Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The affected method is org.codehaus.plexus.util.Expand.extractFile. The maven-doxia-sitetools package does not use the Expand class. It only uses: - org.codehaus.plexus.util.DirectoryScanner - org.codehaus.plexus.util.FileUtils - org.codehaus.plexus.util.IOUtil - org.codehaus.plexus.util.Os - org.codehaus.plexus.util.PathTool - org.codehaus.plexus.util.ReaderFactory - org.codehaus.plexus.util.ReflectionUtils - org.codehaus.plexus.util.StringUtils - org.codehaus.plexus.util.WriterFactory - org.codehaus.plexus.util.xml.pull.MXParser - org.codehaus.plexus.util.xml.pull.XmlPullParser - org.codehaus.plexus.util.xml.pull.XmlPullParserException - org.codehaus.plexus.util.xml.Xpp3Dom