Search CVE reports
1 – 4 of 4 results
CVE-2022-29599
Medium prioritySome fixes available 5 of 8
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
1 affected packages
maven-shared-utils
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maven-shared-utils | — | Fixed | Fixed | Fixed | Fixed |
CVE-2021-26291
Medium prioritySome fixes available 4 of 13
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to...
1 affected packages
maven
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maven | Needs evaluation | Fixed | Fixed | Fixed | Fixed |
CVE-2014-0792
Medium prioritySonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
1 affected packages
maven-indexer
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maven-indexer | — | — | — | Ignored | Ignored |
CVE-2013-0253
Medium priorityThe default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
1 affected packages
maven
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
maven | — | — | — | — | Not affected |