Release Date: | 2022-05-23 |
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
See more information about CVE-2022-29599 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS v3.0 metrics and score provided are preliminary and subject to review.
Base Score: | 9.8 | Base Metrics: | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Access Vector: | Network | Attack Complexity: | Low |
Privileges Required: | None | User Interaction: | None |
Scope: | Unchanged | Confidentiality Impact: | High |
Integrity Impact: | High | Availability Impact: | High |
Platform | Errata | Release Date |
Oracle Linux version 7 (maven-shared-utils) | ELSA-2022-1541 | 2022-04-29 |
Oracle Linux version 8 (aopalliance) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (aopalliance) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-cli) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-cli) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-codec) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-codec) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-io) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-io) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-lang3) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-lang3) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (apache-commons-logging) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (atinject) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (atinject) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (cdi-api) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (cdi-api) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (geronimo-annotation) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (geronimo-annotation) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (glassfish-el) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (google-guice) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (google-guice) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (guava) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (guava20) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (hawtjni) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (httpcomponents-client) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (httpcomponents-client) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (httpcomponents-core) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (httpcomponents-core) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (jansi) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (jansi) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (jansi-native) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (jboss-interceptors-1.2-api) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (jsoup) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (jsoup) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (jsr-305) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (maven) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (maven) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (maven-resolver) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (maven-resolver) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (maven-shared-utils) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (maven-shared-utils) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (maven-wagon) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (maven-wagon) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (plexus-cipher) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (plexus-cipher) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (plexus-classworlds) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (plexus-classworlds) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (plexus-containers) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (plexus-containers) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (plexus-interpolation) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (plexus-interpolation) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (plexus-sec-dispatcher) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (plexus-sec-dispatcher) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (plexus-utils) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (plexus-utils) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (sisu) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (sisu) | ELSA-2022-4798 | 2022-06-01 |
Oracle Linux version 8 (slf4j) | ELSA-2022-4797 | 2022-06-01 |
Oracle Linux version 8 (slf4j) | ELSA-2022-4798 | 2022-06-01 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team