Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Maven | Apache Maven |
Timeline
- Apr 7, 2022 PoC Published
- Jul 19, 2022 CVE Published
- Jul 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 6, 2022 EPSS Score
- Jan 21, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 24, 2023 EPSS Score
- Jun 9, 2023 EPSS Score
- Jul 25, 2023 EPSS Score
- Oct 21, 2023 PoC Published
- Oct 26, 2023 EPSS Score
References
- https://www.oracle.com/security-alerts/cpujul2022.html#AppendixFMW advisory
- https://www.oracle.com/security-alerts/cpujul2022verbose.html#FMW advisory
- https://lists.apache.org/thread.html/r9a027668558264c4897633e66bcb7784099fdec9f9b22c38c2442f00%40%3Cusers.maven.apache.org%3E url
- [maven-dev] 20210423 CVE-2021-26291: Apache Maven: block repositories using http by default mailing-list
- [oss-security] 20210423 CVE-2021-26291: Apache Maven: block repositories using http by default mailing-list
- [announce] 20210423 CVE-2021-26291: Apache Maven: block repositories using http by default mailing-list
- [jena-dev] 20210428 FYI: Maven CVE-2021-26291 mailing-list
- [jena-dev] 20210429 Re: FYI: Maven CVE-2021-26291 mailing-list
- [myfaces-dev] 20210506 [GitHub] [myfaces-tobago] lofwyr14 opened a new pull request #817: build: CVE fix mailing-list
- [kafka-jira] 20210520 [jira] [Created] (KAFKA-12820) Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-dev] 20210520 [jira] [Created] (KAFKA-12820) Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-jira] 20210520 [GitHub] [kafka] dongjinleekr opened a new pull request #10739: KAFKA-12820: Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-jira] 20210520 [jira] [Assigned] (KAFKA-12820) Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-jira] 20210521 [GitHub] [kafka] omkreddy merged pull request #10739: KAFKA-12820: Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-dev] 20210521 [jira] [Resolved] (KAFKA-12820) Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-commits] 20210521 [kafka] branch 2.6 updated: KAFKA-12820: Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-commits] 20210521 [kafka] branch 2.8 updated: KAFKA-12820: Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-jira] 20210521 [jira] [Resolved] (KAFKA-12820) Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-commits] 20210521 [kafka] branch 2.7 updated: KAFKA-12820: Upgrade maven-artifact dependency to resolve CVE-2021-26291 mailing-list
- [kafka-users] 20210617 vulnerabilities mailing-list
…and 25 more