Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:40841

Опубликовано: 16 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: maven:3.8 security update

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information.

Security Fix(es):

  • org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
plexus-utilsnoarch11.module+el8.10.0+1811+d28a527bplexus-utils-3.3.0-11.module+el8.10.0+1811+d28a527b.noarch.rpm
apache-commons-clinoarch5.module+el8.10.0+1811+d28a527bapache-commons-cli-1.5.0-5.module+el8.10.0+1811+d28a527b.noarch.rpm
apache-commons-codecnoarch8.module+el8.10.0+1811+d28a527bapache-commons-codec-1.15-8.module+el8.10.0+1811+d28a527b.noarch.rpm
apache-commons-ionoarch3.module+el8.10.0+1811+d28a527bapache-commons-io-2.11.0-3.module+el8.10.0+1811+d28a527b.noarch.rpm
apache-commons-lang3noarch8.module+el8.10.0+1811+d28a527bapache-commons-lang3-3.12.0-8.module+el8.10.0+1811+d28a527b.noarch.rpm
atinjectnoarch5.module+el8.10.0+1811+d28a527batinject-1.0.5-5.module+el8.10.0+1811+d28a527b.noarch.rpm
cdi-apinoarch7.module+el8.10.0+1811+d28a527bcdi-api-2.0.2-7.module+el8.10.0+1811+d28a527b.noarch.rpm
google-guicenoarch10.module+el8.10.0+1811+d28a527bgoogle-guice-4.2.3-10.module+el8.10.0+1811+d28a527b.noarch.rpm
guavanoarch5.module+el8.10.0+1811+d28a527bguava-31.0.1-5.module+el8.10.0+1811+d28a527b.noarch.rpm
httpcomponents-clientnoarch6.module+el8.10.0+1811+d28a527bhttpcomponents-client-4.5.13-6.module+el8.10.0+1811+d28a527b.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

CVSS3: 8.3
redhat
4 месяца назад

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

CVSS3: 8.8
nvd
4 месяца назад

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

CVSS3: 8.8
msrc
4 месяца назад

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

CVSS3: 8.8
debian
4 месяца назад

Directory Traversal vulnerability in the extractFile method of org.cod ...