USN-8322-2

Source
https://ubuntu.com/security/notices/USN-8322-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-2.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-8322-2
Upstream
Published
2026-07-23T10:39:20Z
Modified
2026-07-23T21:13:49.067399314Z
Summary
commons-beanutils regression
Details

USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was discovered that for Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was incorrectly dropped. This update reintroduces the fix for CVE-2014-0114 and CVE-2019-10086.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Apache Commons BeanUtils incorrectly allowed access to the declaredClass property of Java enum objects when handling externally supplied property paths. An attacker could possibly use this issue to execute arbitrary code.

References

Affected packages

Ubuntu:Pro:16.04:LTS / commons-beanutils

Package

Name
commons-beanutils
Purl
pkg:deb/ubuntu/commons-beanutils?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.2-3ubuntu0.1~esm2

Affected versions

1.*
1.9.2-1
1.9.2-2
1.9.2-3
1.9.2-3ubuntu0.1~esm1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_name": "libcommons-beanutils-java",
            "binary_version": "1.9.2-3ubuntu0.1~esm2"
        }
    ]
}

Database specific

cves_map
{
    "cves": [
        {
            "id": "CVE-2014-0114",
            "severity": [
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        },
        {
            "id": "CVE-2019-10086",
            "severity": [
                {
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type": "CVSS_V3"
                },
                {
                    "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ]
        }
    ],
    "ecosystem": "Ubuntu:Pro:16.04:LTS"
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8322-2.json"