maven:3.6 security and enhancement update

エラータID: AXSA:2022-3587:01

Release date: 
Friday, July 22, 2022 - 02:11
Subject: 
maven:3.6 security and enhancement update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information.

Security Fix(es):

* apache-httpclient: incorrect handling of malformed authority component in request URIs (CVE-2020-13956)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2020-13956
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.

Modularity name: maven
Stream name: 3.6

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. aopalliance-1.0-20.module+el8+1445+45490be6.src.rpm
    MD5: f77caa95cfa6332ddfd7260031673270
    SHA-256: aaf0e1cb25027e95ba9d701ab21aea73149847bd2984defb2302a9479412346a
    Size: 21.85 kB
  2. apache-commons-cli-1.4-7.module+el8+1445+45490be6.src.rpm
    MD5: e079e4e2b6635700eddd4092d87216c2
    SHA-256: 14e614618aafd804996dafe112c9fc1024551c5d5c3419eb2689d3ae9b7358e2
    Size: 158.15 kB
  3. apache-commons-codec-1.13-3.module+el8+1445+45490be6.src.rpm
    MD5: eb66249f8e9be08e19a94ebb5d901a51
    SHA-256: 516a4040c494a95d19584f7ac18f81ac4fee409fa5a0b44f7d20f3abcba4c897
    Size: 392.04 kB
  4. apache-commons-io-2.6-6.module+el8+1445+45490be6.src.rpm
    MD5: 1430a49ff1fd8b032d558f01f717098d
    SHA-256: a6796a26125d83dfca08e34cd0cd18d869985afd96042e0f35338cc4a5571f21
    Size: 386.81 kB
  5. apache-commons-lang3-3.9-4.module+el8+1445+45490be6.src.rpm
    MD5: c9c37d280c49227151d1efb5ced0ee33
    SHA-256: acc177c1502b363ccf0ba3c82d07c0e5401e3815a39519a01bcda41265a49218
    Size: 0.95 MB
  6. atinject-1-31.20100611svn86.module+el8+1445+45490be6.src.rpm
    MD5: d84e94d0b92f2bc9a2a8258878d21084
    SHA-256: 4ec312ac2675dbb570d9284bd28856b4da7077cb2a9a020d9f1d0009141826eb
    Size: 33.80 kB
  7. cdi-api-2.0.1-3.module+el8+1445+45490be6.src.rpm
    MD5: e8e9c0d4a197dcb8530c2a4b4b1ac1a5
    SHA-256: 7d6f20960c5352cec4e06a4b6a6835eba88528bb5d0ffe9e7ed906bf8e21c5ad
    Size: 191.15 kB
  8. geronimo-annotation-1.0-26.module+el8+1445+45490be6.src.rpm
    MD5: 7d471d287b08dd86e62c22f57f1b97d4
    SHA-256: 4958d2e2b2f7be233959e97f704eb714768b4e7ef071375454d1ab785c7bce64
    Size: 27.25 kB
  9. google-guice-4.2.2-4.module+el8+1445+45490be6.src.rpm
    MD5: c6f5fc4f8ec7447a484ace8db7efdd67
    SHA-256: 94fcb80ec828bf950b8278cc9314b289eadfeaae06341d902e878a491e69a96f
    Size: 393.96 kB
  10. guava-28.1-3.module+el8+1445+45490be6.src.rpm
    MD5: 0abb5f7cb9ceca4c32e1ac04c7d709a7
    SHA-256: 1f90e86e8cfb510a825cf7804f6aa81d66e9f850371866bd2a68386885623b3b
