Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-42920

Опубликовано: 04 нояб. 2022
Источник: redhat
CVSS3: 8.1

Описание

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

An out-of-bounds (OOB) write flaw was found in Apache Commons BCEL API. This flaw can be used to produce arbitrary bytecode and may abuse applications that pass attacker-controlled data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected.

Отчет

Fuse 7 ships the code in question but does not utilize it in the product, so it is affected at a reduced impact of Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6org.jboss.windup-windup-cli-parentAffected
Migration Toolkit for Runtimesorg.jboss.windup.plugin-windup-maven-pluginAffected
Migration Toolkit for Runtimesorg.jboss.windup.plugin-windup-maven-plugin-parentAffected
Migration Toolkit for Runtimesorg.jboss.windup.rules-windup-rulesetsAffected
Migration Toolkit for Runtimesorg.jboss.windup.rules-windup-rulesets-parentAffected
Migration Toolkit for Runtimesorg.jboss.windup.web-windup-web-parentAffected
Migration Toolkit for Runtimesorg.jboss.windup-windup-cli-parentAffected
Red Hat Data Grid 8apache-bcelNot affected
Red Hat Integration Camel K 1apache-bcelNot affected
Red Hat JBoss Data Grid 7apache-bcelOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2142707Apache-Commons-BCEL: arbitrary bytecode produced via out-of-bounds writing

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 9.8
nvd
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

CVSS3: 9.8
debian
больше 2 лет назад

Apache Commons BCEL has a number of APIs that would normally only allo ...

suse-cvrf
больше 2 лет назад

Security update for bcel

suse-cvrf
больше 2 лет назад

Security update for bcel

8.1 High

CVSS3