Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

commons-beanutils: security update to 1.9.4 #1968

Closed
1 task done
KexyBiscuit opened this issue Aug 22, 2019 · 1 comment
Closed
1 task done

commons-beanutils: security update to 1.9.4 #1968

KexyBiscuit opened this issue Aug 22, 2019 · 1 comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@KexyBiscuit
Copy link
Member

KexyBiscuit commented Aug 22, 2019

CVE IDs: CVE-2019-10086

Other security advisory IDs: openSUSE-SU-2019:2058-1

Descriptions: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

Patches: BEANUTILS-520: Mitigate CVE-2014-0114 by enabling SuppressPropertiesB…

PoC(s): N/A

Architectural progress:

  • Architecture-independent noarch
@KexyBiscuit KexyBiscuit added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed to-stable labels Aug 22, 2019
@KexyBiscuit KexyBiscuit added this to the Summer 2019 milestone Aug 22, 2019
@KexyBiscuit
Copy link
Member Author

Use AOSA-2019-0216.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

1 participant