### Impact The attacker can execute arbitrary code without being authenticated ### Mitigation Upgrade to a patched version (please check affected/patched version matrix) ### Credits Bug Bounty of Canton du Jura
Update org.mapfish.print:print-lib to 3.28.28; org.mapfish.print:print-lib to 3.30.30; org.mapfish.print:print-lib to 3.31.21; org.mapfish.print:print-lib to 3.33.14; org.mapfish.print:print-lib to 4.0.3; org.mapfish.print:print-servlet to 3.28.28; org.mapfish.print:print-servlet to 3.30.30; org.mapfish.print:print-servlet to 3.31.21; org.mapfish.print:print-servlet to 3.33.14; org.mapfish.print:print-servlet to 4.0.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMapfish Print: Remote Code Injection (RCE) in Dynamic table affects org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven). Severity is critical. ### Impact The attacker can execute arbitrary code without being authenticated ### Mitigation Upgrade to a patched version (please check affected/patched version matrix) ### Credits Bug Bounty of Canton du Jura
AI coding agents often install or upgrade packages automatically in maven. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Impact The attacker can execute arbitrary code without being authenticated ### Mitigation Upgrade to a patched version (please check affected/patched version matrix) ### Credits Bug Bounty of Canton du Jura
Update org.mapfish.print:print-lib to 3.28.28; org.mapfish.print:print-lib to 3.30.30; org.mapfish.print:print-lib to 3.31.21; org.mapfish.print:print-lib to 3.33.14; org.mapfish.print:print-lib to 4.0.3; org.mapfish.print:print-servlet to 3.28.28; org.mapfish.print:print-servlet to 3.30.30; org.mapfish.print:print-servlet to 3.31.21; org.mapfish.print:print-servlet to 3.33.14; org.mapfish.print:print-servlet to 4.0.3 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanMapfish Print: Remote Code Injection (RCE) in Dynamic table affects org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-lib (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven), org.mapfish.print:print-servlet (maven). Severity is critical. ### Impact The attacker can execute arbitrary code without being authenticated ### Mitigation Upgrade to a patched version (please check affected/patched version matrix) ### Credits Bug Bounty of Canton du Jura
AI coding agents often install or upgrade packages automatically in maven. A critical vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package |
|---|
| Affected range |
|---|
| Fixed version |
|---|
| org.mapfish.print:print-libmaven | >=3.23.0,<3.28.28 | 3.28.28 |
|---|---|---|
| org.mapfish.print:print-libmaven | >=3.29.0,<3.30.30 | 3.30.30 |
| org.mapfish.print:print-libmaven | >=3.31.0,<3.31.21 | 3.31.21 |
| org.mapfish.print:print-libmaven | >=3.32.0,<3.33.14 | 3.33.14 |
| org.mapfish.print:print-libmaven | >=3.34.0,<4.0.3 | 4.0.3 |
| org.mapfish.print:print-servletmaven | >=3.23.0,<3.28.28 | 3.28.28 |
| org.mapfish.print:print-servletmaven | >=3.29.0,<3.30.30 | 3.30.30 |
| org.mapfish.print:print-servletmaven | >=3.31.0,<3.31.21 | 3.31.21 |
| org.mapfish.print:print-servletmaven | >=3.32.0,<3.33.14 | 3.33.14 |
| org.mapfish.print:print-servletmaven | >=3.34.0,<4.0.3 | 4.0.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package |
|---|
| Affected range |
|---|
| Fixed version |
|---|
| org.mapfish.print:print-libmaven | >=3.23.0,<3.28.28 | 3.28.28 |
|---|---|---|
| org.mapfish.print:print-libmaven | >=3.29.0,<3.30.30 | 3.30.30 |
| org.mapfish.print:print-libmaven | >=3.31.0,<3.31.21 | 3.31.21 |
| org.mapfish.print:print-libmaven | >=3.32.0,<3.33.14 | 3.33.14 |
| org.mapfish.print:print-libmaven | >=3.34.0,<4.0.3 | 4.0.3 |
| org.mapfish.print:print-servletmaven | >=3.23.0,<3.28.28 | 3.28.28 |
| org.mapfish.print:print-servletmaven | >=3.29.0,<3.30.30 | 3.30.30 |
| org.mapfish.print:print-servletmaven | >=3.31.0,<3.31.21 | 3.31.21 |
| org.mapfish.print:print-servletmaven | >=3.32.0,<3.33.14 | 3.33.14 |
| org.mapfish.print:print-servletmaven | >=3.34.0,<4.0.3 | 4.0.3 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard