Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-33980

55
FAUCET Score

CVE-2022-33980 is a critical vulnerability in Apache Commons Configuration versions 2.4 through 2.7, allowing arbitrary code execution or remote server contact if untrusted configuration values are processed. This flaw stems from default inclusion of "script", "dns", and "url" interpolators, which can dynamically evaluate expressions, resolve DNS records, or load values from URLs. The vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4, < 2.8CPE matchmatch criteria
cpe:2.3:a:apache:commons_configuration:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
42.65%
Probability of exploitation in next 30 days
EPSS Percentile
98.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.4265 is in the 96th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

mavenpatch availablevia ghsa
Product: org.apache.commons:commons-configuration2Fixed in: 2.8.0
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 6.13 for RHEL 8Fixed in: candlepin-0:4.2.13-1.el8sat
View patch
redhatpatch availablevia redhat_api
Product: AMQ Broker 7.10.1Fixed in: commons-configuration2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11.1Fixed in: commons-configuration2
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: jenkins-2-plugins
redhatno patchvia redhat_api
Product: Red Hat support for Spring BootFixed in: commons-configuration2
redhatno patchvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: commons-configuration2
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: jenkins-2-plugins

Vendor Advisories (2)

mavenGHSA-xj57-8qj4-c4m6critical

Code injection in Apache Commons Configuration

Jul 7, 2022
redhatCVE-2022-33980Moderate

apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults

Jul 6, 2022

References

lists.apache.org / thread/tdf5n7j80lfxdhs2764vn0xmpfodm87s
Mailing ListVendor Advisory
security.netapp.com / advisory/ntap-20221028-0015
Third Party Advisory
debian.org / security/2022/dsa-5290
Third Party Advisory
openwall.com / lists/oss-security/2022/07/06/5
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2022/11/15/4
Mailing ListThird Party Advisory