Deserialization of Untrusted Data in Apache commons collections
Critical severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Nov 2, 2023
Package
Affected versions
< 3.2.2
Patched versions
3.2.2
>= 4.01, < 4.02
None
>= 3.2.1, < 3.2.2
None
Description
Published by the National Vulnerability Database
Nov 9, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Nov 3, 2022
Last updated
Nov 2, 2023
It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.
References