VDB

GCVE-VVD-MAGEIA-2019-399

GCVE-VVD-MAGEIA-2019-399
Advisory Published
Vulnetix · Advisory published December 19, 2019
Updated apache-commons-beanutils packages fix security vulnerability: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean (CVE-2019-10086). Also, the apache-commons-collections package has been rebuilt to regenerate the OSGi metadata, to allow the apache-commons-beanutils package to build.

Affected Products

VendorProductVersionsPlatforms
Mageiaapache-commons-beanutils0 (affected), 1.9.4-1.mga7 (unaffected)
Mageiaapache-commons-collections0 (affected), 3.2.2-7.1.mga7 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›