UBUNTU-CVE-2019-10086
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-10086
UBUNTU-CVE-2019-10086
Summary:
Details: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
References: https://ubuntu.com/security/CVE-2019-10086, https://issues.apache.org/jira/browse/BEANUTILS-520, https://github.com/apache/commons-beanutils/pull/7, https://github.com/apache/commons-beanutils/commit/dd48f4e589462a8cdb1f29bbbccb35d6b0291d58, https://ubuntu.com/security/notices/USN-4766-1, https://www.cve.org/CVERecord?id=CVE-2019-10086
Affected packages
Package
Name: commons-beanutils
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
