CVE-2024-29133

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:commons_configuration:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

History

01 May 2025, 19:12

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/03/20/3 - () http://www.openwall.com/lists/oss-security/2024/03/20/3 - Mailing List, Third Party Advisory
References () https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2 - () https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2 - Mailing List, Vendor Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7/ - Third Party Advisory
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS/ - Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
cpe:2.3:a:apache:commons_configuration:*:*:*:*:*:*:*:*
First Time Apache
Apache commons Configuration
Fedoraproject
Fedoraproject fedora

13 Feb 2025, 18:17

Type Values Removed Values Added
Summary (en) Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue. (en) Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

21 Nov 2024, 09:07

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2024/03/20/3 - () http://www.openwall.com/lists/oss-security/2024/03/20/3 -
References () https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2 - () https://lists.apache.org/thread/ccb9w15bscznh6tnp3wsvrrj9crbszh2 -
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7/ -
References () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS/ - () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS/ -

04 Nov 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

01 May 2024, 17:15

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2024/03/20/3 -

30 Mar 2024, 02:15

Type Values Removed Values Added
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SNKDKEEKZNL5FGCTZKJ6CFXFVWFL5FJ7/ -

29 Mar 2024, 05:15

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de escritura fuera de los límites en la configuración de Apache Commons. Este problema afecta a la configuración de Apache Commons: desde 2.0 antes de 2.10.1. Se recomienda a los usuarios actualizar a la versión 2.10.1, que soluciona el problema.
References
  • () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YD4AFTIIQW662LUAQRMWS6BBKYSZG3YS/ -

21 Mar 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 09:15

Updated : 2025-05-01 19:12


NVD link : CVE-2024-29133

Mitre link : CVE-2024-29133

CVE.ORG link : CVE-2024-29133


JSON object : View

Products Affected

apache

  • commons_configuration

fedoraproject

  • fedora
CWE
CWE-787

Out-of-bounds Write