FlawAtlas
Search the atlas
ALSA-2022:4798 Not scored

Important: maven:3.5 security update

The Apache Maven Shared Utils project aims to be an improved functional replacement for plexus-utils in Maven. Security Fix(es): * maven-shared-utils: Command injection via Commandline class (CVE-2022-29599) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Exploit probability Not scored
Published May 30, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 plexus-interpolation
AlmaLinux:8 apache-commons-cli
AlmaLinux:8 jansi
AlmaLinux:8 apache-commons-lang3
AlmaLinux:8 httpcomponents-client
AlmaLinux:8 jboss-interceptors-1.2-api
AlmaLinux:8 sisu-plexus
AlmaLinux:8 slf4j
AlmaLinux:8 maven-resolver-util
AlmaLinux:8 maven-resolver-connector-basic
AlmaLinux:8 hawtjni-runtime
AlmaLinux:8 maven-resolver-api
AlmaLinux:8 maven-resolver-transport-wagon
AlmaLinux:8 sisu-inject
AlmaLinux:8 plexus-containers-component-annotations
AlmaLinux:8 maven-wagon-http-shared
AlmaLinux:8 plexus-classworlds
AlmaLinux:8 plexus-sec-dispatcher
AlmaLinux:8 glassfish-el-api
AlmaLinux:8 apache-commons-codec
AlmaLinux:8 jsoup
AlmaLinux:8 maven-resolver-impl
AlmaLinux:8 jcl-over-slf4j
AlmaLinux:8 cdi-api
AlmaLinux:8 plexus-utils
AlmaLinux:8 maven-shared-utils
AlmaLinux:8 jansi-native
AlmaLinux:8 maven-wagon-file
AlmaLinux:8 guava20
AlmaLinux:8 google-guice
AlmaLinux:8 maven-resolver-spi
AlmaLinux:8 maven-wagon-provider-api
AlmaLinux:8 plexus-cipher
AlmaLinux:8 apache-commons-io
AlmaLinux:8 httpcomponents-core
AlmaLinux:8 maven-lib
AlmaLinux:8 geronimo-annotation
AlmaLinux:8 maven
AlmaLinux:8 aopalliance
AlmaLinux:8 apache-commons-logging
AlmaLinux:8 atinject
AlmaLinux:8 maven-wagon-http

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2022:4798

The Apache Maven Shared Utils project aims to be an improved functional replacement for plexus-utils in Maven. Security Fix(es): * maven-shared-utils: Command injection via Commandline class (CVE-2022-29599) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

View original source

05 / REFERENCES

Further evidence