CVE-2024-29131: Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Out-of-bounds Write vulnerability in Apache Commons Configuration.
Affected versions:
- Apache Commons Configuration 2.0 before 2.10.1
References:
https://www.cve.org/CVERecord?id=CVE-2024-29131 https://issues.apache.org/jira/browse/CONFIGURATION-840
Other sources
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue.
— MITRE
This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29131?
CVE-2024-29131 has a critical severity rating due to its potential to allow remote code execution.
How do I fix CVE-2024-29131?
To fix CVE-2024-29131, upgrade Apache Commons Configuration to version 2.10.1 or later.
Which software is affected by CVE-2024-29131?
CVE-2024-29131 affects Apache Commons Configuration versions prior to 2.10.1, as well as IBM's Analytics Content Hub up to version 2.0.
What type of vulnerability is CVE-2024-29131?
CVE-2024-29131 is an out-of-bounds write vulnerability that can lead to arbitrary code execution.
Who can exploit CVE-2024-29131?
CVE-2024-29131 can be exploited by remote attackers who send specially crafted requests.