CVE-2019-10086: Deserialization of Untrusted Data
(updated )
In Apache Commons Beanutils, a special BeanIntrospector
class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
References
Detect and mitigate CVE-2019-10086 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →