Re: [SECURITY] CVE-2013-0253 Apache Maven 3.0.4

2013-02-23 Thread Olivier Lamy
No idea but has been asked. 2013/2/23 Jason van Zyl : > When will the CVE entry be updated? > > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0253 > > On Feb 23, 2013, at 9:59 AM, Olivier Lamy wrote: > >> VE-2013-0253 Apache Maven >> >> Severity: Medium >> >> Vendor: The Apache Software

Re: [SECURITY] CVE-2013-0253 Apache Maven 3.0.4

2013-02-23 Thread Jason van Zyl
When will the CVE entry be updated? http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0253 On Feb 23, 2013, at 9:59 AM, Olivier Lamy wrote: > VE-2013-0253 Apache Maven > > Severity: Medium > > Vendor: The Apache Software Foundation > > Versions Affected: > - Apache Maven 3.0.4 > - Apach

[SECURITY] CVE-2013-0253 Apache Maven 3.0.4

2013-02-23 Thread Olivier Lamy
VE-2013-0253 Apache Maven Severity: Medium Vendor: The Apache Software Foundation Versions Affected: - Apache Maven 3.0.4 - Apache Maven Wagon 2.1, 2.2, 2.3 Description: Apache Maven 3.0.4 (with Apache Maven Wagon 2.1) has introduced a non-secure SSL mode by default. This mode disables all SSL