cbcvebase.

Debian Commons-Configuration2 vulnerabilities

4 known vulnerabilities affecting debian/commons-configuration2.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2022-33980P2CRITICALCVSS 9.8fixed in commons-configuration2 2.8.0-1 (bookworm)2022
CVE-2022-33980 [CRITICAL] CVE-2022-33980: commons-configuration2 - Apache Commons Configuration performs variable interpolation, allowing propertie... Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and conti
debian
CVE-2020-1953P2CRITICALCVSS 10.0fixed in commons-configuration2 2.7-1 (bookworm)2020
CVE-2020-1953 [CRITICAL] CVE-2020-1953: commons-configuration2 - Apache Commons Configuration uses a third-party library to parse YAML files whic... Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2.4, 2.5, 2.6 did not change the default settings of this library. So if a YAML file was loaded from an untrusted source, it could th
debian
CVE-2024-29131P3HIGHCVSS 7.3fixed in commons-configuration2 2.10.1-1 (forky)2024
CVE-2024-29131 [HIGH] CVE-2024-29131: commons-configuration2 - Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue aff... Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.10.1-1) sid: resolved (fixed in 2.10.1-1) trixie: resolved (fixed in
debian
CVE-2024-29133P4MEDIUMCVSS 5.4fixed in commons-configuration2 2.10.1-1 (forky)2024
CVE-2024-29133 [MEDIUM] CVE-2024-29133: commons-configuration2 - Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue aff... Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.10.1-1) sid: resolved (fixed in 2.10.1-1) trixie: resolved (fixed
debian
Debian Commons-Configuration2 vulnerabilities | cvebase