Rohit Kumar created HDDS-13529:
----------------------------------
Summary: Upgrade Apache Commons Lang to 3.18.0 due to
CVE-2025-48924
Key: HDDS-13529
URL: https://issues.apache.org/jira/browse/HDDS-13529
Project: Apache Ozone
Issue Type: Task
Reporter: Rohit Kumar
*CVE-2025-48924:*
Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects
Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and,
from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods
ClassUtils.getClass(...) can throw StackOverflowError on very long inputs.
Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop. Users are recommended to
upgrade to version 3.18.0, which fixes the issue.
Severity: 8.8 (High)
[https://nvd.nist.gov/vuln/detail/CVE-2025-48924]
[https://security.snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-10734078]
https://github.com/advisories/GHSA-j288-q9x7-2f5v
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]