Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The affected method is org.codehaus.plexus.util.Expand.extractFile. The maven-reporting-impl package does not use the Expand class. It only uses: - org.codehaus.plexus.util.PathTool - org.codehaus.plexus.util.ReaderFactory