Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:4798

Опубликовано: 30 мая 2022
Источник: rocky
Оценка: Important

Описание

Important: maven:3.5 security update

The Apache Maven Shared Utils project aims to be an improved functional replacement for plexus-utils in Maven.

Security Fix(es):

  • maven-shared-utils: Command injection via Commandline class (CVE-2022-29599)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
aopalliancenoarch17.module+el8.6.0+843+5a13dac3aopalliance-1.0-17.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-clinoarch4.module+el8.6.0+843+5a13dac3apache-commons-cli-1.4-4.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-codecnoarch3.module+el8.6.0+843+5a13dac3apache-commons-codec-1.11-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-ionoarch3.module+el8.6.0+843+5a13dac3apache-commons-io-2.6-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-lang3noarch3.module+el8.6.0+843+5a13dac3apache-commons-lang3-3.7-3.module+el8.6.0+843+5a13dac3.noarch.rpm
apache-commons-loggingnoarch13.module+el8.3.0+133+b8b54b58apache-commons-logging-1.2-13.module+el8.3.0+133+b8b54b58.noarch.rpm
atinjectnoarch28.20100611svn86.module+el8.6.0+843+5a13dac3atinject-1-28.20100611svn86.module+el8.6.0+843+5a13dac3.noarch.rpm
cdi-apinoarch8.module+el8.6.0+843+5a13dac3cdi-api-1.2-8.module+el8.6.0+843+5a13dac3.noarch.rpm
geronimo-annotationnoarch23.module+el8.6.0+843+5a13dac3geronimo-annotation-1.0-23.module+el8.6.0+843+5a13dac3.noarch.rpm
glassfish-el-apinoarch0.7.b08.module+el8.6.0+975+c0ed2db8glassfish-el-api-3.0.1-0.7.b08.module+el8.6.0+975+c0ed2db8.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVSS3: 9.8
redhat
около 5 лет назад

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVSS3: 9.8
nvd
около 3 лет назад

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVSS3: 9.8
debian
около 3 лет назад

In Apache Maven maven-shared-utils prior to version 3.3.3, the Command ...

CVSS3: 9.8
redos
около 1 года назад

Уязвимость maven-shared-utils