Back

commons-beanutils: 'class' property is exposed, potentially leading to RCE

Published Jul 8, 2014

Description

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of CVE-2014-0114. CVE abstraction content decisions did not require a second ID. Notes: All CVE users should reference CVE-2014-0114 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

Affected products

Remediation

Red Hat statement

MITRE has rejected this CVE ID, favoring the use of CVE-2014-0114. This flaw was the root cause of CVE-2014-0114, a flaw in Apache Struts 1 that could lead to unauthenticated remote code execution under certains conditions. Other frameworks built on commons-beanutils, such as Apache Stripes, are likely to expose similar issues. commons-beanutils 1.9.2 has now shipped, including a specialized BeanIntrospector implementation that allows suppressing properties. Frameworks built on commons-beantutils can make use of the new pre-configured SuppressPropertiesBeanIntrospector to address this flaw.

Metrics

Weaknesses (0)

No CWE recorded.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Jul 8, 2014
Updated n/a
Reserved n/a
NVD
Status Rejected
Modified Nov 7, 2023
Red Hat
Severity Important
Public date May 1, 2014