CVE-2017-1000487
Summary
| CVE | CVE-2017-1000487 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-03 20:29:00 UTC |
| Updated | 2023-11-07 02:37:00 UTC |
| Description | Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| [SECURITY] [DLA 1236-1] plexus-utils security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [PLXUTILS-161] Commandline shell injection problems · codehaus-plexus/plexus-utils@b38a1b3 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| [SECURITY] [DLA 1237-1] plexus-utils2 security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4146-1 plexus-utils |
DEBIAN |
www.debian.org |
Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Shell Command Injection in org.codehaus.plexus:plexus-utils | Snyk |
MISC |
snyk.io |
Patch, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4149-1 plexus-utils2 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 731324 Atlassian Bamboo Server and Data Center Code Injection and Directory Traversal Vulnerability (BAM-21216)