{"id":"CVE-2022-39243","summary":"NuProcess vulnerable to command-line injection through insertion of NUL character(s)","details":"NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perform command line injection. Java's ProcessBuilder isn't vulnerable because of a check in ProcessBuilder.start. NuProcess is missing that check. This vulnerability can only be exploited to inject command line arguments on Linux. Version 2.0.5 contains a patch. As a workaround, users of the library can sanitize command strings to remove NUL characters prior to passing them to NuProcess for execution.","aliases":["GHSA-cxgf-v2p8-7ph7"],"modified":"2026-08-12T03:51:34.266453319Z","published":"2022-09-26T13:25:11Z","database_specific":{"cwe_ids":["CWE-77"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39243.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39243.json"},{"type":"ADVISORY","url":"https://github.com/brettwooldridge/NuProcess/security/advisories/GHSA-cxgf-v2p8-7ph7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39243"},{"type":"FIX","url":"https://github.com/brettwooldridge/NuProcess/commit/29bc09de561bf00ff9bf77123756363a9709f868"},{"type":"FIX","url":"https://github.com/brettwooldridge/NuProcess/pull/143"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/brettwooldridge/nuprocess","events":[{"introduced":"c993d1a10a0e894580bca56b8bd97679245133dc"},{"fixed":"a2e0b1723d2466cdf79578721f2a76cc0c7d1218"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.2.0"},{"fixed":"2.0.5"}]}}],"versions":["nuprocess-2.0.4","nuprocess-2.0.3","nuprocess-2.0.2","nuprocess-2.0.1","nuprocess-2.0.0","nuprocess-1.2.6","nuprocess-1.2.5","nuprocess-1.2.4","nuprocess-1.2.3","nuprocess-1.2.2","nuprocess-1.2.1","nuprocess-1.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39243.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}