CVE-2022-29599

Aliases:GHSA-rhgr-952r-6p8qRHSA-2022:1541RHSA-2022:1662RHSA-2022:4699RHSA-2022:4797RHSA-2022:4798RHSA-2022:9098RHSA-2023:0573DEBIAN-CVE-2022-29599CGA-2f3w-7whv-hw66CGA-2mv7-hcxh-56frCGA-3399-2r6j-6wfmCGA-4488-gh5r-jmh8CGA-5gv7-r6wp-3jhrCGA-63h6-hrhg-5hj3CGA-6fh5-622c-7j7fCGA-6qv7-qgwc-733fCGA-6x7v-r4rp-752fCGA-73jr-vmqg-hf54CGA-7g7v-rh6w-c96qCGA-7j6g-g9xc-f3pwCGA-7j83-w38v-rh38CGA-7m5p-w35m-fr42CGA-89pw-c47c-mmm6CGA-962x-2jg3-4jfmCGA-9fvr-8g46-43p4CGA-9q2v-2vrp-2p96CGA-cvjg-jj29-6q7pCGA-f75w-m3mc-7vqgCGA-f8vw-3rcq-r594CGA-fcfc-2gvp-766xCGA-fg79-7872-g272CGA-fj4r-mm34-q536CGA-fph7-9m6c-j8w7CGA-g6pf-hr3r-mhfwCGA-g723-rf7x-595jCGA-h3jw-xmvc-hrr9CGA-h7qj-3rg2-h9m3CGA-hgp8-gvmp-vh92CGA-j468-33w2-v874CGA-j57w-gmxj-8j4hCGA-m52x-9pvj-r4j4CGA-mw3x-2j8f-j5f9CGA-p35m-wvgv-3379CGA-q8p6-8m3j-pffcCGA-r7mq-crrp-r67xCGA-r8r4-pcv6-5c48CGA-rcxw-hw34-jqv3CGA-rpgm-rwx7-q9r8CGA-rwhp-v8f5-6rj3CGA-rww3-j97p-gfh7CGA-v42p-wh75-2w66CGA-v9r4-3qr9-g86vCGA-vmv6-qp74-mpqmCGA-vq3m-qqhr-r78qCGA-wfcg-cq76-x8c4CGA-wfr8-8c5j-6g95CGA-wxpc-qc4h-9x6gCGA-x5g3-f9w6-2566CGA-x992-5vfm-f9qrCGA-xx9j-w58r-6mxh
Advisory lineage Upstream: 0 Downstream: 24
Modified
Published: 23 May 2022, 10:25
Last modified:03 Aug 2024, 06:26

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
4.42% LOW
4% probability +3.98%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 May 2022, 10:25
Published
Vulnerability first disclosed
03 Aug 2024, 06:26
Last Modified
Vulnerability information updated

Description

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 4.42% Percentile: 91%

Techniques & Countermeasures

  • CWE-116Improper Encoding or Escaping of Output

    The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Affected Systems

  • apache software foundationapache maven

    ≥ maven-shared-utils, < 3.3.3

  • apachemaven_shared_utils

    < 3.3.3

  • chainguardhadoop-fips-3.3.6

    all

  • chainguardhadoop-fips-3.4.2

    all

  • chainguardhadoop-fips-3.5

    all

  • debianmaven-shared-utils

    < 3.3.0-1+deb11u1 | < 3.3.4-1 | < 3.3.4-1 | < 3.3.4-1

  • debiandebian_linux

    10.0 | 11.0

  • org.apache.maven.sharedmaven-shared-utils

    < 3.3.3

  • redhataopalliance

    < 0:1.0-17.module+el8+2452+b359bfcd | < 0:1.0-20.module+el8.2.0+5557+11a14461 | < 0:1.0-20.module+el8.3.0+6804+157bd82e | < 0:1.0-20.module+el8.6.0+13337+afcb49ec

  • redhatapache-commons-cli

    < 0:1.4-4.module+el8+2452+b359bfcd | < 0:1.4-7.module+el8.2.0+5557+11a14461 | < 0:1.4-7.module+el8.3.0+6804+157bd82e | < 0:1.4-7.module+el8.6.0+13337+afcb49ec

  • redhatapache-commons-codec

    < 0:1.11-3.module+el8+2452+b359bfcd | < 0:1.13-3.module+el8.2.0+5557+11a14461 | < 0:1.13-3.module+el8.3.0+6804+157bd82e | < 0:1.13-3.module+el8.6.0+13337+afcb49ec

