Описание
Recommended update for apache-commons-io
This update for apache-commons-io fixes the following issues:
apache-commons-io was updated from version 2.15.1 to 2.18.0:
-
Key changes across versions:
- Cleaner code and updated dependencies
- Improved security when handling serialized data with the new safe deserialization feature
- New features for advanced file and stream operations
- Various bugs were fixed to improve reliability with fewer crashes and unexpected errors
- For the full list of changes please consult the packaged RELEASE-NOTES.txt
-
Already fixed in previous version:
- CVE-2024-47554: Untrusted input to XmlStreamReader can lead to uncontrolled resource consumption (bsc#1231298)
Список пакетов
Container bci/openjdk-devel:17
apache-commons-io-2.18.0-150200.3.15.1
Container bci/openjdk-devel:latest
apache-commons-io-2.18.0-150200.3.15.1
Container suse/manager/5.0/x86_64/server:latest
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
apache-commons-io-2.18.0-150200.3.15.1
Image server-image
apache-commons-io-2.18.0-150200.3.15.1
SUSE Enterprise Storage 7.1
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server 15 SP3-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server 15 SP4-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server 15 SP5-LTSS
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
apache-commons-io-2.18.0-150200.3.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
apache-commons-io-2.18.0-150200.3.15.1
SUSE Manager Proxy 4.3
apache-commons-io-2.18.0-150200.3.15.1
SUSE Manager Server 4.3
apache-commons-io-2.18.0-150200.3.15.1
openSUSE Leap 15.6
apache-commons-io-2.18.0-150200.3.15.1
apache-commons-io-javadoc-2.18.0-150200.3.15.1
Ссылки
- Link for SUSE-RU-2025:1150-1
- E-Mail link for SUSE-RU-2025:1150-1
- SUSE Security Ratings
- SUSE Bug 1231298
- SUSE CVE CVE-2024-47554 page
Описание
Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.
Затронутые продукты
Container bci/openjdk-devel:17:apache-commons-io-2.18.0-150200.3.15.1
Container bci/openjdk-devel:latest:apache-commons-io-2.18.0-150200.3.15.1
Container suse/manager/5.0/x86_64/server:latest:apache-commons-io-2.18.0-150200.3.15.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:apache-commons-io-2.18.0-150200.3.15.1
Ссылки
- CVE-2024-47554
- SUSE Bug 1231298