CVE-2023-34112 is a command injection vulnerability affecting JavaCPP Presets (bytedeco/javacpp-presets) versions prior to 1.5.9. The flaw stems from insecure handling of the github.event.head_commit.message parameter in GitHub Actions, allowing string interpolation to execute arbitrary commands. With a CVSS score of 8.8 (High), this vulnerability presents a significant risk (FAUCET Risk Score 73/100) due to its low attack complexity and potential for high impact on confidentiality, integrity, and availability, requiring only low privileges and no user interaction. While no active exploitation has been reported and no public exploit code or significant community discussion exists, users are strongly advised to upgrade to version 1.5.9 as a precautionary measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.9CPE matchmatch criteria | cpe:2.3:a:bytedeco:javacpp_presets:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.