Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
pfreitag committed Oct 25, 2019
1 parent 59fda64 commit 16a669c
Showing 1 changed file with 30 additions and 0 deletions.
30 changes: 30 additions & 0 deletions database/java/2019/10086.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
cve: 2019-10086
title: "Apache Commons Beanutils: Deserialization of Untrusted Data"
description: >
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. Beanutils, however was not using this by default characteristic of the PropertyUtilsBean.
references:
- http://mail-archives.apache.org/mod_mbox/www-announce/201908.mbox/%3cC628798F-315D-4428-8CB1-4ED1ECC958E4@apache.org%3e
affected:
- groupId: "commons-beanutils"
artifactId: "commons-beanutils"
version:
- "<=1.9.3"
fixedin:
- ">=1.9.4"
package_urls:
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.9.3/commons-beanutils-1.9.3.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.9.2/commons-beanutils-1.9.2.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.9.2/commons-beanutils-1.9.2.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.9.1/commons-beanutils-1.9.1.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.9.0/commons-beanutils-1.9.0.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.8.3/commons-beanutils-1.8.3.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.8.2/commons-beanutils-1.8.2.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.7.0/commons-beanutils-1.7.0.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.6.1/commons-beanutils-1.6.1.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.6/commons-beanutils-1.6.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.5/commons-beanutils-1.5.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.4.1/commons-beanutils-1.4.1.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.4/commons-beanutils-1.4.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.3/commons-beanutils-1.3.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.2/commons-beanutils-1.2.jar
- https://repo1.maven.org/maven2/commons-beanutils/commons-beanutils/1.0/commons-beanutils-1.0.jar

0 comments on commit 16a669c

Please sign in to comment.