CVE-2013-0253
Published: April 9, 2013Last modified: July 22, 2025
Description
The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | maven | Not affected (3.8.6-r0) |
| Stream | maven | Not affected (3.9.0-r0) | |
| Hardened Containers | 23 LTS | maven | Not affected (3.8.6-r0) |
| Stream | maven | Not affected (3.9.0-r0) |