• CVE-2025-48734

发布时间: 2025年7月4日

修改时间: 2025年7月11日

概要

A vulnerability, which was classified as critical, was found in Apache Commons BeanUtils up to 1.10.x/2.0.0-/1.CWE is classifying the issue as CWE-284. The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.This is going to have an impact on confidentiality, integrity, and availability.Upgrading to version 1.11.0 or 2.0.0-M2 eliminates this vulnerability.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 8.8
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Integrity High
User Interaction None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2728 apache-commons-beanutils security update 2025年7月12日

影响产品

产品 状态
KY3.4-5A apache-commons-beanutils Fixed
V6 apache-commons-beanutils Fixed
KY3.5.3 apache-commons-beanutils Fixed
KY3.5.2 apache-commons-beanutils Fixed