CVE-2022-4245
published 2023-09-25CVE-2022-4245: A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.69%
48.8th percentile
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| codehaus-plexus | plexus-utils | < 3.0.24 | 3.0.24 |
| debian | plexus-utils2 | < plexus-utils2 3.0.24-1 (bookworm) | plexus-utils2 3.0.24-1 (bookworm) |
| redhat | integration_camel_k | < 1.10.1 | 1.10.1 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
codehaus-plexus: XML External Entity (XXE) Injection
vendor_redhat·2022-12-01·CVSS 4.3
CVE-2022-4245 [MEDIUM] CWE-91 codehaus-plexus: XML External Entity (XXE) Injection
codehaus-plexus: XML External Entity (XXE) Injection
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
Package: codehaus-plexus (A-MQ Clients 2) - Will not fix
Package: codehaus-plexus (Red Hat AMQ Broker 7) - Will not fix
Package: codehaus-plexus (Red Hat A-MQ Online) - Not affected
Package: codehaus-plexus (Red Hat build
Debian
CVE-2022-4245: plexus-utils2 - A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterU...
vendor_debian·2022·CVSS 4.3
CVE-2022-4245 [MEDIUM] CVE-2022-4245: plexus-utils2 - A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterU...
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
Scope: local
bookworm: resolved (fixed in 3.0.24-1)
bullseye: resolved (fixed in 3.0.24-1)
forky: resolved (fixed in 3.0.24-1)
sid: resolved (fixed in 3.0.24-1)
trixie: resolved (fixed in 3.0.24-1)
OSV
CVE-2022-4245: A flaw was found in codehaus-plexus
osv·2023-09-25·CVSS 4.3
CVE-2022-4245 [MEDIUM] CVE-2022-4245: A flaw was found in codehaus-plexus
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
OSV
codehaus-plexus vulnerable to XML injection
osv·2023-09-25
CVE-2022-4245 [MEDIUM] codehaus-plexus vulnerable to XML injection
codehaus-plexus vulnerable to XML injection
A flaw was found in codehaus-plexus. The `org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment` fails to sanitize comments for a `-->` sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
GHSA
codehaus-plexus vulnerable to XML injection
ghsa·2023-09-25
CVE-2022-4245 [MEDIUM] CWE-611 codehaus-plexus vulnerable to XML injection
codehaus-plexus vulnerable to XML injection
A flaw was found in codehaus-plexus. The `org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment` fails to sanitize comments for a `-->` sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:2135https://access.redhat.com/errata/RHSA-2023:3906https://access.redhat.com/security/cve/CVE-2022-4245https://bugzilla.redhat.com/show_bug.cgi?id=2149843https://access.redhat.com/errata/RHSA-2023:2135https://access.redhat.com/errata/RHSA-2023:3906https://access.redhat.com/security/cve/CVE-2022-4245https://bugzilla.redhat.com/show_bug.cgi?id=2149843
2023-09-25
Published