Vulnerability DatabaseGHSA-j2pc-v64r-mv4f

GHSA-j2pc-v64r-mv4f
Java vulnerability analysis and mitigation

Overview

A low severity vulnerability (GHSA-j2pc-v64r-mv4f) was discovered in the Protobuf Maven Plugin affecting versions 4.0.0-4.0.1 and versions below 3.10.2. The vulnerability relates to the protocDigest parameter being ignored when protoc is taken from the PATH, which was disclosed on November 3, 2025. The affected package is io.github.ascopes:protobuf-maven-plugin for Maven systems (GitHub Advisory).

Technical details

The vulnerability stems from a validation issue where the protocDigest parameter, intended to verify the integrity of PATH-based binaries, is bypassed. When specifying PATH, the code prematurely returns before performing the digest check, effectively ignoring any specified digest validation. The vulnerability has been assigned a CVSS v4.0 score of 1.0 (Low) with the vector string CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N, indicating local access requirements and high attack complexity (GitHub Advisory).

Impact

The vulnerability affects users who rely on protocDigest for protection against untrusted protoc executables in their PATH. When exploited, it could allow the execution of an unverified protoc binary, potentially compromising the integrity of the build process (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in versions 3.10.2 and 4.0.2. Users are advised to upgrade to these patched versions to ensure proper digest validation for PATH-based protoc executables (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-62275MEDIUM6.9
  • JavaJava
  • com.liferay:com.liferay.blogs.item.selector.web
NoYesNov 01, 2025
CVE-2025-62264MEDIUM5.1
  • JavaJava
  • cpe:2.3:a:liferay:liferay_portal
NoYesOct 31, 2025
CVE-2025-62276MEDIUM4.6
  • JavaJava
  • com.liferay:com.liferay.adaptive.media.web
NoYesNov 01, 2025
CVE-2025-62267MEDIUM4.6
  • JavaJava
  • com.liferay:com.liferay.dynamic.data.mapping.item.selector.web
NoYesOct 31, 2025
GHSA-j2pc-v64r-mv4fLOW1
  • JavaJava
  • io.github.ascopes:protobuf-maven-plugin
NoYesNov 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management