RHSA-2019:4317: Important: rh-maven35-apache-commons-beanutils security update
The rh-maven35-apache-commons-beanutils package provides Java utility methods for accessing and modifying properties of arbitrary JavaBeans.Security Fix(es): apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-maven35-apache-commons-beanutilsto a version that resolves this vulnerability.Fixed in 1.9.3-2.3.el7 - Upgrade
Upgrade
redhat/rh-maven35-apache-commons-beanutils-javadocto a version that resolves this vulnerability.Fixed in 1.9.3-2.3.el7
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:4317?
The severity of RHSA-2019:4317 is classified as important.
How do I fix RHSA-2019:4317?
To fix RHSA-2019:4317, you should update the rh-maven35-apache-commons-beanutils package to version 1.9.3-2.3.el7.
What vulnerability is addressed in RHSA-2019:4317?
RHSA-2019:4317 addresses CVE-2019-10086, a vulnerability in apache-commons-beanutils regarding property suppression.
Which packages are affected by RHSA-2019:4317?
The affected packages under RHSA-2019:4317 include rh-maven35-apache-commons-beanutils and rh-maven35-apache-commons-beanutils-javadoc.
Is RHSA-2019:4317 applicable to different architecture versions?
Yes, RHSA-2019:4317 is applicable to both the standard and noarch architecture versions of the affected packages.