[jbosstools-issues] [JBoss JIRA] (JBDS-3560) Arbitrary remote code execution with InvokerTransformer (COLLECTIONS-580)

Nick Boldt (JIRA) issues at jboss.org
Mon Nov 16 16:50:00 EST 2015


Nick Boldt created JBDS-3560:
--------------------------------

             Summary: Arbitrary remote code execution with InvokerTransformer (COLLECTIONS-580)
                 Key: JBDS-3560
                 URL: https://issues.jboss.org/browse/JBDS-3560
             Project: Developer Studio (JBoss Developer Studio)
          Issue Type: Bug
          Components: server, upstream
    Affects Versions: 9.0.0.GA, 8.1.0.GA, 10.0.0.Alpha1
            Reporter: Nick Boldt
            Assignee: Max Rydahl Andersen


This is a container issue to wrap & track https://issues.apache.org/jira/browse/COLLECTIONS-580

Problem is that JBDS 9 (and probably 8 and 10 too) include org.apache.commons.collections	3.2.0.v2013030210310, which is affected by COLLECTIONS-580 - Arbitrary remote code execution with InvokerTransformer



--
This message was sent by Atlassian JIRA
(v6.4.11#64026)


More information about the jbosstools-issues mailing list