Package
hadoop-fips-3.3.6
Component
plexus-utils
Latest update
9.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Vulnerable plexus-utils JARs (versions 1.5.1 through 3.0.15) are present in the Maven local repository cache at /usr/share/m2/repository/. These are transitive dependencies of Maven build plugins (compiler, surefire, shade, etc.), not project dependencies. The project itself declares plexus-utils 3.1.0 via dependencyManagement (above the fix version), but Maven plugin classpaths resolve independently and pull in older versions. Remediation requires upstream Maven plugin updates to exclude or upgrade their plexus-utils transitive dependencies. A pombump-deps override cannot control Maven plugin dependency resolution.
Status