PT-2019-4682 · Apache+7 · Apache Commons Beanutils+7
CVE-2019-10086
·
Publicado
2019-08-20
·
Atualizado
2026-07-23
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apache Commons Beanutils versions prior to 1.9.2
Description
The issue is related to the BeanIntrospector class in Apache Commons Beanutils, which can lead to the restoration of untrusted data structures in memory. This can allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. A special BeanIntrospector class was added in version 1.9.2 to suppress the ability for an attacker to access the classloader via the class property available on all Java objects.
Recommendations
For versions prior to 1.9.2, consider using the BeanIntrospector class to suppress the ability for an attacker to access the classloader via the class property available on all Java objects.
Update to version 1.9.2 or later, which includes the special BeanIntrospector class by default.
Correção
DoS
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Almalinux
Apache Commons Beanutils
Centos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu