plexus-utils-3.3.0-14.el9_8

エラータID: AXSA:2026-1492:01

Release date: 
Friday, August 7, 2026 - 20:13
Subject: 
plexus-utils-3.3.0-14.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The Plexus project seeks to create end-to-end developer tools for writing applications. At the core is the container, which can be embedded or for a full scale application server. There are many reusable components for hibernate, form processing, jndi, i18n, velocity, etc. Plexus also includes an application server which is like a J2EE application server, without all the baggage.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-67030
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. plexus-utils-3.3.0-14.el9_8.src.rpm
    MD5: 2fa4663062b4890a1ce32d7513ee598f
    SHA-256: 12402ada42a1789230eb9037f5718239444f976a04c06b2bdb0bfe80990ee8ca
    Size: 437.96 kB

Asianux Server 9 for x86_64
  1. plexus-utils-3.3.0-14.el9_8.noarch.rpm
    MD5: 722884b1df4ece887bedd385d58babec
    SHA-256: 14693ce2616943c37c8eef75bda9e1bf5f23fabc122d92bb5adc8b5cad4c0963
    Size: 252.86 kB