Apache Commons BCEL: Remote Code Execution A vulnerability has been discovered in Apache Commons BCEL, which can lead to remote code execution. bcel 2024-05-05 2024-05-05 880447 remote 6.6.0 6.6.0

The Byte Code Engineering Library (Apache Commons BCEL™) is intended to give users a convenient way to analyze, create, and manipulate (binary) Java class files (those ending with .class).

A vulnerability has been discovered in U-Boot tools. Please review the CVE identifier referenced below for details.

Please review the referenced CVE identifier for details.

There is no known workaround at this time.

All Apache Commons BCEL users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-java/bcel-6.6.0"
CVE-2022-34169 CVE-2022-42920 graaff graaff