目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1000 CNY

100.0%

CVE-2022-4245— codehaus-plexus 代码问题漏洞

CVSS 4.3 · Medium EPSS 0.06% · P18
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2022-4245の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Codehaus-plexus: xml external entity (xxe) injection
ソース: NVD (National Vulnerability Database)
脆弱性説明
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
ソース: NVD (National Vulnerability Database)
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
ソース: NVD (National Vulnerability Database)
脆弱性タイプ
XML注入(XPath盲注)
ソース: NVD (National Vulnerability Database)
脆弱性タイトル
codehaus-plexus 代码问题漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
codehaus-plexus是codehaus-plexus开源的一种各种实用程序类的集合。可轻松处理字符串、文件、命令行、XML等。 codehaus-plexus存在安全漏洞,该漏洞源于XML 外部实体(XXE)注入。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
Red HatRHINT Camel-K-1.10.1-cpe:/a:redhat:camel_k:1
Red HatRHPAM 7.13.1 async-cpe:/a:redhat:jboss_enterprise_bpms_platform:7.13
Red HatA-MQ Clients 2-cpe:/a:redhat:a_mq_clients:2
Red HatRed Hat A-MQ Online-cpe:/a:redhat:amq_online:1
Red HatRed Hat build of Apache Camel for Spring Boot-cpe:/a:redhat:camel_spring_boot:3
Red HatRed Hat build of Quarkus-cpe:/a:redhat:quarkus:2
Red HatRed Hat Data Grid 8-cpe:/a:redhat:jboss_data_grid:8
Red HatRed Hat Decision Manager 7-cpe:/a:redhat:jboss_enterprise_brms_platform:7
Red HatRed Hat Enterprise Linux 7-cpe:/o:redhat:enterprise_linux:7
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 8-cpe:/o:redhat:enterprise_linux:8
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat Enterprise Linux 9-cpe:/o:redhat:enterprise_linux:9
Red HatRed Hat Integration Camel Quarkus-cpe:/a:redhat:camel_quarkus:2
Red HatRed Hat Integration Change Data Capture-cpe:/a:redhat:integration:1
Red HatRed Hat Integration Service Registry-cpe:/a:redhat:service_registry:2
Red HatRed Hat JBoss A-MQ 7-cpe:/a:redhat:amq_broker:7
Red HatRed Hat JBoss Data Grid 7-cpe:/a:redhat:jboss_data_grid:7
Red HatRed Hat JBoss Enterprise Application Platform 6-cpe:/a:redhat:jboss_enterprise_application_platform:6
Red HatRed Hat JBoss Enterprise Application Platform 7-cpe:/a:redhat:jboss_enterprise_application_platform:7
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack-cpe:/a:redhat:jbosseapxp
Red HatRed Hat JBoss Fuse 6-cpe:/a:redhat:jboss_fuse:6
Red HatRed Hat JBoss Fuse 7-cpe:/a:redhat:jboss_fuse:7
Red HatRed Hat JBoss Fuse Service Works 6-cpe:/a:redhat:jboss_fuse_service_works:6
Red HatRed Hat JBoss Web Server 3-cpe:/a:redhat:jboss_enterprise_web_server:3
Red HatRed Hat JBoss Web Server 5-cpe:/a:redhat:jboss_enterprise_web_server:5
Red HatRed Hat OpenShift Application Runtimes-cpe:/a:redhat:openshift_application_runtimes:1.0
Red HatRed Hat Process Automation 7-cpe:/a:redhat:jboss_enterprise_bpms_platform:7
Red HatRed Hat Single Sign-On 7-cpe:/a:redhat:red_hat_single_sign_on:7
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat Software Collections-cpe:/a:redhat:rhel_software_collections:3
Red HatRed Hat support for Spring Boot-cpe:/a:redhat:openshift_application_runtimes:1.0

II. CVE-2022-4245の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2022-4245のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Red Hat · 2023-09-25 · 6 CVEs total

CVE-2022-41378.1 HIGHKeycloak: reflected xss attack
CVE-2022-43187.8 HIGHCri-o: /etc/passwd tampering privesc
CVE-2023-51567.5 HIGHGlibc: dos due to memory leak in getaddrinfo.c
CVE-2022-42447.5 HIGHCodehaus-plexus: directory traversal
CVE-2023-427537.0 HIGHKernel: netfilter: potential slab-out-of-bound access due to integer underflow

IV. 関連脆弱性

V. CVE-2022-4245へのコメント

まだコメントはありません


コメントを残す