Skip to content

Update dependency org.codehaus.plexus:plexus-utils to v4.0.3 [SECURITY] - autoclosed#1686

Closed
renovate-bot wants to merge 1 commit intoxwiki:masterfrom
renovate-bot:renovate/maven-org.codehaus.plexus-plexus-utils-vulnerability
Closed

Update dependency org.codehaus.plexus:plexus-utils to v4.0.3 [SECURITY] - autoclosed#1686
renovate-bot wants to merge 1 commit intoxwiki:masterfrom
renovate-bot:renovate/maven-org.codehaus.plexus-plexus-utils-vulnerability

Conversation

@renovate-bot
Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.codehaus.plexus:plexus-utils (source) 4.0.24.0.3 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-67030

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate bot added the dependencies A dependency upgrade label Mar 27, 2026
@renovate-bot renovate-bot added the dependencies A dependency upgrade label Mar 27, 2026
@renovate-bot renovate-bot changed the title Update dependency org.codehaus.plexus:plexus-utils to v4.0.3 [SECURITY] Update dependency org.codehaus.plexus:plexus-utils to v4.0.3 [SECURITY] - autoclosed Mar 30, 2026
@renovate-bot renovate-bot deleted the renovate/maven-org.codehaus.plexus-plexus-utils-vulnerability branch March 30, 2026 07:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies A dependency upgrade

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants