← All tasks
javaDependencyTrack/dependency-track #6025Not a task: not reproduced

Bump bundeled plexus-utils version to 3.6.1 to fix CVE-2025-67030

envgap__DependencyTrack__dependency-track-6025

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
d6e87bddd138afe1edd5cbe3a35ac6ffffa1e197
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

DependencyTrack/dependency-track #6025 · read the original issue
### Current Behavior

Scanning DependencyTrack containers for version 4.14.1 shows it has plexus-utils which is affected by CVE-2025-67030 or GHSA-6fmv-xxpf-w3cw .

File is plexus-utils-3.6.0.jar part of the dependency-track-apiserver.jar



### Steps to Reproduce

```grype dependencytrack/apiserver:4.14.1```

### Expected Behavior

No critical or high on the dependency track files on SCA scans.

### Dependency-Track Version

4.14.1

### Dependency-Track Distribution

Container Image, Executable WAR

### Database Server

N/A

### Database Server Version

_No response_

### Browser

Google Chrome

### Checklist

- [x] I have read and understand the [contributing guidelines](https://github.com/DependencyTrack/dependency-track/blob/master/CONTRIBUTING.md#filing-issues)
- [x] I have checked the [existing issues](https://github.com/DependencyTrack/dependency-track/issues) for whether this defect was already reported
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]