commons-beanutils: 'class' property is exposed, potentially leading to RCE
Published Jul 8, 2014
No CVSS score
EPSS 0.26%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of CVE-2014-0114. CVE abstraction content decisions did not require a second ID. Notes: All CVE users should reference CVE-2014-0114 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
MITRE has rejected this CVE ID, favoring the use of CVE-2014-0114. This flaw was the root cause of CVE-2014-0114, a flaw in Apache Struts 1 that could lead to unauthenticated remote code execution under certains conditions. Other frameworks built on commons-beanutils, such as Apache Stripes, are likely to expose similar issues. commons-beanutils 1.9.2 has now shipped, including a specialized BeanIntrospector implementation that allows suppressing properties. Frameworks built on commons-beantutils can make use of the new pre-configured SuppressPropertiesBeanIntrospector to address this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Dec 12, 2024.
Score over time
Feb–Dec 2024- EPSS v3
Percentile over time
- EPSS v3
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Dec 12, 2024 | 0.26% (0.00259) | 66.22th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.26% (0.00259) | 64.73th | v3 (v2023.03.01) |
No CWE recorded.
References (5)
Change history (0)
No recorded changes yet.