In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apache
Published: 2019-08-20T20:10:15
Updated: 2022-07-22T17:59:36
Reserved: 2019-03-26T00:00:00
Link: CVE-2019-10086
JSON object: View
NVD Information
Status : Modified
Published: 2019-08-20T21:15:12.057
Modified: 2023-11-07T03:02:22.697
Link: CVE-2019-10086
JSON object: View
Redhat Information
No data.
CWE