Lucene search

K
amazonAmazonALAS2-2022-1794
HistoryMay 04, 2022 - 1:01 a.m.

Critical: maven-shared-utils

2022-05-0401:01:00
alas.aws.amazon.com
28

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10 High

AI Score

Confidence

High

0.025 Low

EPSS

Percentile

90.3%

Issue Overview:

org.apache.maven.shared:maven-shared-utils is a functional replacement for plexus-utils in Maven. Affected versions of this package are vulnerable to Command Injection. The Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. The BourneShell class should unconditionally single-quote emitted strings (including the name of the command itself being quoted), with {{‘"’"'}} used for embedded single quotes, for maximum safety across shells implementing a superset of POSIX quoting rules. (CVE-2022-29599)

Affected Packages:

maven-shared-utils

Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.

Issue Correction:
Run yum update maven-shared-utils to update your system.

New Packages:

noarch:  
    maven-shared-utils-0.4-4.amzn2.noarch  
    maven-shared-utils-javadoc-0.4-4.amzn2.noarch  
  
src:  
    maven-shared-utils-0.4-4.amzn2.src  

Additional References

Red Hat: CVE-2022-29599

Mitre: CVE-2022-29599

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

10 High

AI Score

Confidence

High

0.025 Low

EPSS

Percentile

90.3%