Codehaus-plexus: directory traversal
Published Sep 25, 2023
7.5
HIGHCVSS 3.1
EPSS 1.35%
Description
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.
Affected products
-
-
-
-
-
-
- Vendor Red Hat Product Red Hat JBoss Enterprise Application Platform Expansion Pack Defaultaffected
-
-
-
-
-
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat A-MQ Online | affected |
| |||
| Red Hat | Red Hat Data Grid 8 | affected |
| |||
| Red Hat | Red Hat Integration Camel Quarkus | affected |
| |||
| Red Hat | Red Hat Integration Change Data Capture | affected |
| |||
| Red Hat | Red Hat Integration Service Registry | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
| |||
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | affected |
| |||
| Red Hat | Red Hat JBoss Fuse 7 | affected |
| |||
| Red Hat | Red Hat Software Collections | affected |
| |||
| Red Hat | Red Hat build of Apache Camel for Spring Boot | affected |
| |||
| Red Hat | Red Hat build of Quarkus | affected |
| |||
| Red Hat | Red Hat support for Spring Boot | affected |
|
Configuration 1
- < 3.0.24
Configuration 2
- < 1.10.1
No data.
RHINT Camel-K-1.10.1
codehaus-plexus
Fixed · RHSA-2023:3906
RHPAM 7.13.1 async
n/a
Fixed · RHSA-2023:2135
A-MQ Clients 2
codehaus-plexus
Not affected
Red Hat A-MQ Online
codehaus-plexus
Not affected
Red Hat AMQ Broker 7
codehaus-plexus
Not affected
Red Hat Data Grid 8
codehaus-plexus
Will not fix
Red Hat Decision Manager 7
codehaus-plexus
Out of support scope
Red Hat Enterprise Linux 7
plexus-utils
Out of support scope
Red Hat Enterprise Linux 8
maven:3.6/plexus-utils
Not affected
Red Hat Enterprise Linux 8
maven:3.8/plexus-utils
Not affected
Red Hat Enterprise Linux 9
maven:3.8/plexus-utils
Not affected
Red Hat Enterprise Linux 9
plexus-utils
Not affected
Red Hat Fuse 7
codehaus-plexus
Will not fix
Red Hat Integration Camel Quarkus 1
codehaus-plexus
Will not fix
Red Hat JBoss Data Grid 7
codehaus-plexus
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
codehaus-plexus
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
codehaus-plexus
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
codehaus-plexus
Affected
Red Hat JBoss Fuse 6
codehaus-plexus
Out of support scope
Red Hat JBoss Fuse Service Works 6
codehaus-plexus
Out of support scope
Red Hat JBoss Web Server 3
codehaus-plexus
Out of support scope
Red Hat JBoss Web Server 5
codehaus-plexus
Not affected
Red Hat OpenShift Application Runtimes
codehaus-plexus
Not affected
Red Hat Process Automation 7
codehaus-plexus
Out of support scope
Red Hat Single Sign-On 7
org.codehaus.plexus-plexus-utils
Not affected
Red Hat Software Collections
rh-maven36-byte-buddy
Will not fix
Red Hat Software Collections
rh-maven36-maven
Not affected
Red Hat Software Collections
rh-maven36-maven-archiver
Not affected
Red Hat Software Collections
rh-maven36-maven-assembly-plugin
Will not fix
Red Hat Software Collections
rh-maven36-maven-compiler-plugin
Will not fix
Red Hat Software Collections
rh-maven36-maven-jar-plugin
Not affected
Red Hat Software Collections
rh-maven36-maven-plugin-bundle
Will not fix
Red Hat Software Collections
rh-maven36-maven-remote-resources-plugin
Not affected
Red Hat Software Collections
rh-maven36-maven-shade-plugin
Will not fix
Red Hat Software Collections
rh-maven36-maven-source-plugin
Will not fix
Red Hat Software Collections
rh-maven36-maven-surefire
Will not fix
Red Hat Software Collections
rh-maven36-plexus-utils
Not affected
Red Hat build of Apache Camel for Spring Boot 3
codehaus-plexus
Fix deferred
Red Hat build of Apicurio Registry 2
codehaus-plexus
Affected
Red Hat build of Debezium 1
codehaus-plexus
Will not fix
Red Hat build of Quarkus
codehaus-plexus
Not affected
Red Hat support for Spring Boot
codehaus-plexus
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| RHINT Camel-K-1.10.1 | codehaus-plexus | Fixed | RHSA-2023:3906 |
| RHPAM 7.13.1 async | n/a | Fixed | RHSA-2023:2135 |
| A-MQ Clients 2 | codehaus-plexus | Not affected | n/a |
| Red Hat A-MQ Online | codehaus-plexus | Not affected | n/a |
| Red Hat AMQ Broker 7 | codehaus-plexus | Not affected | n/a |
| Red Hat Data Grid 8 | codehaus-plexus | Will not fix | n/a |
