veracode-repository-ruleset / verademo-java-maven

verademo-java-maven
0 stars 0 forks source link

CVE: 2015-6420 found in Apache Commons Collections - Version: 4.0 [JAVA] #7

Open github-actions[bot] opened 7 months ago

github-actions[bot] commented 7 months ago

Veracode Software Composition Analysis

Attribute Details
Library Apache Commons Collections
Description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.
Language JAVA
Vulnerability Arbitrary Code Execution
Vulnerability description Apache Commons Collections (ACC) library is vulnerable to Arbitrary Code Execution. The vulnerability is possible because it directly uses ACC, or contains ACC, in the classpath, which allows an attacker to gain read access to unnecessary information in debug messages by sending modified requests.
CVE 2015-6420
CVSS score 7.5
Vulnerability present in version/s 4.0-4.0
Found library version/s 4.0
Vulnerability fixed in version 4.1
Library latest version 4.4
Fix

Links:

github-actions[bot] commented 4 months ago

Veracode issue link to PR: https://github.com/veracode-repository-ruleset/verademo-java-maven/pull/54