First published: Fri Mar 01 2013(Updated: )
Apache Maven 3.0.4 (with Apache Maven Wagon 2.1) has introduced a non-secure SSL mode by default. This mode disables all SSL certificate checking, including: host name verification , date validity, and certificate chain. Not validating the certificate introduces the possibility of a man-in-the-middle attack. Version 3.0.5 corrects this flaw. External References: <a href="https://maven.apache.org/security.html">https://maven.apache.org/security.html</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/maven | <3.0.5 | 3.0.5 |
Apache Maven | =3.0.4 | |
Apache Maven Wagon | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.