[GHSA-rmqp-9w4c-gc7w] ** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN... #2849
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates
Comments
Advisory title from https://lists.apache.org/thread/gs0qgk2mgss7zfhzdd6ftfjvm4kp7v82.
Apache's announcement says versions through 1.3 are applicable, with 1.3 being the newest tag on https://github.com/apache/axis-axis1-java. However, a 1.4 release was announced on https://axis.apache.org/axis/ in 2006 and also contains the vulnerable function ServiceFactory.getService in org/apache/axis/client/ServiceFactory.java (see https://repo1.maven.org/maven2/org/apache/axis/axis/1.4/axis-1.4-sources.jar).