CVE-2013-0253: Apache Maven

Medium severity, CVSS 5.8. EPSS: 1.6% chance of exploitation in the next 30 days.

The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.

Affected products

  • Apache Maven: version 3.0.4 only

Published 2013-04-09. Last modified 2026-06-16.