CVE & CISA-KEV Catalog

CVE-2021-26291

CRITICALEPSS 94th pctl
9.1
CVSS v3
NVD

Description

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html

How to fix

Remediation Available
mavenDebian
Fixed in:3.8.6-1CVE-2021-26291
Fixed in:3.8.6-1CVE-2021-26291
Fixed in:3.8.6-1CVE-2021-26291
jenkinsRocky
Fixed in:0:2.426.3.1706515686-3.el8RHSA-2024:0778
Fixed in:0:2.426.3.1706516254-3.el8RHSA-2024:0776
Fixed in:0:2.387.1.1683009763-3.el8RHSA-2023:3198
Fixed in:0:2.426.3.1706516254-3.el8RHSA-2024:0776
Fixed in:0:2.387.1.1683009763-3.el8RHSA-2023:3198
Fixed in:0:2.426.3.1706515686-3.el8RHSA-2024:0778
jenkinsRed Hat / RHEL
Fixed in:0:2.426.3.1706516254-3.el8RHSA-2024:0776
Fixed in:0:2.426.3.1706515686-3.el8RHSA-2024:0778
Fixed in:0:2.426.3.1706515686-3.el8RHSA-2024:0778
Fixed in:0:2.387.1.1683009763-3.el8RHSA-2023:3198
Fixed in:0:2.387.1.1683009763-3.el8RHSA-2023:3198
Fixed in:0:2.426.3.1706516254-3.el8RHSA-2024:0776
jenkins-2-pluginsRocky
Fixed in:0:4.12.1706515741-1.el8RHSA-2024:0778
Fixed in:0:4.13.1706516346-1.el8RHSA-2024:0776
Fixed in:0:4.13.1706516346-1.el8RHSA-2024:0776
Fixed in:0:4.11.1683009941-1.el8RHSA-2023:3198
Fixed in:0:4.11.1683009941-1.el8RHSA-2023:3198
Fixed in:0:4.12.1706515741-1.el8RHSA-2024:0778
jenkins-2-pluginsRed Hat / RHEL
Fixed in:0:4.13.1706516346-1.el8RHSA-2024:0776
Fixed in:0:4.13.1706516346-1.el8RHSA-2024:0776
Fixed in:0:4.11.1683009941-1.el8RHSA-2023:3198
Fixed in:0:4.11.1683009941-1.el8RHSA-2023:3198
Fixed in:0:4.12.1706515741-1.el8RHSA-2024:0778
Fixed in:0:4.12.1706515741-1.el8RHSA-2024:0778
libmaven3-core-javaUbuntu
Fixed in:3.3.9-3ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.0-1~18.04.1ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.3-1ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.3-5ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.3-5ubuntu1.1USN-5805-1
mavenUbuntu
Fixed in:3.3.9-3ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.0-1~18.04.1ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.3-1ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.3-5ubuntu0.1~esm1USN-5245-1
Fixed in:3.6.3-5ubuntu1.1USN-5805-1

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityNone

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Exploit Intelligence

8.69%probability of exploitation in 30 days
94thpercentile

High risk: more likely to be exploited than 94% of all known CVEs.

References

Embed a live status badge for CVE-2021-26291
CVE-2021-26291 severity badge

Markdown

[![CVE-2021-26291](https://tridentstack.com/cve/badge/CVE-2021-26291.svg)](https://tridentstack.com/cve/CVE-2021-26291)

HTML

<a href="https://tridentstack.com/cve/CVE-2021-26291"><img src="https://tridentstack.com/cve/badge/CVE-2021-26291.svg" alt="CVE-2021-26291"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.