Closed nidhi0512 closed 2 years ago
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Issue still exists.
Description
The framework Apache Commons Collections before 4.3 is vulnerable to Stack Overflow. The function
add()
in the filesrc/main/java/org/apache/commons/collections4/list/SetUniqueList.java
throws a StackOverflowError when theadd()
method is called with its own list. To resolve this issue - upgrade to version 4.3. Please note: the package name was changed to org.apache.commons:commons-collections4 on version 4.0.HIGH Vulnerable Package issue exists @ commons-collections:commons-collections in branch master
Vulnerability ID: Cx78f40514-81ff
Package Name: commons-collections:commons-collections
Severity: HIGH
CVSS Score: 7.5
Publish Date: 2018-10-31T10:39:00
Current Package Version: 3.2.1
Remediation Upgrade Recommendation:
Link To SCA