{
"advisory": {
"aliases": [
"CVE-2025-46392"
],
"cve": "CVE-2025-46392",
"id": "GHSA-pvp8-3xj6-8c6x",
"type": "component_with_known_vulnerability"
},
"base_severity": "medium",
"code_location": {
"column_end": 22,
"column_start": 9,
"filename": "test/plugin/scenarios/hystrix-scenario/pom.xml",
"line_end": 77,
"line_start": 73
},
"detection_changed_at": 1766518394577,
"finding_id": "ZXhhbXBsZS1saWJyYXJ5LXZ1bG4tMTIzNDU2Nzg5MGFi",
"finding_type": "library_vulnerability",
"first_seen_at": 1763488117383,
"git": {
"author": {
"name": "ci-bot"
},
"default_branch": "main",
"is_default_branch": true,
"repository_id": "github.com/example-org/java-app",
"repository_url": "github.com/example-org/java-app",
"sha": "abc123def456789012345678901234567890abcd"
},
"is_in_security_inbox": false,
"last_seen_at": 1766522443454,
"metadata": {
"schema_version": "2"
},
"origin": [
"ci"
],
"package": {
"declaration": {
"block": {
"column_end": 22,
"column_start": 9,
"filename": "test/plugin/scenarios/hystrix-scenario/pom.xml",
"line_end": 77,
"line_start": 73
},
"name": {
"column_end": 37,
"column_start": 25,
"filename": "test/plugin/scenarios/hystrix-scenario/pom.xml",
"line_end": 75,
"line_start": 75
},
"version": {
"column_end": 39,
"column_start": 33,
"filename": "test/plugin/scenarios/hystrix-scenario/pom.xml",
"line_end": 34,
"line_start": 34
}
},
"dependency_type": "transitive",
"manager": "maven",
"name": "commons-configuration:commons-configuration",
"normalized_name": "commons-configuration:commons-configuration",
"root_parents": [
{
"declaration": {
"version": {
"column_end": 39,
"column_start": 33,
"filename": "test/plugin/scenarios/hystrix-scenario/pom.xml",
"line_end": 34,
"line_start": 34
}
},
"language": "jvm",
"name": "com.netflix.hystrix:hystrix-core",
"version": "1.4.20"
}
],
"scope": "production",
"version": "1.8"
},
"related_services": [
"example-service"
],
"remediation": {
"description": "Try upgrading to a version > 1.10 (if released)",
"is_available": true,
"package": {
"closest_no_vulnerabilities": [
{
"fixed_advisories": [
{
"base_severity": "medium",
"id": "GHSA-pvp8-3xj6-8c6x"
}
],
"name": "org.apache.commons:commons-configuration2",
"version": "2.10.1"
}
],
"latest_no_vulnerabilities": [
{
"fixed_advisories": [
{
"base_severity": "medium",
"id": "GHSA-pvp8-3xj6-8c6x"
}
],
"name": "commons-configuration:commons-configuration",
"version": "20041012.002804"
}
]
},
"recommended": {
"fixed_advisories": [
{
"base_severity": "medium",
"id": "GHSA-pvp8-3xj6-8c6x"
}
],
"name": "org.apache.commons:commons-configuration2",
"original_library_name": "commons-configuration:commons-configuration",
"version": "2.10.1",
"vulnerable_package": true
}
},
"resource_id": "abc123def456789012345678901234ab",
"resource_name": "github.com/example-org/java-app",
"resource_type": "repository",
"risk": {
"has_exploit_available": false,
"has_high_exploitability_chance": false,
"is_exposed_to_attacks": false,
"is_function_reachable": false,
"is_production": true
},
"risk_details": {
"has_exploit_available": {
"evidence": {
"type": "unavailable"
},
"impact_cvss": "safer",
"value": false
},
"has_high_exploitability_chance": {
"evidence": {
"epss_score": 0.00181,
"epss_severity": "low"
},
"impact_cvss": "safer",
"value": false
},
"is_exposed_to_attacks": {
"impact_cvss": "neutral",
"value": false
},
"is_function_reachable": {
"value": false
},
"is_production": {
"impact_cvss": "neutral",
"value": true
}
},
"severity": "low",
"severity_details": {
"adjusted": {
"score": 1.7,
"value": "low",
"value_id": 1,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/MAC:H"
},
"base": {
"score": 6.9,
"value": "medium",
"value_id": 2,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"
}
},
"status": "open",
"tags": [
"dd_rule_type:not-empty",
"team:backend",
"scored:false",
"origin:ci",
"source:datadog",
"service:example-service"
],
"title": "Apache Commons Configuration Uncontrolled Resource Consumption",
"vulnerability": {
"cwes": [
"CWE-400"
],
"first_commit": "abc123def456789012345678901234567890aaaa",
"hash": "abc123def456789012345678901234567890abcdef12345678901234567890ab",
"last_commit": "abc123def456789012345678901234567890abcd",
"stack": {
"ecosystem": "maven",
"language": "jvm"
}
},
"workflow": {
"mute": {
"is_muted": false
}
}
}