Uploaded image for project: 'Apache Gora'
  1. Apache Gora
  2. GORA-642

Use HTTPS to resolve dependencies in Maven Build

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 0.9
    • 1.0
    • build process
    • None

    Description

      This is a security fix for a vulnerability in Apache Maven pom.xml file(s).

      The build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. This leaves build vulnerable to allowing a Man in the Middle (MITM) attackers to execute arbitrary code on local computer or CI/CD system.

      Attachments

        Activity

          People

            djkevincr Kevin Ratnasekera
            djkevincr Kevin Ratnasekera
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: