rpm package
almalinux/apache-commons-net
pkg:rpm/almalinux/apache-commons-net
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-54513 | Hig | 8.1 | < 3.6-3.module_el8.5.0+2577+9e95fe00 | 3.6-3.module_el8.5.0+2577+9e95fe00 | Jun 23, 2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), | |
| CVE-2025-67030 | Hig | 8.8 | < 3.6-3.module_el8.0.0+6004+2fc32706 | 3.6-3.module_el8.0.0+6004+2fc32706 | Mar 25, 2026 | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code | |
| CVE-2025-52999 | Hig | — | < 3.6-3.module_el8.5.0+2577+9e95fe00 | 3.6-3.module_el8.5.0+2577+9e95fe00 | Jun 25, 2025 | jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the de | |
| CVE-2025-48734 | Hig | 8.8 | < 3.6-3.module_el8.0.0+6004+2fc32706 | 3.6-3.module_el8.0.0+6004+2fc32706 | May 28, 2025 | Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no | |
| CVE-2020-36518 | Hig | 7.5 | < 3.6-3.module_el8.5.0+2577+9e95fe00 | 3.6-3.module_el8.5.0+2577+9e95fe00 | Mar 11, 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| CVE-2019-10086 | Hig | 7.3 | < 3.6-3.module_el8.0.0+6004+2fc32706 | 3.6-3.module_el8.0.0+6004+2fc32706 | Aug 20, 2019 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop |
- affected < 3.6-3.module_el8.5.0+2577+9e95fe00fixed 3.6-3.module_el8.5.0+2577+9e95fe00
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(),
- affected < 3.6-3.module_el8.0.0+6004+2fc32706fixed 3.6-3.module_el8.0.0+6004+2fc32706
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
- affected < 3.6-3.module_el8.5.0+2577+9e95fe00fixed 3.6-3.module_el8.5.0+2577+9e95fe00
jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the de
- affected < 3.6-3.module_el8.0.0+6004+2fc32706fixed 3.6-3.module_el8.0.0+6004+2fc32706
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no
- affected < 3.6-3.module_el8.5.0+2577+9e95fe00fixed 3.6-3.module_el8.5.0+2577+9e95fe00
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
- affected < 3.6-3.module_el8.0.0+6004+2fc32706fixed 3.6-3.module_el8.0.0+6004+2fc32706
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop