<reportApi _class='io.jenkins.plugins.analysis.core.restapi.ReportApi'><issue><addedAt>0</addedAt><authorEmail>-</authorEmail><authorName>-</authorName><baseName>commons-lang-2.6.jar</baseName><category></category><columnEnd>0</columnEnd><columnStart>0</columnStart><commit>-</commit><description></description><fileName>/usr/local/tomcat/webapps/govway.war/WEB-INF/lib/commons-lang-2.6.jar</fileName><fingerprint>FALLBACK-f48ad3a6</fingerprint><lineEnd>1</lineEnd><lineStart>1</lineStart><message>CVE-2025-48924: LanguageSpecificPackageVulnerability

commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

For additional help see: **Vulnerability CVE-2025-48924**
| Severity | Package | Fixed Version | Link |
| --- | --- | --- | --- |
|MEDIUM|commons-lang:commons-lang||[CVE-2025-48924](https://avd.aquasec.com/nvd/cve-2025-48924)|

Uncontrolled Recursion vulnerability in Apache Commons Lang.

This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.

The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a 
StackOverflowError could cause an application to stop.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Package: commons-lang:commons-lang
Installed Version: 2.6
Vulnerability CVE-2025-48924
Severity: MEDIUM
Fixed Version: 
Link: [CVE-2025-48924](https://avd.aquasec.com/nvd/cve-2025-48924)</message><moduleName></moduleName><origin>trivy</origin><originName>Trivy Security Scanner</originName><packageName>-</packageName><reference>1383</reference><severity>NORMAL</severity><toString>commons-lang-2.6.jar(1,0): CVE-2025-48924: : CVE-2025-48924: LanguageSpecificPackageVulnerability

commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang

For additional help see: **Vulnerability CVE-2025-48924**
| Severity | Package | Fixed Version | Link |
| --- | --- | --- | --- |
|MEDIUM|commons-lang:commons-lang||[CVE-2025-48924](https://avd.aquasec.com/nvd/cve-2025-48924)|

Uncontrolled Recursion vulnerability in Apache Commons Lang.

This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.

The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a 
StackOverflowError could cause an application to stop.

Users are recommended to upgrade to version 3.18.0, which fixes the issue.

Package: commons-lang:commons-lang
Installed Version: 2.6
Vulnerability CVE-2025-48924
Severity: MEDIUM
Fixed Version: 
Link: [CVE-2025-48924](https://avd.aquasec.com/nvd/cve-2025-48924)</toString><type>CVE-2025-48924</type></issue><size>1</size><toString>1 warning (normal: 1)</toString></reportApi>