Uploaded image for project: 'ActiveMQ Classic'
  1. ActiveMQ Classic
  2. AMQ-7247

Update maven plugin API + Pax URL versions

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 5.15.9
    • 5.15.10, 5.16.0
    • None
    • None

    Description

      We should update the maven plugin + pax url versions to eliminate the following CVEs from the build:

      plexus-utils-1.0.4.jar (pkg:maven/org.codehaus.plexus/plexus-utils@1.0.4, cpe:2.3:a:plexus-utils_project:plexus-utils:1.0.4:::::::*) : CVE-2017-1000487, Directory traversal in org.codehaus.plexus.util.Expand, Possible XML Injection

      pax-url-aether-2.4.3.jar/META-INF/maven/org.apache.httpcomponents/httpclient/pom.xml (pkg:maven/org.apache.httpcomponents/httpclient@4.3.5, cpe:2.3:a:apache:httpclient:4.3.5:::::::*) : CVE-2015-5262

      Attachments

        Issue Links

          Activity

            People

              jbonofre Jean-Baptiste Onofré
              coheigea Colm O hEigeartaigh
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 20m
                  20m