CVE-2021-26291: block repositories using http by default

Published Apr 23, 2021
·
Updated

A flaw was found in maven. Repositories that are defined in a dependency’s Project Object Model (pom), which may be unknown to users, are used by default resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. The highest threat from this vulnerability is to data confidentiality and integrity.

Other sources

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior.

References:

https://lists.apache.org/thread.html/r9a027668558264c4897633e66bcb7784099fdec9f9b22c38c2442f00%40%3Cusers.maven.apache.org%3E https://lists.apache.org/thread.html/r06db4057b74e0598a412734f693a34a8836ac6f06d16d139e5e1027c@%3Cdev.maven.apache.org%3E https://lists.apache.org/thread.html/r9a027668558264c4897633e66bcb7784099fdec9f9b22c38c2442f00@%3Cusers.maven.apache.org%3E http://www.openwall.com/lists/oss-security/2021/04/23/5 https://lists.apache.org/thread.html/r0556ce5db7231025785477739ee416b169d8aff5ee9bac7854d64736@%3Cannounce.apache.org%3E https://lists.apache.org/thread.html/ra88a0eba7f84658cefcecc0143fd8bbad52c229ee5dfcbfdde7b6457@%3Cdev.jena.apache.org%3E https://lists.apache.org/thread.html/r3f0450dcab7e63b5f233ccfbc6fca5f1867a75c8aa2493ea82732381@%3Cdev.jena.apache.org%3E

Red Hat

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html

block repositories using http by default

Microsoft

FasterXML Jackson Core is vulnerable to a denial of service, caused by improper input validation by the StreamReadConstraints value field. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause the application to crash.

IBM

Affected Software

17 affected componentsFixes available
maven/org.apache.maven:maven-core<3.8.1
3.8.1
maven/org.apache.maven:maven-compat<3.8.1
3.8.1
redhat/jenkins<2-plugins-0:4.11.1683009941-1.el8
2-plugins-0:4.11.1683009941-1.el8
redhat/maven<3.8.1
3.8.1
IBM Cloud Pak for Business Automation<=V23.0.1 - V23.0.1-IF001
IBM Cloud Pak for Business Automation<=V21.0.3 - V21.0.3-IF023
IBM Cloud Pak for Business Automation<=V22.0.2 - V22.0.2-IF006 and later fixes V22.0.1 - V22.0.1-IF006 and later fixes V21.0.2 - V21.0.2-IF012 and later fixes V21.0.1 - V21.0.1-IF007 and later fixes V20.0.1 - V20.0.3 and later fixes V19.0.1 - V19.0.3 and later fixes V18.0.0 - V18.0.2 and later fixes
Apache Maven<3.8.1
Quarkus Quarkus<1.13.5
Oracle Financial Services Analytical Applications Infrastructure>=8.0.6.0.0<=8.0.9.0.0
Oracle Financial Services Analytical Applications Infrastructure>=8.1.0.0.0<=8.1.2.0
Oracle Goldengate Big Data And Application Adapters=23.1
Microsoft maven-debuginfo-3.8.1-1.cm1.aarch64.rpm
Microsoft cm1 maven 3.8.1-1
Microsoft maven-3.8.1-1.cm1.x86_64.rpm
Microsoft maven-debuginfo-3.8.1-1.cm1.x86_64.rpm
Microsoft maven-3.8.1-1.cm1.aarch64.rpm

Event History

Apr 23, 2021
CVE Published
12:00 AM
CVE Published
via MITRE·02:20 PM
Data Sourced
via MITRE·02:20 PM
DescriptionWeakness
Apr 30, 2021
Data Sourced
via Red Hat·05:58 PM
DescriptionSeverityAffected Software
May 5, 2021
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·12:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Jun 16, 2021
Advisory Published
05:32 PM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-26291?

CVE-2021-26291 is a vulnerability found in Apache Maven that allows a malicious actor to take over repositories defined in a dependency's Project Object Model (POM).

2

How does CVE-2021-26291 impact users?

CVE-2021-26291 can result in potential risk if a malicious actor takes over a repository or pretends to be a repository.

3

What is the severity of CVE-2021-26291?

The severity of CVE-2021-26291 is critical with a CVSS score of 9.1.

4

Which software versions are affected by CVE-2021-26291?

Apache Maven versions up to and excluding 3.8.1 are affected by CVE-2021-26291.

5

How can I fix CVE-2021-26291?

To fix CVE-2021-26291, upgrade to Apache Maven version 3.8.1 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203