Back to Security Advisories
High 2026-07-17

Maven:3.8 Security Update — AlmaLinux 8 (ALSA-2026:40841)

AlmaLinux 8

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): * org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …

Affected Versions

3.8

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …

Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in …

Type:
security

Severity:
important

Release date:
2026-07-17

Description:
Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project’s build, reporting and documentation from a central piece of information.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 jansi-2.4.0-7.module_el8.10.0+3805+55513176.aarch64.rpm b142d9450692e8fbf2654bfc545c2205ad94b3e96ad20537c9eb2997008bf1ee
noarch apache-commons-cli-1.5.0-5.module_el8.10.0+3805+55513176.noarch.rpm 0f1bd0485f08cf241212290a1820a2abdd79d85c1151a6dd14d4890078e8c79a
noarch maven-resolver-1.7.3-6.module_el8.10.0+3805+55513176.noarch.rpm 11224b0fd44644c23cb91ac7441fb149502328cccb6a723a37974d27e8517580
noarch maven-wagon-3.5.1-3.module_el8.10.0+3805+55513176.noarch.rpm 15542f79dbdee24d7027142f3f76a08ae1ccfb3dc5dad83f50fb8297819b1778
noarch plexus-interpolation-1.26-13.module_el8.10.0+3805+55513176.noarch.rpm 279316c48ed6a75dca087977f2cc72d9d3de612d8a7a95abfbaf05a8057513ed
noarch sisu-0.3.5-3.module_el8.10.0+3805+55513176.noarch.rpm 359b319b90d5882ef79531744707dc048eb5fc38453c67c807e18483319c5e42
noarch maven-openjdk8-3.8.5-6.module_el8.10.0+3805+55513176.noarch.rpm 3a71f5ddb267e5c0b9e812efe1d3360ba5cd209400ca7a2967a0b564b07b0c64
noarch guava-31.0.1-5.module_el8.10.0+3805+55513176.noarch.rpm 3c3887641e5a333583b8bfa7a6a575a2b457475ab6ed4156835dcadc65149b53
noarch plexus-classworlds-2.6.0-13.module_el8.10.0+3805+55513176.noarch.rpm 3f6eff55b4d3cc97325fc5014b0bb854bbbd3331160232d1e8916e8b078b7262
noarch httpcomponents-client-4.5.13-6.module_el8.10.0+3805+55513176.noarch.rpm 44914de7115e0609e41f74d6f46c411485064e74491c8517f64e8a1d9478dca5
noarch apache-commons-lang3-3.12.0-8.module_el8.10.0+3805+55513176.noarch.rpm 4ca698a5034dff9ee989920230259550922c2904991f966aa430090443244ca3
noarch maven-openjdk11-3.8.5-6.module_el8.10.0+3805+55513176.noarch.rpm 533449c7f763b537b8377ec04fe8aa5aab15bc23deabe4dedcf3de604e9fb957
noarch slf4j-1.7.32-5.module_el8.10.0+3805+55513176.noarch.rpm 5904d6f3c667ab61ec93496a13d0e9846e7b1deef4067a21a89c2e97b1ad552f
noarch google-guice-4.2.3-10.module_el8.10.0+3805+55513176.noarch.rpm 604460a84ed8741d05c6b18c6552a52a405976b6bccd9929a6e6297bf46ef1b6
noarch maven-lib-3.8.5-6.module_el8.10.0+3805+55513176.noarch.rpm 61b92c96106b71127cd7a3033deec400248a153453fcfc645c06b32802ccc37a
noarch jakarta-annotations-1.3.5-15.module_el8.10.0+3805+55513176.noarch.rpm 61e2a3ef70efcbd8b7a255663534d48d57735688b1a81ef75e5d1f0c8ef34be0
noarch plexus-cipher-2.0-3.module_el8.10.0+3805+55513176.noarch.rpm 621c1fd20bfef9221721d0b898b6ce409fbc627d801e3fc50822c037c7010a55
noarch maven-shared-utils-3.3.4-6.module_el8.10.0+3805+55513176.noarch.rpm 64810b7ac5e97b117a5dd331725c192399911649a7b7a9b7288dfd273c3a6e93
noarch plexus-utils-3.3.0-11.module_el8.10.0+4229+5e0a6206.1.noarch.rpm 7d84e2100b24b9cf64226280bb5c901ffdf595ee43c879fe9624ef1d25fc9791
noarch apache-commons-io-2.11.0-3.module_el8.10.0+3805+55513176.noarch.rpm 7e6c4596519cdbcce14d60ba680721c58864586c3bc97817626da25c09e4a174
noarch maven-openjdk17-3.8.5-6.module_el8.10.0+3805+55513176.noarch.rpm 83642f83df1d1cff8573f6747e98f68a8930bbc6d66455d0c08aff0a451c0a1d
noarch cdi-api-2.0.2-7.module_el8.10.0+3805+55513176.noarch.rpm 847f06749308637a9fa8e16689861311d382c5e9202555f2b7b5ecb9b38a4732
noarch plexus-sec-dispatcher-2.0-5.module_el8.10.0+3805+55513176.noarch.rpm 995cbfa359c34762109bc9a10be6b51578c56a589b2d68ee2575dabf4da5ed36
noarch jcl-over-slf4j-1.7.32-5.module_el8.10.0+3805+55513176.noarch.rpm a3d510e491871acb6a13aa178f55be47d05e117ad9038181dd1b7f56efa3daba
noarch plexus-containers-component-annotations-2.1.1-3.module_el8.10.0+3805+55513176.noarch.rpm ab956c4efe20416414653fa862fdad3de922b1e3aed078fa7e3c0075095c19be
noarch maven-openjdk21-3.8.5-6.module_el8.10.0+3805+55513176.noarch.rpm cde1d2b69f921d546fc272f7b6e03930c532da06a97fa385df21dde252a072cf
noarch httpcomponents-core-4.4.13-8.module_el8.10.0+3805+55513176.noarch.rpm d9bf602b972aebf92d7bc16d24b5901519a0c2366d51ece5cfc0bbe068e82c01
noarch jsr-305-3.0.2-7.module_el8.10.0+3805+55513176.noarch.rpm db87b4494dd3175f10d2e445d1edbc09bf6fabc70fbd2d5a0d3f0eddd2bd600f
noarch atinject-1.0.5-5.module_el8.10.0+3805+55513176.noarch.rpm dbaae5a176cac57aac2d84edd7f9f36cde3ddcf8f2300a7bda84b1e31a188fbe
noarch apache-commons-codec-1.15-8.module_el8.10.0+3805+55513176.noarch.rpm dcb929eda6b25b0a986f419fcff1e9733bbf09d45dc9a50e19cd007d72928ac9
noarch maven-3.8.5-6.module_el8.10.0+3805+55513176.noarch.rpm ed075a938c596ec751ed459de116819daa9baa0625bcc59da97805c1f7b5e0ae
ppc64le jansi-2.4.0-7.module_el8.10.0+3805+55513176.ppc64le.rpm f751ba1b7ee39b26cad1e9176f6bc171fd57fb95e9ed5dd0903e2948b1d388d2
s390x jansi-2.4.0-7.module_el8.10.0+3805+55513176.s390x.rpm 375459f303f0fc57966c51d5b80b10e842b519bb914a97a8add8fe5bdd41a297
x86_64 jansi-2.4.0-7.module_el8.10.0+3805+55513176.x86_64.rpm 80b279ffbbfecdbf1b90409522298374994cace0388ad1abffcd1caae7473e1b

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Size uygun tam düzeltme komutlarını görmek için ürününüzü ve işletim sisteminizi seçin.

Check Your System