← All tasks
javadependency-check/DependencyCheck #7704Not a task: already works

CVE-2025-48734

envgap__dependency-check__DependencyCheck-7704

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
e49d28d93f6ed08d9adff4e76ecbaeedeccdf47e
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

dependency-check/DependencyCheck #7704 · read the original issue
Hi,

Are there plans to bump dependency for common-beanutils to v1.11.0 in upcoming releases?
CVE-2025-48734 has been flagged out in Dependency check v12.1.0

Trivy Scan:
   {
          "VulnerabilityID": "CVE-2025-48734",
          "PkgName": "commons-beanutils:commons-beanutils",
          "PkgPath": "usr/share/dependency-check/lib/commons-beanutils-1.9.4.jar",
          "PkgIdentifier": {
            "PURL": "pkg:maven/commons-beanutils/commons-beanutils@1.9.4",
            "UID": "e6a50b692f42c7fb"
          },
          "InstalledVersion": "1.9.4",
          "FixedVersion": "1.11.0",
          "Status": "fixed",
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]