First published: Fri May 29 2020(Updated: )
A flaw was found in the maven-shared-utils package. This issue allows a Command Injection due to improper escaping, allowing a shell injection attack.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Maven Shared Utils | <3.3.3 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
redhat/jenkins | <2-plugins-0:4.11.1683009941-1.el8 | 2-plugins-0:4.11.1683009941-1.el8 |
redhat/jenkins | <2-plugins-0:4.12.1686649756-1.el8 | 2-plugins-0:4.12.1686649756-1.el8 |
redhat/jenkins | <2-plugins-0:4.13.1686680473-1.el8 | 2-plugins-0:4.13.1686680473-1.el8 |
redhat/maven-shared-utils | <0:0.4-4.el7_9 | 0:0.4-4.el7_9 |
redhat/jenkins | <2-plugins-0:4.10.1670851835-1.el8 | 2-plugins-0:4.10.1670851835-1.el8 |
redhat/jenkins | <2-plugins-0:4.9.1674644684-1.el8 | 2-plugins-0:4.9.1674644684-1.el8 |
redhat/rh-maven36-maven-shared-utils | <0:3.2.1-0.2.3.el7 | 0:3.2.1-0.2.3.el7 |
redhat/maven-shared-utils | <3.3.3 | 3.3.3 |
debian/maven-shared-utils | <=3.3.0-1 | 3.3.0-1+deb10u1 3.3.0-1+deb11u1 3.3.4-1 |
ubuntu/maven-shared-utils | <3.3.0-1ubuntu0.18.04.1~ | 3.3.0-1ubuntu0.18.04.1~ |
ubuntu/maven-shared-utils | <3.3.0-1ubuntu0.20.04.1 | 3.3.0-1ubuntu0.20.04.1 |
ubuntu/maven-shared-utils | <3.3.0-1ubuntu0.22.04.1 | 3.3.0-1ubuntu0.22.04.1 |
ubuntu/maven-shared-utils | <0.4-1ubuntu0.1~ | 0.4-1ubuntu0.1~ |
ubuntu/maven-shared-utils | <0.9-1ubuntu0.1~ | 0.9-1ubuntu0.1~ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)