rpm package
almalinux/maven-openjdk17
pkg:rpm/almalinux/maven-openjdk17
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-67030 | Hig | 8.8 | < 1:3.9.9-13.module_el9.8.0+229+787fb9a7 | 1:3.9.9-13.module_el9.8.0+229+787fb9a7 | Mar 25, 2026 | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code | |
| CVE-2022-29599 | Cri | 9.8 | < 1:3.6.2-7.module_el8.6.0+2786+d7c38b21 | 1:3.6.2-7.module_el8.6.0+2786+d7c38b21 | May 23, 2022 | In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. | |
| CVE-2020-13956 | Med | 5.3 | < 1:3.6.2-7.module_el8.6.0+2786+d7c38b21 | 1:3.6.2-7.module_el8.6.0+2786+d7c38b21 | Dec 2, 2020 | Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. |
- affected < 1:3.9.9-13.module_el9.8.0+229+787fb9a7fixed 1:3.9.9-13.module_el9.8.0+229+787fb9a7
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
- affected < 1:3.6.2-7.module_el8.6.0+2786+d7c38b21fixed 1:3.6.2-7.module_el8.6.0+2786+d7c38b21
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.
- affected < 1:3.6.2-7.module_el8.6.0+2786+d7c38b21fixed 1:3.6.2-7.module_el8.6.0+2786+d7c38b21
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.