Vulnerability Description
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codehaus-Plexus | Plexus-Utils | < 3.0.16 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:1322Third Party Advisory
- https://github.com/codehaus-plexus/plexus-utils/commit/b38a1b3a4352303e4312b2bb6PatchThird Party Advisory
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b667
- https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633
- https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995
- https://lists.debian.org/debian-lts-announce/2018/01/msg00010.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00011.htmlMailing ListThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31522PatchThird Party Advisory
- https://www.debian.org/security/2018/dsa-4146Third Party Advisory
- https://www.debian.org/security/2018/dsa-4149Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1322Third Party Advisory
- https://github.com/codehaus-plexus/plexus-utils/commit/b38a1b3a4352303e4312b2bb6PatchThird Party Advisory
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b667
- https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633
FAQ
What is CVE-2017-1000487?
CVE-2017-1000487 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
How severe is CVE-2017-1000487?
CVE-2017-1000487 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-1000487?
Check the references section above for vendor advisories and patch information. Affected products include: Codehaus-Plexus Plexus-Utils, Debian Debian Linux.