Back

HIGH

apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default

Published Aug 20, 2019

Description

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Affected products

Remediation

Red Hat mitigation

There is no currently known mitigation for this flaw.

Metrics

References (97)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 20, 2019
Updated Aug 4, 2024
Reserved Mar 26, 2019
NVD
Status Modified
Modified Aug 25, 2026
Red Hat
Severity Important
Public date Aug 15, 2019
GHSA-6PHF-73Q6-GH87