Maven · repo1.maven.org
co.elastic.apm:apm-agent-attach-cli
Java Jndi Lookup: JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family).
Why PkgRadar flagged 1.56.0
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Jndi Lookup | JNDI / Naming.lookup — remote class-loading primitive (Log4Shell family). · org/apache/logging/log4j/core/net/JndiManager.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · META-INF/versions/9/net/bytebuddy/agent/ByteBuddyAgent.java |
| medium | Java Dynamic Classload | URLClassLoader / defineClass — runs attacker-provided bytecode. · co/elastic/apm/attach/bytebuddy/agent/ByteBuddyAgent.java |
| medium | Java Unsafe Deserialize | ObjectInputStream / XStream.fromXML — untrusted deserialization sink. · org/apache/logging/log4j/util/SortedArrayStringMap.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · META-INF/versions/9/net/bytebuddy/agent/ByteBuddyAgent.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · META-INF/versions/9/net/bytebuddy/agent/VirtualMachine.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · co/elastic/apm/attach/bytebuddy/agent/ByteBuddyAgent.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · co/elastic/apm/attach/bytebuddy/agent/VirtualMachine.java |
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · com/sun/jna/NativeLibrary.java |
| medium | Java Static Init Side Effect | Static-initializer block contains process/network/reflection — runs on first class load (contributory signal). · com/sun/jna/NativeLibrary.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
1.56.0 | Review | 152 | 2026-06-15 |
Block this in CI
pkgradar gate --ecosystem maven co.elastic.apm:[email protected]