Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:40841: Important: maven:3.8 security update

  • What: Security update for maven:3.8
  • Impact: Addresses multiple vulnerabilities in Maven
Read Full Article →

Red Hat Product Errata RHSA-2026:40841 - Security Advisory Issued: 2026-07-16 Updated: 2026-07-16 RHSA-2026:40841 - Security Advisory Overview Updated Packages Synopsis Important: maven:3.8 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the maven:3.8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Maven is a software project management and comprehension tool. Based on the concept of a project object model (POM), Maven can manage a project's build, reporting and documentation from a central piece of information. Security Fix(es): org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2451409 - CVE-2025-67030 org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method CVEs CVE-2025-67030 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM apache-commons-cli-1.5.0-5.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: b70ffc7c63119226a8606109216cdd6699239ede3ab40333e47bf2133b38b355 apache-commons-codec-1.15-8.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: e62cfb58eb763801c432e0322d047be82eb4d21ff1186d3521184989e51ec0ce apache-commons-io-2.11.0-3.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 8bb688d91c0dd444356083f576a6ff6989f1d9a6683c0b40d94ff6650165f5e9 apache-commons-lang3-3.12.0-8.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 05a8d7ae93b899ba0c1ccea092d3b68acf9232e2668b276a4adc0326b251eb02 atinject-1.0.5-5.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 7f517d67826294d8bb36eb5be6fe57966cc60ddaf3bd0374d5e222acc51142d2 cdi-api-2.0.2-7.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 3d096ec9b959e69ed5a7f273cec1af254445f19d0bd40d135ae516ded3f6b75c google-guice-4.2.3-10.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 5d90c575dbcc2351df1fbe970d61c7c90c1bea32ed43ab8f999ce6b4d0668465 guava-31.0.1-5.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: cdaeb1cf9a60b596fe51829253c3319b5f822db76cd1fdd418c92e215cfc66bb httpcomponents-client-4.5.13-6.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: a63cdca675771cc899ef2112e2d4878cca09c62ee703550b5acf3e3f4cb6e13e httpcomponents-core-4.4.13-8.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 405cf6dc7de73903543cfa8af3099bff788e807e9902234e06d849a9444c2335 jakarta-annotations-1.3.5-15.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 390f2ec83d754e738443d11b4c586c833d7047a4a82ca7c2a52fa36e87cc204e jansi-2.4.0-7.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: fbf5e21541257724e315f2412edb2e6b4cffdcf3c2b2730e0dd083b5b9c7ece9 jsr-305-3.0.2-7.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 9423d062a09a0b4dc5d2b739d3cc9198e61d06a3743e34a01564b63f3f8eb3ff maven-3.8.5-6.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: bbb7edd82fe74cbb20833b37fedf18890f002f08a53919949e73fbb4feceacfb maven-resolver-1.7.3-6.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 3f3a9622c43ebcf91f020665e14d346104d2d7c5c86bae200ba6b55b097efcc9 maven-shared-utils-3.3.4-6.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 408321c7cfbcd2477a44f7cb5f2d52b01c55d4a6b5132720c6c07b223852129c maven-wagon-3.5.1-3.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 855a617957858debf9667a6ecf320166d17f64862d3a65c9ce4019a6bae85acc plexus-cipher-2.0-3.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 863dc37e02ec29a1796025f01437b269accc4a3b2915a24c27dac120692f926d plexus-classworlds-2.6.0-13.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 9688f60116d100a623b51f09586b2f750df126e07d07275d24eff905e30c3d98 plexus-containers-2.1.1-3.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: e0c02e3c666576d2e026a9985fabaf3f3427ec4769e4348b78b16fefc09e32d0 plexus-interpolation-1.26-13.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 1fe1c2dfd10e51eea72a4c61d7697ea6a0904eea81b923f8a11fee9683668698 plexus-sec-dispatcher-2.0-5.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: 7d1c51b354eaf0c9a2e62da01171ef13eca7d7733ff8a303f918f9c5045ffd6e plexus-utils-3.3.0-11.module+el8.10.0+24366+080b405b.1.src.rpm SHA-256: 28885843ac090f8cd006ba75cc00b920c058dc65a908153ef2d6477184758443 sisu-0.3.5-3.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: ceae8198ff041f76e9010d4b10560087a608280e89be2af9dcfad7667363c1fa slf4j-1.7.32-5.module+el8.10.0+21301+657f54a3.src.rpm SHA-256: d35a70913fe3f3e7cd01ecec8dfdf7158370a5cf73b64f47faf07d7595e98fb9 x86_64 apache-commons-cli-1.5.0-5.