GHSA-6hgm-866r-3cjv

Suggest an improvement
Source
https://github.com/advisories/GHSA-6hgm-866r-3cjv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/06/GHSA-6hgm-866r-3cjv/GHSA-6hgm-866r-3cjv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6hgm-866r-3cjv
Aliases
  • CVE-2015-6420
Published
2020-06-15T20:36:20Z
Modified
2024-11-28T05:40:45.267146Z
Summary
Insecure Deserialization in Apache Commons Collection
Details

Serialized-object interfaces in Java applications using the Apache Commons Collections (ACC) library may allow remote attackers to execute arbitrary commands via a crafted serialized Java object.

Database specific
{
    "nvd_published_at": "2015-12-15T05:59:00Z",
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-11T15:58:44Z"
}
References

Affected packages

Maven / org.apache.commons:commons-collections4

Package

Name
org.apache.commons:commons-collections4
View open source insights on deps.dev
Purl
pkg:maven/org.apache.commons/commons-collections4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1

Affected versions

4.*

4.0

Maven / commons-collections:commons-collections

Package

Name
commons-collections:commons-collections
View open source insights on deps.dev
Purl
pkg:maven/commons-collections/commons-collections

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.2

Affected versions

1.*

1.0

2.*

2.0
2.0.20020914.015953
2.0.20020914.020746
2.0.20020914.020858
2.1
2.1.1

3.*

3.0
3.0-dev2
3.1
3.2
3.2.1

Maven / net.sourceforge.collections:collections-generic

Package

Name
net.sourceforge.collections:collections-generic
View open source insights on deps.dev
Purl
pkg:maven/net.sourceforge.collections/collections-generic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.0.1

Maven / org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-generic

Package

Name
org.apache.servicemix.bundles:org.apache.servicemix.bundles.collections-generic
View open source insights on deps.dev
Purl
pkg:maven/org.apache.servicemix.bundles/org.apache.servicemix.bundles.collections-generic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.01

Maven / org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collections

Package

Name
org.apache.servicemix.bundles:org.apache.servicemix.bundles.commons-collections
View open source insights on deps.dev
Purl
pkg:maven/org.apache.servicemix.bundles/org.apache.servicemix.bundles.commons-collections

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
3.2.1