CVE-2022-42920: Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing
An out-of-bounds (OOB) write flaw was found in Apache Commons BCEL API. This flaw can be used to produce arbitrary bytecode and may abuse applications that pass attacker-controlled data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected.
Other sources
Apache Commons BCEL could allow a remote attacker to bypass security restrictions, caused by an out-of-bounds write flaw in the APIs. By sending a specially-crafted request, an attacker could exploit this vulnerability to gain control over the resulting bytecode than otherwise expected.
— IBM
Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bcelto a version that resolves this vulnerability.Fixed in 0:5.2-19.el7_9 - Upgrade
Upgrade
redhat/bcelto a version that resolves this vulnerability.Fixed in 0:6.4.1-9.el9_1 - Upgrade
Upgrade
redhat/bcelto a version that resolves this vulnerability.Fixed in 0:6.4.1-9.el9_0 - Upgrade
Upgrade
redhat/rh-maven36-bcelto a version that resolves this vulnerability.Fixed in 0:6.3.1-2.3.el7 - Upgrade
Upgrade
maven/org.apache.bcel:bcelto a version that resolves this vulnerability.Fixed in 6.6.0 - Upgrade
Upgrade
debian/bcelto a version that resolves this vulnerability.Fixed in 6.5.0-1+deb11u1Fixed in 6.5.0-2Fixed in 6.10.0-1 - Upgrade
Upgrade
redhat/Apache Commons BCELto a version that resolves this vulnerability.Fixed in 6.6.0 - Upgrade
Upgrade
Apache Commons BCELto a version that resolves this vulnerability.Fixed in 6.6.0
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-42920?
CVE-2022-42920 is an out-of-bounds (OOB) write flaw found in Apache Commons BCEL API.
How can CVE-2022-42920 be exploited?
CVE-2022-42920 can be exploited by passing attacker-controllable data to the affected APIs in Apache Commons BCEL.
What is the severity of CVE-2022-42920?
CVE-2022-42920 has a severity rating of 9.8 out of 10, which is classified as critical.
Which software versions are affected by CVE-2022-42920?
Apache Commons BCEL versions up to exclusive 6.6.0, bcel versions up to exclusive 0:5.2-19.el7_9, bcel versions up to exclusive 0:6.4.1-9.el9_1, bcel versions up to exclusive 0:6.4.1-9.el9_0, and rh-maven36-bcel versions up to exclusive 0:6.3.1-2.3.el7 are affected by CVE-2022-42920.
How do I mitigate CVE-2022-42920?
To mitigate CVE-2022-42920, it is recommended to update to Apache Commons BCEL version 6.6.0.