    Size: 4.85 MB
  11. httpcomponents-client-4.5.10-4.module+el8+1445+45490be6.src.rpm
    MD5: ac6932ae114793963b55c61500be7e21
    SHA-256: 67c3bde880be37a9896e9effb379ce4ba9f01ea563d75fd35fc3d68f71b2708c
    Size: 821.82 kB
  12. httpcomponents-core-4.4.12-3.module+el8+1445+45490be6.src.rpm
    MD5: 8a87ff09e1c2db8876037e807c9d0827
    SHA-256: 354898c61cb6a177aa06b52407d917542a1a3ac9e47363d0d18bd409d850f728
    Size: 569.22 kB
  13. jansi-1.18-4.module+el8+1445+45490be6.src.rpm
    MD5: b6aec49f580461e3b59f2440ff9f9c72
    SHA-256: 126a4bf8351a17289e47d51c023bf0b7660b96beb53593c9df6db8db8df33cea
    Size: 280.83 kB
  14. jsoup-1.12.1-3.module+el8+1445+45490be6.src.rpm
    MD5: 2455a008aef2561d44957907ff5bc599
    SHA-256: f53994701e54bafca10051c304506909e35c8ebd850e420a397707c3669a5639
    Size: 243.72 kB
  15. jsr-305-0-0.25.20130910svn.module+el8+1445+45490be6.src.rpm
    MD5: 908611e4837cb748b5f9e78fe318da44
    SHA-256: 6294cdfe4ef87782c1a44772da19e814513090c05cb267dfee49ba2c3552f80e
    Size: 50.59 kB
  16. maven-resolver-1.4.1-3.module+el8+1445+45490be6.src.rpm
    MD5: 25a45e1f70b846317c389c49be4f1d2f
    SHA-256: 23de563d32999b75030a7922c7446e3b882fb2ff61ca8448c33343fa3e5b8abf
    Size: 935.41 kB
  17. maven-shared-utils-3.2.1-0.4.module+el8+1445+45490be6.src.rpm
    MD5: 45ee444297eebaaf0c18bdf4da9da16d
    SHA-256: 2ba3814baa633e59c0bfa2192a86aff1c6155b41dc9aa1ee06d916e7ed8ab3d7
    Size: 241.40 kB
  18. maven-3.6.2-7.module+el8+1445+45490be6.src.rpm
    MD5: 0dbed100e1e561aa2686de189ccfe8bf
    SHA-256: b3e55cfef38d3bcf8ac93ac3f2f32b8c666d17073b2b3bf985d4d10bc389043f
    Size: 2.66 MB
  19. maven-wagon-3.3.4-2.module+el8+1445+45490be6.src.rpm
    MD5: 1283313110bad60c3048484776e2ebdd
    SHA-256: 10e2301719eefb17ff55d5576f4a2933be049cba19a719409ac6c842db16974b
    Size: 488.29 kB
  20. plexus-cipher-1.7-17.module+el8+1445+45490be6.src.rpm
    MD5: 2769588f2ada98db0f4add8a84708b82
    SHA-256: b0110cedd86f5530704379e7ea8971df4ffb4608c00adab90de0b91c019c6e0a
    Size: 26.66 kB
  21. plexus-classworlds-2.6.0-4.module+el8+1445+45490be6.src.rpm
    MD5: b8371c3740e802fc17e0639a8aeadb28
    SHA-256: 12e794705cbca4352bc1235bd6ca2fe7c6fab626973de2948b5e11c33aa9f066
    Size: 70.18 kB
  22. plexus-containers-2.1.0-2.module+el8+1445+45490be6.src.rpm
    MD5: e1e9057d7d647f12cb7cb1132d39bfb7
    SHA-256: feb1528d4ebd79e4a4f75475cece29121c72ef388f6e2a6424f74a3dfa3d64df
    Size: 361.19 kB
  23. plexus-interpolation-1.26-3.module+el8+1445+45490be6.src.rpm
    MD5: ed7b8612aa762c8c2921d8c85d2125f9
