VYPR

rpm package

almalinux/bcel

pkg:rpm/almalinux/bcel

Vulnerabilities (4)

  • CVE-2025-67030HigMar 25, 2026
    affected < 6.2-2.module_el8.0.0+6004+2fc32706fixed 6.2-2.module_el8.0.0+6004+2fc32706

    Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

  • CVE-2025-48734HigMay 28, 2025
    affected < 6.2-2.module_el8.0.0+6004+2fc32706fixed 6.2-2.module_el8.0.0+6004+2fc32706

    Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no

  • CVE-2022-42920CriNov 7, 2022
    affected < 6.4.1-9.el9_1fixed 6.4.1-9.el9_1

    Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controlla

  • CVE-2019-10086HigAug 20, 2019
    affected < 6.2-2.module_el8.0.0+6004+2fc32706fixed 6.2-2.module_el8.0.0+6004+2fc32706

    In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop