Description
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This issue means that text contained in the command string could be interpreted as XML and allow for XML injection.
References (4)
Scores
CVSS v3
4.3
EPSS
0.0006
EPSS Percentile
18.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-611
CWE-91
Status
published
Products (3)
codehaus-plexus/plexus-utils
< 3.0.24
org.codehaus.plexus/plexus-utils
0 - 3.0.24Maven
redhat/integration_camel_k
< 1.10.1
Published
Sep 25, 2023
Tracked Since
Feb 18, 2026