    SHA-256: 687b15c011aacfab1e9ae6c48d0db0c6852bd361836fa66febb68d11c8032e6f
    Size: 71.48 kB
  24. plexus-sec-dispatcher-1.4-29.module+el8+1445+45490be6.src.rpm
    MD5: 8b44986999a5279a02f0a8ebc4573f89
    SHA-256: e8812f53216c941c8bbc9cbf15c38b90dc57ccb81918eb2922ebc28acab77aa9
    Size: 22.86 kB
  25. plexus-utils-3.3.0-3.module+el8+1445+45490be6.src.rpm
    MD5: fa7303d4e8521231f2fc91789b0c9e0b
    SHA-256: 4cc0243e79fea519d0e118f16b0d4496f361ce0755ce8e5152ae7fb113265827
    Size: 441.41 kB
  26. sisu-0.3.4-2.module+el8+1445+45490be6.src.rpm
    MD5: 795c81ec43a7f4b9da1a7d75aa54b9b4
    SHA-256: ef801ab758c0afeadf15797eb82d235f51576904417a27fc219a86eb8ac689fe
    Size: 693.63 kB
  27. slf4j-1.7.28-3.module+el8+1445+45490be6.src.rpm
    MD5: 9a4a3968fa0d3805b2beea0c864624f6
    SHA-256: e74002d384e9cd39c1287813940e9233b9680589163c20257a0a33e081352398
    Size: 2.17 MB

Asianux Server 8 for x86_64
  1. aopalliance-1.0-20.module+el8+1445+45490be6.noarch.rpm
    MD5: f8537d1d0c50d6242e1aca7466569c05
    SHA-256: 1aa889d2178a56e8a4527b321630e67cd8727dc15fcf3fd7ebdec22cccfc8d1b
    Size: 16.18 kB
  2. apache-commons-cli-1.4-7.module+el8+1445+45490be6.noarch.rpm
    MD5: b0fc4361064a8cc5d9213d31fe8f5986
    SHA-256: 031c9652b7f4450fe981fad0f1f0b0b88c572be73c931f59253fc59e22dbcc80
    Size: 72.93 kB
  3. apache-commons-codec-1.13-3.module+el8+1445+45490be6.noarch.rpm
    MD5: 510a7ee5a26736ed9d1626fab586607d
    SHA-256: ae0dc519ff1f01c9b6c647454c4627eb324cfc71453284225543583b89bd0f9a
    Size: 299.50 kB
  4. apache-commons-io-2.6-6.module+el8+1445+45490be6.noarch.rpm
    MD5: 173b4c38116940a6e0b1148951e0f87a
    SHA-256: 1879e163fb36db124701a2c89088650e05e7075087d79e97363e8e8cfd51eca1
    Size: 222.53 kB
  5. apache-commons-lang3-3.9-4.module+el8+1445+45490be6.noarch.rpm
    MD5: a4154a51932a174c8359180f1a3d14f1
    SHA-256: ca653ff23ed93445f61ccf1740445aa3d5777e96028554546654bd7524643f75
    Size: 491.98 kB
  6. atinject-1-31.20100611svn86.module+el8+1445+45490be6.noarch.rpm
    MD5: 30ef029246d1abbb84e55c2d3aa35a58
    SHA-256: ac89a0a5e73798988565747f957b32129e4e4b7072958e65f06e93861303dce3
    Size: 19.22 kB
  7. cdi-api-2.0.1-3.module+el8+1445+45490be6.noarch.rpm
    MD5: 33f85e775997ff042791d5bb1355b591
    SHA-256: 2f672b2f51f984d0fc292e34d7c6d362f6050338fe8c340d03d388242f53cd0d
    Size: 94.75 kB
  8. geronimo-annotation-1.0-26.module+el8+1445+45490be6.noarch.rpm
    MD5: db5ec87b76d889a6a7b11c57092aabf0
    SHA-256: b4b4ba23cec4ee744d1427ad445d61b1193ad55392a3645c7fd0105fc7d95066
    Size: 24.29 kB
