In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
References
| Link | Resource |
|---|---|
| https://github.com/apache/maven-shared-utils/pull/40 | Patch Third Party Advisory |
| https://issues.apache.org/jira/browse/MSHARED-297 | Patch Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/05/23/3 | Mailing List Third Party Advisory |
Configurations
Information
Published : 2022-05-23 11:16
Updated : 2022-06-03 15:07
NVD link : CVE-2022-29599
Mitre link : CVE-2022-29599
JSON object : View
Products Affected
apache
- maven_shared_utils
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
