org.apache.commons:commons-dbcp2@2.3.0 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.apache.commons:commons-dbcp2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Information Exposure

org.apache.commons:commons-dbcp2 is a software that implements Database Connection Pooling

Affected versions of this package are vulnerable to Information Exposure. If a BasicDataSource is created with jmxName set, the password property is exposed via jmx and is visible to anyone who is connected to jmx port.

How to fix Information Exposure?

Upgrade org.apache.commons:commons-dbcp2 to version 2.9.0 or higher.

[0,2.9.0)