In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
| Software | From | Fixed in |
|---|---|---|
| apache / maven_shared_utils | - | 3.3.3 |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |
org.apache.maven.shared / maven-shared-utils
|
- | 3.3.3 |