-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from how flattenIterator handles Iterable objects. The commit diff shows a specific check was added for Path objects to break the recursion chain. The JIRA ticket CONFIGURATION-840 and test case demonstrate that Path objects triggered infinite recursion in this method. The CWE-787 classification aligns with uncontrolled recursion causing stack exhaustion (a form of out-of-bounds write).
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.commons:commons-configuration2 | maven | >= 2.0, < 2.10.1 | 2.10.1 |
KEV Misses 88% of Exploited CVEs- Get the report