Bug 2270673 (CVE-2024-29133)

Summary: CVE-2024-29133 commons-configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Product: [Other] Security Response Reporter: TEJ RATHI <trathi>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: adupliak, aileenc, anstephe, apjagtap, asatyam, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, cmiranda, cmoulliard, darran.lofthouse, dhanak, diagrawa, dkreling, dosoudil, dpalmer, drichtar, ecerquei, fjuma, fmariani, fmongiar, gmalinko, ibek, ikanello, ivassile, iweiss, janstey, jnethert, jpoth, jrokos, jross, kverlaen, lgao, lthon, mnovotny, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, pcongius, pdelbell, pdrozd, peholase, pgallagh, pjindal, pmackay, porcelli, pskopek, rguimara, rjohnson, rkieley, rowaters, rruss, rstancel, sabiswas, saroy, smaestri, sthorger, tcunning, tom.jenkinson, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: commons-configuration 2.10.1 Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in Apache Commons-Configuration2, where a Stack Overflow Error occurs when calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree. This issue could allow an attacker to trigger an out-of-bounds write that could lead to memory corruption or cause a denial of service condition.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2270689    
Bug Blocks: 2270899    

Description TEJ RATHI 2024-03-21 11:10:28 UTC
Out-of-bounds Write vulnerability in Apache Commons Configuration.

Affected versions:

- Apache Commons Configuration 2.0 before 2.10.1

References:

https://www.cve.org/CVERecord?id=CVE-2024-29133
https://issues.apache.org/jira/browse/CONFIGURATION-841

Comment 5 TEJ RATHI 2024-03-21 12:54:05 UTC
Created apache-commons-configuration tracking bugs for this issue:

Affects: fedora-39 [bug 2270689]