OSV-2022-871

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/apache-commons-configuration/OSV-2022-871.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2022-871
Published
2022-09-10T00:00:24.780487Z
Modified
2024-08-27T14:15:10.826875Z
Summary
Security exception in java.base/java.util.Collections$UnmodifiableCollection.forEach
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51154

Crash type: Security exception
Crash state:
java.base/java.util.Collections$UnmodifiableCollection.forEach
org.apache.commons.configuration2.tree.NodeTreeWalker.dfs
org.apache.commons.configuration2.tree.NodeTreeWalker.lambda$dfs$0
References

Affected packages

OSS-Fuzz / apache-commons-configuration

Package

Name
apache-commons-configuration
Purl
pkg:generic/apache-commons-configuration

Affected ranges

Type
GIT
Repo
https://gitbox.apache.org/repos/asf/commons-configuration.git
Events
Introduced
4117b2050ab011f131d5a81c824bf89ddde303d4
Fixed
2dd35aafc88f45f12c7eea052c3dfc515cbf3526

Affected versions

commons-configuration-2.*

commons-configuration-2.10.0-RC1
commons-configuration-2.10.1-RC1
commons-configuration-2.11.0-RC1
commons-configuration-2.9.0-RC1

rel/commons-configuration-2.*

rel/commons-configuration-2.10.0
rel/commons-configuration-2.10.1
rel/commons-configuration-2.11.0
rel/commons-configuration-2.9.0

Ecosystem specific

{
    "severity": "LOW"
}