Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-48734

Опубликовано: 28 мая 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Improper Access Control vulnerability in Apache Commons.

A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default.

Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:commons_beanutils:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 1.11.0 (исключая)
cpe:2.3:a:apache:commons_beanutils:2.0.0:milestone1:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00212
Низкий

8.8 High

CVSS3

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8.8
ubuntu
22 дня назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedPropert...

CVSS3: 8.3
redhat
22 дня назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
debian
22 дня назад

Improper Access Control vulnerability in Apache Commons. A special ...

suse-cvrf
15 дней назад

Security update for apache-commons-beanutils

CVSS3: 8.8
github
22 дня назад

Apache Commons Improper Access Control vulnerability

EPSS

Процентиль: 44%
0.00212
Низкий

8.8 High

CVSS3

Дефекты

CWE-284
NVD-CWE-Other