Another gadget (*) type report regarding a class of commons-configuration (and later commons-configuration2) package(s)
Mitre id: not yet allocated
Reporter: @ybhou1993
Fixed in:
- 2.9.10 and later
- 2.8.11.5
- 2.6.7.3
- does not affect 2.10.0 and later
(*) See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for more on general problem type