Описание
com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
Пакеты
Наименование
com.google.cloud.tools:jib-core
maven
Затронутые версииВерсия исправления
< 0.22.0
0.22.0
Связанные уязвимости
CVSS3: 9.8
redhat
больше 3 лет назад
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
CVSS3: 5.6
nvd
больше 3 лет назад
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.