The Apache Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.
Language
JAVA
Vulnerability
Remote Code Execution (RCE) Via Java Object Deserialization
Vulnerability description
commons-io is vulnerable to remote code execution (RCE) attacks. These attacks are possible because the library doesn't restrict the classes which can be accepted when deserializing a binary.
Veracode Software Composition Analysis
Links: