commons-beanutils:commons-beanutils
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting commons-beanutils:commons-beanutilspage 1 of 1
- CVE-2014-0114NONECVSS 0.0✓ Fixed in 1.9.42014-04-30
vulnerable: 1.8.0 ... 1.9.3 (8 versions)
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote atta…
- CVE-2019-10086HIGHCVSS 7.3EG 7.3✓ Fixed in 1.9.42019-08-20
vulnerable: 1.0 ... 1.9.3 (18 versions)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using t…
Check whether commons-beanutils:commons-beanutils is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for commons-beanutils:commons-beanutils CVEs against the assets you own.
Start Free Scan →