-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: rh-maven35-apache-commons-beanutils security update
Advisory ID:       RHSA-2019:4317-01
Product:           Red Hat Software Collections
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:4317
Issue date:        2019-12-18
CVE Names:         CVE-2019-10086 
====================================================================
1. Summary:

An update for rh-maven35-apache-commons-beanutils is now available for Red
Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch

3. Description:

The rh-maven35-apache-commons-beanutils package provides Java utility
methods for accessing and modifying properties of arbitrary JavaBeans.

Security Fix(es):

* apache-commons-beanutils: does not suppresses the class property in
PropertyUtilsBean by default (CVE-2019-10086)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1767483 - CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default

6. Package List:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm
rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm
rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):

Source:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm
rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):

Source:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm
rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):

Source:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm
rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):

Source:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm

noarch:
rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm
rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2019-10086
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXfpF/tzjgjWX9erEAQiGCA/9Ewr7O2skn0CNbTHeDp+grKWdY59+QZpD
mhx7WNj18kf6qimFrssC1x/jffqLOHQs70OkxU9cmg0XlvvnHtGqkgwQiOUSYHip
PZjuy+xYZ6TvCmTWWpgV4RKvVL+9WqiW3B7Y0y40DRKerD2y9I6mBTYIGNn2uOK1
O0zfXJkztToPR3n63gB42LphiuNLRhhGal+lwWV5v2pjxi2m7vYp21hZspdMzDAo
QMHJV6vnz+8lbtfvUCx9NM+JBkBY8UFGlxKf4bQZQUYCGcNCyndB0NaXJKGnEzJe
qvtBYEmlZtr99Jv73SJtu8zavO9feBwfr7Jn3y1uHyK23bnqdtz3ufvUu9jKeY9v
hv7uGduZu5n6axf28f+FLBpSVo6zBQh9Q3CNP3OB0s4cKQ6f3NNg1V+TF9TIDNkC
UJ03Mv3okC+/9dua+vKGBuw8KnAk7Yi8w8oz1soV94XHpN4BZoxejXcUbSSHTe4F
H+Bqu5Fncyc92NrRMPKfE0d5EnYTo+suW/RCnJUlrRmPrXCrylLfSfZiu9OnG7Bn
vxLN94xjPAHSZd7IEfEvcPHuCcC+xhrhCqOuv6hQB2UQqH6QQnNbRX4NTGP5IkWd
kj6BcIYb66DByeqT/7x1PLhpc9GrTLpruTUBWxzn0wE0ocbpTGEFB9XgFkp3JtIM
DK4zqdPIZpM=q1r7
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2019-4317:01 Important: rh-maven35-apache-commons-beanutils

An update for rh-maven35-apache-commons-beanutils is now available for Red Hat Software Collections

Summary

The rh-maven35-apache-commons-beanutils package provides Java utility methods for accessing and modifying properties of arbitrary JavaBeans.
Security Fix(es):
* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2019-10086 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm
noarch: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm
noarch: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):
Source: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm
noarch: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):
Source: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm
noarch: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):
Source: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm
noarch: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.src.rpm
noarch: rh-maven35-apache-commons-beanutils-1.9.3-2.3.el7.noarch.rpm rh-maven35-apache-commons-beanutils-javadoc-1.9.3-2.3.el7.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2019:4317-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2019:4317
Issued Date: : 2019-12-18
CVE Names: CVE-2019-10086

Topic

An update for rh-maven35-apache-commons-beanutils is now available for RedHat Software Collections.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch


Bugs Fixed

1767483 - CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default


Related News