[JIRA] (JENKINS-58849) Logstash plugin: requires insecure "mask-passwords"

10 views
Skip to first unread message

tyler@tylercipriani.com (JIRA)

unread,
Aug 7, 2019, 10:45:03 AM8/7/19
to jenkinsc...@googlegroups.com
Tyler Cipriani created an issue
 
Jenkins / Bug JENKINS-58849
Logstash plugin: requires insecure "mask-passwords"
Issue Type: Bug Bug
Assignee: Jakub Bochenski
Components: logstash-plugin, mask-passwords-plugin
Created: 2019-08-07 14:44
Labels: security plugin
Priority: Minor Minor
Reporter: Tyler Cipriani

The mask-passwords plugin contains CVE-2019-10370 for which there is no released fix; however, the Logstash plugin depends on this plugin:

 

https://github.com/jenkinsci/logstash-plugin/blob/master/pom.xml#L162

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)

bochenski.kuba+jenkins@gmail.com (JIRA)

unread,
Aug 7, 2019, 11:15:02 AM8/7/19
to jenkinsc...@googlegroups.com
Jakub Bochenski closed an issue as Cannot Reproduce
 

The dependency you link to is only used in test (as can be seen by it's scope).

I fail to see why it would be a problem. Please reopen if I'm missing something

Change By: Jakub Bochenski
Status: Open Closed
Resolution: Cannot Reproduce

tyler@tylercipriani.com (JIRA)

unread,
Aug 7, 2019, 11:26:02 AM8/7/19
to jenkinsc...@googlegroups.com
Tyler Cipriani commented on Bug JENKINS-58849
 
Re: Logstash plugin: requires insecure "mask-passwords"

In the Jenkins UI "This plugin cannot be uninstalled it has one or more dependents Logstash" when I hover over "Uninstall" for "Mask Passwords Plugin"

tyler@tylercipriani.com (JIRA)

unread,
Aug 7, 2019, 11:30:04 AM8/7/19
to jenkinsc...@googlegroups.com
Tyler Cipriani reopened an issue
 

Change By: Tyler Cipriani
Resolution: Cannot Reproduce
Status: Closed Reopened

bochenski.kuba+jenkins@gmail.com (JIRA)

unread,
Aug 7, 2019, 12:42:02 PM8/7/19
to jenkinsc...@googlegroups.com
Jakub Bochenski commented on Bug JENKINS-58849
 
Re: Logstash plugin: requires insecure "mask-passwords"

Please try upgrading the plugin to latest version, as old versions depended on mask-passwords

Reply all
Reply to author
Forward
0 new messages