Re: CVE-2021-26291 for plugin writers

2023-08-31 Thread Hervé Boutemy
> From: Anton Vodonosov > Sent: Monday, August 28, 2023 11:14:30 AM > To: dev@maven.apache.org > Subject: CVE-2021-26291 for plugin writers > > Maven 3.8.1 release notes describe CVE-2021-26291 fixed in that version: > https://na01.safelinks.protection.ou

Re: CVE-2021-26291 for plugin writers

2023-08-30 Thread Jeremy Landis
Anton Vodonosov Sent: Monday, August 28, 2023 11:14:30 AM To: dev@maven.apache.org Subject: CVE-2021-26291 for plugin writers Maven 3.8.1 release notes describe CVE-2021-26291 fixed in that version: https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmaven.apache.org%2Fdocs%2F3.8.1%2Fr

CVE-2021-26291 for plugin writers

2023-08-28 Thread Anton Vodonosov
Maven 3.8.1 release notes describe CVE-2021-26291 fixed in that version: https://maven.apache.org/docs/3.8.1/release-notes.html That's the best explanation of this CVE of all I saw online. But it misses guide for plugin authors. GitHub's security scanner created this alert for my plugin https://