Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 41: 2025-3eb7c0066f important: apache-commons-beanutils access issue

fedora
Calendar Grey June 22, 2025
Dist Fedora Esm H88
The Fedora 41 update resolves a security vulnerability in apache-commons-beanutils, improving access controls and overall system protection.
Fix improper access control vulnerability Resolves: CVE-2025-48734

Summary

The scope of this package is to create a package of Java utility methods

for accessing and modifying the properties of arbitrary JavaBeans. No

dependencies outside of the JDK are required, so the use of this package

is very lightweight.

Update Information:

Fix improper access control vulnerability Resolves: CVE-2025-48734

Change Log

* Fri Jun 13 2025 Mikolaj Izdebski - 1.9.4-39 - Fix improper access control vulnerability * Thu Jan 16 2025 Fedora Release Engineering - 1.9.4-38 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Jan 13 2025 Mikolaj Izdebski - 1.9.4-37 - Update upstream URL * Fri Nov 29 2024 Mikolaj Izdebski - 1.9.4-34 - Update javapackages test plan to f42 * Tue Sep 3 2024 Mikolaj Izdebski - 1.9.4-33 - Use %autosetup -C

References


[ 1 ] Bug #2369088 - CVE-2025-48734 apache-commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369088

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-3eb7c0066f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: apache-commons-beanutils
Product: Fedora 41
Version: 1.9.4
Release: 39.fc41
Summary: Java utility methods for accessing and modifying the properties of arbitrary JavaBeans

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here