Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-48924

Опубликовано: 11 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.3

Описание

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

РелизСтатусПримечание
devel

not-affected

2.6-12
esm-apps-legacy/xenial

released

2.6-6ubuntu2+esm1
esm-apps/bionic

released

2.6-8ubuntu0.1~esm1
esm-apps/focal

released

2.6-9ubuntu0.20.04.1~esm1
esm-apps/jammy

released

2.6-9ubuntu0.22.04.1
esm-apps/noble

released

2.6-10ubuntu0.1
esm-apps/resolute

not-affected

2.6-12
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

released

2.6-3ubuntu2+esm1
jammy

released

2.6-9ubuntu0.22.04.1

Показывать по

РелизСтатусПримечание
devel

not-affected

3.17.0-2
esm-apps-legacy/xenial

released

3.4-1ubuntu0.1~esm1
esm-apps/bionic

released

3.8-1~18.04.2+esm1
esm-apps/focal

released

3.8-2ubuntu0.1~esm1
esm-apps/jammy

released

3.11-1ubuntu0.1
esm-apps/noble

released

3.14.0-1ubuntu0.1~esm1
esm-apps/resolute

not-affected

3.17.0-2
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

released

3.2.1-1ubuntu0.1~esm1
jammy

released

3.11-1ubuntu0.1

Показывать по

EPSS

Процентиль: 80%
0.02164
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
около 1 года назад

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

CVSS3: 5.3
nvd
около 1 года назад

Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

CVSS3: 5.3
msrc
11 месяцев назад

Apache Commons Lang, Apache Commons Lang: ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs

CVSS3: 5.3
debian
около 1 года назад

Uncontrolled Recursion vulnerability in Apache Commons Lang. This iss ...

suse-cvrf
6 дней назад

Security update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn

EPSS

Процентиль: 80%
0.02164
Низкий

5.3 Medium

CVSS3