VYPR
Medium severity5.5NVD Advisory· Published Nov 19, 2022· Updated Jun 17, 2026

CVE-2022-4065

CVE-2022-4065

Description

A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 7.5.1 and 7.7.1 is able to address this issue. The patch is named 9150736cd2c123a6a3b60e6193630859f9f0422b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-214027.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.testng:testngMaven
>= 6.13, < 7.5.17.5.1
org.testng:testngMaven
>= 7.6.0, < 7.7.07.7.0

Affected products

42

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.