More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2368956 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
I don't maintain this package anymore. I orphaned it in January. In any case, the linked bug says that the vulnerability is in apache-commons-beanutils. Why have you filed this bug against apache-commons-configuration?
This might be a false positive match. Is beanutils included as a dependency perhaps?
Not affected. Vulnerable code not present. Yes indeed, commons-beanutils is a dependency of commons-configuration.