CVE-2022-4245

Severity
4.3MEDIUM
EPSS
0.1%
top 81.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25

Description

A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

🔴Vulnerability Details

4
OSV
CVE-2022-4245: A flaw was found in codehaus-plexus2023-09-25
OSV
codehaus-plexus vulnerable to XML injection2023-09-25
CVEList
Codehaus-plexus: xml external entity (xxe) injection2023-09-25
GHSA
codehaus-plexus vulnerable to XML injection2023-09-25

📋Vendor Advisories

2
Red Hat
codehaus-plexus: XML External Entity (XXE) Injection2022-12-01
Debian
CVE-2022-4245: plexus-utils2 - A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterU...2022
CVE-2022-4245 (MEDIUM CVSS 4.3) | A flaw was found in codehaus-plexus | cvebase.io