OS Command Injection in Maven Shared Utils - CVE-2022-29599
Published: April 26, 2022
Vulnerability identifier: #VU62608
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29599
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing double-quoted strings. A remote attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Affected software
Maven Shared Utils
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat Software Collections
OpenShift Developer Tools and Services
IBM App Connect Enterprise
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libmaven-shared-utils-java (Ubuntu package)
jsr-305
sisu-inject
sisu-plexus
sisu
maven-shared-utils
maven-shared-utils-javadoc
jboss-interceptors-1.2-api
aopalliance
geronimo-annotation
maven-resolver-impl
maven-resolver-spi
maven-resolver-api
maven-resolver-transport-wagon
maven-resolver-connector-basic
maven-resolver-util
cdi-api
apache-commons-logging
maven-resolver
apache-commons-cli
plexus-sec-dispatcher
plexus-containers-component-annotations
jansi-native
plexus-cipher
jcl-over-slf4j
slf4j
apache-commons-codec
jsoup
hawtjni-runtime
jansi
plexus-interpolation
cri-o (Red Hat package)
atinject
plexus-classworlds
apache-commons-io
jenkins (Red Hat package)
glassfish-el-api
maven-wagon-http
maven-wagon-http-shared
maven-wagon-file
maven-wagon-provider-api
plexus-utils
rh-maven36-maven-shared-utils (Red Hat package)
maven-shared-utils (Debian package)
maven-shared-utils-help
maven-wagon
maven
maven-lib
maven-openjdk8
maven-openjdk17
maven-openjdk11
apache-commons-lang3
google-guice
httpcomponents-core
httpcomponents-client
jenkins-2-plugins (Red Hat package)
guava20
guava
IBM Integration Bus
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle WebLogic Server
watsonx.data
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat Software Collections
OpenShift Developer Tools and Services
IBM App Connect Enterprise
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libmaven-shared-utils-java (Ubuntu package)
jsr-305
sisu-inject
sisu-plexus
sisu
maven-shared-utils
maven-shared-utils-javadoc
jboss-interceptors-1.2-api
aopalliance
geronimo-annotation
maven-resolver-impl
maven-resolver-spi
maven-resolver-api
maven-resolver-transport-wagon
maven-resolver-connector-basic
maven-resolver-util
cdi-api
apache-commons-logging
maven-resolver
apache-commons-cli
plexus-sec-dispatcher
plexus-containers-component-annotations
jansi-native
plexus-cipher
jcl-over-slf4j
slf4j
apache-commons-codec
jsoup
hawtjni-runtime
jansi
plexus-interpolation
cri-o (Red Hat package)
atinject
plexus-classworlds
apache-commons-io
jenkins (Red Hat package)
glassfish-el-api
maven-wagon-http
maven-wagon-http-shared
maven-wagon-file
maven-wagon-provider-api
plexus-utils
rh-maven36-maven-shared-utils (Red Hat package)
maven-shared-utils (Debian package)
maven-shared-utils-help
maven-wagon
maven
maven-lib
maven-openjdk8
maven-openjdk17
maven-openjdk11
apache-commons-lang3
google-guice
httpcomponents-core
httpcomponents-client
jenkins-2-plugins (Red Hat package)
guava20
guava
IBM Integration Bus
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle WebLogic Server
watsonx.data
How to mitigate CVE-2022-29599
Install updates from vendor's website.
Maven Shared Utils - update to 3.3.3
Red Hat OpenShift Container Platform - addressed in versions 3.11.705, 4.9.55, 4.10.46
libmaven-shared-utils-java (Ubuntu package) - addressed in versions Ubuntu Pro, 3.3.0-1ubuntu0.20.04.1, 3.3.0-1ubuntu0.22.04.1
jsr-305 - update to 0-0.25.20130910svn
sisu-inject - update to 0.3.3-6
sisu-plexus - update to 0.3.3-6
sisu - update to 0.3.4-2
maven-shared-utils - addressed in versions 0.4-4.0.1, 3.2.1-0.2, 3.2.1-0.5
maven-shared-utils-javadoc - update to 0.4-4.0.1
jboss-interceptors-1.2-api - update to 1.0.0-8
aopalliance - addressed in versions 1.0-17, 1.0-20
geronimo-annotation - addressed in versions 1.0-23, 1.0-26
maven-resolver-impl - update to 1.1.1-2
maven-resolver-spi - update to 1.1.1-2
maven-resolver-api - update to 1.1.1-2
maven-resolver-transport-wagon - update to 1.1.1-2
maven-resolver-connector-basic - update to 1.1.1-2
maven-resolver-util - update to 1.1.1-2
cdi-api - addressed in versions 1.2-8, 2.0.1-3
apache-commons-logging - update to 1.2-13
maven-resolver - update to 1.4.1-3
apache-commons-cli - addressed in versions 1.4-4, 1.4-7
plexus-sec-dispatcher - addressed in versions 1.4-26, 1.4-29
plexus-containers-component-annotations - addressed in versions 1.7.1-8, 2.1.0-2
jansi-native - update to 1.7-7
plexus-cipher - addressed in versions 1.7-14, 1.7-17
jcl-over-slf4j - addressed in versions 1.7.25-4, 1.7.28-3
slf4j - addressed in versions 1.7.25-4, 1.7.28-3
apache-commons-codec - addressed in versions 1.11-3, 1.13-3
jsoup - addressed in versions 1.11.3-3, 1.12.1-3
hawtjni-runtime - update to 1.16-2
jansi - addressed in versions 1.17.1-1, 1.18-4
plexus-interpolation - addressed in versions 1.22-9, 1.26-3
cri-o (Red Hat package) - addressed in versions 1.23.4-3.rhaos4.10.git8240333.el7, 1.23.4-3.rhaos4.10.git8240333.el8
atinject - addressed in versions 1-28.20100611svn86, 1-31.20100611svn86
watsonx.data - update to 2.0.2
plexus-classworlds - addressed in versions 2.5.2-9, 2.6.0-4
apache-commons-io - addressed in versions 2.6-3, 2.6-6
jenkins (Red Hat package) - addressed in versions 2.387.1.1683009763-3.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8
glassfish-el-api - update to 3.0.1-0.7.b08
maven-wagon-http - update to 3.1.0-1
maven-wagon-http-shared - update to 3.1.0-1
maven-wagon-file - update to 3.1.0-1
maven-wagon-provider-api - update to 3.1.0-1
plexus-utils - addressed in versions 3.1.0-3, 3.3.0-3
rh-maven36-maven-shared-utils (Red Hat package) - update to 3.2.1-0.2.3.el7
maven-shared-utils - update to 3.2.1-0.9.fc34
maven-shared-utils (Debian package) - update to 3.3.0-1+deb11u1
maven-shared-utils - update to 3.3.3-1
maven-shared-utils-help - update to 3.3.3-1
maven-wagon - update to 3.3.4-2
maven-shared-utils - update to 3.3.4-4
maven - addressed in versions 3.5.4-5, 3.6.2-7
maven-lib - addressed in versions 3.5.4-5, 3.6.2-7
maven-openjdk8 - update to 3.6.2-7
maven-openjdk17 - update to 3.6.2-7
maven-openjdk11 - update to 3.6.2-7
apache-commons-lang3 - addressed in versions 3.7-3, 3.9-4
google-guice - addressed in versions 4.1-11, 4.2.2-4
httpcomponents-core - addressed in versions 4.4.10-3, 4.4.12-3
httpcomponents-client - addressed in versions 4.5.5-5, 4.5.10-4
jenkins-2-plugins (Red Hat package) - addressed in versions 4.9.1674644684-1.el8, 4.10.1670851835-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1686649756-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8
guava20 - update to 20.0-8
guava - update to 28.1-3
Red Hat OpenShift Container Platform - addressed in versions 3.11.705, 4.9.55, 4.10.46
libmaven-shared-utils-java (Ubuntu package) - addressed in versions Ubuntu Pro, 3.3.0-1ubuntu0.20.04.1, 3.3.0-1ubuntu0.22.04.1
jsr-305 - update to 0-0.25.20130910svn
sisu-inject - update to 0.3.3-6
sisu-plexus - update to 0.3.3-6
sisu - update to 0.3.4-2
maven-shared-utils - addressed in versions 0.4-4.0.1, 3.2.1-0.2, 3.2.1-0.5
maven-shared-utils-javadoc - update to 0.4-4.0.1
jboss-interceptors-1.2-api - update to 1.0.0-8
aopalliance - addressed in versions 1.0-17, 1.0-20
geronimo-annotation - addressed in versions 1.0-23, 1.0-26
maven-resolver-impl - update to 1.1.1-2
maven-resolver-spi - update to 1.1.1-2
maven-resolver-api - update to 1.1.1-2
maven-resolver-transport-wagon - update to 1.1.1-2
maven-resolver-connector-basic - update to 1.1.1-2
maven-resolver-util - update to 1.1.1-2
cdi-api - addressed in versions 1.2-8, 2.0.1-3
apache-commons-logging - update to 1.2-13
maven-resolver - update to 1.4.1-3
apache-commons-cli - addressed in versions 1.4-4, 1.4-7
plexus-sec-dispatcher - addressed in versions 1.4-26, 1.4-29
plexus-containers-component-annotations - addressed in versions 1.7.1-8, 2.1.0-2
jansi-native - update to 1.7-7
plexus-cipher - addressed in versions 1.7-14, 1.7-17
jcl-over-slf4j - addressed in versions 1.7.25-4, 1.7.28-3
slf4j - addressed in versions 1.7.25-4, 1.7.28-3
apache-commons-codec - addressed in versions 1.11-3, 1.13-3
jsoup - addressed in versions 1.11.3-3, 1.12.1-3
hawtjni-runtime - update to 1.16-2
jansi - addressed in versions 1.17.1-1, 1.18-4
plexus-interpolation - addressed in versions 1.22-9, 1.26-3
cri-o (Red Hat package) - addressed in versions 1.23.4-3.rhaos4.10.git8240333.el7, 1.23.4-3.rhaos4.10.git8240333.el8
atinject - addressed in versions 1-28.20100611svn86, 1-31.20100611svn86
watsonx.data - update to 2.0.2
plexus-classworlds - addressed in versions 2.5.2-9, 2.6.0-4
apache-commons-io - addressed in versions 2.6-3, 2.6-6
jenkins (Red Hat package) - addressed in versions 2.387.1.1683009763-3.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8
glassfish-el-api - update to 3.0.1-0.7.b08
maven-wagon-http - update to 3.1.0-1
maven-wagon-http-shared - update to 3.1.0-1
maven-wagon-file - update to 3.1.0-1
maven-wagon-provider-api - update to 3.1.0-1
plexus-utils - addressed in versions 3.1.0-3, 3.3.0-3
rh-maven36-maven-shared-utils (Red Hat package) - update to 3.2.1-0.2.3.el7
maven-shared-utils - update to 3.2.1-0.9.fc34
maven-shared-utils (Debian package) - update to 3.3.0-1+deb11u1
maven-shared-utils - update to 3.3.3-1
maven-shared-utils-help - update to 3.3.3-1
maven-wagon - update to 3.3.4-2
maven-shared-utils - update to 3.3.4-4
maven - addressed in versions 3.5.4-5, 3.6.2-7
maven-lib - addressed in versions 3.5.4-5, 3.6.2-7
maven-openjdk8 - update to 3.6.2-7
maven-openjdk17 - update to 3.6.2-7
maven-openjdk11 - update to 3.6.2-7
apache-commons-lang3 - addressed in versions 3.7-3, 3.9-4
google-guice - addressed in versions 4.1-11, 4.2.2-4
httpcomponents-core - addressed in versions 4.4.10-3, 4.4.12-3
httpcomponents-client - addressed in versions 4.5.5-5, 4.5.10-4
jenkins-2-plugins (Red Hat package) - addressed in versions 4.9.1674644684-1.el8, 4.10.1670851835-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1686649756-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8
guava20 - update to 20.0-8
guava - update to 28.1-3
External References
Related Security Bulletins
- OS Command injection in Apache Maven Shared Utils
- Red Hat Enterprise Linux 7 update for maven-shared-utils
- Red Hat Software Collections update for rh-maven36-maven-shared-utils
- Red Hat Enterprise Linux Update Services for SAP Solutions 8.1 update for the maven:3.5 module
- Red Hat Enterprise Linux 8 update for maven-shared-utils
- Multiple vulnerabilities in OpenShift Container Platform 3.11
- Red Hat Enterprise Linux 8 update for maven:3.6 module
- Debian update for maven-shared-utils
- Command injection in OpenShift Container Platform 4.10
- OpenShift Container Platform 4.9 update for Maven Shared Utils
- Multiple vulnerabilities in Middleware Common Libraries and Tools
- OpenShift Developer Tools and Services for OCP 4.11 update for jenkins and jenkins-2-plugins
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- OpenShift Developer Tools and Services for OCP 4.13 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.12 update for jenkins and jenkins-2-plugins
- Multiple vulnerabilities in Oracle WebLogic Server
- OpenShift Developer Tools and Services for OCP 4.13 update for jenkins and jenkins-2-plugins
- Red Hat Product OCP Tools 4.12 update for Openshift Jenkins
- Red Hat Product OCP Tools 4.11 update for Openshift Jenkins
- OpenShift Developer Tools and Services for OCP 4.11 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.13 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.14 update for jenkins and jenkins-2-plugins
- OpenShift Developer Tools and Services for OCP 4.12 update for Jenkins and Jenkins-2-plugins
- openEuler update for maven-shared-utils
- Ubuntu update for maven-shared-utils
- Amazon Linux AMI update for maven-shared-utils
- Multiple vulnerabilities in IBM watsonx.data
- Fedora 34 update for maven-shared-utils
- Anolis OS update for maven-shared-utils
- Anolis OS update for maven:3.6 module
- Anolis OS update for maven:3.5 module
- Multiple vulnerabilities in Oracle Middleware Common Libraries and Tools