Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:9318

Опубликовано: 29 июл. 2025
Источник: rocky
Оценка: Important

Описание

Important: javapackages-tools:201801 security update

The javapackages-tools packages provide macros and scripts to support Java packaging.

Security Fix(es):

  • apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)

  • commons-beanutils: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default (CVE-2025-48734)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
aopalliancenoarch17.module+el8.6.0+843+5a13dac3aopalliance-1.0-17.module+el8.6.0+843+5a13dac3.noarch.rpm
aopalliancenoarch17.module+el8.6.0+843+5a13dac3aopalliance-1.0-17.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-clinoarch4.module+el8.6.0+843+5a13dac3apache-commons-cli-1.4-4.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-clinoarch4.module+el8.6.0+843+5a13dac3apache-commons-cli-1.4-4.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-codecnoarch3.module+el8.6.0+843+5a13dac3apache-commons-codec-1.11-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-codecnoarch3.module+el8.6.0+843+5a13dac3apache-commons-codec-1.11-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-ionoarch3.module+el8.6.0+843+5a13dac3apache-commons-io-2.6-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-ionoarch3.module+el8.6.0+843+5a13dac3apache-commons-io-2.6-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-lang3noarch3.module+el8.6.0+843+5a13dac3apache-commons-lang3-3.7-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-lang3noarch3.module+el8.6.0+843+5a13dac3apache-commons-lang3-3.7-3.module+el8.6.0+843+5a13dac3.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
6 месяцев назад

ELSA-2025-9318: javapackages-tools:201801 security update (IMPORTANT)

CVSS3: 7.3
ubuntu
больше 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
redhat
больше 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
nvd
больше 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.

CVSS3: 7.3
debian
больше 6 лет назад

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class wa ...