| Red Hat Decision Manager 7 | codehaus-plexus | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | plexus-utils | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | maven:3.6/plexus-utils | Not affected | n/a |
| Red Hat Enterprise Linux 8 | maven:3.8/plexus-utils | Not affected | n/a |
| Red Hat Enterprise Linux 9 | maven:3.8/plexus-utils | Not affected | n/a |
| Red Hat Enterprise Linux 9 | plexus-utils | Not affected | n/a |
| Red Hat Fuse 7 | codehaus-plexus | Will not fix | n/a |
| Red Hat Integration Camel Quarkus 1 | codehaus-plexus | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | codehaus-plexus | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | codehaus-plexus | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | codehaus-plexus | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | codehaus-plexus | Affected | n/a |
| Red Hat JBoss Fuse 6 | codehaus-plexus | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | codehaus-plexus | Out of support scope | n/a |
| Red Hat JBoss Web Server 3 | codehaus-plexus | Out of support scope | n/a |
| Red Hat JBoss Web Server 5 | codehaus-plexus | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | codehaus-plexus | Not affected | n/a |
| Red Hat Process Automation 7 | codehaus-plexus | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | org.codehaus.plexus-plexus-utils | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-byte-buddy | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-maven | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-maven-archiver | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-maven-assembly-plugin | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-maven-compiler-plugin | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-maven-jar-plugin | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-maven-plugin-bundle | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-maven-remote-resources-plugin | Not affected | n/a |
| Red Hat Software Collections | rh-maven36-maven-shade-plugin | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-maven-source-plugin | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-maven-surefire | Will not fix | n/a |
| Red Hat Software Collections | rh-maven36-plexus-utils | Not affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 3 | codehaus-plexus | Fix deferred | n/a |
| Red Hat build of Apicurio Registry 2 | codehaus-plexus | Affected | n/a |
| Red Hat build of Debezium 1 | codehaus-plexus | Will not fix | n/a |
| Red Hat build of Quarkus | codehaus-plexus | Not affected | n/a |
| Red Hat support for Spring Boot | codehaus-plexus | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Single Sign-On uses this package for testing purposes and is not delivered with the distribution. Hence not affected status.
References (10)
- https://access.redhat.com/errata/RHSA-2023:2135 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:3906 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-4244 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2149841 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-g6ph-x5wf-g337 Advisory
- https://github.com/codehaus-plexus/plexus-utils/commit/33a2853df8185b4519b1b8bfae284f03392618ef
- https://github.com/codehaus-plexus/plexus-utils/issues/4
- https://nvd.nist.gov/vuln/detail/CVE-2022-4244
- https://security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31521
- https://www.cve.org/CVERecord?id=CVE-2022-4244
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2023:2135 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2023:3906 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-4244 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2149841 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-g6ph-x5wf-g337 | Advisory | |
| https://github.com/codehaus-plexus/plexus-utils/commit/33a2853df8185b4519b1b8bfae284f03392618ef | ||
| https://github.com/codehaus-plexus/plexus-utils/issues/4 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-4244 | ||
| https://security.snyk.io/vuln/SNYK-JAVA-ORGCODEHAUSPLEXUS-31521 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-4244 |
Change history (0)
No recorded changes yet.