CVE-2022-29599

Name
CVE-2022-29599
Description
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/apache/maven-shared-utils/pull/40
MISC https://issues.apache.org/jira/browse/MSHARED-297
MLIST http://www.openwall.com/lists/oss-security/2022/05/23/3
Mailing List https://lists.debian.org/debian-lts-announce/2022/08/msg00018.html
Third Party Advisory https://www.debian.org/security/2022/dsa-5242

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:apache:maven_shared_utils:*:*:*:*:*:*:*:* maven_shared_utils >= None < 3.3.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status