Apache Software Foundation Apache Maven vulnerabilities
2 known vulnerabilities affecting apache_software_foundation/apache_maven.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2022-29599CRITICALCVSS 9.8≥ maven-shared-utils, < 3.3.32022-05-23
CVE-2022-29599 [CRITICAL] CWE-116 CVE-2022-29599: In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quo
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
cvelistv5nvd
CVE-2021-26291CRITICALCVSS 9.1≥ Apache Maven, ≤ 3.8.12021-04-23
CVE-2021-26291 [CRITICAL] CWE-346 CVE-2021-26291: Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom)
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to n
cvelistv5nvd