CVE-2013-0253
published 2013-04-09CVE-2013-0253: The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers…
PriorityP427medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.57%
72.6th percentile
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | maven | — | — |
| jenkins | maven | >= 0 < 3.0.5-1 | 3.0.5-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
maven-wagon: all SSL certificate checking is disabled by default
vendor_redhat·2013-02-23·CVSS 5.8
CVE-2013-0253 [MEDIUM] maven-wagon: all SSL certificate checking is disabled by default
maven-wagon: all SSL certificate checking is disabled by default
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
GHSA
GHSA-33jw-8g2v-hrp6: The default configuration of Apache Maven 3
ghsa_unreviewed·2022-05-05
CVE-2013-0253 [MEDIUM] GHSA-33jw-8g2v-hrp6: The default configuration of Apache Maven 3
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
OSV
CVE-2013-0253: The default configuration of Apache Maven 3
osv·2013-04-09·CVSS 5.8
CVE-2013-0253 [MEDIUM] CVE-2013-0253: The default configuration of Apache Maven 3
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0253 maven: all SSL certificate checking is disabled by default [fedora-all]
bugzilla·2013-03-01·CVSS 5.8
CVE-2013-0253 [MEDIUM] CVE-2013-0253 maven: all SSL certificate checking is disabled by default [fedora-all]
CVE-2013-0253 maven: all SSL certificate checking is disabled by default [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this i
Bugzilla
CVE-2013-0253 maven-wagon: all SSL certificate checking is disabled by default
bugzilla·2013-03-01·CVSS 5.8
CVE-2013-0253 [MEDIUM] CVE-2013-0253 maven-wagon: all SSL certificate checking is disabled by default
CVE-2013-0253 maven-wagon: all SSL certificate checking is disabled by default
Apache Maven 3.0.4 (with Apache Maven Wagon 2.1) has introduced a non-secure SSL mode by default. This mode disables all SSL certificate checking, including: host name verification , date validity, and certificate chain. Not validating the certificate introduces the possibility of a man-in-the-middle attack.
Version 3.0.5 corrects this flaw.
External References:
https://maven.apache.org/security.html
Discussion:
Created maven tracking bugs for this issue
Affects: fedora-all [bug 917086]
---
As far as I know this does not affect any version Fedora.
This is a bug in maven-wagon package, not maven.
Fedora uses maven-wagon 1.0 which is unaffected by this vulnerability.
Please confirm if the above statemen
http://rhn.redhat.com/errata/RHSA-2013-0700.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=917084https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://maven.apache.org/security.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0700.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=917084https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://maven.apache.org/security.html
2013-04-09
Published