CVE Vulnerabilities

CVE-2013-0253

Published: Apr 09, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
5.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.

Affected Software

NameVendorStart VersionEnd Version
MavenApache3.0.4 (including)3.0.4 (including)
RHEL 6 Version of OpenShift EnterpriseRedHatjenkins-0:1.506-1.el6op*
MavenUbuntuprecise*
MavenUbuntuquantal*
MavenUbunturaring*
MavenUbuntusaucy*
MavenUbuntuupstream*

References