CVE-2022-44262: Code Injection
Published Dec 1, 2022
·Updated
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
Affected Software
2 affected componentsFixes available
maven/org.ff4j:ff4j-core>=1.8.1<1.9
1.9
ff4j ff4j=1.8.1
Event History
Dec 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityAffected Software
Advisory Published
06:30 AM
Frequently Asked Questions
1
What is CVE-2022-44262?
CVE-2022-44262 is a vulnerability in ff4j 1.8.1 that allows remote code execution (RCE).
2
How severe is CVE-2022-44262?
CVE-2022-44262 has a severity rating of critical.
3
How can I fix CVE-2022-44262?
To fix CVE-2022-44262, update your ff4j version to 1.9 or later.
4
Where can I find more information about CVE-2022-44262?
You can find more information about CVE-2022-44262 at the following references: [Link 1](https://nvd.nist.gov/vuln/detail/CVE-2022-44262), [Link 2](https://github.com/ff4j/ff4j/issues/624), [Link 3](https://github.com/ff4j/ff4j/commit/62d03140f3bfbd380d0f4b4e5a94dcb8baa9d9c6).
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-44262?
The CWE ID for CVE-2022-44262 is CWE-94.