]
Nick Boldt edited comment on JBDS-3560 at 1/25/16 1:25 AM:
-----------------------------------------------------------
Upstream dali & wtp issues are resolved now.
contains org.apache.commons.collections_3.2.2.v201511171945.jar (and 3.2.0, too)
contains org.apache.commons.collections_3.2.2.v201511171945.jar (but no 3.2.0)
So... since the fixed version is in both TPs used for JBT 4.3.1.Beta2 / JBDS 9.1.0 Beta2,
I would think we can resolve this for fixversion 9.1.0.Beta2.
Any reason this is set to fixversion 9.1.0.CR1, and unresolved?
Are we waiting for a new m2e release? JBIDE-21119 ?
was (Author: nickboldt):
contains org.apache.commons.collections_3.2.2.v201511171945.jar (and 3.2.0, too)
contains org.apache.commons.collections_3.2.2.v201511171945.jar (but no 3.2.0)
So... since the fixed version is in both TPs used for JBT 4.3.1.Beta2 / JBDS 9.1.0 Beta2,
I would think we can resolve this for fixversion 9.1.0.Beta2.
Any reason this is set to fixversion 9.1.0.CR1, and unresolved?
Arbitrary remote code execution with InvokerTransformer
(COLLECTIONS-580)
-------------------------------------------------------------------------
Key: JBDS-3560
URL:
https://issues.jboss.org/browse/JBDS-3560
Project: Developer Studio (JBoss Developer Studio)
Issue Type: Bug
Components: upstream
Affects Versions: 8.1.0.GA, 9.0.0.GA, 10.0.0.Alpha1
Reporter: Nick Boldt
Assignee: Nick Boldt
Fix For: 9.1.0.CR1, 10.0.0.Alpha1
Attachments: apache-commons-collections-in-JBDS7,8,9,10.png,
apache-commons-collections-in-JBDS7,8,9,10_refs1.png,
apache-commons-collections-in-JBDS7,8,9,10_refs10.png,
apache-commons-collections-in-JBDS7,8,9,10_refs7.png,
apache-commons-collections-in-JBDS7,8,9,10_refs8-IS-fuse.png,
apache-commons-collections-in-JBDS7,8,9,10_refs8.png,
apache-commons-collections-in-JBDS7,8,9,10_refs9.png,
orbit.R20150519210750_vs_I20151117200049.log.txt,
orbit.R20150519210750_vs_I20151117200049.log_onlyLatest.txt
This is a container issue to wrap & track
https://issues.apache.org/jira/browse/COLLECTIONS-580
Problem is that JBDS 9 (and probably 8 and 10 too) include
org.apache.commons.collections 3.2.0.v2013030210310, which is affected by COLLECTIONS-580
- Arbitrary remote code execution with InvokerTransformer