Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2025:1150-1

Опубликовано: 07 апр. 2025
Источник: suse-cvrf

Описание

Recommended update for apache-commons-io

This update for apache-commons-io fixes the following issues:

apache-commons-io was updated from version 2.15.1 to 2.18.0:

  • Key changes across versions:

    • Cleaner code and updated dependencies
    • Improved security when handling serialized data with the new safe deserialization feature
    • New features for advanced file and stream operations
    • Various bugs were fixed to improve reliability with fewer crashes and unexpected errors
    • For the full list of changes please consult the packaged RELEASE-NOTES.txt
  • Already fixed in previous version:

    • CVE-2024-47554: Untrusted input to XmlStreamReader can lead to uncontrolled resource consumption (bsc#1231298)

Список пакетов

Container bci/openjdk-devel:17
apache-commons-io-2.18.0-150200.3.15.1
Container bci/openjdk-devel:latest
apache-commons-io-2.18.0-150200.3.15.1
Container suse/manager/5.0/x86_64/server:latest
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
apache-commons-io-2.18.0-150200.3.15.1
Image server-image
apache-commons-io-2.18.0-150200.3.15.1
SUSE Enterprise Storage 7.1
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server 15 SP3-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server 15 SP4-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server 15 SP5-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
apache-commons-io-2.18.0-150200.3.15.1
SUSE Manager Proxy 4.3
apache-commons-io-2.18.0-150200.3.15.1
SUSE Manager Server 4.3
apache-commons-io-2.18.0-150200.3.15.1
openSUSE Leap 15.6
apache-commons-io-2.18.0-150200.3.15.1
apache-commons-io-javadoc-2.18.0-150200.3.15.1

Описание

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.


Затронутые продукты
Container bci/openjdk-devel:17:apache-commons-io-2.18.0-150200.3.15.1
Container bci/openjdk-devel:latest:apache-commons-io-2.18.0-150200.3.15.1
Container suse/manager/5.0/x86_64/server:latest:apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:apache-commons-io-2.18.0-150200.3.15.1

Ссылки