org.apache.commons:commons-dbcp2@2.6.0 vulnerabilities

  • latest version

    2.13.0

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    8 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.commons:commons-dbcp2 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Information Exposure

    org.apache.commons:commons-dbcp2 is a software that implements Database Connection Pooling

    Affected versions of this package are vulnerable to Information Exposure. If a BasicDataSource is created with jmxName set, the password property is exposed via jmx and is visible to anyone who is connected to jmx port.

    How to fix Information Exposure?

    Upgrade org.apache.commons:commons-dbcp2 to version 2.9.0 or higher.

    [0,2.9.0)