CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue affects Apache Common...Show more |
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted conf...Show more |
2Apache Fedoraproject2Commons Configuration FedoraJun 17, 2026 Mar 21, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue. |
3Apache FedoraprojectNetapp4Commons Configuration FedoraOntap Tools+1 moreJun 17, 2026 Mar 21, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue. |
3Apache DebianNetapp3Commons Configuration Debian LinuxSnapcenterJun 17, 2026 Jul 6, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an i...Show more |
2Apache Oracle3Commons Configuration Database ServerHealthcare FoundationJun 17, 2026 Mar 13, 2020 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration versions 2.2, 2.3, 2....Show more |