First published: Thu Oct 06 2022(Updated: )
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After review by the JXPath maintainers, the original report was found to be invalid.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Commons Jxpath | <=1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40159 refers to a vulnerability in Apache Commons Jxpath that was originally reported by the oss-fuzz project without considering the security context and without contacting the JXPath maintainers.
The severity of CVE-2022-40159 is medium with a CVSS score of 6.5.
The Apache Commons Jxpath version 1.3 is affected by CVE-2022-40159.
The CWEs for CVE-2022-40159 are CWE-787 (Out-of-bounds Write) and CWE-121 (Stack-based Buffer Overflow).
As of now, there is no official fix available for CVE-2022-40159. It is recommended to stay updated with the security advisories provided by Apache Commons Jxpath.