UBUNTU-CVE-2022-4245
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-4245
Summary:
Details: A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
References: https://ubuntu.com/security/CVE-2022-4245, https://security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-461102, https://github.com/codehaus-plexus/plexus-utils/commit/f933e5e78dc2637e485447ed821fe14904f110de, https://github.com/codehaus-plexus/plexus-utils/issues/3, https://www.cve.org/CVERecord?id=CVE-2022-4245
Affected packages
Package
Name: plexus-utils2
Purl: pkg:deb/ubuntu/[email protected]+deb7u1build0.14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
