CVE-2022-4245 (Medium) detected in plexus-utils-1.2.jar
Opened this issue · 0 comments
CVE-2022-4245 - Medium Severity Vulnerability
Vulnerable Library - plexus-utils-1.2.jar
Path to dependency file: /geotools/build/maven/jar-collector/pom.xml
Path to vulnerable library: /2/repository/org/codehaus/plexus/plexus-utils/1.2/plexus-utils-1.2.jar,/2/repository/org/codehaus/plexus/plexus-utils/1.2/plexus-utils-1.2.jar,/2/repository/org/codehaus/plexus/plexus-utils/1.2/plexus-utils-1.2.jar
Dependency Hierarchy:
- ❌ plexus-utils-1.2.jar (Vulnerable Library)
Found in base branch: master
Vulnerability Details
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
Publish Date: 2023-09-25
URL: CVE-2022-4245
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://bugzilla.suse.com/show_bug.cgi?id=1205930
Release Date: 2023-09-25
Fix Resolution: 3.0.24
Step up your Open Source Security Game with Mend here