Lucene search

K
githubGitHub Advisory DatabaseGHSA-FJQ5-5J5F-MVXH
HistoryMay 13, 2022 - 1:25 a.m.

Deserialization of Untrusted Data in Apache commons collections

2022-05-1301:25:20
CWE-502
GitHub Advisory Database
github.com
155

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.018 Low

EPSS

Percentile

88.4%

It was found that the Apache commons-collections library permitted code execution when deserializing objects involving a specially constructed chain of classes. A remote attacker could use this flaw to execute arbitrary code with the permissions of the application using the commons-collections library.

Affected configurations

Vulners
Node
org.apache.servicemix.bundles\org.apache.servicemix.bundles.collectionsMatchgeneric
OR
net.sourceforge.collections\collectionsMatchgeneric4.01
OR
org.apache.servicemix.bundles\org.apache.servicemix.bundles.commonsMatchcollections
OR
org.apache.commons\commonsMatchcollections4
OR
apachecommons_collectionsRange<3.2.2

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.018 Low

EPSS

Percentile

88.4%