Description
We should update the maven plugin + pax url versions to eliminate the following CVEs from the build:
plexus-utils-1.0.4.jar (pkg:maven/org.codehaus.plexus/plexus-utils@1.0.4, cpe:2.3:a:plexus-utils_project:plexus-utils:1.0.4:::::::*) : CVE-2017-1000487, Directory traversal in org.codehaus.plexus.util.Expand, Possible XML Injection
pax-url-aether-2.4.3.jar/META-INF/maven/org.apache.httpcomponents/httpclient/pom.xml (pkg:maven/org.apache.httpcomponents/httpclient@4.3.5, cpe:2.3:a:apache:httpclient:4.3.5:::::::*) : CVE-2015-5262
Attachments
Issue Links
- links to