CVE-2022-4065

A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 7.5.1 and 7.7.1 is able to address this issue. The patch is named 9150736cd2c123a6a3b60e6193630859f9f0422b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-214027.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
testng_projecttestng
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
testng
bookworm
6.9.12-4
fixed
bullseye
6.9.12-4
fixed
sid
6.9.12-4
fixed
trixie
6.9.12-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
testng
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
snakeyaml
suse enterprise desktop 15 SP5
2.2-150200.3.15.1
fixed
suse enterprise desktop 15 SP6
2.2-150200.3.15.1
fixed
suse enterprise desktop 15 SP7
2.2-150200.3.15.1
fixed
suse enterprise sap 15 SP2
2.2-150200.3.15.1
fixed
suse enterprise sap 15 SP3
2.2-150200.3.15.1
fixed
suse enterprise sap 15 SP4
2.2-150200.3.15.1
fixed
suse enterprise sap 15 SP5
2.2-150200.3.15.1
fixed
suse enterprise sap 15 SP6
2.2-150200.3.15.1
fixed
suse enterprise sap 15 SP7
2.2-150200.3.15.1
fixed
suse enterprise server 15 SP2
2.2-150200.3.15.1
fixed
suse enterprise server 15 SP3
2.2-150200.3.15.1
fixed
suse enterprise server 15 SP4
2.2-150200.3.15.1
fixed
suse enterprise server 15 SP5
2.2-150200.3.15.1
fixed
suse enterprise server 15 SP6
2.2-150200.3.15.1
fixed
suse enterprise server 15 SP7
2.2-150200.3.15.1
fixed
testng
suse enterprise desktop 15 SP5
7.4.0-150200.3.7.1
fixed
suse enterprise desktop 15 SP6
7.4.0-150200.3.7.1
fixed
suse enterprise desktop 15 SP7
7.4.0-150200.3.7.1
fixed
suse enterprise sap 15 SP2
7.10.1-150200.3.10.1
fixed
suse enterprise sap 15 SP3
7.10.1-150200.3.10.1
fixed
suse enterprise sap 15 SP4
7.10.1-150200.3.10.1
fixed
suse enterprise sap 15 SP5
7.4.0-150200.3.7.1
fixed
suse enterprise sap 15 SP6
7.4.0-150200.3.7.1
fixed
suse enterprise sap 15 SP7
7.4.0-150200.3.7.1
fixed
suse enterprise server 15 SP2
7.10.1-150200.3.10.1
fixed
suse enterprise server 15 SP3
7.10.1-150200.3.10.1
fixed
suse enterprise server 15 SP4
7.10.1-150200.3.10.1
fixed
suse enterprise server 15 SP5
7.4.0-150200.3.7.1
fixed
suse enterprise server 15 SP6
7.4.0-150200.3.7.1
fixed
suse enterprise server 15 SP7
7.4.0-150200.3.7.1
fixed