]
Nick Boldt commented on JBDS-3560:
----------------------------------
I checked a couple of the plugins[1],[2] (didn't see any features) that depend on
a.commons.collections and they only state a dependency on 3.2.0+ in their manifests. So if
our TP includes 3.2.2 instead of 3.2.0, that should be installed instead.
[1] o.apache.velocity 1.5.0
[2] o.j.t.hibernate.runtime 3 5 or 3 6
Arbitrary remote code execution with InvokerTransformer
(COLLECTIONS-580)
-------------------------------------------------------------------------
Key: JBDS-3560
URL:
https://issues.jboss.org/browse/JBDS-3560
Project: Developer Studio (JBoss Developer Studio)
Issue Type: Bug
Components: upstream
Affects Versions: 8.1.0.GA, 9.0.0.GA, 10.0.0.Alpha1
Reporter: Nick Boldt
Assignee: Max Rydahl Andersen
Fix For: 9.1.0.Beta1, 10.0.0.Alpha1
Attachments: apache-commons-collections-in-JBDS7,8,9,10.png,
apache-commons-collections-in-JBDS7,8,9,10_refs1.png,
apache-commons-collections-in-JBDS7,8,9,10_refs10.png,
apache-commons-collections-in-JBDS7,8,9,10_refs7.png,
apache-commons-collections-in-JBDS7,8,9,10_refs8-IS-fuse.png,
apache-commons-collections-in-JBDS7,8,9,10_refs8.png,
apache-commons-collections-in-JBDS7,8,9,10_refs9.png,
orbit.R20150519210750_vs_I20151117200049.log.txt,
orbit.R20150519210750_vs_I20151117200049.log_onlyLatest.txt
This is a container issue to wrap & track
https://issues.apache.org/jira/browse/COLLECTIONS-580
Problem is that JBDS 9 (and probably 8 and 10 too) include
org.apache.commons.collections 3.2.0.v2013030210310, which is affected by COLLECTIONS-580
- Arbitrary remote code execution with InvokerTransformer