[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable

2021-06-11 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Description:   Note: This vulnerability has been assigned CVE-2021-29425. h4. ADV

[jira] [Updated] (MNG-7168) maven-shared-utils package is vulnerable to Command Injection

2021-06-11 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MNG-7168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MNG-7168: - Description:   Project:[https://github.com/apache/maven-shared-utils/pull/40] Project:htt

[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Affects Version/s: (was: maven-shared-utils-3.3.3) > maven-shared-components u

[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Component/s: (was: maven-shared-utils) > maven-shared-components uses commons-

[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Description: h4. EXPLANATION The {{commons-io}} package is vulnerable to Path Trav

[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Description: (was: maven-shared-components uses commons-io 2.6 which is vulner

[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Labels: (was: Java8) > maven-shared-components uses commons-io 2.5 which is vuln

[jira] [Updated] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MSHARED-992?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MSHARED-992: Labels: Security (was: ) > maven-shared-components uses commons-io 2.5 which is v

[jira] [Created] (MSHARED-992) maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705

2021-06-03 Thread Dwayne E Culbertson (Jira)
Dwayne E Culbertson created MSHARED-992: --- Summary: maven-shared-components uses commons-io 2.5 which is vulnerable to sonatype-2018-0705 Key: MSHARED-992 URL: https://issues.apache.org/jira/browse/MSHARED-99

[jira] [Updated] (MNG-7168) SONATYPE-2020-0491

2021-06-03 Thread Dwayne E Culbertson (Jira)
[ https://issues.apache.org/jira/browse/MNG-7168?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Dwayne E Culbertson updated MNG-7168: - Labels: Security (was: ) > SONATYPE-2020-0491 > -- > > Key

[jira] [Created] (MNG-7168) SONATYPE-2020-0491

2021-06-03 Thread Dwayne E Culbertson (Jira)
Dwayne E Culbertson created MNG-7168: Summary: SONATYPE-2020-0491 Key: MNG-7168 URL: https://issues.apache.org/jira/browse/MNG-7168 Project: Maven Issue Type: Bug Reporter: Dw