Uploaded image for project: 'TomEE'
  1. TomEE
  2. TOMEE-4111

Upgrade bcel component in TomEE

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 9.0.0.RC1, 8.0.13
    • 8.0.14, 9.0.0
    • TomEE Core Server

    Description

      Vulnerability Details
      CVE-2022-42920

      Affected Component(s): Apache Commons BCEL, commons-bcel
      Vulnerability Published: 2022-11-07 08:15 EST
      Vulnerability Updated: 2022-11-07 23:20 EST
      CVSS Score: 9.8 (overall), 9.8 (base)

      Summary: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

      Solution: N/A

      Workaround: N/A

      Attachments

        1. tomee-8.x.txt
          983 kB
          Richard Zowalla

        Activity

          People

            rzo1 Richard Zowalla
            somasaninikhil Nikhil
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 40m
                40m