Bug 34330 - apache-commons-beanutils new security issue CVE-2025-48734
Summary: apache-commons-beanutils new security issue CVE-2025-48734
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-06-02 10:12 CEST by Nicolas Salguero
Modified: 2025-11-15 20:53 CET (History)
5 users (show)

See Also:
Source RPM: apache-commons-beanutils-1.9.4-7.mga9.src.rpm
CVE: CVE-2025-48734
Status comment:


Attachments

Description Nicolas Salguero 2025-06-02 10:12:48 CEST
CVE-2025-48734 was announced here:
https://openwall.com/lists/oss-security/2025/05/28/6
Nicolas Salguero 2025-06-02 10:13:49 CEST

Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2025-48734
Source RPM: (none) => apache-commons-beanutils-1.9.4-9.mga10.src.rpm, apache-commons-beanutils-1.9.4-7.mga9.src.rpm

Nicolas Salguero 2025-06-02 10:14:07 CEST

Status comment: (none) => Fixed upstream in 1.11.0

Comment 1 Marja Van Waes 2025-06-05 21:23:35 CEST
Assigning to the registered maintainer, CC'ing daviddavid.

CC: (none) => geiger.david68210, marja11
Assignee: bugsquad => mageia

Comment 3 Nicolas Salguero 2025-06-25 16:04:16 CEST
Debian has issued an advisory on June 25:
https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html
Comment 4 Nicolas Salguero 2025-11-14 10:12:01 CET
apache-commons-beanutils-1.9.4-10.mga10 fixed that issue.

Version: Cauldron => 9
Source RPM: apache-commons-beanutils-1.9.4-9.mga10.src.rpm, apache-commons-beanutils-1.9.4-7.mga9.src.rpm => apache-commons-beanutils-1.9.4-7.mga9.src.rpm
Whiteboard: MGA9TOO => (none)

Comment 5 Nicolas Salguero 2025-11-14 10:21:39 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default. (CVE-2025-48734)

References:
https://openwall.com/lists/oss-security/2025/05/28/6
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2E6EAPMCB5XKVDGJ23HGV347WTMBLWMJ/
https://lists.debian.org/debian-lts-announce/2025/06/msg00027.html
========================

Updated packages in core/updates_testing:
========================
apache-commons-beanutils-1.9.4-7.1.mga9
apache-commons-beanutils-javadoc-1.9.4-7.1.mga9

from SRPM:
apache-commons-beanutils-1.9.4-7.1.mga9.src.rpm

Status: NEW => ASSIGNED
Assignee: mageia => qa-bugs
Status comment: Fixed upstream in 1.11.0 => (none)

katnatek 2025-11-14 21:40:42 CET

Keywords: (none) => advisory

Comment 6 katnatek 2025-11-14 21:44:13 CET
installing apache-commons-beanutils-1.9.4-7.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ###################################################################################################
      1/1: apache-commons-beanutils
                                 ###################################################################################################
      1/1: removing apache-commons-beanutils-1.9.4-7.mga9.noarch
                                 ###################################################################################################

Clean update

Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-11-15 02:54:13 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 8 Dan Fandrich 2025-11-15 07:28:33 CET
The advisory text says:

  Also, the apache-commons-collections package has been rebuilt to
  regenerate the OSGi metadata, to allow the apache-commons-beanutils
  package to build.

but there is no apache-commons-collections package in updates_testing. Is this line valid?

CC: (none) => dan

Comment 9 katnatek 2025-11-15 18:28:09 CET
(In reply to Dan Fandrich from comment #8)
> The advisory text says:
> 
>   Also, the apache-commons-collections package has been rebuilt to
>   regenerate the OSGi metadata, to allow the apache-commons-beanutils
>   package to build.
> 
> but there is no apache-commons-collections package in updates_testing. Is
> this line valid?

Fixed, thank you I have other tab from previous round and I select text from the wromg one
Comment 10 Mageia Robot 2025-11-15 20:53:42 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0299.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.