Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-48734

Опубликовано: 28 мая 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

РелизСтатусПримечание
devel

not-affected

fix already present
esm-apps-legacy/xenial

released

1.9.2-3ubuntu0.1~esm1
esm-apps/bionic

released

1.9.3-1ubuntu0.1~esm2
esm-apps/focal

released

1.9.4-1ubuntu0.20.04.1~esm1
esm-apps/jammy

released

1.9.4-1+deb11u1build0.22.04.1
esm-apps/noble

released

1.9.4-2ubuntu0.1~esm1
esm-apps/resolute

not-affected

fix already present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

released

1.9.1-1ubuntu0.1~esm2
focal

ignored

end of standard support, was needs-triage

Показывать по

EPSS

Процентиль: 72%
0.01548
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty(). Sta...

CVSS3: 8.8
nvd
около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was not enabled by default. PropertyUtilsBean (and consequently BeanUtilsBean) now disallows declared class level property access by default. Releases 1.11.0 and 2.0.0-M2 address a potential security issue when accessing enum properties in an uncontrolled way. If an application using Commons BeanUtils passes property paths from an external source directly to the getProperty() method of PropertyUtilsBean, an attacker can access the enum’s class loader via the “declaredClass” property available on all Java “enum” objects. Accessing the enum’s “declaredClass” allows remote attackers to access the ClassLoader and execute arbitrary code. The same issue exists with PropertyUtilsBean.getNestedProperty()

CVSS3: 8.8
debian
около 1 года назад

Improper Access Control vulnerability in Apache Commons. A special ...

suse-cvrf
около 1 года назад

Security update for apache-commons-beanutils

CVSS3: 8.8
github
около 1 года назад

Apache Commons Improper Access Control vulnerability

EPSS

Процентиль: 72%
0.01548
Низкий

8.8 High

CVSS3