plexus-utils: Mishandled strings in Commandline class allow for command injection
Published Jan 3, 2018
9.8
CRITICALCVSS 3.1
EPSS 6.49%
Description
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.
Affected products
No data.
Configuration 1
- < 3.0.16
Configuration 2
- 7.0
- 8.0
- 9.0
No data.
Red Hat JBoss A-MQ 6.3
plexus-utils
Fixed · RHSA-2018:1322
Red Hat JBoss Fuse 6.3
plexus-utils
Fixed · RHSA-2018:1322
JBoss Developer Studio 10
plexus-utils
Under investigation
JBoss Developer Studio 8
plexus-utils
Under investigation
Red Hat BPM Suite 6
plexus-utils
Not affected
Red Hat Enterprise Linux 7
plexus-utils
Will not fix
Red Hat Enterprise Linux 8
plexus-utils
Not affected
Red Hat JBoss A-MQ 6
plexus-utils
Affected
Red Hat JBoss BRMS 6
plexus-utils
Not affected
Red Hat JBoss Data Virtualization 6
plexus-utils
Not affected
Red Hat JBoss Fuse Service Works 6
plexus-utils
Will not fix
Red Hat JBoss Portal 6
plexus-utils
Under investigation
Red Hat OpenStack Platform 8 (Liberty)
opendaylight
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
opendaylight
Will not fix
Red Hat Satellite 6
plexus-utils
Not affected
Red Hat Single Sign-On 7
rh-sso7-keycloak
Not affected
Red Hat Software Collections
rh-maven33-plexus-utils
Not affected
Red Hat Software Collections
rh-maven35-plexus-utils
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss A-MQ 6.3 | plexus-utils | Fixed | RHSA-2018:1322 |
| Red Hat JBoss Fuse 6.3 | plexus-utils | Fixed | RHSA-2018:1322 |
| JBoss Developer Studio 10 | plexus-utils | Under investigation | n/a |
| JBoss Developer Studio 8 | plexus-utils | Under investigation | n/a |
| Red Hat BPM Suite 6 | plexus-utils | Not affected | n/a |
| Red Hat Enterprise Linux 7 | plexus-utils | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | plexus-utils | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | plexus-utils | Affected | n/a |
| Red Hat JBoss BRMS 6 | plexus-utils | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | plexus-utils | Not affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | plexus-utils | Will not fix | n/a |
| Red Hat JBoss Portal 6 | plexus-utils | Under investigation | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | opendaylight | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | opendaylight | Will not fix | n/a |
| Red Hat Satellite 6 | plexus-utils | Not affected | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Not affected | n/a |
| Red Hat Software Collections | rh-maven33-plexus-utils | Not affected | n/a |
| Red Hat Software Collections | rh-maven35-plexus-utils | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of plexus-utils as shipped with Red Hat Enterprise Linux 7 as well as Red Hat Satellite 6.0 and 6.1. Red Hat Satellite 6.2 and later do not ship plexus-utils, as such they are not affected by this vulnerability. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (52 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.49% (0.06490) | 93.55th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.54% (0.06543) | 92.91th | v5 (v2026.06.15) |
| Jan 13, 2026 | 7.80% (0.07798) | 91.68th | v4 (v2025.03.14) |
| Jan 8, 2026 | 22.57% (0.22571) | 95.65th | v4 (v2025.03.14) |
| Jan 4, 2026 | 15.86% (0.15856) | 94.52th | v4 (v2025.03.14) |
| Jan 1, 2026 | 5.18% (0.05185) | 89.65th | v4 (v2025.03.14) |
| Dec 4, 2025 | 15.86% (0.15856) | 94.47th | v4 (v2025.03.14) |
| Dec 1, 2025 | 5.18% (0.05185) | 89.57th | v4 (v2025.03.14) |
| Nov 4, 2025 | 15.86% (0.15856) | 94.45th | v4 (v2025.03.14) |
| Nov 1, 2025 | 5.18% (0.05185) | 89.48th | v4 (v2025.03.14) |
| Oct 6, 2025 | 14.90% (0.14897) | 94.29th | v4 (v2025.03.14) |
| Oct 4, 2025 | 11.54% (0.11538) | 93.34th | v4 (v2025.03.14) |
| Oct 1, 2025 | 3.61% (0.03611) | 87.36th | v4 (v2025.03.14) |
| Sep 13, 2025 | 11.54% (0.11538) | 93.37th | v4 (v2025.03.14) |
