Improper Input Validation in Apache Commons BeanUtils (CVE-2014-0114) 

Issue date: 26-04-2018
Affects versions: 12.2, 11.2, 10.2

Issue ID: SECURITY-34

Affected Product Version(s)
This vulnerability affects all versions of both CMS and delivery applications based on Hippo CMS prior to 11.2.7 and 10.2.11, and also repository-only deployments prior to 12.3.0 and 12.2.1.

Severity 
high

Description

Apache Commons BeanUtils does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter. See: CVE-2014-0114

This vulnerability is classified with severity high, and may (also) apply to project specific usages of the Apache Commons BeanUtils libraries within a Hippo CMS project. 

The Apache Commons BeanUtils version in all supported CMS maintenance versions 10.2.11, 11.2.7, 12.2.1, and 12.3.0 has been updated to version 1.9.3.

Instructions

Every CMS customer is strongly advised to upgrade as soon as possible to the latest CMS maintenance release as indicated above, or higher.

Because the upgrade for these CMS maintenance versions may require some additonal steps and verification, specific upgrade documentation is available to our customers for upgrading to version 10.2.11, 11.2.7, or to 12.2.1 and 12.3.0 (login required).