Arbitrary remote code execution with InvokerTransformer
Bug #1514985 reported by
Steve Beattie
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libcommons-collections3-java (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned | ||
libcommons-collections4-java (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
Upstream bug report: https:/
With InvokerTransformer serializable collections can be build that execute arbitrary Java code. sun.reflect.
https:/
[No CVE has been assigned for this yet]
Status changed to 'Confirmed' because the bug affects multiple users.