  • redhatapache-commons-io

    < 1:2.6-3.module+el8+2452+b359bfcd | < 1:2.6-6.module+el8.2.0+5557+11a14461 | < 1:2.6-6.module+el8.3.0+6804+157bd82e | < 1:2.6-6.module+el8.6.0+13337+afcb49ec

  • redhatapache-commons-lang3

    < 0:3.7-3.module+el8+2452+b359bfcd | < 0:3.9-4.module+el8.2.0+5557+11a14461 | < 0:3.9-4.module+el8.3.0+6804+157bd82e | < 0:3.9-4.module+el8.6.0+13337+afcb49ec

  • redhatapache-commons-logging

    < 0:1.2-13.module+el8+2452+b359bfcd

  • redhatatinject

    < 0:1-28.20100611svn86.module+el8+2452+b359bfcd | < 0:1-31.20100611svn86.module+el8.2.0+5557+11a14461 | < 0:1-31.20100611svn86.module+el8.3.0+6804+157bd82e | < 0:1-31.20100611svn86.module+el8.6.0+13337+afcb49ec

  • redhatcdi-api

    < 0:1.2-8.module+el8+2452+b359bfcd | < 0:2.0.1-3.module+el8.2.0+5557+11a14461 | < 0:2.0.1-3.module+el8.3.0+6804+157bd82e | < 0:2.0.1-3.module+el8.6.0+13337+afcb49ec

  • redhatgeronimo-annotation

    < 0:1.0-23.module+el8+2452+b359bfcd | < 0:1.0-26.module+el8.2.0+5557+11a14461 | < 0:1.0-26.module+el8.3.0+6804+157bd82e | < 0:1.0-26.module+el8.6.0+13337+afcb49ec

  • redhatglassfish-el

    < 0:3.0.1-0.7.b08.module+el8+2452+b359bfcd

  • redhatglassfish-el-api

    < 0:3.0.1-0.7.b08.module+el8+2452+b359bfcd

  • redhatgoogle-guice

    < 0:4.1-11.module+el8+2452+b359bfcd | < 0:4.2.2-4.module+el8.2.0+5557+11a14461 | < 0:4.2.2-4.module+el8.3.0+6804+157bd82e | < 0:4.2.2-4.module+el8.6.0+13337+afcb49ec

  • redhatguava

    < 0:28.1-3.module+el8.2.0+5557+11a14461 | < 0:28.1-3.module+el8.3.0+6804+157bd82e | < 0:28.1-3.module+el8.6.0+13337+afcb49ec

  • redhatguava20

    < 0:20.0-8.module+el8+2452+b359bfcd

  • redhathawtjni

    < 0:1.16-2.module+el8+2452+b359bfcd

  • redhathawtjni-runtime

    < 0:1.16-2.module+el8+2452+b359bfcd

  • redhathttpcomponents-client

    < 0:4.5.5-4.module+el8+2452+b359bfcd | < 0:4.5.10-3.module+el8.2.0+5557+11a14461 | < 0:4.5.10-3.module+el8.3.0+6804+157bd82e | < 0:4.5.10-4.module+el8.6.0+13337+afcb49ec | < 0:4.5.5-5.module+el8.6.0+13298+7b5243c0

  • redhathttpcomponents-core

    < 0:4.4.10-3.module+el8+2452+b359bfcd | < 0:4.4.12-3.module+el8.2.0+5557+11a14461 | < 0:4.4.12-3.module+el8.3.0+6804+157bd82e | < 0:4.4.12-3.module+el8.6.0+13337+afcb49ec

  • redhatjansi

    < 0:1.17.1-1.module+el8+2452+b359bfcd | < 0:1.18-4.module+el8.2.0+5557+11a14461 | < 0:1.18-4.module+el8.3.0+6804+157bd82e | < 0:1.18-4.module+el8.6.0+13337+afcb49ec

  • redhatjansi-native

    < 0:1.7-7.module+el8+2452+b359bfcd

  • redhatjboss-interceptors-1.2-api

    < 0:1.0.0-8.module+el8+2452+b359bfcd

  • redhatjcl-over-slf4j

    < 0:1.7.25-4.module+el8+2452+b359bfcd | < 0:1.7.28-3.module+el8.2.0+5557+11a14461 | < 0:1.7.28-3.module+el8.3.0+6804+157bd82e | < 0:1.7.28-3.module+el8.6.0+13337+afcb49ec

