Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97xg-phpr-rg8q

Опубликовано: 07 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Apache Commons BCEL vulnerable to out-of-bounds write

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

Пакеты

Наименование

org.apache.bcel:bcel

maven
Затронутые версииВерсия исправления

< 6.6.0

6.6.0

EPSS

Процентиль: 88%
0.03792
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 8.1
redhat
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 9.8
nvd
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 9.8
debian
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allo ...

suse-cvrf
больше 2 лет назад

Security update for bcel

EPSS

Процентиль: 88%
0.03792
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-787