Bug 2270674 (CVE-2024-29131)

Summary: CVE-2024-29131 commons-configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Product: [Other] Security Response Reporter: TEJ RATHI <trathi>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: adupliak, aileenc, anstephe, apjagtap, asatyam, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, cmiranda, cmoulliard, darran.lofthouse, dhanak, diagrawa, dkreling, dosoudil, dpalmer, drichtar, ecerquei, fjuma, fmariani, fmongiar, gmalinko, ibek, ikanello, ivassile, iweiss, janstey, jnethert, jpoth, jrokos, jross, kverlaen, lgao, lthon, mnovotny, mosmerov, msochure, mstefank, msvehla, mulliken, nwallace, pcongius, pdelbell, pdrozd, peholase, pgallagh, pjindal, pmackay, porcelli, pskopek, rguimara, rjohnson, rkieley, rowaters, rruss, rstancel, sabiswas, saroy, smaestri, sthorger, tcunning, tom.jenkinson, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: commons-configuration 2.10.1 Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in Apache Commons-Configuration2, where a Stack Overflow Error can occur when adding a property in AbstractListDelimiterHandler.flattenIterator(). This issue could allow an attacker to corrupt memory or execute a denial of service attack by crafting malicious property that triggers an out-of-bounds write issue when processed by the vulnerable method.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2270689    
Bug Blocks: 2270899    

Description TEJ RATHI 2024-03-21 11:10:32 UTC
Out-of-bounds Write vulnerability in Apache Commons Configuration.

Affected versions:

- Apache Commons Configuration 2.0 before 2.10.1

References:

https://www.cve.org/CVERecord?id=CVE-2024-29131
https://issues.apache.org/jira/browse/CONFIGURATION-840

Comment 5 TEJ RATHI 2024-03-21 12:54:22 UTC
Created apache-commons-configuration tracking bugs for this issue:

Affects: fedora-39 [bug 2270689]

Comment 11 errata-xmlrpc 2024-05-21 14:19:04 UTC
This issue has been addressed in the following products:

  Red Hat JBoss AMQ

Via RHSA-2024:2945 https://access.redhat.com/errata/RHSA-2024:2945

Comment 12 Valerie Sroka 2024-06-08 02:47:01 UTC
Updated affects to be out of new status to resolve sla issues