CVE-2023-34112

MEDIUM

JavaCPP Presets <1.5.9 - Command Injection

Title source: llm
STIX 2.1

Description

JavaCPP Presets is a project providing Java distributions of native C++ libraries. All the actions in the `bytedeco/javacpp-presets` use the `github.event.head_commit.message​` parameter in an insecure way. For example, the commit message is used in a run statement - resulting in a command injection vulnerability due to string interpolation. No exploitation has been reported. This issue has been addressed in version 1.5.9. Users of JavaCPP Presets are advised to upgrade as a precaution.

References (2)

Core 2

Scores

CVSS v3 4.3
EPSS 0.0195
EPSS Percentile 77.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
bytedeco/javacpp_presets < 1.5.9
Published Jun 09, 2023
Tracked Since Feb 18, 2026