{"api_version":"v1","generated_at":"2026-10-06T08:00:00+00:00","product":{"cve_count":5,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-commons-configuration-2a6202074dfa","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Commons Configuration","next_cursor":null,"observations":[{"affected":"2.2 < 2.15.0","affected_versions_present":true,"cve_id":"CVE-2026-45205","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45205","fixed":"Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings. The References section of this erratum contains a download link (you must log in to download the update).","last_modified":"2026-05-14T20:31:47.159Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-45205","primary_source":"","published":"2026-05-14T11:22:43.908Z"},{"affected":"1 < 2.0.0","affected_versions_present":true,"cve_id":"CVE-2025-46392","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-46392","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-13T19:15:39.662Z","patch_url":"","primary_source":"","published":"2025-05-09T09:34:38.854Z"},{"affected":"2.0 < 2.10.1","affected_versions_present":true,"cve_id":"CVE-2024-29131","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29131","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:47:38.259Z","patch_url":"","primary_source":"","published":"2024-03-21T09:07:13.627Z"},{"affected":"2.0 < 2.10.1","affected_versions_present":true,"cve_id":"CVE-2024-29133","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29133","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T17:47:38.808Z","patch_url":"","primary_source":"","published":"2024-03-21T09:05:47.597Z"},{"affected":"Apache Commons Configuration < 2.8.0","affected_versions_present":true,"cve_id":"CVE-2022-33980","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-33980","fixed":"For Red Hat Satellite 6.13, see the following documentation for the release. https://access.redhat.com/documentation/en-us/red_hat_satellite/6.13 The important instructions on how to upgrade are available below. https://access.redhat.com/documentation/en-us/red_hat_satellite/6.13/html/upgrading_and_updating_red_hat_satellite","last_modified":"2024-08-03T08:16:16.672Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-33980","primary_source":"","published":"2022-07-06T00:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
