oss-sec mailing list archives
CVE request: Maven downloads JARs via HTTP
From: Martin Prpic <mprpic () redhat com>
Date: Mon, 02 Mar 2015 14:07:00 +0100
Hi, I don't see a CVE assigned for this anywhere: https://jira.codehaus.org/browse/MNG-5672 "Maven Central can now be accessed via HTTPS. I think the default configuration should be switched to use that, rather than the current unsecured HTTP transport." This was fixed in Maven 3.2.3: https://maven.apache.org/docs/3.2.3/release-notes.html Thanks, -- Martin Prpič / Red Hat Product Security
Current thread:
- CVE request: Maven downloads JARs via HTTP Martin Prpic (Mar 02)
- Re: CVE request: Maven downloads JARs via HTTP gremlin (Mar 02)
- Re: CVE request: Maven downloads JARs via HTTP Martin Prpic (Mar 02)
- Re: CVE request: Maven downloads JARs via HTTP gremlin (Mar 02)
- Re: CVE request: Maven downloads JARs via HTTP Simon McVittie (Mar 02)
- Re: validation on update gremlin (Mar 03)
- Re: validation on update Kurt Seifried (Mar 03)
- Re: CVE request: Maven downloads JARs via HTTP Martin Prpic (Mar 02)
- Re: CVE request: Maven downloads JARs via HTTP gremlin (Mar 02)