668
VMScore

CVE-2017-1000487

Published: 03/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Plexus-utils prior to 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

plexus-utils project plexus-utils

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Fuse/A-MQ 63 R7 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabilit ...
Charles Duffy discovered that the Commandline class in the utilities for the Plexus framework performs insufficient quoting of double-encoded strings, which could result in the execution of arbitrary shell commands For the oldstable distribution (jessie), this problem has been fixed in version 3015-1+deb8u1 For the stable distribution (stretch) ...
Plexus-utils before 3016 is vulnerable to command injection because it does not correctly process the contents of double quoted strings ...