  9. google-guice-4.2.2-4.module+el8+1445+45490be6.noarch.rpm
    MD5: 8b74f1747050b78ba8209603002b769f
    SHA-256: 32317be4071484f4fc0900fc28ade6db2237cf321350120a708bbe353a5b0606
    Size: 549.98 kB
  10. guava-28.1-3.module+el8+1445+45490be6.noarch.rpm
    MD5: e90f8dbc8f139824033e76e0c044ea52
    SHA-256: c8641a963982acf09d9acfc3bee26b3139de2bfbbb00635f88e5cf940be02f5a
    Size: 2.30 MB
  11. httpcomponents-client-4.5.10-4.module+el8+1445+45490be6.noarch.rpm
    MD5: be0f028670eec6b24959f18a581f5f9a
    SHA-256: ec734c37224afe331ab6b01196d7f8a9d65a7f7450de6c9e6a0162855fbb14e6
    Size: 667.74 kB
  12. httpcomponents-core-4.4.12-3.module+el8+1445+45490be6.noarch.rpm
    MD5: ef801bc825d2ca4d1d238f01a23b52b6
    SHA-256: 3d61a21e386b724ce28e9b70d6f7927c54c014c946c8345173be01211e95a065
    Size: 641.44 kB
  13. jansi-1.18-4.module+el8+1445+45490be6.noarch.rpm
    MD5: 704f4d67fea57f369516e98f64dafe47
    SHA-256: 545beabd62a4b526f9a7f42facc7a8a3228342f2b5b65fcb8adbc88224b5f30e
    Size: 66.95 kB
  14. jsoup-1.12.1-3.module+el8+1445+45490be6.noarch.rpm
    MD5: af4d5f7a2317c6732d50f5ad632bb4ea
    SHA-256: 2000bd544c63946b1f4cf2254de26e75be78eddfa5adf8c401479f1d9f03b3e8
    Size: 387.50 kB
  15. jsr-305-0-0.25.20130910svn.module+el8+1445+45490be6.noarch.rpm
    MD5: b77b0445da73816543c1ce1ad438d324
    SHA-256: d1158a974873f7f9aa03d0ea131909e281d3ad3041ea22559907b49686b98653
    Size: 33.56 kB
  16. maven-resolver-1.4.1-3.module+el8+1445+45490be6.noarch.rpm
    MD5: c4511a990748eb55b91be71c233cd616
    SHA-256: b1ea0649cbc73986dd20ab34a6eb43ab9c6d3f67b6534378fc090fe30106011c
    Size: 519.07 kB
  17. maven-shared-utils-3.2.1-0.4.module+el8+1445+45490be6.noarch.rpm
    MD5: 2b48000940f3237c1e120cb9498b39cf
    SHA-256: 7ed403c13b6798cc1d25e2346d4d51373f6bcd8c2316aa8dd2203d0e8fca3e0c
    Size: 163.91 kB
  18. maven-openjdk17-3.6.2-7.module+el8+1445+45490be6.noarch.rpm
    MD5: 2f0683e11113fe614c7ba6118810719b
    SHA-256: fefa399df388f941c75943e02286f08a42712ecb8fa617a6f526cfdcf544a8b6
    Size: 24.35 kB
  19. maven-openjdk8-3.6.2-7.module+el8+1445+45490be6.noarch.rpm
    MD5: 4288d676e0f85e298cd8d700d838be64
    SHA-256: c13353bc0a5d01bb06d6a9617eb38d977b829f25441d982c8dedb88e15e0caa6
    Size: 24.34 kB
  20. maven-3.6.2-7.module+el8+1445+45490be6.noarch.rpm
    MD5: abbcf9984a5eb4920c3e78d93558cedf
    SHA-256: 9d8e4483f88cebe5d7884b95a1b91a8383fb2b4e3c4b6b827b8a07371195b15f
    Size: 32.98 kB
  21. maven-lib-3.6.2-7.module+el8+1445+45490be6.noarch.rpm
    MD5: f7ec8b8de16095ac8fbd248a13a5fafc
