Skip to content

Does Spring Framework use InvokerTransformer from Apache Collections? [SPR-13675] #18250

Closed
@spring-projects-issues

Description

@spring-projects-issues

Kamill Sokol opened SPR-13675 and commented

Yesterday announced about de-serialisation vulnerability (CVE-2015-4852):

https://blogs.apache.org/foundation/entry/apache_commons_statement_to_widespread

If Spring Framework use InvokerTransformer it can be vulnerable for the de-serialisation vulnerability (CVE-2015-4852).

Does Spring Framework use InvokerTransformer from Apache Commons Collection?


Reference URL: http://www.oracle.com/technetwork/topics/security/alert-cve-2015-4852-2763333.html

Issue Links:

Metadata

Metadata

Assignees

Labels

status: invalidAn issue that we don't feel is valid

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions