CVE-2022-29599
23.05.2022, 11:16
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.Enginsight
| Vendor | Product | Version |
|---|---|---|
| apache | maven_shared_utils | 𝑥 < 3.3.3 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| maven-shared-utils |
|
References