CVE-2022-29599
published 2022-05-23CVE-2022-29599: In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
4.30%
90.1th percentile
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | maven_shared_utils | < 3.3.3 | 3.3.3 |
| apache_software_foundation | apache_maven | >= maven-shared-utils < 3.3.3 | 3.3.3 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | maven-shared-utils | < maven-shared-utils 3.3.4-1 (bookworm) | maven-shared-utils 3.3.4-1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Maven Shared Utils vulnerability
vendor_ubuntu·2024-04-11
CVE-2022-29599 Apache Maven Shared Utils vulnerability
Title: Apache Maven Shared Utils vulnerability
Summary: maven-shared-utils could be made to run programs if it received
specially crafted input.
It was discovered that Apache Maven Shared Utils did not handle double-quoted
strings properly, allowing shell injection attacks. This could allow an
attacker to run arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Maven Shared Utils) — CVE-2022-29599
vendor_oracle·2023-10-15·CVSS 9.8
CVE-2022-29599 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Maven Shared Utils) — CVE-2022-29599
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (Apache Maven Shared Utils) vulnerability
CVE: CVE-2022-29599
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Maven) — CVE-2022-29599
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2022-29599 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Maven) — CVE-2022-29599
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Maven) vulnerability
CVE: CVE-2022-29599
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Debian
CVE-2022-29599: maven-shared-utils - In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class...
vendor_debian·2022·CVSS 9.8
CVE-2022-29599 [CRITICAL] CVE-2022-29599: maven-shared-utils - In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class...
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
Scope: local
bookworm: resolved (fixed in 3.3.4-1)
bullseye: resolved (fixed in 3.3.0-1+deb11u1)
forky: resolved (fixed in 3.3.4-1)
sid: resolved (fixed in 3.3.4-1)
trixie: resolved (fixed in 3.3.4-1)
Red Hat
maven-shared-utils: Command injection via Commandline class
vendor_redhat·2020-05-29·CVSS 9.8
CVE-2022-29599 [CRITICAL] CWE-77 maven-shared-utils: Command injection via Commandline class
maven-shared-utils: Command injection via Commandline class
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
A flaw was found in the maven-shared-utils package. This issue allows a Command Injection due to improper escaping, allowing a shell injection attack.
Statement: Red Hat Satellite ships Candlepin component, which uses the Tomcatjss module from the RHEL AppStream repository. In turn, Tomcatjss relies on Maven, which itself depends on affected Apache Maven Shared Utils. Due to the fact that Satellite does not directly use Apache Maven Shared Utils, or expose it in its code, it is considered not affected by the flaw. Satellite customers can resolve the security w
OSV
Command injection in Apache Maven maven-shared-utils
osv·2022-05-24
CVE-2022-29599 [CRITICAL] Command injection in Apache Maven maven-shared-utils
Command injection in Apache Maven maven-shared-utils
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
GHSA
Command injection in Apache Maven maven-shared-utils
ghsa·2022-05-24
CVE-2022-29599 [CRITICAL] CWE-116 Command injection in Apache Maven maven-shared-utils
Command injection in Apache Maven maven-shared-utils
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
OSV
CVE-2022-29599: In Apache Maven maven-shared-utils prior to version 3
osv·2022-05-23·CVSS 9.8
CVE-2022-29599 [CRITICAL] CVE-2022-29599: In Apache Maven maven-shared-utils prior to version 3
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys
blogs_qualys·2023-10-18
Oracle Patch Tuesday, October 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its fourth quarterly edition of Critical Patch Update, which contains a group of patches for 387 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During the Q4 2023 Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of 103 patches, constituting 26% of the total patches released. Oracle Communications and Oracle Fusion Middleware fo
Qualys
Oracle Patch Tuesday, October 2023 Security Update Review
blogs_qualys·2023-10-18
Oracle Patch Tuesday, October 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its fourth quarterly edition of Critical Patch Update, which contains a group of patches for 387 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During the Q4 2023 Oracle Critical Patch Update, Oracle Financial Services Applications received the highest number of 103 patches, constituting 26% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed,
Qualys
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
blogs_qualys·2023-04-19
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Mi
Qualys
Oracle Patch Tuesday April 2023 Security Update Review
blogs_qualys·2023-04-19
Oracle Patch Tuesday April 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Middlewar
http://www.openwall.com/lists/oss-security/2022/05/23/3https://github.com/apache/maven-shared-utils/pull/40https://issues.apache.org/jira/browse/MSHARED-297https://lists.debian.org/debian-lts-announce/2022/08/msg00018.htmlhttps://www.debian.org/security/2022/dsa-5242http://www.openwall.com/lists/oss-security/2022/05/23/3https://github.com/apache/maven-shared-utils/pull/40https://issues.apache.org/jira/browse/MSHARED-297https://lists.debian.org/debian-lts-announce/2022/08/msg00018.htmlhttps://www.debian.org/security/2022/dsa-5242
2022-05-23
Published