Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0114

Опубликовано: 30 апр. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.9.2-3
disco

not-affected

1.9.2-3
eoan

not-affected

1.9.2-3
esm-apps/bionic

released

1.9.3-1ubuntu0.1~esm1
esm-apps/focal

not-affected

1.9.2-3
esm-apps/jammy

not-affected

1.9.2-3
esm-apps/xenial

released

1.9.2-3ubuntu0.1~esm1
esm-infra-legacy/trusty

released

1.9.1-1ubuntu0.1~esm1
focal

not-affected

1.9.2-3

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

nvd
больше 11 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

debian
больше 11 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8. ...

github
около 5 лет назад

Arbitrary code execution in Apache Commons BeanUtils

oracle-oval
больше 11 лет назад

ELSA-2014-0474: struts security update (IMPORTANT)

7.5 High

CVSS2