CVE Feed

    Dashboard / CVE / CVE-2023-34112

    CVE-2023-34112

    JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.event.head_commit.message​` parameter in an insecure way. For example, the commit message is used in a run statement - resulting in a command injection vulnerability due to string interpolation. No exploitation has been reported. This issue has been addressed in version 1.5.9. Users of JavaCPP Presets are advised to upgrade as a precaution.

    Published:Jun 8, 2023
    Last Modified:Jan 6, 2025
    EPS:Jun 8, 2023
    EPSS Score:0.02011
    CVSS Score:4.3

    Affected Products

    Vendor
    Bytedeco
    Product
    Javacpp Presets

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High