Medium severity5.6NVD Advisory· Published Sep 8, 2022· Updated Jun 17, 2026
CVE-2022-25914
CVE-2022-25914
Description
The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.google.cloud.tools:jib-coreMaven | < 0.22.0 | 0.22.0 |
Affected products
3- com.google.cloud.tools/jib-coredescription
Patches
Vulnerability mechanics
References
5- github.com/GoogleContainerTools/jib/commit/67fa40bc2c484da0546333914ea07a89fe44eaafnvdPatchThird Party AdvisoryWEB
- github.com/GoogleContainerTools/jib/pull/3744nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-936v-cg49-m2g5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25914ghsaADVISORY
- security.snyk.io/vuln/SNYK-JAVA-COMGOOGLECLOUDTOOLS-2968871nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.