CVE-2022-40160
Last modified
CVE-2022-40160 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. EPSS estimates a 1.19% chance of exploitation in the next 30 days.
Description
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After review by the JXPath maintainers, the original report was found to be invalid.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Commons Jxpath | <= 1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-40160?
How severe is CVE-2022-40160?
How do I fix CVE-2022-40160?
Are you affected by CVE-2022-40160?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
