Uploaded image for project: 'Commons Configuration'
  1. Commons Configuration
  2. CONFIGURATION-818

Stackoverflow bugs fixed in 2.8.0

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.7
    • 2.8.0
    • None

    Description

      Dear Apache Commons Configuration maintainers,

      The Code Intelligence JVM fuzzer Jazzer has found multiple vulnerabilities in Apache Commons Configuration during a fuzzing run in Google OSS-Fuzz. The vulnerabilities were already fixed. Version <= 2.7 of Apache Commons Configuration is vulnerable.

      Detailed Information can be found here:

      https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48737

      https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48610

      https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48522

      https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48391

      https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=48195

       

      Please let me know if you have any questions regarding fuzzing or the OSS-Fuzz integration.

      Attachments

        1. 48737.zip
          12.75 MB
          Henry Lin
        2. 48610.zip
          12.75 MB
          Henry Lin
        3. 48522.zip
          12.75 MB
          Henry Lin
        4. 48391.zip
          12.75 MB
          Henry Lin
        5. 48195.zip
          12.75 MB
          Henry Lin

        Activity

          People

            Unassigned Unassigned
            hlin Henry Lin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: