First published: Fri Apr 23 2021(Updated: )
A flaw was found in maven. Repositories that are defined in a dependency’s Project Object Model (pom), which may be unknown to users, are used by default resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. The highest threat from this vulnerability is to data confidentiality and integrity.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.maven:maven-core | <3.8.1 | 3.8.1 |
maven/org.apache.maven:maven-compat | <3.8.1 | 3.8.1 |
redhat/jenkins | <2-plugins-0:4.11.1683009941-1.el8 | 2-plugins-0:4.11.1683009941-1.el8 |
Apache Maven | <3.8.1 | |
Quarkus Quarkus | <1.13.5 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.0.6.0.0<=8.0.9.0.0 | |
Oracle Financial Services Analytical Applications Infrastructure | >=8.1.0.0.0<=8.1.2.0 | |
Oracle Goldengate Big Data And Application Adapters | =23.1 | |
redhat/maven | <3.8.1 | 3.8.1 |
IBM Cloud Pak for Business Automation | <=V23.0.1 - V23.0.1-IF001 | |
IBM Cloud Pak for Business Automation | <=V21.0.3 - V21.0.3-IF023 | |
IBM Cloud Pak for Business Automation | <=V22.0.2 - V22.0.2-IF006 and later fixes V22.0.1 - V22.0.1-IF006 and later fixes V21.0.2 - V21.0.2-IF012 and later fixes V21.0.1 - V21.0.1-IF007 and later fixes V20.0.1 - V20.0.3 and later fixes V19.0.1 - V19.0.3 and later fixes V18.0.0 - V18.0.2 and later fixes |
To avoid possible man-in-the-middle related attacks with this flaw, ensure any linked repositories in maven POMs use https and not http.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-26291 is a vulnerability found in Apache Maven that allows a malicious actor to take over repositories defined in a dependency's Project Object Model (POM).
CVE-2021-26291 can result in potential risk if a malicious actor takes over a repository or pretends to be a repository.
The severity of CVE-2021-26291 is critical with a CVSS score of 9.1.
Apache Maven versions up to and excluding 3.8.1 are affected by CVE-2021-26291.
To fix CVE-2021-26291, upgrade to Apache Maven version 3.8.1 or later.