Apache Maven Shared Utils Vulnerability CVE-2022-29599
Issue date: 21-09-2022Affects versions: 15.1, 14.7, 13.4
Security Issue ID
SECURITY-356
Affected Product Version(s)
15.1.0, 14.7.8, 13.4.18, and all previous versions
Severity
High
Description
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
The problem has been recognized and patched. The fix is available in version 3.3.4
Instructions
Customers are recommended to upgrade to the latest version. As of the time of writing, 15.1.1, 14.7.9 or 13.4.19