{"id":"GHSA-jcwr-x25h-x5fh","summary":"codehaus-plexus vulnerable to XML injection","details":"A flaw was found in codehaus-plexus. The `org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment` fails to sanitize comments for a `--\u003e` sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection. ","aliases":["CVE-2022-4245"],"modified":"2024-05-03T20:32:52.547057Z","published":"2023-09-25T21:30:26Z","database_specific":{"cwe_ids":["CWE-611","CWE-91"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-09-26T19:38:53Z","nvd_published_at":"2023-09-25T20:15:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4245"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/issues/3"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/commit/f933e5e78dc2637e485447ed821fe14904f110de"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2023:2135"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2023:3906"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2022-4245"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2149843"},{"type":"PACKAGE","url":"https://github.com/codehaus-plexus/plexus-utils"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-461102"}],"affected":[{"package":{"name":"org.codehaus.plexus:plexus-utils","ecosystem":"Maven","purl":"pkg:maven/org.codehaus.plexus/plexus-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.24"}]}],"versions":["1.0.4","1.0.5","1.1","1.2","1.3","1.4","1.4-alpha-1","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.1","3.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.15","3.0.16","3.0.17","3.0.18","3.0.19","3.0.2","3.0.20","3.0.21","3.0.22","3.0.23","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-jcwr-x25h-x5fh/GHSA-jcwr-x25h-x5fh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}