CVE-2015-6420
Insecure Deserialization in Apache Commons Collection
EPSS 18.8%
描述
Serialized-object interfaces in Java applications using the Apache Commons Collections (ACC) library may allow remote attackers to execute arbitrary commands via a crafted serialized Java object.
如何修補 CVE-2015-6420
要修補 CVE-2015-6420,請將受影響套件升級到下列已修補版本。
- Maven/commons-collections:commons-collections—升級至 3.2.2 或更新版本
- Maven/net.sourceforge.collections:collections-generic—未列出修補版本
- Maven/org.apache.commons:commons-collections4—升級至 4.1 或更新版本
- —未列出修補版本
- —未列出修補版本
CVE-2015-6420 正在被利用嗎?
中等 — EPSS 為 18.8%,可持續追蹤但非最高優先。
受影響套件(5)
- from 0, < 3.2.2
- from 0, <= 4.0.1
- from 0, < 4.1
- from 0, <= 4.01
- from 0, <= 3.2.1