The package com.google.cloud.tools:jib-core before 0.22.0 are vulnerable to Remote Code Execution (RCE) via the isDockerInstalled function, due to attempting to execute input.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jib | Jib_project | * | 0.22.0 (excluding) |
Migration Toolkit for Runtimes 1 on RHEL 8 | RedHat | org.jboss.windup-windup-openshift-parent | * |