Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 23 Apr 2021 10:21:24 -0400
From: Brian Fox <brianf@...che.org>
To: oss-security@...ts.openwall.com
Subject: CVE-2021-26291: Apache Maven: block repositories using http by default

Subject: CVE-2021-26291: Apache Maven: block repositories using http by default

Description:

Apache Maven will follow repositories that are defined in a
dependency’s Project Object Model (pom) which may be surprising to
some users, resulting in potential risk if a malicious actor takes
over that repository or is able to insert themselves into a position
to pretend to be that repository. Maven is changing the default
behavior in 3.8.1+ to no longer follow http (non-SSL) repository
references by default. More details available in the referenced urls.

If you are currently using a repository manager to govern the
repositories used by your builds, you are unaffected by the risks
present in the legacy behavior, and are unaffected by this
vulnerability and change to default behavior. See this link for more
information about repository management:
https://maven.apache.org/repository-management.html

This issue is being tracked as MNG-7118

Credit:

Apache Maven would like to thank Jonathan Leitschuh for highlighting
the need for this change.

References:

https://lists.apache.org/thread.html/r9a027668558264c4897633e66bcb7784099fdec9f9b22c38c2442f00%40%3Cusers.maven.apache.org%3E

ASF-EmailInstructionsChanges

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.