[ 
https://issues.apache.org/jira/browse/AMQ-7247?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16893669#comment-16893669
 ] 

ASF subversion and git services commented on AMQ-7247:
------------------------------------------------------

Commit 01955dd758c19e0e713d866bc5d4c91df8886276 in activemq's branch 
refs/heads/master from Jean-Baptiste Onofré
[ https://gitbox.apache.org/repos/asf?p=activemq.git;h=01955dd ]

Merge pull request #378 from coheigea/AMQ-7247

AMQ-7247 - Update maven plugin API + Pax URL versions

> Update maven plugin API + Pax URL versions
> ------------------------------------------
>
>                 Key: AMQ-7247
>                 URL: https://issues.apache.org/jira/browse/AMQ-7247
>             Project: ActiveMQ
>          Issue Type: Improvement
>    Affects Versions: 5.15.9
>            Reporter: Colm O hEigeartaigh
>            Priority: Major
>             Fix For: 5.16.0, 5.15.10
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> We should update the maven plugin + pax url versions to eliminate the 
> following CVEs from the build:
> plexus-utils-1.0.4.jar (pkg:maven/org.codehaus.plexus/[email protected], 
> cpe:2.3:a:plexus-utils_project:plexus-utils:1.0.4:*:*:*:*:*:*:*) : 
> CVE-2017-1000487, Directory traversal in org.codehaus.plexus.util.Expand, 
> Possible XML Injection
> pax-url-aether-2.4.3.jar/META-INF/maven/org.apache.httpcomponents/httpclient/pom.xml
>  (pkg:maven/org.apache.httpcomponents/[email protected], 
> cpe:2.3:a:apache:httpclient:4.3.5:*:*:*:*:*:*:*) : CVE-2015-5262



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Reply via email to