First published: Wed Dec 18 2019(Updated: )
The rh-maven35-apache-commons-beanutils package provides Java utility methods for accessing and modifying properties of arbitrary JavaBeans.<br>Security Fix(es):<br><li> apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-maven35-apache-commons-beanutils | <1.9.3-2.3.el7 | 1.9.3-2.3.el7 |
redhat/rh-maven35-apache-commons-beanutils | <1.9.3-2.3.el7 | 1.9.3-2.3.el7 |
redhat/rh-maven35-apache-commons-beanutils-javadoc | <1.9.3-2.3.el7 | 1.9.3-2.3.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2019:4317 is classified as important.
To fix RHSA-2019:4317, you should update the rh-maven35-apache-commons-beanutils package to version 1.9.3-2.3.el7.
RHSA-2019:4317 addresses CVE-2019-10086, a vulnerability in apache-commons-beanutils regarding property suppression.
The affected packages under RHSA-2019:4317 include rh-maven35-apache-commons-beanutils and rh-maven35-apache-commons-beanutils-javadoc.
Yes, RHSA-2019:4317 is applicable to both the standard and noarch architecture versions of the affected packages.