A vulnerability, which was classified as critical, has been found in Apache Commons Configuration up to 2.10.0. Affected by this issue is some unknown functionality of the component Configuration Handler. The manipulation leads to out-of-bounds write.

This vulnerability is handled as CVE-2024-29131. Access to the local network is required for this attack to succeed. There is no exploit available.

It is recommended to upgrade the affected component.