Uploaded image for project: 'Karaf'
  1. Karaf
  2. KARAF-7223

Upgrade maven artifacts to mitigate CVE-2021-26291

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 4.3.2
    • 4.3.8, 4.4.2
    • karaf
    • None
    • Apache Karaf - OSGi

    Description

      We are using Apache Karaf 4.3.2 in our project and our security scans report CVE-2021-26291 (https://nvd.nist.gov/vuln/detail/CVE-2021-26291) on our package because Karaf by default packs maven 3.6.x. The fix for the specified CVE is Maven 3.8.1+. (https://maven.apache.org/docs/3.8.1/release-notes.html) . Apache Karaf should update to use later versions of Maven resolver etc so that this vulnerability is mitigated.

      Attachments

        Issue Links

          Activity

            People

              jbonofre Jean-Baptiste Onofré
              karthickm512 Karthick
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: