Medium severity4.3NVD Advisory· Published Sep 25, 2023· Updated Jun 17, 2026
CVE-2022-4245
CVE-2022-4245
Description
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.codehaus.plexus:plexus-utilsMaven | < 3.0.24 | 3.0.24 |
Affected products
31- Red Hat/A-MQ Clients 2v5cpe:/a:redhat:a_mq_clients:2
- Red Hat/Red Hat JBoss A-MQ 7v5cpe:/a:redhat:amq_broker:7
- cpe:/a:redhat:amq_online:1
- Red Hat/RHINT Camel-K-1.10.1v5cpe:/a:redhat:camel_k:1
- cpe:/a:redhat:camel_quarkus:2
- cpe:/a:redhat:camel_spring_boot:3
- Red Hat/Red Hat Integration Change Data Capturev5cpe:/a:redhat:integration:1
- Red Hat/Red Hat JBoss Data Grid 7v5cpe:/a:redhat:jboss_data_grid:7
- Red Hat/Red Hat Data Grid 8v5cpe:/a:redhat:jboss_data_grid:8
cpe:/a:redhat:jboss_enterprise_application_platform:6+ 1 more
- cpe:/a:redhat:jboss_enterprise_application_platform:6
- cpe:/a:redhat:jboss_enterprise_application_platform:7
- cpe:/a:redhat:jboss_enterprise_bpms_platform:7
- Red Hat/RHPAM 7.13.1 asyncv5cpe:/a:redhat:jboss_enterprise_bpms_platform:7.13
- cpe:/a:redhat:jboss_enterprise_brms_platform:7
cpe:/a:redhat:jboss_enterprise_web_server:3+ 1 more
- cpe:/a:redhat:jboss_enterprise_web_server:3
- cpe:/a:redhat:jboss_enterprise_web_server:5
- Red Hat/Red Hat JBoss Fuse 6v5cpe:/a:redhat:jboss_fuse:6
- Red Hat/Red Hat JBoss Fuse 7v5cpe:/a:redhat:jboss_fuse:7
- cpe:/a:redhat:jboss_fuse_service_works:6
- cpe:/a:redhat:jbosseapxp
- cpe:/a:redhat:openshift_application_runtimes:1.0
- cpe:/a:redhat:quarkus:2
- cpe:/a:redhat:red_hat_single_sign_on:7
- cpe:/a:redhat:rhel_software_collections:3
- cpe:/a:redhat:service_registry:2
cpe:/o:redhat:enterprise_linux:7+ 2 more
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8
- cpe:/o:redhat:enterprise_linux:9
Patches
Vulnerability mechanics
References
9- access.redhat.com/errata/RHSA-2023:2135nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2023:3906nvdThird Party AdvisoryWEB
- access.redhat.com/security/cve/CVE-2022-4245nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-jcwr-x25h-x5fhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-4245ghsaADVISORY
- github.com/codehaus-plexus/plexus-utils/commit/f933e5e78dc2637e485447ed821fe14904f110deghsaWEB
- github.com/codehaus-plexus/plexus-utils/issues/3ghsaWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-461102ghsaWEB
News mentions
0No linked articles in our index yet.