MGASA-2019-0399 - Updated apache-commons-beanutils packages fix security vulnerability

Publication date: 19 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0399.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-10086

Updated apache-commons-beanutils packages fix security vulnerability:

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was
added which allows suppressing the ability for an attacker to access the
classloader via the class property available on all Java objects. We,
however were not using this by default characteristic of the
PropertyUtilsBean (CVE-2019-10086).

Also, the apache-commons-collections package has been rebuilt to regenerate
the OSGi metadata, to allow the apache-commons-beanutils package to build.

References:
- https://bugs.mageia.org/show_bug.cgi?id=25765
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10086

SRPMS:
- 7/core/apache-commons-beanutils-1.9.4-1.mga7
- 7/core/apache-commons-collections-3.2.2-7.1.mga7

Mageia 2019-0399: apache-commons-beanutils security update

Updated apache-commons-beanutils packages fix security vulnerability: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ab...

Summary

Updated apache-commons-beanutils packages fix security vulnerability:
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean (CVE-2019-10086).
Also, the apache-commons-collections package has been rebuilt to regenerate the OSGi metadata, to allow the apache-commons-beanutils package to build.

References

- https://bugs.mageia.org/show_bug.cgi?id=25765

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10086

Resolution

MGASA-2019-0399 - Updated apache-commons-beanutils packages fix security vulnerability

SRPMS

- 7/core/apache-commons-beanutils-1.9.4-1.mga7

- 7/core/apache-commons-collections-3.2.2-7.1.mga7

Severity
Publication date: 19 Dec 2019
URL: https://advisories.mageia.org/MGASA-2019-0399.html
Type: security
CVE: CVE-2019-10086

Related News