CVE Feed

    Dashboard / CVE / CVE-2021-26291

    CVE-2021-26291

    Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html

    Published:Apr 23, 2021
    Last Modified:Nov 21, 2024
    EPS:Apr 23, 2021
    EPSS Score:0.45481
    CVSS Score:9.1

    Affected Products

    Vendor
    Apache
    Product
    Maven
    Vendor
    Oracle
    Product
    Financial Services Analytical Applications Infrastructure
    Vendor
    Oracle
    Product
    Goldengate Big Data And Application Adapters
    Vendor
    Quarkus
    Product
    Quarkus
    Vendor
    Redhat
    Product
    Camel Quarkus
    Vendor
    Redhat
    Product
    Integration
    Vendor
    Redhat
    Product
    Jboss Enterprise Bpms Platform
    Vendor
    Redhat
    Product
    Ocp Tools
    Vendor
    Redhat
    Product
    Openshift Application Runtimes

    Common Attack Pattern Enumeration and Classification (CAPEC)

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High