| Sep 5, 2025 | 13.17% (0.13173) | 93.88th | v4 (v2025.03.14) |
| Sep 1, 2025 | 3.56% (0.03558) | 87.33th | v4 (v2025.03.14) |
| Aug 5, 2025 | 13.17% (0.13173) | 93.83th | v4 (v2025.03.14) |
| Aug 1, 2025 | 3.56% (0.03558) | 87.37th | v4 (v2025.03.14) |
| Jul 20, 2025 | 13.17% (0.13173) | 93.79th | v4 (v2025.03.14) |
| Jul 13, 2025 | 15.55% (0.15546) | 94.36th | v4 (v2025.03.14) |
| Jul 4, 2025 | 17.61% (0.17611) | 94.78th | v4 (v2025.03.14) |
| Jul 1, 2025 | 5.00% (0.04995) | 89.28th | v4 (v2025.03.14) |
| Jun 19, 2025 | 17.61% (0.17611) | 94.75th | v4 (v2025.03.14) |
| Jun 10, 2025 | 22.17% (0.22172) | 95.46th | v4 (v2025.03.14) |
| Jun 1, 2025 | 7.63% (0.07628) | 91.43th | v4 (v2025.03.14) |
| May 5, 2025 | 22.17% (0.22172) | 95.42th | v4 (v2025.03.14) |
| May 1, 2025 | 7.63% (0.07628) | 91.41th | v4 (v2025.03.14) |
| Apr 16, 2025 | 22.17% (0.22172) | 95.39th | v4 (v2025.03.14) |
| Apr 14, 2025 | 24.80% (0.24804) | 95.72th | v4 (v2025.03.14) |
| Apr 13, 2025 | 7.52% (0.07523) | 91.01th | v4 (v2025.03.14) |
| Apr 2, 2025 | 24.80% (0.24804) | 95.70th | v4 (v2025.03.14) |
| Apr 1, 2025 | 7.19% (0.07193) | 90.75th | v4 (v2025.03.14) |
| Mar 30, 2025 | 25.06% (0.25059) | 95.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 47.67% (0.47666) | 96.65th | v4 (v2025.03.14) |
| Mar 18, 2025 | 25.06% (0.25059) | 95.75th | v4 (v2025.03.14) |
| Mar 17, 2025 | 7.19% (0.07193) | 90.94th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.40% (0.00395) | 74.28th | v3 (v2023.03.01) |
| Feb 29, 2024 | 0.40% (0.00395) | 72.86th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.43% (0.00426) | 73.67th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.43% (0.00426) | 71.45th | v3 (v2023.03.01) |
| Jul 30, 2023 | 0.59% (0.00592) | 75.47th | v3 (v2023.03.01) |
| Jul 6, 2023 | 0.75% (0.00754) | 78.53th | v3 (v2023.03.01) |
| May 27, 2023 | 0.86% (0.00865) | 80.01th | v3 (v2023.03.01) |
| May 8, 2023 | 0.71% (0.00709) | 77.51th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.56% (0.00556) | 74.16th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.54% (0.03535) | 84.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.54% (0.03535) | 83.33th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.54% (0.03535) | 66.49th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.48% (0.02476) | 54.92th | v1 |
| Jan 6, 2022 | 2.48% (0.02476) | 54.49th | v1 |
| Sep 1, 2021 | 2.48% (0.02476) | 78.74th | v1 |
| Apr 14, 2021 | 2.48% (0.02476) | 0.00th | v1 |
References (20)
- https://access.redhat.com/errata/RHSA-2018:1322 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-1000487 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1532497 Issue Tracking
- https://github.com/advisories/GHSA-8vhq-qq4p-grq3 Advisory
- https://github.com/codehaus-plexus/plexus-utils/commit/b38a1b3a4352303e4312b2bb601a0d7ec6e28f41 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633d54579a4377e62%40%3Cdev.avro.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r2e94f72f53df432302d359fd66cfa9e9efb8d42633d54579a4377e62@%3Cdev.avro.apache.org%3E
- https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9584c4304c888f651d214341a939bd264ed30c9e3d0d30fe85097ecf@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995ec908ce7624d26@%3Ccommits.pulsar.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/01/msg00010.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/01/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000487
- https://snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31522 x_refsource_MISCPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-1000487
- https://www.debian.org/security/2018/dsa-4146 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.debian.org/security/2018/dsa-4149 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.