[JIRA] (JENKINS-61666) Outdated/vulnerable dependency (commons-io)

3 views
Skip to first unread message

foundation-security-members@cloudbees.com (JIRA)

unread,
Mar 24, 2020, 9:34:03 AM3/24/20
to jenkinsc...@googlegroups.com
CloudBees Foundation Security created an issue
 
Jenkins / Bug JENKINS-61666
Outdated/vulnerable dependency (commons-io)
Issue Type: Bug Bug
Assignee: Andrey Stroilov
Components: google-oauth-plugin
Created: 2020-03-24 13:33
Priority: Minor Minor
Reporter: CloudBees Foundation Security

The plugin includes a library (commons-io) with a vulnerability. Please update it to 2.6. In addition to that, a second vulnerability is present in 2.6 on the method FileNameUtils.normalize. As the correction is planned for 2.7 but this version is not yet released, please ensure you are not using this method in your code and provide your finding in this ticket.

Ticket to follow the second vulnerability:

https://issues.apache.org/jira/browse/IO-559

Although the plugin may not use the dependency the way it's exploitable, it's better to avoid the buggy dependency in order to:

Thank you.
by Félix Queiruga

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.13.12#713012-sha1:6e07c38)
Atlassian logo

foundation-security-members@cloudbees.com (JIRA)

unread,
Mar 24, 2020, 9:47:02 AM3/24/20
to jenkinsc...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages