FlawAtlas
Search the atlas
SUSE-RU-2024:3971-1 Not scored

Recommended update for mojo-parent

This update for mojo-parent fixes the following issues: xalan-j2 was updated from version 2.7.2 to 2.7.3: - Security issues fixed: * CVE-2022-34169: Fixed integer truncation issue when processing malicious XSLT stylesheets (bsc#1201684) - Changes and Bugs fixed: * Java 8 is now the minimum requirement * Upgraded to Apache Commons BCEL 6.7.0 * Upgraded to Xerces-J 2.12.2 mojo-parent was updated from version 70 to 82: - Main changes: * Potentially Breaking Changes: + mojo.java.target should be set as '8', without '1.' + spotless plugin must be executed by JDK 11 at least + ossrh-snapshots repository was removed from parent * New features and improvements: + Removed SHA-512 checksum for source release artifact + Use only project version as tag for release + Added space before close empty elements in poms by spotless + Using Checkstyle together with Spotless + Introduce spotless for automatic code formatting + Introduce enforcer rule for minimal version of Java and Maven + Use new Plugin Tools report - maven-plugin-report-plugin + Added sisu-maven-plugin + Introduced maven.version property + Execute spotless by JDK 11 at least + Use release options for m-compiler-p with newer JDKs + Allow override of invoker.streamLogsOnFailures + Require Maven 3.9.x at least for releases + Added maven-wrapper-plugin to pluginManagement + Removed ossrh-snapshots repository from MojoHaus parent + Added build-helper-maven-plugin to pluginManagement + Require Maven 3.6.3+ + Updated palantirJavaFormat for spotless - JDK 21 compatible + Added dependencyManagement for maven-shade-plugin + Dropped recommendedJavaBuildVersion property + Format Markdown files with Spotless Plugin * Bugs fixed: + Restore source release distribution in child projects + Rename property maven.version to mavenVersion + minimalMavenBuildVersion should not be overriding by mavenVersion + Use simple checkstyle rules since spotless is executed by default + Use old spotless version only for JDK < 11 + Fixed spotless configuration for markdown - Other changes: * Removed Google search box due to privacy * Put version for mrm-maven-plugin in property * Added streamLogsOnFailures to m-invoker-p * Added property for maven-fluido-skin version * Setup Apache Matomo analytics * Require Maven 3.2.5 * Added SHA-512 hashes * Extract plugin version as variable so child pom can override if needed * Removed issue-tracking as no longer exists * Removed cim report as no longer exists bcel was updated from version 5.2 to 6.10: - Many APIs have been extended - Added riscv64 support - Various bugs were fixed apache-commons-lang3 was updated to version 3.12.0 to 3.16.0: - Included new APIs that are needed by bcel 6.x - Various minor bugs were fixed xerces-j2: - Improved RPM packaging build instructions netty3: - Generate sources with protobuf instead of using pre-generated ones

