Disputed CVE-2022-40159: JXPath XPath Flaw Marked False
CVE-2022-40159 Published on October 6, 2022

Stack Overflow in JXPath
** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then allocated by Google in breach of the CNA rules. After review by the JXPath maintainers, the original report was found to be invalid.

NVD

Weakness Type

What is a Stack Overflow Vulnerability?

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

CVE-2022-40159 has been classified to as a Stack Overflow vulnerability or weakness.


Products Associated with CVE-2022-40159

Want to know whenever a new CVE is published for Apache Commons Jxpath? stack.watch will email you.

 

Affected Versions

jxpath:

Exploit Probability

EPSS
1.87%
Percentile
82.83%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.