Skip to content

[SECURITY] Bump karaf.version from 4.2.2 to 4.2.3#1051

Closed
kemitix wants to merge 2 commits intoapache:masterfrom
kemitix:dependabot/maven/karaf.version-4.2.3
Closed

[SECURITY] Bump karaf.version from 4.2.2 to 4.2.3#1051
kemitix wants to merge 2 commits intoapache:masterfrom
kemitix:dependabot/maven/karaf.version-4.2.3

Conversation

@kemitix
Copy link
Contributor

@kemitix kemitix commented Mar 14, 2019

Bumps karaf.version from 4.2.2 to 4.2.3.

Updates karaf from 4.2.2 to 4.2.3

Updates org.apache.karaf.system.core from 4.2.2 to 4.2.3

Updates org.apache.karaf.shell.core from 4.2.2 to 4.2.3

Signed-off-by: dependabot[bot] support@dependabot.com

Bumps `karaf.version` from 4.2.2 to 4.2.3.

Updates `karaf` from 4.2.2 to 4.2.3

Updates `org.apache.karaf.system.core` from 4.2.2 to 4.2.3

Updates `org.apache.karaf.shell.core` from 4.2.2 to 4.2.3

Signed-off-by: dependabot[bot] <support@dependabot.com>
@kemitix
Copy link
Contributor Author

kemitix commented Mar 25, 2019

Sourced from The GitHub Security Advisory Database.

Moderate severity vulnerability that affects org.apache.karaf:karaf and org.apache.karaf:apache-karaf
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes out the content of these paths to the Karaf repo and resources directories. However, it doesn't do any validation on the paths in the zip file. This means that a malicious user could craft a .kar file with ".." directory names and break out of the directories to write arbitrary content to the filesystem. This is the "Zip-slip" vulnerability - https://snyk.io/research/zip-slip-vulnerability. This vulnerability is low if the Karaf process user has limited permission on the filesystem. Any Apache Karaf releases prior 4.2.3 is impacted.

Affected versions: ["< 4.2.3"]

@kemitix kemitix changed the title Bump karaf.version from 4.2.2 to 4.2.3 [SECURITY] Bump karaf.version from 4.2.2 to 4.2.3 Mar 25, 2019
@aledsage
Copy link
Contributor

The change looks reasonable, but it’s still scary the knock-on consequences of a version bump like this (e.g. what else has bumped version).

If you've tested it @kemitix then I'm ok with us merging it. Can you confirm what testing you've done?

I need to write up some stuff (commands, debugging tips etc) from last time I fought with versions in karaf dependencies.

@kemitix
Copy link
Contributor Author

kemitix commented Mar 25, 2019

@aledsage Needs a little more work. Testing had been pretty basic with just brooklyn-server. I'm seeing a maven enforcer error when I try to build the whole of brooklyn.

@dependabot-preview dependabot-preview bot deleted the dependabot/maven/karaf.version-4.2.3 branch March 26, 2019 06:39
@kemitix kemitix restored the dependabot/maven/karaf.version-4.2.3 branch March 26, 2019 07:16
@nakomis
Copy link
Contributor

nakomis commented Nov 26, 2019

@kemitix Can you take a look at this please to see if it is still relevant, and address the comments above if appropriate

Thanks

@kemitix
Copy link
Contributor Author

kemitix commented Dec 2, 2019

Closed: Superceeded by #1068

@kemitix kemitix closed this Dec 2, 2019
@kemitix kemitix deleted the dependabot/maven/karaf.version-4.2.3 branch December 2, 2019 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants