Your dependencies cross-checked against the OSV vulnerability database.
-
Serious GHSA-2f88-5hg8-9x2x Origin Validation Error in Apache Maven
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2021-26291). Fix: Update that package to its patched version.
-
Serious GHSA-8vhq-qq4p-grq3 OS Command Injection in Plexus-utils
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2017-1000487). Fix: Update that package to its patched version.
-
Serious GHSA-8vhq-qq4p-grq3 OS Command Injection in Plexus-utils
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/check-harness/pom.xml
A package you depend on has a known security hole (CVE-2017-1000487). Fix: Update that package to its patched version.
-
Serious GHSA-8vhq-qq4p-grq3 OS Command Injection in Plexus-utils
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/resolve/pom.xml
A package you depend on has a known security hole (CVE-2017-1000487). Fix: Update that package to its patched version.
-
Serious GHSA-8vhq-qq4p-grq3 OS Command Injection in Plexus-utils
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/m2repo/maven/plugins/maven-dependency-plugin/test/maven-dependency-plugin-test.pom
A package you depend on has a known security hole (CVE-2017-1000487). Fix: Update that package to its patched version.
-
Worth fixing GHSA-hcxq-x77q-3469 Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2018-1002200). Fix: Update that package to its patched version.
-
Worth fixing GHSA-wh3p-fphp-9h2m Arbitrary File Creation in AbstractUnArchiver
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2023-37460). Fix: Update that package to its patched version.
-
Worth fixing GHSA-6fmv-xxpf-w3cw Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2025-67030). Fix: Update that package to its patched version.
-
Worth fixing GHSA-g6ph-x5wf-g337 plexus-codehaus vulnerable to directory traversal
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2022-4244). Fix: Update that package to its patched version.
-
Worth fixing GHSA-jcwr-x25h-x5fh codehaus-plexus vulnerable to XML injection
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/pom.xml
A package you depend on has a known security hole (CVE-2022-4245). Fix: Update that package to its patched version.
-
Worth fixing GHSA-6fmv-xxpf-w3cw Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/check-harness/pom.xml
A package you depend on has a known security hole (CVE-2025-67030). Fix: Update that package to its patched version.
-
Worth fixing GHSA-g6ph-x5wf-g337 plexus-codehaus vulnerable to directory traversal
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/check-harness/pom.xml
A package you depend on has a known security hole (CVE-2022-4244). Fix: Update that package to its patched version.
-
Worth fixing GHSA-jcwr-x25h-x5fh codehaus-plexus vulnerable to XML injection
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/check-harness/pom.xml
A package you depend on has a known security hole (CVE-2022-4245). Fix: Update that package to its patched version.
-
Worth fixing GHSA-6fmv-xxpf-w3cw Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/resolve/pom.xml
A package you depend on has a known security hole (CVE-2025-67030). Fix: Update that package to its patched version.
-
Worth fixing GHSA-g6ph-x5wf-g337 plexus-codehaus vulnerable to directory traversal
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/resolve/pom.xml
A package you depend on has a known security hole (CVE-2022-4244). Fix: Update that package to its patched version.
-
Worth fixing GHSA-jcwr-x25h-x5fh codehaus-plexus vulnerable to XML injection
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/its/resolve/pom.xml
A package you depend on has a known security hole (CVE-2022-4245). Fix: Update that package to its patched version.
-
Worth fixing GHSA-hcxq-x77q-3469 Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/m2repo/maven/plugins/maven-dependency-plugin/test/maven-dependency-plugin-test.pom
A package you depend on has a known security hole (CVE-2018-1002200). Fix: Update that package to its patched version.
-
Worth fixing GHSA-wh3p-fphp-9h2m Arbitrary File Creation in AbstractUnArchiver
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/m2repo/maven/plugins/maven-dependency-plugin/test/maven-dependency-plugin-test.pom
A package you depend on has a known security hole (CVE-2023-37460). Fix: Update that package to its patched version.
-
Worth fixing GHSA-6fmv-xxpf-w3cw Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/m2repo/maven/plugins/maven-dependency-plugin/test/maven-dependency-plugin-test.pom
A package you depend on has a known security hole (CVE-2025-67030). Fix: Update that package to its patched version.
-
Worth fixing GHSA-g6ph-x5wf-g337 plexus-codehaus vulnerable to directory traversal
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/m2repo/maven/plugins/maven-dependency-plugin/test/maven-dependency-plugin-test.pom
A package you depend on has a known security hole (CVE-2022-4244). Fix: Update that package to its patched version.
-
Worth fixing GHSA-jcwr-x25h-x5fh codehaus-plexus vulnerable to XML injection
/workdirs/scan-7d12f0d8-8e85-4d91-9254-61b05dcce3a1/src/test/resources/m2repo/maven/plugins/maven-dependency-plugin/test/maven-dependency-plugin-test.pom
A package you depend on has a known security hole (CVE-2022-4245). Fix: Update that package to its patched version.