Apache Commons Configuration
cpe:2.3:a:apache:commons_configuration:*:*:*:*:*:*:*
- >= 2.2, < 2.15.0
A vulnerability allowing uncontrolled recursion has been identified in Apache Commons Configuration versions 2.2 prior to 2.15.0. When processing untrusted YAML configuration files that contain cycles, the library can enter an infinite loop, leading to a StackOverflowError. This issue arises from the inability to detect and manage processing cycles in the YAML input.
Exploitation of this vulnerability causes a StackOverflowError, leading to a denial of service condition where the application crashes or becomes unresponsive.
Users are advised to upgrade to Apache Commons Configuration version 2.15.0 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.