Origin validation error in Apache Maven - CVE-2021-26291

 

Origin validation error in Apache Maven - CVE-2021-26291

Published: April 22, 2022


Vulnerability identifier: #VU62492
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-26291
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to Apache Maven follows by default all repositories that are defined in a dependency’s Project Object Model (pom), including repositories accessible over HTTP protocol (e.g. without TLS encryption). A remote attacker can perform MitM attack and compromise the application.


Affected software

Apache Maven
DataStage on Cloud Pak for Data
IBM Business Automation Manager Open Editions
Integration Bus for z/OS
OpenShift Developer Tools and Services
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
SecurID Authentication Manager
Oracle WebLogic Server
openEuler
Ubuntu
Oracle GoldenGate Big Data and Application Adapters
IBM InfoSphere Information Server
watsonx.data
jenkins (Red Hat package)
maven-javadoc
maven-lib
maven
maven (Ubuntu package)
libmaven3-core-java (Ubuntu package)
jenkins-2-plugins (Red Hat package)
IBM Cloud Pak for Business Automation
Oracle GoldenGate Big Data

How to mitigate CVE-2021-26291

Install updates from vendor's website.

Apache Maven - update to 3.8.1
DataStage on Cloud Pak for Data - update to 5.2.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.2
IBM Business Automation Manager Open Editions - update to 8.0.2
SecurID Authentication Manager - addressed in versions 8.6 Patch 4, 8.7 Patch 1
watsonx.data - update to 2.0.2
jenkins (Red Hat package) - addressed in versions 2.387.1.1683009763-3.el8, 2.426.3.1706515686-3.el8, 2.426.3.1706516254-3.el8
maven-javadoc - update to 3.5.4-9
maven-lib - update to 3.5.4-9
maven - update to 3.5.4-9
maven (Ubuntu package) - update to 3.6.3-5ubuntu1.1
libmaven3-core-java (Ubuntu package) - update to 3.6.3-5ubuntu1.1
jenkins-2-plugins (Red Hat package) - addressed in versions 4.11.1683009941-1.el8, 4.12.1706515741-1.el8, 4.13.1706516346-1.el8
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
Oracle GoldenGate Big Data - update to 23.1

External References

Related Security Bulletins