CVE-2024-29131 is an out-of-bounds write vulnerability in Apache Commons Configuration, affecting versions 2.0 through 2.10.0. This high-severity flaw (CVSS 7.3) can be exploited remotely with low attack complexity, potentially leading to limited confidentiality, integrity, and availability impacts. While no public exploits or active exploitation are currently reported, the vulnerability has garnered some community discussion and media coverage, and users are advised to upgrade to version 2.10.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.10.1CPE matchmatch criteria | cpe:2.3:a:apache:commons_configuration:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.