Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30170
HistoryApr 26, 2021 - 8:35 a.m.

Man-in-the-middle(MitM)

2021-04-2608:35:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
21
apache-maven security vulnerability
mitm attack
privilege escalation

EPSS

0.002

Percentile

57.8%

apache-maven is vulnerable to privilege escalation. The vulnerability exists because it allows downloading code from external repositories via HTTP by default, resulting in a potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository.

References