-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: rh-java-common-apache-commons-beanutils security update
Advisory ID:       RHSA-2020:0057-01
Product:           Red Hat Software Collections
Advisory URL:      https://access.redhat.com/errata/RHSA-2020:0057
Issue date:        2020-01-08
CVE Names:         CVE-2019-10086 
====================================================================
1. Summary:

An update for rh-java-common-apache-commons-beanutils is now available for
Red Hat Software Collections.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch

3. Description:

The Apache Commons BeanUtils library provides utility methods for accessing
and modifying properties of arbitrary JavaBeans.

Security Fix(es):

* apache-commons-beanutils: does not suppresses the class property in
PropertyUtilsBean by default (CVE-2019-10086)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1767483 - CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default

6. Package List:

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.14.el6.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.14.el6.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):

Source:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm

noarch:
rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm
rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2019-10086
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXhW7I9zjgjWX9erEAQi07hAAnqYy1It2cfETmNkrdvsr8686DAUnfQxL
S8K1NcOZIziEbBaOJ1UX3rCJZ91vOOrgKyXpWRUwM0+yQVgYp/n8/FBedlD7tF+K
FWrD0YbOMNy0h8ovuHD51ff6Kb1hVL7RKu66oSAeQJIPb5Z6V9TotXqVpt1/jjp8
puPI4sfMmG5axtSBviXr3P9peQaGmfrURtrf8OwF5pleSVxapb3YsgHwOtqRviM1
314CY4deORPQKK/j7gYYmWwohb2OpGCXxWmCUHg1COVXhiy1xt9W3raijCn2mNKD
C7K4LgjL/XOow0h8ZZXReN56CO9dlOccmnCkfJVNF9k+5XY0clp2lon14yQWa7am
CgaivfztvasmFVgxlx7Jx4q937DGDB1emYexzG9G3aof7qq8Z3wE6X0ezF+dr4Wc
01QZVxoPvR/3fmTmxjCESocf+CbR4Aq3BtR283GKtac+wVitPYT+2MIm8hCbFyGv
E/OaGJbjvlDjI5pt/51+Kt2frDeeUXLIN+kTDDkyLY8LpsQXZCMa7RAcdv3xMf7k
eR352qfSIoaWlF0Fu/Za57loTdh7aqawTXjx8v7J3a/ylSy3IPXkK63XoocYSUsl
tq0AdM9zWsJs4wXLvubs+jimNMy2nq9TNSIoVr8T2UDntuQsCIfE4rRbeYFVasst
Tb4oz4jlxow=TnYE
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2020-0057:01 Important:

An update for rh-java-common-apache-commons-beanutils is now available for Red Hat Software Collections

Summary

The Apache Commons BeanUtils library provides utility methods for accessing and modifying properties of arbitrary JavaBeans.
Security Fix(es):
* apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default (CVE-2019-10086)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2019-10086 https://access.redhat.com/security/updates/classification/#important

Package List

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.14.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.14.el6.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.14.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7):
Source: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.src.rpm
noarch: rh-java-common-apache-commons-beanutils-1.8.3-14.15.el7.noarch.rpm rh-java-common-apache-commons-beanutils-javadoc-1.8.3-14.15.el7.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2020:0057-01
Product: Red Hat Software Collections
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0057
Issued Date: : 2020-01-08
CVE Names: CVE-2019-10086

Topic

An update for rh-java-common-apache-commons-beanutils is now available forRed Hat Software Collections.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch

Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch


Bugs Fixed

1767483 - CVE-2019-10086 apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default


Related News