QID 980293
QID 980293: Java (maven) Security Update for commons-beanutils:commons-beanutils (GHSA-6phf-73q6-gh87)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6phf-73q6-gh87 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6phf-73q6-gh87 -
github.com/advisories/GHSA-6phf-73q6-gh87
CVEs related to QID 980293
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6phf-73q6-gh87 | commons-beanutils:commons-beanutils |
|