[ 
https://issues.apache.org/jira/browse/AMQ-7247?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jean-Baptiste Onofré resolved AMQ-7247.
---------------------------------------
    Resolution: Fixed

> Update maven plugin API + Pax URL versions
> ------------------------------------------
>
>                 Key: AMQ-7247
>                 URL: https://issues.apache.org/jira/browse/AMQ-7247
>             Project: ActiveMQ
>          Issue Type: Improvement
>    Affects Versions: 5.15.9
>            Reporter: Colm O hEigeartaigh
>            Assignee: Jean-Baptiste Onofré
>            Priority: Major
>             Fix For: 5.16.0, 5.15.10
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> We should update the maven plugin + pax url versions to eliminate the 
> following CVEs from the build:
> plexus-utils-1.0.4.jar (pkg:maven/org.codehaus.plexus/[email protected], 
> cpe:2.3:a:plexus-utils_project:plexus-utils:1.0.4:*:*:*:*:*:*:*) : 
> CVE-2017-1000487, Directory traversal in org.codehaus.plexus.util.Expand, 
> Possible XML Injection
> pax-url-aether-2.4.3.jar/META-INF/maven/org.apache.httpcomponents/httpclient/pom.xml
>  (pkg:maven/org.apache.httpcomponents/[email protected], 
> cpe:2.3:a:apache:httpclient:4.3.5:*:*:*:*:*:*:*) : CVE-2015-5262



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Reply via email to