From a5be4419e2753593ddac1f7948f0731a2ce0a843 Mon Sep 17 00:00:00 2001 From: Rob Tompkins Date: Wed, 5 Jun 2019 20:38:37 -0400 Subject: [PATCH 1/2] Fix CVE-2019-10086 Backported from upstream commit 62e82ad92cf4818709d6044aaf257b73d42659a4 --- .../java/org/apache/commons/beanutils/PropertyUtilsBean.java | 1 + 1 file changed, 1 insertion(+) diff --git a/src/main/java/org/apache/commons/beanutils/PropertyUtilsBean.java b/src/main/java/org/apache/commons/beanutils/PropertyUtilsBean.java index 5e76d97b..36eb7f57 100644 --- a/src/main/java/org/apache/commons/beanutils/PropertyUtilsBean.java +++ b/src/main/java/org/apache/commons/beanutils/PropertyUtilsBean.java @@ -188,6 +188,7 @@ public class PropertyUtilsBean { public final void resetBeanIntrospectors() { introspectors.clear(); introspectors.add(DefaultBeanIntrospector.INSTANCE); + introspectors.add(SuppressPropertiesBeanIntrospector.SUPPRESS_CLASS); } /** -- 2.49.0