<Vulnerability name="CVE-2022-33980">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2022-07-06T00:00:00</PublicDate>
    <Bugzilla id="2105067" url="https://bugzilla.redhat.com/show_bug.cgi?id=2105067" xml:lang="en:us">
apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <Details xml:lang="en:us" source="Mitre">
Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup that performs the interpolation. Starting with version 2.4 and continuing through 2.7, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Configuration 2.8.0, which disables the problematic interpolators by default.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Apache Commons Configuration's variable interpolation, which by default included several lookup actions that could permit script invocation on remote servers. This issue could allow an attacker to use one of these actions to send a request to execute arbitrary code on the server.
    </Details>
    <Statement xml:lang="en:us">
Red Hat Satellite embeds affected commons-configuration2 with Candlepin, however, product is not affected since vulnerable org.apache.commons.configuration2.interpol.Lookup is not exposed in code. Product Security has rated this vulnerability Low for Satellite and there is no harm identified to confidentiality, integrity, and availability.
    </Statement>
    <AffectedRelease cpe="cpe:/a:redhat:amq_broker:7">
        <ProductName>AMQ Broker 7.10.1</ProductName>
        <ReleaseDate>2022-10-12T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2022:6916">RHSA-2022:6916</Advisory>
        <Package name="commons-configuration2">commons-configuration2</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:jboss_fuse:7">
        <ProductName>Red Hat Fuse 7.11.1</ProductName>
        <ReleaseDate>2022-11-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2022:8652">RHSA-2022:8652</Advisory>
        <Package name="commons-configuration2">commons-configuration2</Package>
    </AffectedRelease>
    <AffectedRelease impact="low" cpe="cpe:/a:redhat:satellite:6.13::el8">
        <ProductName>Red Hat Satellite 6.13 for RHEL 8</ProductName>
        <ReleaseDate>2023-05-03T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2023:2097">RHSA-2023:2097</Advisory>
        <Package name="candlepin">candlepin-0:4.2.13-1.el8sat</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:a_mq_clients:2">
        <ProductName>A-MQ Clients 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:amq_online:1">
        <ProductName>Red Hat A-MQ Online</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quarkus:2">
        <ProductName>Red Hat build of Quarkus</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_data_grid:8">
        <ProductName>Red Hat Data Grid 8</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_brms_platform:7">
        <ProductName>Red Hat Decision Manager 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:integration:1">
        <ProductName>Red Hat Integration Camel K 1</ProductName>
        <FixState>Affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_data_grid:7">
        <ProductName>Red Hat JBoss Data Grid 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_application_platform:7">
        <ProductName>Red Hat JBoss Enterprise Application Platform 7</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jbosseapxp">
        <ProductName>Red Hat JBoss Enterprise Application Platform Expansion Pack</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:3.11">
        <ProductName>Red Hat OpenShift Container Platform 3.11</ProductName>
        <FixState>Will not fix</FixState>
        <PackageName>jenkins-2-plugins</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift:4">
        <ProductName>Red Hat OpenShift Container Platform 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>jenkins-2-plugins</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:jboss_enterprise_bpms_platform:7">
        <ProductName>Red Hat Process Automation 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_application_runtimes:1.0">
        <ProductName>Red Hat support for Spring Boot</ProductName>
        <FixState>Affected</FixState>
        <PackageName>commons-configuration2</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2022-33980
https://nvd.nist.gov/vuln/detail/CVE-2022-33980
    </References>
</Vulnerability>