## This update for Maven fixes the following issues: maven-dependency-analyzer was updated from version 1.13.2 to 1.15.1: * Key changes across versions: * Bug fixes and improved support of dynamic types * Dependency upgrades (ASM, Maven core, and notably the removal of commons-io) * Improved error handling by logging instead of failing * Improved dependency usage tracking maven-dependency-plugin was updated from version 3.6.0 to 3.8.1: * Key changes across versions: * Dependency upgrades on maven-dependency-analyzer and Doxia * Deprecated dependency:sources in favor of dependency:resolve-sources * Documentation improvements * New dependency analysis goal to check for invalid exclusions * New JSON output option for dependency:tree * Performance improvements * Several bug fixes addressing:
Cross-
* CVE-2020-13936
CVSS scores:
* CVE-2020-13936 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2020-13936 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* Development Tools Module 15-SP6
* openSUSE Leap 15.6
* SUSE Enterprise Storage 7.1
* SUSE Linux Enterprise Desktop 15 SP6
* SUSE Linux Enterprise High Performance Computing 15 SP3
* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
Get the latest Linux and open source security news straight to your inbox.