SCA: security update for commons-configuration:commons-configuration (GHSA-pvp8-3xj6-8c6x)

medium Tenable Self-Hosted Container Security Plugin ID 446549

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of
issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading
untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does
not intend to fix these issues in 1.x. Apache Commons Configuration 1.x is still safe to use in scenario's
where you only load trusted configurations. Users that load untrusted configurations or give attackers
control over usage patterns are recommended to upgrade to the 2.x version line, which fixes these issues.
Apache Commons Configuration 2.x is not a drop-in replacement, but as it uses a separate Maven groupId and
Java package namespace they can be loaded side-by-side, making it possible to do a gradual migration.
(CVE-2025-46392)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-pvp8-3xj6-8c6x

Plugin Details

Severity: Medium

ID: 446549

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.69

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2025-46392

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/9/2025

Vulnerability Publication Date: 5/9/2025

Reference Information

CVE: CVE-2025-46392

cwe: CWE-400