[JIRA] (JENKINS-54838) OWASP Dependency-Check plugin loses trace of bcprov-jdk15on.jar vulnerabilities

12 views
Skip to first unread message

segarrra@gmail.com (JIRA)

unread,
Nov 23, 2018, 9:11:02 AM11/23/18
to jenkinsc...@googlegroups.com
Marc Peña created an issue
 
Jenkins / Bug JENKINS-54838
OWASP Dependency-Check plugin loses trace of bcprov-jdk15on.jar vulnerabilities
Issue Type: Bug Bug
Assignee: Unassigned
Components: dependency-check-jenkins-plugin
Created: 2018-11-23 14:10
Labels: plugin jenkins dependency-check
Priority: Minor Minor
Reporter: Marc Peña

We're using the Jenkins plugin to analyze our software and are experimenting a buggy behavior. Every time we do a scan the plugin says that we got: 

{{12 new vulnerabilities
12 Fixed vulnerabilities}}

And the problem is that all of them are the same vulnerabilities, scan after scan, related to the Bouncy Castle provider: bcprov-jdk15on.jar

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)

segarrra@gmail.com (JIRA)

unread,
Nov 23, 2018, 9:11:02 AM11/23/18
to jenkinsc...@googlegroups.com
Marc Peña updated an issue
Change By: Marc Peña
We're using the Jenkins plugin to analyze our software and are experimenting a buggy behavior. Every time we do a scan the plugin says that we got: 

{ { code:java}
12 new vulnerabilities
12 Fixed vulnerabilities
{code } }

And the problem is that all of them are the same vulnerabilities, scan after scan, related to the Bouncy Castle provider: *bcprov-jdk15on.jar*

*!https://user-images.githubusercontent.com/3256953/48907536-0e604600-ee68-11e8-86a3-c95710e01986.png!*

*!https://user-images.githubusercontent.com/3256953/48907421-a9a4eb80-ee67-11e8-9e90-3ea378a70852.png!*

steve.springett@owasp.org (JIRA)

unread,
Nov 23, 2018, 4:31:02 PM11/23/18
to jenkinsc...@googlegroups.com
Steve Springett commented on Bug JENKINS-54838
 
Re: OWASP Dependency-Check plugin loses trace of bcprov-jdk15on.jar vulnerabilities

What version of the Dependency-Check Jenkins plugin are you using?

 

What version of analysis-core (Static Code Analysis Plugins) is installed?

 

Do you have the warnings or warnings-ng plugin installed? If so, what version?

steve.springett@owasp.org (JIRA)

unread,
Nov 23, 2018, 4:33:01 PM11/23/18
to jenkinsc...@googlegroups.com
Steve Springett edited a comment on Bug JENKINS-54838
What version of the Dependency-Check Jenkins plugin are you using?

 

What version of analysis-core (Static Code Analysis Plugins) is installed?

 

Do you have the warnings or warnings-ng plugin installed? If so, what version?


 

Did you use the Dependency-Check Maven plugin, CLI, or the Jenkins plugin to produce dependency-check-result.xml?

steve.springett@owasp.org (JIRA)

unread,
Nov 23, 2018, 4:34:02 PM11/23/18
to jenkinsc...@googlegroups.com

segarrra@gmail.com (JIRA)

unread,
Nov 24, 2018, 7:38:02 PM11/24/18
to jenkinsc...@googlegroups.com
Marc P updated an issue
Change By: Marc P
We're using the Dependency-Check Jenkins plugin *version 3.3.4* to analyze our software and are experimenting a buggy behavior. Every time we do a scan the plugin says that we got: 

{code:java}
12 new vulnerabilities
12 Fixed vulnerabilities{code}
And the problem is that all of them are the same vulnerabilities, scan after scan, related to the Bouncy Castle provider: *bcprov-jdk15on.jar*

*!https://user-images.githubusercontent.com/3256953/48907536-0e604600-ee68-11e8-86a3-c95710e01986.png!*

*!https://user-images.githubusercontent.com/3256953/48907421-a9a4eb80-ee67-11e8-9e90-3ea378a70852.png!*

segarrra@gmail.com (JIRA)

unread,
Nov 24, 2018, 7:50:02 PM11/24/18
to jenkinsc...@googlegroups.com
Marc P commented on Bug JENKINS-54838
 
Re: OWASP Dependency-Check plugin loses trace of bcprov-jdk15on.jar vulnerabilities

We are using version 3.3.4 of Dependency-Check Jenkins plugin.

I don't know how to check the version of analysis-core.

I think that we don't have the warnings/-ng plugins installed.

We used the Jenkins plugin to produce dependency-check-result.xml

segarrra@gmail.com (JIRA)

unread,
Nov 26, 2018, 4:33:02 AM11/26/18
to jenkinsc...@googlegroups.com
Marc P commented on Bug JENKINS-54838

By the way, we just upgraded to Dependency-Check Jenkins plugin version 4.0.0 and the issue remains the same.

steve.springett@owasp.org (JIRA)

unread,
Nov 26, 2018, 11:25:02 AM11/26/18
to jenkinsc...@googlegroups.com

Ok thanks for the info. I'll take a look in the next few days and try to reproduce.

steve.springett@owasp.org (JIRA)

unread,
Jul 6, 2019, 11:26:03 PM7/6/19
to jenkinsc...@googlegroups.com
Steve Springett closed an issue as Won't Do
 

No longer relevant with v5.0.0

Change By: Steve Springett
Status: Open Closed
Resolution: Won't Do
Reply all
Reply to author
Forward
0 new messages