Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-4245

Опубликовано: 25 сент. 2023
Источник: debian

Описание

A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
plexus-utils2fixed3.0.24-1package

Примечания

  • https://security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-461102

  • https://github.com/codehaus-plexus/plexus-utils/commit/f933e5e78dc2637e485447ed821fe14904f110de (plexus-utils-3.0.24)

  • https://github.com/codehaus-plexus/plexus-utils/issues/3

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 2 лет назад

A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.

CVSS3: 4.3
redhat
около 3 лет назад

A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.

CVSS3: 4.3
nvd
больше 2 лет назад

A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.

CVSS3: 4.3
github
больше 2 лет назад

codehaus-plexus vulnerable to XML injection

CVSS3: 4.3
fstec
около 3 лет назад

Уязвимость библиотеки codehaus-plexus фреймворка Apache Maven, связана с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю выполнить произвольный код

Уязвимость CVE-2022-4245