CVE-2022-39243
Description
NuProcess is an external process execution implementation for Java. In all the versions of NuProcess where it forks processes by using the JVM's Java_java_lang_UNIXProcess_forkAndExec method (1.2.0+), attackers can use NUL characters in their strings to perform command line injection. Java's ProcessBuilder isn't vulnerable because of a check in ProcessBuilder.start. NuProcess is missing that check. This vulnerability can only be exploited to inject command line arguments on Linux. Version 2.0.5 contains a patch. As a workaround, users of the library can sanitize command strings to remove NUL characters prior to passing them to NuProcess for execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.zaxxer:nuprocessMaven | >= 1.2.0, < 2.0.5 | 2.0.5 |
Affected products
3- cpe:2.3:a:nuprocess_project:nuprocess:*:*:*:*:*:*:*:*Range: >=1.2.0,<2.0.5
- brettwooldridge/NuProcessv5Range: >= 1.2.0, < 2.0.5
Patches
Vulnerability mechanics
References
5- github.com/brettwooldridge/NuProcess/commit/29bc09de561bf00ff9bf77123756363a9709f868nvdPatchThird Party AdvisoryWEB
- github.com/brettwooldridge/NuProcess/pull/143nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-cxgf-v2p8-7ph7ghsaADVISORY
- github.com/brettwooldridge/NuProcess/security/advisories/GHSA-cxgf-v2p8-7ph7nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-39243ghsaADVISORY
News mentions
0No linked articles in our index yet.