CVE-2022-29599

NameCVE-2022-29599
DescriptionIn Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3059-1, DLA-3086-1, DSA-5242-1
Debian Bugs1012314

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
maven-shared-utils (PTS)buster3.3.0-1vulnerable
buster (security)3.3.0-1+deb10u1fixed
bullseye (security), bullseye3.3.0-1+deb11u1fixed
sid, trixie, bookworm3.3.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
maven-shared-utilssourcestretch3.0.0-1+deb9u1DLA-3059-1
maven-shared-utilssourcebuster3.3.0-1+deb10u1DLA-3086-1
maven-shared-utilssourcebullseye3.3.0-1+deb11u1DSA-5242-1
maven-shared-utilssource(unstable)3.3.4-11012314

Notes

https://github.com/apache/maven-shared-utils/pull/40
https://issues.apache.org/jira/browse/MSHARED-297
https://github.com/apache/maven-shared-utils/commit/f751e614c09df8de1a080dc1153931f3f68991c9 (maven-shared-utils-3.3.1)

Search for package or bug name: Reporting problems