[Apollo] Advisories Statistics light light Login

RLSA-2026:38796

Security Mirrored from RHSA-2026:38796
Issued at: 2026-07-29
Updated at: 2026-07-29

Synopsis

Important: plexus-utils security update



Description

The Plexus project seeks to create end-to-end developer tools for writing applications. At the core is the container, which can be embedded or for a full scale application server. There are many reusable components for hibernate, form processing, jndi, i18n, velocity, etc. Plexus also includes an application server which is like a J2EE application server, without all the baggage.

Security Fix(es):

* org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method (CVE-2025-67030)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2451409

CVEs

CVE-2025-67030

Affected packages

Rocky Linux 9 x86_64 - AppStream

plexus-utils-0:3.3.0-14.el9_8.noarch.rpm plexus-utils-0:3.3.0-14.el9_8.src.rpm

Rocky Linux 9 aarch64 - AppStream

plexus-utils-0:3.3.0-14.el9_8.noarch.rpm plexus-utils-0:3.3.0-14.el9_8.src.rpm

Rocky Linux 9 s390x - AppStream

plexus-utils-0:3.3.0-14.el9_8.noarch.rpm plexus-utils-0:3.3.0-14.el9_8.src.rpm

Rocky Linux 9 ppc64le - AppStream

plexus-utils-0:3.3.0-14.el9_8.noarch.rpm plexus-utils-0:3.3.0-14.el9_8.src.rpm