Uploaded image for project: 'Maven WAR Plugin'
  1. Maven WAR Plugin
  2. MWAR-456

Latest maven-war-plugin causing vulnerable .jars to be downloaded

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Blocker
    • Resolution: Fixed
    • 3.3.2
    • 3.4.0
    • None
    • None
    • Linux, Windows
    • Patch, Important

    Description

      We are planning to upgrade our project's parent pom.xml file to use maven-war-plugin 3.3.2, which is the latest version, but somehow it is causing 2 vulnerable .jar files, plexus-utils-2.0.5.jar, and maven-shared-utils-3.2.1.jar, to download from our JFrog Artifactory repository when it shouldn't be. Other versions of the maven-war-plugin seem to result in the same issue.

      Is there someone available who can assist with this issue as soon as possible? Our development efforts are currently blocked because of this issue. We need to be able to upgrade to the latest version of the maven-war-plugin and prevent vulnerable .jar files from being downloaded as soon as possible before our remediation deadline in a few weeks. Thank you (see the maven console logs attached for more details).

      Attachments

        1. Console-Log-Edit.JPG
          91 kB
          Joseph Angotti

        Activity

          People

            dennisl Dennis Lundberg
            jangotti1 Joseph Angotti
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 60h
                60h
                Remaining:
                Remaining Estimate - 60h
                60h
                Logged:
                Time Spent - Not Specified
                Not Specified