[ 
https://issues.apache.org/jira/browse/HDDS-13529?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Attila Doroszlai updated HDDS-13529:
------------------------------------
    Fix Version/s: 1.4.2

> Upgrade Apache Commons Lang to 3.18.0 due to CVE-2025-48924
> -----------------------------------------------------------
>
>                 Key: HDDS-13529
>                 URL: https://issues.apache.org/jira/browse/HDDS-13529
>             Project: Apache Ozone
>          Issue Type: Task
>            Reporter: Rohit Kumar
>            Assignee: Rohit Kumar
>            Priority: Major
>              Labels: pull-request-available
>             Fix For: 2.1.0, 1.4.2
>
>
> *CVE-2025-48924:*
> Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue 
> affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 
> 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The 
> methods ClassUtils.getClass(...) can throw StackOverflowError on very long 
> inputs. Because an Error is usually not handled by applications and 
> libraries, a StackOverflowError could cause an application to stop. Users are 
> recommended to upgrade to version 3.18.0, which fixes the issue.
> Severity: 8.8 (High)
> [https://nvd.nist.gov/vuln/detail/CVE-2025-48924] 
> [https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-10734078] 
> https://github.com/advisories/GHSA-j288-q9x7-2f5v



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to