mirror of
https://github.com/internetarchive/heritrix3.git
synced 2026-09-20 20:55:49 +00:00
vuln-fix: Use HTTPS instead of HTTP to resolve deps CVE-2021-26291
This fixes a security vulnerability in this project where the `pom.xml` files were configuring Maven to resolve dependencies over HTTP instead of HTTPS. Weakness: CWE-829: Inclusion of Functionality from Untrusted Control Sphere Severity: High CVSS: 8.1 Detection: CodeQL & OpenRewrite (https://app.moderne.io/recipes/org.openrewrite.maven.security.UseHttpsForRepositories) Reported-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com> Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com> Bug-tracker: https://github.com/JLLeitschuh/security-research/issues/8 Detection: CodeQL (https://codeql.github.com/codeql-query-help/java/java-maven-non-https-url/) & OpenRewrite (https://app.moderne.io/recipes/org.openrewrite.maven.security.UseHttpsForRepositories) Reported-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com> Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com> Bug-tracker: https://github.com/JLLeitschuh/security-research/issues/8 Use this link to re-run the recipe: https://app.moderne.io/recipes/builder/IfHkrYfxx?organizationId=QWxsIEdpdEh1Yg%3D%3D Co-authored-by: Moderne <team@moderne.io>
This commit is contained in:
co-authored by
Moderne
parent
d3ca691f8d
commit
ea89c56c1d
@@ -91,14 +91,14 @@ http://maven.apache.org/guides/mini/guide-m1-m2.html
|
||||
<pluginRepositories>
|
||||
<pluginRepository>
|
||||
<id>builds.archive.org,maven2</id>
|
||||
<url>http://builds.archive.org/maven2</url>
|
||||
<url>https://builds.archive.org/maven2</url>
|
||||
</pluginRepository>
|
||||
</pluginRepositories>
|
||||
|
||||
<repositories>
|
||||
<repository>
|
||||
<id>builds.archive.org,maven2</id>
|
||||
<url>http://builds.archive.org/maven2</url>
|
||||
<url>https://builds.archive.org/maven2</url>
|
||||
</repository>
|
||||
<repository>
|
||||
<id>oracleReleases</id>
|
||||
|
||||
Reference in New Issue
Block a user