CVE-2025-48734
envgap__dependency-check__DependencyCheck-7704
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
e49d28d93f6ed08d9adff4e76ecbaeedeccdf47e- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
dependency-check/DependencyCheck #7704 · read the original issue
Hi,
Are there plans to bump dependency for common-beanutils to v1.11.0 in upcoming releases?
CVE-2025-48734 has been flagged out in Dependency check v12.1.0
Trivy Scan:
{
"VulnerabilityID": "CVE-2025-48734",
"PkgName": "commons-beanutils:commons-beanutils",
"PkgPath": "usr/share/dependency-check/lib/commons-beanutils-1.9.4.jar",
"PkgIdentifier": {
"PURL": "pkg:maven/commons-beanutils/commons-beanutils@1.9.4",
"UID": "e6a50b692f42c7fb"
},
"InstalledVersion": "1.9.4",
"FixedVersion": "1.11.0",
"Status": "fixed",04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]