| Release | Version |
|---|---|
| bullseye | 2.8.0-1~deb11u1 |
| bookworm | 2.8.0-2 |
| trixie | 2.11.0-2 |
| forky | 2.11.0-2 |
| sid | 2.11.0-3 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2024-29133 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fixed | Out-of-bounds Write vulnerability in Apache Commons Configuration.This ... |
| CVE-2024-29131 | vulnerable (no DSA) | vulnerable (no DSA) | fixed | fixed | fixed | Out-of-bounds Write vulnerability in Apache Commons Configuration.This ... |
| Bug | Description |
|---|---|
| CVE-2025-46392 | Uncontrolled Resource Consumption vulnerability in Apache Commons Conf ... |
| CVE-2022-33980 | Apache Commons Configuration performs variable interpolation, allowing ... |
| CVE-2020-1953 | Apache Commons Configuration uses a third-party library to parse YAML ... |
| DSA / DLA | Description |
|---|---|
| DSA-5290-1 | commons-configuration2 - security update |