.. _vulnerabilityManagement_skip_registry_33x_CVE-2022-42920: CVE-2022-42920 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Data: 2023-03-09 Severity: Critical CVSS Score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) Riferimenti: `https://nvd.nist.gov/vuln/detail/CVE-2022-42920 `_ Libreria: org.apache.bcel:bcel < 6.6.0 **Descrizione** Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the resulting bytecode than otherwise expected. Update to Apache Commons BCEL 6.6.0. **Falso Positivo per GovWay** La libreria non viene inclusa in GovWay e quindi la segnalazione รจ considerabile un falso positivo. Configuration File: `false-positive.xml `_