Exploit probability Not scored
Published November 11, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 apache-commons-lang3
SUSE:Linux Enterprise Module for Development Tools 15 SP5 apache-commons-lang3
openSUSE:Leap 15.6 xerces-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 netty3
SUSE:Manager Server Module 4.3 apache-commons-lang3
SUSE:Linux Enterprise Server 15 SP2-LTSS apache-commons-lang3
SUSE:Enterprise Storage 7.1 bcel
openSUSE:Leap 15.5 netty3
SUSE:Linux Enterprise Module for Basesystem 15 SP5 bcel
SUSE:Linux Enterprise Server 15 SP2-LTSS bcel
SUSE:Manager Server 4.3 xalan-j2
openSUSE:Leap 15.6 netty3
SUSE:Manager Proxy 4.3 xalan-j2
SUSE:Enterprise Storage 7.1 xalan-j2
SUSE:Linux Enterprise Module for Development Tools 15 SP6 netty3
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 xerces-j2
SUSE:Manager Server 4.3 bcel
SUSE:Linux Enterprise Server 15 SP4-LTSS xalan-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 bcel
SUSE:Manager Proxy 4.3 xerces-j2
SUSE:Manager Proxy 4.3 bcel
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 apache-commons-lang3
SUSE:Linux Enterprise Module for Basesystem 15 SP5 xalan-j2
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS xerces-j2
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS xerces-j2
SUSE:Enterprise Storage 7.1 netty3
openSUSE:Leap 15.6 mojo-parent
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 bcel
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS netty3
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 xalan-j2
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS netty3
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS xalan-j2
SUSE:Linux Enterprise Module for Basesystem 15 SP6 xerces-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 xalan-j2
SUSE:Linux Enterprise Server 15 SP3-LTSS xalan-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 xerces-j2
SUSE:Linux Enterprise Server 15 SP3-LTSS apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS apache-commons-lang3
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 netty3
SUSE:Linux Enterprise Server 15 SP3-LTSS xerces-j2
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS apache-commons-lang3
SUSE:Linux Enterprise Server 15 SP2-LTSS xalan-j2
openSUSE:Leap 15.6 apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS netty3
openSUSE:Leap 15.5 xalan-j2-extras
SUSE:Linux Enterprise Server 15 SP4-LTSS xerces-j2
openSUSE:Leap 15.5 xerces-j2
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS xalan-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 bcel
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS bcel
openSUSE:Leap 15.6 xalan-j2
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS bcel
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS xerces-j2
SUSE:Linux Enterprise Server 15 SP2-LTSS netty3
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS xalan-j2
SUSE:Linux Enterprise Server 15 SP3-LTSS netty3
SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS bcel
openSUSE:Leap 15.5 apache-commons-lang3
SUSE:Enterprise Storage 7.1 xerces-j2
openSUSE:Leap 15.6 xalan-j2-extras
SUSE:Linux Enterprise Server 15 SP3-LTSS bcel
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS apache-commons-lang3
SUSE:Linux Enterprise Module for Basesystem 15 SP6 xalan-j2
SUSE:Linux Enterprise Server 15 SP4-LTSS netty3
SUSE:Linux Enterprise Module for Basesystem 15 SP6 apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS netty3
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 netty3
SUSE:Linux Enterprise Server 15 SP4-LTSS bcel
SUSE:Linux Enterprise Module for Development Tools 15 SP5 netty3
SUSE:Linux Enterprise Server 15 SP4-LTSS apache-commons-lang3
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS xalan-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP4 xerces-j2
openSUSE:Leap 15.5 mojo-parent
openSUSE:Leap 15.6 bcel
SUSE:Manager Server 4.3 xerces-j2
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 xalan-j2
SUSE:Linux Enterprise Module for Basesystem 15 SP6 bcel
SUSE:Linux Enterprise Server 15 SP2-LTSS xerces-j2
openSUSE:Leap 15.5 bcel
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS bcel
openSUSE:Leap 15.5 xalan-j2
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS xerces-j2
SUSE:Linux Enterprise Module for Basesystem 15 SP5 xerces-j2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-RU-2024:3971-1

This update for mojo-parent fixes the following issues: xalan-j2 was updated from version 2.7.2 to 2.7.3: - Security issues fixed: * CVE-2022-34169: Fixed integer truncation issue when processing malicious XSLT stylesheets (bsc#1201684) - Changes and Bugs fixed: * Java 8 is now the minimum requirement * Upgraded to Apache Commons BCEL 6.7.0 * Upgraded to Xerces-J 2.12.2 mojo-parent was updated from version 70 to 82: - Main changes: * Potentially Breaking Changes: + mojo.java.target should be set as '8', without '1.' + spotless plugin must be executed by JDK 11 at least + ossrh-snapshots repository was removed from parent * New features and improvements: + Removed SHA-512 checksum for source release artifact + Use only project version as tag for release + Added space before close empty elements in poms by spotless + Using Checkstyle together with Spotless + Introduce spotless for automatic code formatting + Introduce enforcer rule for minimal version of Java and Maven + Use new Plugin Tools report - maven-plugin-report-plugin + Added sisu-maven-plugin + Introduced maven.version property + Execute spotless by JDK 11 at least + Use release options for m-compiler-p with newer JDKs + Allow override of invoker.streamLogsOnFailures + Require Maven 3.9.x at least for releases + Added maven-wrapper-plugin to pluginManagement + Removed ossrh-snapshots repository from MojoHaus parent + Added build-helper-maven-plugin to pluginManagement + Require Maven 3.6.3+ + Updated palantirJavaFormat for spotless - JDK 21 compatible + Added dependencyManagement for maven-shade-plugin + Dropped recommendedJavaBuildVersion property + Format Markdown files with Spotless Plugin * Bugs fixed: + Restore source release distribution in child projects + Rename property maven.version to mavenVersion + minimalMavenBuildVersion should not be overriding by mavenVersion + Use simple checkstyle rules since spotless is executed by default + Use old spotless version only for JDK < 11 + Fixed spotless configuration for markdown - Other changes: * Removed Google search box due to privacy * Put version for mrm-maven-plugin in property * Added streamLogsOnFailures to m-invoker-p * Added property for maven-fluido-skin version * Setup Apache Matomo analytics * Require Maven 3.2.5 * Added SHA-512 hashes * Extract plugin version as variable so child pom can override if needed * Removed issue-tracking as no longer exists * Removed cim report as no longer exists bcel was updated from version 5.2 to 6.10: - Many APIs have been extended - Added riscv64 support - Various bugs were fixed apache-commons-lang3 was updated to version 3.12.0 to 3.16.0: - Included new APIs that are needed by bcel 6.x - Various minor bugs were fixed xerces-j2: - Improved RPM packaging build instructions netty3: - Generate sources with protobuf instead of using pre-generated ones

View original source

05 / REFERENCES

Further evidence