Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The affected method is org.codehaus.plexus.util.Expand.extractFile. The maven-clean-plugin package does not use the Expand class.