Apache Commons 中存在符号名称无法正确映射到对应对象的漏洞。 BCEL(字节码工程库)会将由攻击者控制的类以其自我声明的名称进行缓存,而不会验证所请求的名称是否合法。这导致后续的名称查找以及基于名称的验证结果可能指向不同的类。 该漏洞影响 Apache Commons 的 6.13.0 之前版本。 建议用户升级至 6.13.0 版本,该版本已修复此问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Commons BCEL | < 6.13.0 |
affected |
< 14890bf2b9014df25f9b4de86f29b5e917e5656b |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Commons BCEL | 0 ~ 6.13.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105244 | 5.3 MEDIUM | Apache log4net: RemoteSyslogAppender silently deletes non-ASCII content |
| CVE-2026-105243 | 5.3 MEDIUM | Apache log4net: Oversize EventLogAppender record silently discarded |
| CVE-2026-105242 | 5.3 MEDIUM | Apache log4net: Request validation failure drops the event in the aspnet-request converter |
| CVE-2026-105241 | 5.3 MEDIUM | Apache log4net: Unencodable content discards a whole SmtpPickupDirAppender batch |
| CVE-2026-105240 | 5.3 MEDIUM | Apache log4net: NUL character truncates OutputDebugStringAppender records |
| CVE-2026-105239 | 5.3 MEDIUM | Apache log4net: NUL character truncates EventLogAppender records |
| CVE-2026-105111 | 4.7 MEDIUM | Apache Commons BCEL: Class2HTML emits unescaped class strings, enabling stored XSS |
No comments yet