[JIRA] (JENKINS-61511) Outdated/vulnerable dependency (commons-io)

6 views
Skip to first unread message

foundation-security-members@cloudbees.com (JIRA)

unread,
Mar 18, 2020, 11:58:03 AM3/18/20
to jenkinsc...@googlegroups.com
CloudBees Foundation Security created an issue
 
Jenkins / Bug JENKINS-61511
Outdated/vulnerable dependency (commons-io)
Issue Type: Bug Bug
Assignee: Craig Barber
Components: google-storage-plugin
Created: 2020-03-18 15:57
Priority: Major Major
Reporter: CloudBees Foundation Security

The library commons-io contains a vulnerability in all released versions. The correction is planned for 2.7, but unreleased yet. To prevent any issue with this library, please ensure you are not using FileNameUtils.normalize and post your analysis here.

Ticket to follow the vulnerability:

https://issues.apache.org/jira/browse/IO-559

by Ramón León

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.13.12#713012-sha1:6e07c38)
Atlassian logo

foundation-security-members@cloudbees.com (JIRA)

unread,
Mar 18, 2020, 12:28:03 PM3/18/20
to jenkinsc...@googlegroups.com
Change By: CloudBees Foundation Security
The library *_commons-io_* contains a vulnerability in all released versions. The correction is planned for 2.7, but unreleased yet. To prevent any issue with this library, please ensure you are not using _FileNameUtils.normalize_ and post your analysis here.


Ticket to follow the vulnerability:

https://issues.apache.org/jira/browse/IO-559

Although the plugin may not use the dependency the way it's exploitable, it's better to avoid the buggy dependency in order to:

* avoid security reports warning about that
* avoid future risky uses of the library that may exploit the vulnerability
If you like, you can use the bom approach to avoid dealing with the right version, it will take the one used by Jenkins core: https://jenkins.io/doc/developer/plugin-development/dependency-management/

Thank you.

_by_ [_Ramón León_|https://issues.jenkins-ci.org/secure/ViewProfile.jspa?name=MRamonLeon]
Reply all
Reply to author
Forward
0 new messages