VYPR

Maven

by Apache

Source repositories

CVEs (2)

  • CVE-2021-26291CriApr 23, 2021
    risk 0.53cvss 9.1epss 0.09

    Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to…

  • CVE-2013-0253Apr 9, 2013
    risk 0.00cvss epss 0.02

    The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.