Apache Commons是美国阿帕奇(Apache)基金会的一个专注于可重用 Java 组件各个方面的 Apache 项目。 Apache Commons存在安全漏洞,该漏洞源于访问控制不当,可能导致攻击者通过枚举对象的declaredClass属性访问类加载器并执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Commons BeanUtils 1.x | 1.0< 1.11.0 |
affected |
| Apache Software Foundation | Apache Commons BeanUtils 2.x | 2.0.0-M1< 2.0.0-M2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Commons BeanUtils 1.x | 1.0 ~ 1.11.0 | - |
|
| Apache Software Foundation | Apache Commons BeanUtils 2.x | 2.0.0-M1 ~ 2.0.0-M2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-27528 | Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File | |
| CVE-2025-27526 | Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass | |
| CVE-2025-27522 | Apache InLong: JDBC Vulnerability during verification processing |
No comments yet