Title: Security Vulnerabilities in usb4java 1.3.0 - CVE-2025-48924 and CVE-2020-15250 · Issue #92 · usb4java/usb4java · GitHub
Open Graph Title: Security Vulnerabilities in usb4java 1.3.0 - CVE-2025-48924 and CVE-2020-15250 · Issue #92 · usb4java/usb4java
X Title: Security Vulnerabilities in usb4java 1.3.0 - CVE-2025-48924 and CVE-2020-15250 · Issue #92 · usb4java/usb4java
Description: Environment: OS: yocto linux dunfell Java version 1.8 usb4java version 1.3.0 Bug description We are using usb4java version 1.3.0 in our project and noticed that it includes dependencies with known vulnerabilities: CVE-2025-48924: Uncontr...
Open Graph Description: Environment: OS: yocto linux dunfell Java version 1.8 usb4java version 1.3.0 Bug description We are using usb4java version 1.3.0 in our project and noticed that it includes dependencies with known ...
X Description: Environment: OS: yocto linux dunfell Java version 1.8 usb4java version 1.3.0 Bug description We are using usb4java version 1.3.0 in our project and noticed that it includes dependencies with known ...
Opengraph URL: https://github.com/usb4java/usb4java/issues/92
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Security Vulnerabilities in usb4java 1.3.0 - CVE-2025-48924 and CVE-2020-15250","articleBody":"**Environment:**\n - OS: yocto linux dunfell\n - Java version 1.8\n - usb4java version 1.3.0\n\n**Bug description**\nWe are using `usb4java` version 1.3.0 in our project and noticed that it includes dependencies with known vulnerabilities:\n\n- **CVE-2025-48924**: Uncontrolled recursion in Apache Commons Lang (fixed in commons-lang3 3.18.0)\n- **CVE-2020-15250**: Information disclosure in JUnit TemporaryFolder (fixed in JUnit 4.13.1)\n\nCould you please confirm:\n- Whether these vulnerabilities impact usb4java usage directly?\n- Any recommended mitigation steps?\n- If there is a plan for a new release that updates these dependencies?\n\n\n**Reproduction**\nVulnerabilities from dependencies: CVE-2025-48924CVE-2020-15250\nReference link: https://mvnrepository.com/artifact/org.usb4java/usb4java/1.3.0\n\n\n**Expected behavior**\nReported Vulnerabilities to be solved. ","author":{"url":"https://github.com/sharath2mobile","@type":"Person","name":"sharath2mobile"},"datePublished":"2025-08-20T06:03:54.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/92/usb4java/issues/92"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:710b1941-f35a-50d5-83f8-49ddbce73a7a |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | AB90:216B79:764258:9BE7B4:696B49A6 |
| html-safe-nonce | 1a5f56207a82ec8c70b146fff28cdca6548a8345b3246b558283307d1db49ad4 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBQjkwOjIxNkI3OTo3NjQyNTg6OUJFN0I0OjY5NkI0OUE2IiwidmlzaXRvcl9pZCI6IjY0NjAwNDM4MDE4Mjc5NTMwNjIiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 7194da89cbecf6392a33a482cb683e3ad18a389ce14b365ad23630571a37ca7c |
| hovercard-subject-tag | issue:3336681522 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/usb4java/usb4java/92/issue_layout |
| twitter:image | https://opengraph.githubassets.com/9e7eafe75e519661b4688a8909086e4f68479b955c5ec5c84c7685c33ab56e5f/usb4java/usb4java/issues/92 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/9e7eafe75e519661b4688a8909086e4f68479b955c5ec5c84c7685c33ab56e5f/usb4java/usb4java/issues/92 |
| og:image:alt | Environment: OS: yocto linux dunfell Java version 1.8 usb4java version 1.3.0 Bug description We are using usb4java version 1.3.0 in our project and noticed that it includes dependencies with known ... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | sharath2mobile |
| hostname | github.com |
| expected-hostname | github.com |
| None | 5f99f7c1d70f01da5b93e5ca90303359738944d8ab470e396496262c66e60b8d |
| turbo-cache-control | no-preview |
| go-import | github.com/usb4java/usb4java git https://github.com/usb4java/usb4java.git |
| octolytics-dimension-user_id | 5460495 |
| octolytics-dimension-user_login | usb4java |
| octolytics-dimension-repository_id | 1528861 |
| octolytics-dimension-repository_nwo | usb4java/usb4java |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 1528861 |
| octolytics-dimension-repository_network_root_nwo | usb4java/usb4java |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 82560a55c6b2054555076f46e683151ee28a19bc |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width