Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-29131

Опубликовано: 20 мар. 2024
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

A vulnerability was found in Apache Commons-Configuration2, where a Stack Overflow Error can occur when adding a property in AbstractListDelimiterHandler.flattenIterator(). This issue could allow an attacker to corrupt memory or execute a denial of service attack by crafting malicious property that triggers an out-of-bounds write issue when processed by the vulnerable method.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AMQ Clientscommons-configuration2Not affected
A-MQ Clients 2commons-configuration2Will not fix
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
Red Hat build of Apache Camel 4 for Quarkus 3commons-configuration2Not affected
Red Hat build of Apache Camel for Spring Boot 3commons-configuration2Not affected
Red Hat build of Apache Camel for Spring Boot 4commons-configuration2Not affected
Red Hat build of OptaPlanner 8commons-configuration2Not affected
Red Hat Data Grid 8commons-configuration2Not affected
Red Hat Fuse 7commons-configuration2Out of support scope
Red Hat Integration Camel K 1commons-configuration2Will not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-121->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2270674commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

EPSS

Процентиль: 42%
0.00203
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 2 года назад

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

CVSS3: 7.3
nvd
почти 2 года назад

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

CVSS3: 7.3
debian
почти 2 года назад

Out-of-bounds Write vulnerability in Apache Commons Configuration.This ...

CVSS3: 6.5
github
почти 2 года назад

Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()

CVSS3: 9.8
fstec
почти 2 года назад

Уязвимость функции AbstractListDelimiterHandler.flattenIterator() библиотеки Apache Commons Configuration, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 42%
0.00203
Низкий

4.4 Medium

CVSS3