Date: Mon, 02 Mar 2015 14:07:00 +0100 From: Martin Prpic <mprpic@...hat.com> To: "oss-security\@...ts.openwall.com" <oss-security@...ts.openwall.com> Subject: CVE request: Maven downloads JARs via HTTP Hi, I don't see a CVE assigned for this anywhere: https://jira.codehaus.org/browse/MNG-5672 "Maven Central can now be accessed via HTTPS. I think the default configuration should be switched to use that, rather than the current unsecured HTTP transport." This was fixed in Maven 3.2.3: https://maven.apache.org/docs/3.2.3/release-notes.html Thanks, -- Martin Prpič / Red Hat Product Security
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