{"id":"CVE-2022-25914","aliases":["GHSA-936v-cg49-m2g5"],"url":"https://o3.security/vulnerability/CVE-2022-25914","summary":"Remote Code Execution (RCE)","details":"The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.","published":"2022-09-08T05:05:17.747Z","modified":"2026-07-22T02:24:43.004558Z","cvss":{"score":5.6,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.google.cloud.tools:jib-core","fixedVersion":"0.22.0"}],"fix":{"url":"https://github.com/GoogleContainerTools/jib/commit/67fa40bc2c484da0546333914ea07a89fe44eaaf","label":"GoogleContainerTools/jib@67fa40b"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-COMGOOGLECLOUDTOOLS-2968871"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25914.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25914"},{"type":"FIX","url":"https://github.com/GoogleContainerTools/jib/commit/67fa40bc2c484da0546333914ea07a89fe44eaaf"},{"type":"FIX","url":"https://github.com/GoogleContainerTools/jib/pull/3744"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-22T02:24:43.004558Z"}}