First published: Wed Jan 08 2020(Updated: )
The Apache Commons BeanUtils library provides utility methods for accessing and modifying properties of arbitrary JavaBeans.<br>Security Fix(es):<br><li> apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-java-common-apache-commons-beanutils | <1.8.3-14.15.el7 | 1.8.3-14.15.el7 |
redhat/rh-java-common-apache-commons-beanutils | <1.8.3-14.15.el7 | 1.8.3-14.15.el7 |
redhat/rh-java-common-apache-commons-beanutils-javadoc | <1.8.3-14.15.el7 | 1.8.3-14.15.el7 |
redhat/rh-java-common-apache-commons-beanutils | <1.8.3-14.14.el6 | 1.8.3-14.14.el6 |
redhat/rh-java-common-apache-commons-beanutils | <1.8.3-14.14.el6 | 1.8.3-14.14.el6 |
redhat/rh-java-common-apache-commons-beanutils-javadoc | <1.8.3-14.14.el6 | 1.8.3-14.14.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:0057 is classified as important.
To fix RHSA-2020:0057, update to version 1.8.3-14.15.el7 or higher for affected packages.
The affected packages include rh-java-common-apache-commons-beanutils and rh-java-common-apache-commons-beanutils-javadoc.
RHSA-2020:0057 addresses the vulnerability CVE-2019-10086 in the Apache Commons BeanUtils library.
There is no documented workaround for RHSA-2020:0057, so upgrading is the recommended action.