Uploaded image for project: 'Talend DI components'
  1. Talend DI components
  2. TDI-45272

Apache Maven Shared Utils: OS Command Injection in Talend/cloud-components

Apply templateInsert Lucidchart Diagram
    XMLWordPrintable

Details

    • Work Item
    • Status: Done
    • Minor
    • Resolution: Fixed
    • None
    • connectors/1.17.0
    • None

    Description

      OS Command Injection in Talend/component-runtime (master)
      Issue Details
      Vulnerability: OS Command Injection
      Severity: High
      Project: Talend/component-runtime
      Branch: master
      Scan Date: Unknown
      Issue Description
      maven-shared-utils is vulnerable to OS command injection. An attacker is able to inject and execute arbitrary OS commands on the host OS via the Commandline class due to insecure validation and escaping of double-quoted strings.

      View more details

      and https://sca.analysiscenter.veracode.com/workspaces/WzzF47x/issues/vulnerabilities/51179269

      Attachments

        Issue Links

          Activity

            People

              pteyssier pierre teyssier
              emmanuel_g emmanuel gallois
              Christophe LeSaec, Liang Xia
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 4 hours
                  4h