/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-xv24-h679-93r5

Published

Last updated

https://images.chainguard.dev/security/CGA-xv24-h679-93r5
Package

hadoop-fips-3.3.6

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2022-42920
  • GHSA-97xg-phpr-rg8q

Severity

Unknown

Summary

Apache Commons BCEL vulnerable to out-of-bounds write

Description

Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs