rpm package
almalinux/plexus-component-factories-pom
pkg:rpm/almalinux/plexus-component-factories-pom
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-48734 | — | < 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706 | 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706 | May 28, 2025 | Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no | ||
| CVE-2019-10086 | — | < 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706 | 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706 | Aug 20, 2019 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop |
- CVE-2025-48734May 28, 2025affected < 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706fixed 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706
Improper Access Control vulnerability in Apache Commons. A special BeanIntrospector class was added in version 1.9.2. This can be used to stop attackers from using the declared class property of Java enum objects to get access to the classloader. However this protection was no
- CVE-2019-10086Aug 20, 2019affected < 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706fixed 1.0-0.15.alpha11.module_el8.0.0+6004+2fc32706
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the Prop