Skip to main content

Configuration

CVE-2013-0253

Severity Medium
Score 5.8/10

Summary

The default configuration of Apache Maven 3.0.4, when using Maven Wagon prior to 2.4, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.

  • MEDIUM
  • NETWORK
  • NONE
  • PARTIAL
  • PARTIAL
  • NONE

CWE-16 - Configuration

Weaknesses in this category are typically introduced during the configuration of the software.

Advisory Timeline

  • Published