VYPR

rpm package

almalinux/apache-commons-net

pkg:rpm/almalinux/apache-commons-net

Vulnerabilities (4)

  • CVE-2025-52999HigJun 25, 2025
    affected < 3.6-3.module_el8.5.0+2577+9e95fe00fixed 3.6-3.module_el8.5.0+2577+9e95fe00

    jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the de

  • CVE-2025-48734May 28, 2025
    affected < 3.6-3.module_el8.0.0+6004+2fc32706fixed 3.6-3.module_el8.0.0+6004+2fc32706

    Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no

  • CVE-2020-36518Mar 11, 2022
    affected < 3.6-3.module_el8.5.0+2577+9e95fe00fixed 3.6-3.module_el8.5.0+2577+9e95fe00

    jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.

  • CVE-2019-10086Aug 20, 2019
    affected < 3.6-3.module_el8.0.0+6004+2fc32706fixed 3.6-3.module_el8.0.0+6004+2fc32706

    In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop