-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: rh-maven35-apache-commons-collections4 security update
Advisory ID:       RHSA-2020:4274-01
Product:           Red Hat Software Collections
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:4274
Issue date:        2020-10-19
CVE Names:         CVE-2015-7501 
====================================================================
1. Summary:

An update for rh-maven35-apache-commons-collections4 is now available for
Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch

3. Description:

The Apache Commons Collections library provides new interfaces,
implementations, and utilities to extend the features of the Java
Collections Framework.

Security Fix(es):

* apache-commons-collections: InvokerTransformer code execution during
deserialisation (CVE-2015-7501)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1279330 - CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation

6. Package List:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm
rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm
rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):

Source:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm
rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):

Source:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm
rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):

Source:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm
rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2015-7501
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/solutions/2045023

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBX41gLtzjgjWX9erEAQiYHxAAicNOJdc7Ia9Gw/XgGzq94NGys714dgYF
RlbIOsCAquAbes42AO/odyOWpiM7JO7LzLA5ZB0Txh7C79qf8eQtc5UrpoNhBq08
9wA+TuaCSXjk+JWPYyv5eS/ubZX80ORKeggRP3GZF3AHrPDC3VmHtPFnRrSm4rc7
BBQ4A4MbNKmVwKSHPIEGw4uOWEaamgg5iU58186G1CFO5bbSyN0g6+xRaxJSdPnn
AD0CEoPsaxWvq8DYT326SZUBvXwG3P2QKHxAWLXdHNpuBSPX7rtexFa3LRnXXloU
KKGYsInOJgB7gv8Yut5O52Wx+aGEzRUw7/m8+t+mFdCJloBgXCH07ErmVXaAF4dI
RxSJvnfToN+pS5J4sMNaU0lPIF+1iaM9NYLRBRmeOLPDc0fgMNzpsxYhfIfquv2r
QFDRVHXfFubG1PsCOmb865sDehG5rTMPJNiUXFTaPsVX2hAFU0mi++oQdhssrniy
FY3e7Zr0WB7zLWf/NsGYahnJE/PR1L4e3e1wK31DXPt0dixMGZ2SQzI2ycvskeEk
F3YyO0zWD2Crt7uLgy0xzyUJhlZVBbA41z4GJm/4ncUgXtScZXjpSMClc/wTU06j
IuMhYBx019XoiMGjFq/FVL6PJoounta1YPe5/MJiIDtIUdYOql/SpyO3vTkwDXp7
8GnR2rs5F/Y=+Jvx
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-4274:01 Important: rh-maven35-apache-commons-collections4

An update for rh-maven35-apache-commons-collections4 is now available for Red Hat Software Collections

Summary

The Apache Commons Collections library provides new interfaces, implementations, and utilities to extend the features of the Java Collections Framework.
Security Fix(es):
* apache-commons-collections: InvokerTransformer code execution during deserialisation (CVE-2015-7501)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2015-7501 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/solutions/2045023

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm
noarch: rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm
noarch: rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):
Source: rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm
noarch: rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):
Source: rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm
noarch: rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-maven35-apache-commons-collections4-4.0-7.3.el7.src.rpm
noarch: rh-maven35-apache-commons-collections4-4.0-7.3.el7.noarch.rpm rh-maven35-apache-commons-collections4-javadoc-4.0-7.3.el7.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:4274-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2020:4274
Issued Date: : 2020-10-19
CVE Names: CVE-2015-7501

Topic

An update for rh-maven35-apache-commons-collections4 is now available forRed Hat Software Collections.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch


Bugs Fixed

1279330 - CVE-2015-7501 apache-commons-collections: InvokerTransformer code execution during deserialisation


Related News