Vulnerability Database
Blog
FAQ
Docs
MGASA-2023-0230
See a problem?
Please try reporting it
to the source
first.
Source
https://advisories.mageia.org/MGASA-2023-0230.html
Import Source
https://advisories.mageia.org/MGASA-2023-0230.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0230
Related
CVE-2021-26291
Published
2023-07-19T19:53:31Z
Modified
2023-07-19T18:32:00Z
Summary
Updated maven packages fix security vulnerability
Details
No longer use http (non-SSL) repository references by default.
References
https://advisories.mageia.org/MGASA-2023-0230.html
https://bugs.mageia.org/show_bug.cgi?id=28924
https://www.openwall.com/lists/oss-security/2021/04/23/5
https://ubuntu.com/security/notices/USN-5805-1
https://lists.suse.com/pipermail/sle-security-updates/2023-May/014769.html
Credits
Mageia - COORDINATOR
https://wiki.mageia.org/en/Packages_Security_Team
Affected packages
Mageia:8
/
maven
Package
Name
maven
Purl
pkg:rpm/mageia/maven?distro=mageia-8
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.6.3-8.1.mga8
Ecosystem specific
{ "section": "core" }
MGASA-2023-0230 - OSV