{"id":"SUSE-SU-2026:21608-1","summary":"Security update for ongres-scram, ongres-stringprep, plexus-testing, maven, maven-doxia, mojo-parent, sisu","details":"This update for ongres-scram, ongres-stringprep, plexus-testing, maven, maven-doxia, mojo-parent, sisu fixes the following issues:\n\nChanges in ongres-scram:\n\n- Version 3.2\n  * Fix Timing Attack Vulnerability in SCRAM Authentication\n    (bsc#1250399, CVE-2025-59432)\n  * Updated dependencies and maven plugins\n  * Use central-publishing-maven-plugin to deploy to Maven Central.\n\n- Do not create multirelease jar if the only Java 9+ class file is\n  module-info.class\n\nChanges in ongres-stringprep:\n\n- Do not create multirelease jar if the only Java 9+ class file is\n  module-info.class\n\nChanges in plexus-testing:\n\n- The build without tests does not need the full junit5; the\n  junit5-minimal (built with ant) is enough\n\nChanges in maven:\n\n- Upgrade to upstream version 3.9.14\n\n  * Bug Fixes\n\n    + plexus-testing dependencies should be used in test scope\n\n- Upgrade to upstream version 3.9.13\n  * Bug Fixes\n    + Bug: SecDispatcher is managed by legacy Plexus DI\n    + [3.9.x] MavenPluginJavaPrerequisiteChecker: Handle 8/1.8\n      Java version in ranges as well\n\n  * Maintenance\n\n    + Update Maven plugin versions in default-bindings.xml\n    + Migrate to JUnit 5 - avoid using TestCase\n\nChanges in maven-doxia:\n\nUpgrade to upstream version 2.1.0:\n\n  * New features and improvements\n\n    + Distinguish between linebreaks for formatting markup and\n      linebreaks in output\n    + Return SinkEventAttributes instead of super class\n      MutableAttributeSet for filterAttributes\n    + Optionally leave fragments of internal links untouched\n    Support strikethrough for Markdown sink\n    + DOXIA-770: Only escape when necessary\n    + DOXIA-760: Clarify table justification semantics and introduce\n      new \"JUSTIFY_DEFAULT\" alignment\n    + DOXIA-756: Allow to customize macro execution\n    + DOXIA-759: Support anchors in MarkdownSink\n\n  * Bug Fixes\n\n    + MarkdownSink: Fix verbatim inside table cell\n    + Make sure to emit metadata prior everything else\n    + Convert all globally available attributes to HTML5 compliant\n      ones\n    + Html5BaseSink: Convert non-compliant HTML5 attributes to\n      compliant ones\n    + Support \"name\" attribute in \"a\" element still in XHTML5\n    + Never emit Markdown inside HTML context\n    + Use JSoup to convert HTML to XHTML after parsing with Flexmark\n    + DOXIA-764: Strip leading newline after\n    + DOXIA-763: Distinguish between verbatim source and non-source\n      in MarkdownSink\n    + DOXIA-758: Consider emitComments flag in MarkdownSink\n    + DOXIA-757: Don't strip leading \"#\" from link names\n    + DOXIA-753: Do not end lists with a blank line\n    + DOXIA-751: Linked inline code must be emitted in right order\n    + DOXIA-749: Correctly indent and separate blocks inside list\n      items\n    + DOXIA-750: Properly apply inlines inside HTML blocks\n    + DOXIA-747: Emit headings at beginning of line for Markdown\n\n  * Documentation updates\n\n    + Site: Convert APT to Markdown\n    + Improve documentation of supported extensions\n    + (doc) Fix missing references in JavaDocs\n\n  * Maintenance\n\n    + Cleanup tests\n    + JUnit Jupiter best practices\n    + Remove commons-lang3 and commons-text dependencies\n    + feat: enable prevent branch protection rules\n    + Cleanup pom, remove redundant dependencies\n    + Drop almost all usages of plexus-utils\n    + Remove not used and outdated clirr-maven-plugin\n    + Enable Github Issues\n    + DOXIA-772: Deprecate Sink.sectionTitle() and sectionTitle_()\n    + DOXIA-754: Clarify method order for nested lists\n\nChanges in mojo-parent:\n\n- Do not import junit-bom in the parent. This creates unnecessary\n  build cycles with junit5.\n","modified":"2026-05-16T18:24:43.104459001Z","published":"2026-05-12T12:36:08Z","related":["CVE-2025-59432"],"upstream":["CVE-2025-59432"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621608-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1250399"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59432"}],"schema_version":"1.7.5"}