rpm package
almalinux/aopalliance
pkg:rpm/almalinux/aopalliance
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-67030 | Hig | 8.8 | < 1.0-51.module_el9.6.0+148+fb6dc857 | 1.0-51.module_el9.6.0+148+fb6dc857 | Mar 25, 2026 | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code | |
| CVE-2025-48734 | Hig | 8.8 | < 1.0-17.module_el8.0.0+6004+2fc32706 | 1.0-17.module_el8.0.0+6004+2fc32706 | May 28, 2025 | Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no | |
| CVE-2022-29599 | Cri | 9.8 | < 1.0-20.module_el8.6.0+2786+d7c38b21 | 1.0-20.module_el8.6.0+2786+d7c38b21 | May 23, 2022 | In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. | |
| CVE-2020-13956 | Med | 5.3 | < 1.0-20.module_el8.6.0+2786+d7c38b21 | 1.0-20.module_el8.6.0+2786+d7c38b21 | Dec 2, 2020 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. | |
| CVE-2019-10086 | Hig | 7.3 | < 1.0-17.module_el8.0.0+6004+2fc32706 | 1.0-17.module_el8.0.0+6004+2fc32706 | Aug 20, 2019 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop |
- affected < 1.0-51.module_el9.6.0+148+fb6dc857fixed 1.0-51.module_el9.6.0+148+fb6dc857
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
- affected < 1.0-17.module_el8.0.0+6004+2fc32706fixed 1.0-17.module_el8.0.0+6004+2fc32706
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no
- affected < 1.0-20.module_el8.6.0+2786+d7c38b21fixed 1.0-20.module_el8.6.0+2786+d7c38b21
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
- affected < 1.0-20.module_el8.6.0+2786+d7c38b21fixed 1.0-20.module_el8.6.0+2786+d7c38b21
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
- affected < 1.0-17.module_el8.0.0+6004+2fc32706fixed 1.0-17.module_el8.0.0+6004+2fc32706
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop