OS Command Injection in Maven Shared Utils - CVE-2022-29599

 

OS Command Injection in Maven Shared Utils - CVE-2022-29599

Published: April 26, 2022


Vulnerability identifier: #VU62608
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29599
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation when processing double-quoted strings. A remote attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.


Affected software

Maven Shared Utils
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Ubuntu
openEuler
Fedora
Red Hat Software Collections
OpenShift Developer Tools and Services
IBM App Connect Enterprise
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libmaven-shared-utils-java (Ubuntu package)
jsr-305
sisu-inject
sisu-plexus
sisu
maven-shared-utils
maven-shared-utils-javadoc
jboss-interceptors-1.2-api
aopalliance
geronimo-annotation
maven-resolver-impl
maven-resolver-spi
maven-resolver-api
maven-resolver-transport-wagon
maven-resolver-connector-basic
maven-resolver-util
cdi-api
apache-commons-logging
maven-resolver
apache-commons-cli
plexus-sec-dispatcher
plexus-containers-component-annotations
jansi-native
plexus-cipher
jcl-over-slf4j
slf4j
apache-commons-codec
jsoup
hawtjni-runtime
jansi
plexus-interpolation
cri-o (Red Hat package)
atinject
plexus-classworlds
apache-commons-io
jenkins (Red Hat package)
glassfish-el-api
maven-wagon-http
maven-wagon-http-shared
maven-wagon-file
maven-wagon-provider-api
plexus-utils
rh-maven36-maven-shared-utils (Red Hat package)
maven-shared-utils (Debian package)
maven-shared-utils-help
maven-wagon
maven
maven-lib
maven-openjdk8
maven-openjdk17
maven-openjdk11
apache-commons-lang3
google-guice
httpcomponents-core
httpcomponents-client
jenkins-2-plugins (Red Hat package)
guava20
guava
IBM Integration Bus
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Oracle WebLogic Server
watsonx.data

How to mitigate CVE-2022-29599

Install updates from vendor's website.

Maven Shared Utils - update to 3.3.3
Red Hat OpenShift Container Platform - addressed in versions 3.11.705, 4.9.55, 4.10.46
libmaven-shared-utils-java (Ubuntu package) - addressed in versions Ubuntu Pro, 3.3.0-1ubuntu0.20.04.1, 3.3.0-1ubuntu0.22.04.1
jsr-305 - update to 0-0.25.20130910svn
sisu-inject - update to 0.3.3-6
sisu-plexus - update to 0.3.3-6
sisu - update to 0.3.4-2
maven-shared-utils - addressed in versions 0.4-4.0.1, 3.2.1-0.2, 3.2.1-0.5
maven-shared-utils-javadoc - update to 0.4-4.0.1
jboss-interceptors-1.2-api - update to 1.0.0-8
aopalliance - addressed in versions 1.0-17, 1.0-20
geronimo-annotation - addressed in versions 1.0-23, 1.0-26
maven-resolver-impl - update to 1.1.1-2
maven-resolver-spi - update to 1.1.1-2
maven-resolver-api - update to 1.1.1-2
maven-resolver-transport-wagon - update to 1.1.1-2
maven-resolver-connector-basic - update to 1.1.1-2
maven-resolver-util - update to 1.1.1-2
cdi-api - addressed in versions 1.2-8, 2.0.1-3
apache-commons-logging - update to 1.2-13
maven-resolver - update to 1.4.1-3
apache-commons-cli - addressed in versions 1.4-4, 1.4-7
plexus-sec-dispatcher - addressed in versions 1.4-26, 1.4-29
plexus-containers-component-annotations - addressed in versions 1.7.1-8, 2.1.0-2
jansi-native - update to 1.7-7
plexus-cipher - addressed in versions 1.7-14, 1.7-17
jcl-over-slf4j - addressed in versions 1.7.25-4, 1.7.28-3
slf4j - addressed in versions 1.7.25-4, 1.7.28-3
apache-commons-codec - addressed in versions 1.11-3, 1.13-3
jsoup - addressed in versions 1.11.3-3, 1.12.1-3
hawtjni-runtime - update to 1.16-2
jansi - addressed in versions 1.17.1-1, 1.18-4
plexus-interpolation - addressed in versions 1.22-9, 1.26-3
cri-o (Red Hat package) - addressed in versions 1.23.4-3.rhaos4.10.git8240333.el7, 1.23.4-3.rhaos4.10.git8240333.el8
atinject - addressed in versions 1-28.20100611svn86, 1-31.20100611svn86
watsonx.data - update to 2.0.2
plexus-classworlds - addressed in versions 2.5.2-9, 2.6.0-4
apache-commons-io - addressed in versions 2.6-3, 2.6-6
jenkins (Red Hat package) - addressed in versions 2.387.1.1683009763-3.el8, 2.401.1.1686649641-3.el8, 2.401.1.1686680404-3.el8, 2.414.3.1698292201-3.el8, 2.414.3.1698293911-3.el8, 2.414.3.1698298955-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8, 2.426.3.1706516352-3.el8, 2.426.3.1706516929-3.el8
glassfish-el-api - update to 3.0.1-0.7.b08
maven-wagon-http - update to 3.1.0-1
maven-wagon-http-shared - update to 3.1.0-1
maven-wagon-file - update to 3.1.0-1
maven-wagon-provider-api - update to 3.1.0-1
plexus-utils - addressed in versions 3.1.0-3, 3.3.0-3
rh-maven36-maven-shared-utils (Red Hat package) - update to 3.2.1-0.2.3.el7
maven-shared-utils - update to 3.2.1-0.9.fc34
maven-shared-utils (Debian package) - update to 3.3.0-1+deb11u1
maven-shared-utils - update to 3.3.3-1
maven-shared-utils-help - update to 3.3.3-1
maven-wagon - update to 3.3.4-2
maven-shared-utils - update to 3.3.4-4
maven - addressed in versions 3.5.4-5, 3.6.2-7
maven-lib - addressed in versions 3.5.4-5, 3.6.2-7
maven-openjdk8 - update to 3.6.2-7
maven-openjdk17 - update to 3.6.2-7
maven-openjdk11 - update to 3.6.2-7
apache-commons-lang3 - addressed in versions 3.7-3, 3.9-4
google-guice - addressed in versions 4.1-11, 4.2.2-4
httpcomponents-core - addressed in versions 4.4.10-3, 4.4.12-3
httpcomponents-client - addressed in versions 4.5.5-5, 4.5.10-4
jenkins-2-plugins (Red Hat package) - addressed in versions 4.9.1674644684-1.el8, 4.10.1670851835-1.el8, 4.11.1683009941-1.el8, 4.11.1698299029-1.el8, 4.11.1706516946-1.el8, 4.12.1686649756-1.el8, 4.12.1698294000-1.el8, 4.12.1706515741-1.el8, 4.13.1686680473-1.el8, 4.13.1698292274-1.el8, 4.13.1706516346-1.el8, 4.14.1706516441-1.el8
guava20 - update to 20.0-8
guava - update to 28.1-3

External References

Related Security Bulletins