
library causes the Java serialization parser for the entire JVM process
to go from being a state machine to a turing machine. A turing machine
with an exec() function!

https://commons.apache.org/proper/commons-collections/security-reports.html
http://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/

Also, do consider using Guava in the future.

Version 3.2.1 has a CVSS 10.0 vulnerability. That's the worst kind of
vulnerability that exists. By merely existing on the classpath, this
library causes the Java serialization parser for the entire JVM process
to go from being a state machine to a turing machine. A turing machine
with an exec() function!
https://commons.apache.org/proper/commons-collections/security-reports.htmlhttp://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/
@JamesRTaylor

Copy link
Copy Markdown
Contributor

Thanks for the patch, @jart. I've filed PHOENIX-2749 for this.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jart@JamesRTaylor