    SHA-256: 81340ce171e13431bf5a0f7a5e8fac78d6d7286235147cd29c28bd181b653169
    Size: 1.50 MB
  22. maven-openjdk11-3.6.2-7.module+el8+1445+45490be6.noarch.rpm
    MD5: 99ef0e2705a547bcc7f0fcf728fc6e9e
    SHA-256: 963f70b68d913fbc1b4f9215a559edaa983e7ac84aca792b871464268c93cb0b
    Size: 24.35 kB
  23. maven-wagon-3.3.4-2.module+el8+1445+45490be6.noarch.rpm
    MD5: af6e44c5bb8175ae257c671ac1047d8d
    SHA-256: 5378cb34ae4bca2dd387f4dfb0da992930dcd830bc2118c3103fcb7bfdba4ee4
    Size: 115.85 kB
  24. plexus-cipher-1.7-17.module+el8+1445+45490be6.noarch.rpm
    MD5: 69c3ffc78049dbc8ee6e66b88b4d7874
    SHA-256: 1a5aeb2b91fbcadabd289e32762f62791cb47b0b845f4c5c385b969a060039e6
    Size: 27.71 kB
  25. plexus-classworlds-2.6.0-4.module+el8+1445+45490be6.noarch.rpm
    MD5: 22b3bd47dce54e11bad54c48531b4c7f
    SHA-256: a41b11bf887cf0d6e7133f62bf78fa82956f83a790a929a984a4a510c5d8c8e9
    Size: 64.28 kB
  26. plexus-containers-2.1.0-2.module+el8+1445+45490be6.noarch.rpm
    MD5: e19323edd3e429ae1efb5a14666ce3ff
    SHA-256: eb65a0cb791c3055c92b6270c4cfe377bd11c2c7bc230fed514ad9820b50e793
    Size: 19.62 kB
  27. plexus-containers-component-annotations-2.1.0-2.module+el8+1445+45490be6.noarch.rpm
    MD5: ccce000718de67a3d864b518efc8bfaa
    SHA-256: eb0fb6cb2c8e9d3dc81fbbf0082ed329ceef44e5515317f6c0c0dd6dd81365f5
    Size: 22.90 kB
  28. plexus-interpolation-1.26-3.module+el8+1445+45490be6.noarch.rpm
    MD5: f09d432d86b08860d46a81acf7484040
    SHA-256: be2f6249db123076877fe830ae08a5faa32078e50a1ab1d07fc955fea2909da3
    Size: 81.98 kB
  29. plexus-sec-dispatcher-1.4-29.module+el8+1445+45490be6.noarch.rpm
    MD5: 4d6c31636ec06eb87cc5b7b4d0b188e3
    SHA-256: 870b267f064ba5213402f1cdda1c5f207a21f3316bd8b6741550b4abcc9039cc
    Size: 35.52 kB
  30. plexus-utils-3.3.0-3.module+el8+1445+45490be6.noarch.rpm
    MD5: a18644b628299f8007f4137d679c80c5
    SHA-256: 8b23a4c7df6c4c090cb4a9a93b8d6c6e984bf6e357627d4754de6c3739edc20c
    Size: 259.93 kB
  31. sisu-0.3.4-2.module+el8+1445+45490be6.noarch.rpm
    MD5: 1db0422b4b9bcfc5096b6f151f8ef9e1
    SHA-256: 449cea70915a79c722163e32ba8679a6b5d740c50c23c6cfceb8fe199934516e
    Size: 520.16 kB
  32. jcl-over-slf4j-1.7.28-3.module+el8+1445+45490be6.noarch.rpm
    MD5: 8dbc4b9575fdd0bcf56b51229fe0b861
    SHA-256: f05d52b45a3bae23d566cd6868f68eaa740fdbc941e146db7936e03ae9bb79f2
    Size: 30.92 kB
  33. slf4j-1.7.28-3.module+el8+1445+45490be6.noarch.rpm
    MD5: d29c91fd207cda8fa45760443e32f759
    SHA-256: eb8cc1c15a2a792b26c5e1573c55a1374d1e19f0ef210f4ef6655d1fd43ece2e
    Size: 76.05 kB