Severity
4.3
Medium severity
Details
- CVSS score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CWE ID
Overview
About vulnerability
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a –> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.Details
- Affected product:
- Apache Hadoop , Apache Hive , Apache Maven , Apache Struts , Eclipse Jetty , Hibernate , Plexus , Spring , activemq , avro , cocoon , cxf , druid , gradle , karaf , kotlin , maven , org.apache.karaf.features.core , org.ops4j.pax.url , pax-url-aether , sisu , sonatype-aether , tesla-aether
- Affected packages:
- fcgi-server @ 9.4.60 (+3558 more)