CVE-2022-29599

Source
https://cve.org/CVERecord?id=CVE-2022-29599
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29599.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-29599
Aliases
Downstream
Related
Published
2022-05-23T11:16:10.877Z
Modified
2026-01-31T11:43:39.183069Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

References

Affected packages

Git / github.com/apache/maven-shared-utils

Affected ranges

Type
GIT
Repo
https://github.com/apache/maven-shared-utils
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

maven-shared-utils-0.*
maven-shared-utils-0.1
maven-shared-utils-0.2
maven-shared-utils-0.3
maven-shared-utils-0.4
maven-shared-utils-0.5
maven-shared-utils-0.6
maven-shared-utils-0.7
maven-shared-utils-0.8
maven-shared-utils-0.9
maven-shared-utils-3.*
maven-shared-utils-3.0.0
maven-shared-utils-3.0.1
maven-shared-utils-3.1.0
maven-shared-utils-3.2.0
maven-shared-utils-3.2.1
maven-shared-utils-3.3.0
maven-shared-utils-3.3.1
maven-shared-utils-3.3.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29599.json"