CVE-2024-29133: Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Out-of-bounds Write vulnerability in Apache Commons Configuration.
Affected versions:
- Apache Commons Configuration 2.0 before 2.10.1
References:
https://www.cve.org/CVERecord?id=CVE-2024-29133 https://issues.apache.org/jira/browse/CONFIGURATION-841
Other sources
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue.
— MITRE
This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-29133?
CVE-2024-29133 is considered a critical severity vulnerability due to potential arbitrary code execution.
How can I mitigate CVE-2024-29133?
To mitigate CVE-2024-29133, upgrade to Apache Commons Configuration version 2.10.1 or later.
Which software is affected by CVE-2024-29133?
CVE-2024-29133 affects Apache Commons Configuration versions between 2.0 and 2.10.1, as well as IBM Analytics Content Hub versions up to 2.0.
What type of attack does CVE-2024-29133 enable?
CVE-2024-29133 enables remote attackers to execute arbitrary code on the system by sending specially crafted requests.
Is there a fix available for CVE-2024-29133?
Yes, the fix for CVE-2024-29133 is available in Apache Commons Configuration version 2.10.1.