[Git][security-tracker-team/security-tracker][master] Add commons-configuration (1.x) for clarity to CVE-2026-45205

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 14 23:14:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e034be5d by Salvatore Bonaccorso at 2026-05-14T23:40:13+02:00
Add commons-configuration (1.x) for clarity to CVE-2026-45205

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -302,6 +302,7 @@ CVE-2026-45371 (SiYuan is an open-source personal knowledge management system. P
 	NOT-FOR-US: SiYuan
 CVE-2026-45205 (Uncontrolled Recursion vulnerability in Apache Commons.  When processi ...)
 	- commons-configuration2 <unfixed>
+	- commons-configuration <not-affected> (Vulnerable code not present)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/05/14/5
 	NOTE: https://github.com/apache/commons-configuration/pull/634
 	NOTE: https://github.com/apache/commons-configuration/commit/b51f6bf26e774f3416fdf782a5e1edf33f32ba82 (commons-configuration-2.15.0-RC1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e034be5daba41cc7491db86b53745db5dc1b7e6e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e034be5daba41cc7491db86b53745db5dc1b7e6e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260514/0681a500/attachment.htm>


More information about the debian-security-tracker-commits mailing list