UbuntuUpdates.org

Package "libmaven-shared-utils-java-doc"

Name: libmaven-shared-utils-java-doc

Description:

Replacement for plexus-utils in Maven (documentation)

Latest version: 3.3.0-1ubuntu0.22.04.1
Release: jammy (22.04)
Level: security
Repository: universe
Head package: maven-shared-utils
Homepage: http://maven.apache.org/shared/maven-shared-utils/

Links


Download "libmaven-shared-utils-java-doc"


Other versions of "libmaven-shared-utils-java-doc" in Jammy

Repository Area Version
base universe 3.3.0-1
updates universe 3.3.0-1ubuntu0.22.04.1

Changelog

Version: 3.3.0-1ubuntu0.22.04.1 2024-04-11 23:06:52 UTC

  maven-shared-utils (3.3.0-1ubuntu0.22.04.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Commandline class can emit double-quoted strings
    without proper escaping, allowing shell injection attacks.
    - debian/patches/CVE-2022-29599.patch: BourneShell unconditionally
      single quotes executable and arguments.
    - CVE-2022-29599

 -- Chris Kim <email address hidden> Wed, 27 Mar 2024 16:31:18 -0700

CVE-2022-29599 In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing she



About   -   Send Feedback to @ubuntu_updates