Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-337m-mw94-2v6g

Опубликовано: 14 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Apache Commons Configuration: StackOverflowError for YAML input with cycles

Uncontrolled Recursion vulnerability in Apache Commons.

When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0.

Users are recommended to upgrade to version 2.15.0, which fixes the issue.

Пакеты

Наименование

org.apache.commons:commons-configuration2

maven
Затронутые версииВерсия исправления

>= 2.2, < 2.15.0

2.15.0

EPSS

Процентиль: 38%
0.00469
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-674

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 7.5
redhat
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 5.3
nvd
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Commons: from 2.2 before 2.15.0. Users are recommended to upgrade to version 2.15.0, which fixes the issue.

CVSS3: 5.3
debian
3 месяца назад

Uncontrolled Recursion vulnerability in Apache Commons. When processi ...

suse-cvrf
около 1 месяца назад

Security update for apache-commons-configuration2, apache-commons-text

EPSS

Процентиль: 38%
0.00469
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-674