CVE-2022-4245

NameCVE-2022-4245
DescriptionA flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesELA-963-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
plexus-utils2 (PTS)jessie, jessie (lts)3.0.15-1+deb8u2fixed
stretch (lts), stretch3.0.22-1+deb9u1fixed
buster3.1.1-1fixed
bullseye3.3.0-1fixed
sid, trixie, bookworm3.4.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
plexus-utils2sourcejessie3.0.15-1+deb8u2ELA-963-1
plexus-utils2sourcestretch3.0.22-1+deb9u1ELA-963-1
plexus-utils2source(unstable)3.0.24-1

Notes

https://security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-461102
https://github.com/codehaus-plexus/plexus-utils/commit/f933e5e78dc2637e485447ed821fe14904f110de (plexus-utils-3.0.24)
https://github.com/codehaus-plexus/plexus-utils/issues/3

Search for package or bug name: Reporting problems