  • redhatjenkins-2-plugins

    < 0:4.10.1670851835-1.el8 | < 0:4.9.1674644684-1.el8

  • redhatjsoup

    < 0:1.11.3-3.module+el8+2452+b359bfcd | < 0:1.12.1-3.module+el8.2.0+5557+11a14461 | < 0:1.12.1-3.module+el8.3.0+6804+157bd82e | < 0:1.12.1-3.module+el8.6.0+13337+afcb49ec

  • redhatjsr-305

    < 0:0-0.25.20130910svn.module+el8.2.0+5557+11a14461 | < 0:0-0.25.20130910svn.module+el8.3.0+6804+157bd82e | < 0:0-0.25.20130910svn.module+el8.6.0+13337+afcb49ec

  • redhatmaven

    < 1:3.5.4-5.module+el8+2452+b359bfcd | < 1:3.6.2-4.module+el8.2.0+5560+b953ed0b | < 1:3.6.2-6.module+el8.4.0+9250+1786af37 | < 1:3.6.2-7.module+el8.6.0+13337+afcb49ec

  • redhatmaven-lib

    < 1:3.5.4-5.module+el8+2452+b359bfcd | < 1:3.6.2-4.module+el8.2.0+5560+b953ed0b | < 1:3.6.2-6.module+el8.4.0+9250+1786af37 | < 1:3.6.2-7.module+el8.6.0+13337+afcb49ec

  • redhatmaven-openjdk11

    < 1:3.6.2-4.module+el8.2.0+5560+b953ed0b | < 1:3.6.2-6.module+el8.4.0+9250+1786af37 | < 1:3.6.2-7.module+el8.6.0+13337+afcb49ec

  • redhatmaven-openjdk17

    < 1:3.6.2-7.module+el8.6.0+13337+afcb49ec

  • redhatmaven-openjdk8

    < 1:3.6.2-4.module+el8.2.0+5560+b953ed0b | < 1:3.6.2-6.module+el8.4.0+9250+1786af37 | < 1:3.6.2-7.module+el8.6.0+13337+afcb49ec

  • redhatmaven-resolver

    < 1:1.1.1-2.module+el8+2452+b359bfcd | < 0:1.4.1-3.module+el8.2.0+5557+11a14461 | < 0:1.4.1-3.module+el8.3.0+6804+157bd82e | < 0:1.4.1-3.module+el8.6.0+13337+afcb49ec

  • redhatmaven-resolver-api

    < 1:1.1.1-2.module+el8+2452+b359bfcd

  • redhatmaven-resolver-connector-basic

    < 1:1.1.1-2.module+el8+2452+b359bfcd

  • redhatmaven-resolver-impl

    < 1:1.1.1-2.module+el8+2452+b359bfcd

  • redhatmaven-resolver-spi

    < 1:1.1.1-2.module+el8+2452+b359bfcd

  • redhatmaven-resolver-transport-wagon

    < 1:1.1.1-2.module+el8+2452+b359bfcd

  • redhatmaven-resolver-util

    < 1:1.1.1-2.module+el8+2452+b359bfcd

  • redhatmaven-shared-utils

    < 0:0.4-4.el7_9 | < 0:0.4-4.el7_9 | < 0:0.4-4.el7_9 | < 0:0.4-4.el7_9 | < 0:3.2.1-0.2.module+el8.1.0+15171+4eab2c6b | < 0:3.2.1-0.5.module+el8.2.0+15047+acf0c170 | < 0:3.2.1-0.5.module+el8.4.0+15048+bdaf849b | < 0:3.2.1-0.5.module+el8.6.0+15049+43453910 | < 0:3.2.1-0.2.module+el8.2.0+15046+b52d227a | < 0:3.2.1-0.2.module+el8.4.0+15140+8e8c2c6f | < 0:3.2.1-0.2.module+el8.6.0+15045+b1156105

  • redhatmaven-shared-utils-javadoc

    < 0:0.4-4.el7_9 | < 0:0.4-4.el7_9 | < 0:0.4-4.el7_9 | < 0:0.4-4.el7_9

  • redhatmaven-wagon

    < 0:3.1.0-1.module+el8+2452+b359bfcd | < 0:3.3.4-2.module+el8.2.0+5557+11a14461 | < 0:3.3.4-2.module+el8.3.0+6804+157bd82e | < 0:3.3.4-2.module+el8.6.0+13337+afcb49ec

  • redhatmaven-wagon-file

    < 0:3.1.0-1.module+el8+2452+b359bfcd

  • redhatmaven-wagon-http

    < 0:3.1.0-1.module+el8+2452+b359bfcd

Showing first 50 affected entries in server-rendered view.

References (26)