mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by wh…
严重 CVSS 9.8
摘要
mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an attacker can provoke an application to read a maliciously crafted `jaxax.naming.Reference` or serialized object, they can provoke the download and execution of malicious code. Implementations of this functionality within the …
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/swaldman/mchange-commons-java/security/advisories/GHSA-m2cm-222f-qw44 Patch
- https://mogwailabs.de/en/blog/2025/02/c3p0-you-little-rascal Exploit
- https://www.mchange.com/projects/c3p0/#configuring_security Issue Tracking
- https://www.mchange.com/projects/c3p0/#security-note Release Notes
- https://access.redhat.com/errata/RHSA-2026:14873
- https://access.redhat.com/errata/RHSA-2026:14874
- https://access.redhat.com/errata/RHSA-2026:18054
- https://access.redhat.com/errata/RHSA-2026:18055
- https://access.redhat.com/errata/RHSA-2026:18059
- https://access.redhat.com/errata/RHSA-2026:34365
- https://access.redhat.com/errata/RHSA-2026:3890
- https://access.redhat.com/errata/RHSA-2026:4285
- https://access.redhat.com/security/cve/CVE-2026-27727
- https://bugzilla.redhat.com/show_bug.cgi?id=2442671
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27727.json
时间线
- nvd_ingest NVD