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 0c1d87d751c7fc7dd287a0563349505d3e05633b58a507ef8466ffc476c76af3 apache-commons-codec-1.15-8.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: f591c624648ab93d98c5f7e4cb72499ee3a3536dc172ef677ea30cd2384e4365 apache-commons-io-2.11.0-3.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: a5bb25859bab17b45dbb8703fda6b7a0b53e0178d4573f33c4254a4d45fd4d94 apache-commons-lang3-3.12.0-8.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 10a1b541627d9006432ea24625d9f7d996c1656de5e9dff8fa1a81d605edfcd3 atinject-1.0.5-5.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 5b487765b54466d3d3635bdc50113c4d1484f31043192f457951a04aa41e8f67 cdi-api-2.0.2-7.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: bf8dce071db58bc13bf3a107ac6478ecc781755fd55ae27dca9bd1e737b8f7ac google-guice-4.2.3-10.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: bd9dbed1d82816c50ac0559fd90ba70755755f504d21ad2552faa055e365accb guava-31.0.1-5.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: a1ac0eaa3324f1aa80f7ce7d2ea44857b282255a4761375a6afea6f3e788fbbf httpcomponents-client-4.5.13-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 6dd23d77eab8e9e1d96d09d82ddfc3448c9f934ab5007cc03e85cb2da472a4ae httpcomponents-core-4.4.13-8.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: dcf2213e094fbb47529a8512a8180c05077475f6f922eb6a351f58212568b615 jakarta-annotations-1.3.5-15.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: f44be215fe1200a29d5bb80f6256d58bf9b5d3b0abb08fb7f3640a61b6ac78d6 jansi-2.4.0-7.module+el8.10.0+21301+657f54a3.x86_64.rpm SHA-256: 2cfb008076bec6d2cebbcd11848fac1e352c05af899536b6d12e326b9d122cb8 jansi-debuginfo-2.4.0-7.module+el8.10.0+21301+657f54a3.x86_64.rpm SHA-256: c560e686bffc65e5b55744ce49e2bf7f71c82059b801c5999697e49be2bc3cd1 jansi-debugsource-2.4.0-7.module+el8.10.0+21301+657f54a3.x86_64.rpm SHA-256: 92d41db8922e923134558bd7c47c7c763afcd1a40d7cead9bd21fd49ea76d258 jcl-over-slf4j-1.7.32-5.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 8e2fd946dc0886325a1eeadf9bea2e3ecd945383d4f2cf8be18770bc5b8a61bd jsr-305-3.0.2-7.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: bf94424e6534e569abf066a9c9e03376285464cc0f2982dc59880d3e06c3e9a5 maven-3.8.5-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 6cb066427a7e4c7301aea18ef7214622bbd2ef579940d0baa29842a80e84b565 maven-lib-3.8.5-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 892c91bc2164da467f6e472b78f2bc68adaa161efd4d5cc456874b32c73f1b1e maven-openjdk11-3.8.5-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 225a2686f3d134de9e2add52eef73db2ce2419b07ee256184a9b073614a5965f maven-openjdk17-3.8.5-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 91fe73e60c10f326be661d6d20171fb077e7f64e5d3e389fe6f94de9afded224 maven-openjdk21-3.8.5-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 19b03801856635c7087c94590ad73b115b82d0a9ae1dbf982581d16c80f093de maven-openjdk8-3.8.5-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 9d8f2d840f1dfa86d4b6ab93bb6152b59056e0bf043bfae95ac74b923640d6dc maven-resolver-1.7.3-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: baeae8728a4724cb9f0efe9e94e58edd7fdc4c5a881749bb982c7a022ec5f875 maven-shared-utils-3.3.4-6.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: fb8413a246c5ff577e1cbe1bbfbe42fd964f94d3c3d41747bfbe01576758f60a maven-wagon-3.5.1-3.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 0fc44db9a24048ca94686936c1f4ec5fc0660262aafc83d80a94b10a2744df20 plexus-cipher-2.0-3.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 83f78f2e3d68586bef9b007f35879072d44c668ab7ae14513738208c977a3596 plexus-classworlds-2.6.0-13.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: a1a8481a49959c2887f8c399e8890bc4b1bf1155fb8b1a1bbbe2ee499f6b954e plexus-containers-component-annotations-2.1.1-3.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 9de9b79ede10053ff1163f6badcabe632a8cf40f13bc856068a03acc6969e801 plexus-interpolation-1.26-13.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 39afe562b8ad242f74d326d19280a63ce2a0ea9202533af85a5faba38e90a690 plexus-sec-dispatcher-2.0-5.module+el8.10.0+21301+657f54a3.noarch.rpm SHA-256: 4dcfa965054e610f795783287194c6a49a42d389313ebb3e093af4cd37e1484f plexus-utils-3.3.0-11.module+el8.10.0+24366+080b405b.1.noarch.rpm SHA-256: 1447

Share this article