[JIRA] (JENKINS-51344) Jackson-Databind needs to be upgraded to 2.9.4+ to address CVE-2018-5968

7 views
Skip to first unread message

bill@stephensfamily.us (JIRA)

unread,
May 15, 2018, 10:40:02 AM5/15/18
to jenkinsc...@googlegroups.com
Bill Stephens created an issue
 
Jenkins / Improvement JENKINS-51344
Jackson-Databind needs to be upgraded to 2.9.4+ to address CVE-2018-5968
Issue Type: Improvement Improvement
Assignee: Marcel Birkner
Components: ec2-deployment-dashboard-plugin, github-plugin, jira-plugin
Created: 2018-05-15 14:39
Priority: Major Major
Reporter: Bill Stephens

Jackson-databind jar needs to be updated to 2.9.4+ to address https://nvd.nist.gov/vuln/detail/CVE-2018-5968

Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v7.3.0#73011-sha1:3c73d0e)
Atlassian logo

dbeck@cloudbees.com (JIRA)

unread,
May 15, 2018, 10:47:02 AM5/15/18
to jenkinsc...@googlegroups.com
Daniel Beck commented on Improvement JENKINS-51344
 
Re: Jackson-Databind needs to be upgraded to 2.9.4+ to address CVE-2018-5968

Specifically, the CVE being identified by crappy security scanners, as none of these plugins opt in to the affected feature in jackson-databind, last time I checked at least.

o.v.nenashev@gmail.com (JIRA)

unread,
May 15, 2018, 10:50:02 AM5/15/18
to jenkinsc...@googlegroups.com

Bill Stephens just for the future, please follow the https://jenkins.io/security/#reporting-vulnerabilities process if you see security-related issues. Regarding this particular CVE, we recently did investigation, and we didn't discover any usages of the vulnerable API in JIRA. Updates would be nice, but there is no security defect on the Jenkins side. If you see ones, please report them accordingly.

Generally all listed plugins should switch to Jackson Databind Plugin or Jackson2 API Plugin so that they do not bundle the dependencies on their own

o.v.nenashev@gmail.com (JIRA)

unread,
May 15, 2018, 10:50:03 AM5/15/18
to jenkinsc...@googlegroups.com

o.v.nenashev@gmail.com (JIRA)

unread,
May 16, 2018, 6:14:01 AM5/16/18
to jenkinsc...@googlegroups.com
 
Re: Jackson-Databind needs to be upgraded to 2.9.4+ to address CVE-2018-5968

Bill Stephens I suggest creating a separate issue for each plugin in question

olamy@apache.org (JIRA)

unread,
Oct 12, 2018, 4:05:03 AM10/12/18
to jenkinsc...@googlegroups.com
Olivier Lamy updated an issue
 
Change By: Olivier Lamy
Component/s: jira-plugin
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)

cuksany@qq.com (JIRA)

unread,
Jul 29, 2019, 10:19:04 PM7/29/19
to jenkinsc...@googlegroups.com

cuksany@qq.com (JIRA)

unread,
Jul 29, 2019, 10:40:01 PM7/29/19
to jenkinsc...@googlegroups.com

cuksany@qq.com (JIRA)

unread,
Jul 29, 2019, 11:42:03 PM7/29/19
to jenkinsc...@googlegroups.com
Lai DaZhi started work on Improvement JENKINS-51344
 
Change By: Lai DaZhi
Status: Open In Progress
Reply all
Reply to author
Forward
0 new messages