Updated apache-commons-beanutils packages fix security vulnerability: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, . MGASA-2019-0399 - Updated apache-commons-beanutils packages fix security vulnerability Publication date: 19 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0399.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-10086 Updated apache-commons-beanutils packages fix security vulnerability: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean (CVE-2019-10086). Also, the apache-commons-collections package has been rebuilt to regenerate the OSGi metadata, to allow the apache-commons-beanutils package to build. References: - https://bugs.mageia.org/show_bug.cgi?id=25765 - - https://www.cve.org/CVERecord?id=CVE-2019-10086 SRPMS: - 7/core/apache-commons-beanutils-1.9.4-1.mga7 - 7/core/apache-commons-collections-3.2.2-7.1.mga7 . The latest apache-commons-beanutils releases address a security vulnerability in Mageia linked to improper access controls within the Java classloader.. apache commons beanutils update, Mageia security advisory, classloader vulnerability, Java security issue. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for apache-commons-beanutils ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2058-1 Rating: important References: #1146657 Cross-References: CVE-2019-10086 Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for apache-commons-beanutils fixes the following issues: Security issue fixed: - CVE-2019-10086: Added special BeanIntrospector class which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects (bsc#1146657). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2058=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2058=1 Package List: - openSUSE Leap 15.1 (noarch): apache-commons-beanutils-1.9.2-lp151.3.3.1 apache-commons-beanutils-javadoc-1.9.2-lp151.3.3.1 - openSUSE Leap 15.0 (noarch): apache-commons-beanutils-1.9.2-lp150.2.3.1 apache-commons-beanutils-javadoc-1.9.2-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-10086.html https://bugzilla.suse.com/1146657 -- . Critical security patch released for Fedora addressing vulnerability in Apache Commons Beanutils. Discover the steps to implement the update today.. openSUSE Update, Apache Commons, Security Warning, Major Fixes. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for apache-commons-beanutils ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2245-1 Rating: important References: #1146657 Cross-References: CVE-2019-10086 Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP1 SUSE Linux Enterprise Module for Web Scripting 15 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for apache-commons-beanutils fixes the following issues: Security issue fixed: - CVE-2019-10086: Added special BeanIntrospector class which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects (bsc#1146657). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP1: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP1-2019-2245=1 - SUSE Linux Enterprise Module for Web Scripting 15: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-2019-2245=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2245=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2245=1 Package List: - SUSE Linux Enterprise Module for Web Scripting15-SP1 (noarch): apache-commons-beanutils-1.9.2-4.3.1 - SUSE Linux Enterprise Module for Web Scripting 15 (noarch): apache-commons-beanutils-1.9.2-4.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (noarch): apache-commons-beanutils-javadoc-1.9.2-4.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (noarch): apache-commons-beanutils-javadoc-1.9.2-4.3.1 References: https://www.suse.com/security/cve/CVE-2019-10086.html https://bugzilla.suse.com/1146657 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for apache-commons-beanutils ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2244-1 Rating: important References: #1146657 Cross-References: CVE-2019-10086 Affected Products: SUSE Linux Enterprise Server 12-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for apache-commons-beanutils fixes the following issues: Security issue fixed: - CVE-2019-10086: Added special BeanIntrospector class which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects (bsc#1146657). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-2244=1 Package List: - SUSE Linux Enterprise Server 12-SP4 (noarch): apache-commons-beanutils-1.9.2-3.3.1 apache-commons-beanutils-javadoc-1.9.2-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-10086.html https://bugzilla.suse.com/1146657 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.