Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update bundled Apache Mina-sshd plugins #7623

Merged
merged 2 commits into from Feb 6, 2023

Conversation

MarkEWaite
Copy link
Contributor

@MarkEWaite MarkEWaite commented Feb 3, 2023

Update sshd-common and sshd-core plugins from 2.9.1 to 2.9.2

Changelog: The Apache MINA sshd 2.9.2 changelog links to CVE-2022-45047 - Unsafe deserialization in SimpleGeneratorHostKeyProvider

Jenkins core does not reference the SimpleGeneratorHostKeyProvider class.

SimpleGeneratorHostKeyProvider is referenced from sshd plugin

Users can upgrade the plugin themselves during installation but it is easier if we bundle the updated plugin version with new releases rather than requiring that the user perform the update.

See JENKINS-70554.

Testing done

  • Confirmed that the Jenkins 2.389 war file includes mina-sshd-api-common.hpi and mina-sshd-api-core.hpi 2.9.1-44.v476733c11f82
  • Generated the war file and confirmed that mina-sshd-api-common.hpi and mina-sshd-api-core.hpi 2.9.2-50.va_0e1f42659a_a are included
  • Ran the war file with mvn -pl war -Dhost=0.0.0.0 jetty:run and confirmed the Apache Mina SSHD plugins were not installed but were offered for install as 2.9.2-50.va_0e1f42659a_a

Proposed changelog entries

  • Update bundled Apache Mina SSHD API plugins from 2.9.1-44.v476733c11f82 to 2.9.2-50.va_0e1f42659a_a.
    Include fix for CVE-2022-45047 - Unsafe deserialization in SimpleGeneratorHostKeyProvider.

Proposed upgrade guidelines

N/A

Submitter checklist

  • The Jira issue, if it exists, is well-described.
  • The changelog entries and upgrade guidelines are appropriate for the audience affected by the change (users or developers, depending on the change) and are in the imperative mood (see examples).
    • Fill in the Proposed upgrade guidelines section only if there are breaking changes or changes that may require extra steps from users during upgrade.
  • There is automated testing or an explanation as to why this change has no tests.
  • New public classes, fields, and methods are annotated with @Restricted or have @since TODO Javadocs, as appropriate.
  • New deprecations are annotated with @Deprecated(since = "TODO") or @Deprecated(forRemoval = true, since = "TODO"), if applicable.
  • New or substantially changed JavaScript is not defined inline and does not call eval to ease future introduction of Content Security Policy (CSP) directives (see documentation).
  • For dependency updates, there are links to external changelogs and, if possible, full differentials.
  • For new APIs and extension points, there is a link to at least one consumer.

Desired reviewers

Maintainer checklist

Before the changes are marked as ready-for-merge:

  • There are at least two (2) approvals for the pull request and no outstanding requests for change.
  • Conversations in the pull request are over, or it is explicit that a reviewer is not blocking the change.
  • Changelog entries in the pull request title and/or Proposed changelog entries are accurate, human-readable, and in the imperative mood.
  • Proper changelog labels are set so that the changelog can be generated automatically.
  • If the change needs additional upgrade steps from users, the upgrade-guide-needed label is set and there is a Proposed upgrade guidelines section in the pull request title (see example).
  • If it would make sense to backport the change to LTS, a Jira issue must exist, be a Bug or Improvement, and be labeled as lts-candidate to be considered (see query).

Update `sshd-common` plugin and `sshd-core` plugin from
2.9.1-44.v476733c11f82 to 2.9.2-50.va_0e1f42659a_a

Changelog

https://github.com/apache/mina-sshd/blob/master/docs/changes/2.9.2.md
links to http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45047
Unsafe deserialization in SimpleGeneratorHostKeyProvider

Jenkins core does not reference the SimpleGeneratorHostKeyProvider class.

It is referenced from sshd plugin at
https://github.com/jenkinsci/sshd-plugin/blob/251d59011530b4d3a4db4a3e6ee8f076c61c3bfe/src/main/java/org/jenkinsci/main/modules/sshd/SSHD.java#L162

Users can upgrade the plugin themselves during installation but it is
easier if we bundle the updated plugin version with new releases rather
than requiring that the user perform the update.
@MarkEWaite MarkEWaite added the bug For changelog: Minor bug. Will be listed after features label Feb 3, 2023
@MarkEWaite MarkEWaite changed the title Update bundled mina-sshd plugins Update bundled Apache mina-sshd plugins Feb 3, 2023
@MarkEWaite MarkEWaite changed the title Update bundled Apache mina-sshd plugins Update bundled Apache Mina-sshd plugins Feb 3, 2023
@MarkEWaite
Copy link
Contributor Author

This PR is now ready for merge. We will merge it after approximately 24 hours if there is no negative feedback.

@MarkEWaite MarkEWaite added the ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback label Feb 6, 2023
@MarkEWaite MarkEWaite merged commit 31974d3 into jenkinsci:master Feb 6, 2023
@MarkEWaite MarkEWaite deleted the use-apache-mina-sshd-2.9.2 branch February 6, 2023 22:01
NotMyFault pushed a commit to NotMyFault/jenkins that referenced this pull request Feb 10, 2023
Embed Apache mina sshd plugins 2.9.2 (common and core)

Update `sshd-common` plugin and `sshd-core` plugin from
2.9.1-44.v476733c11f82 to 2.9.2-50.va_0e1f42659a_a

Changelog

https://github.com/apache/mina-sshd/blob/master/docs/changes/2.9.2.md
links to http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45047
Unsafe deserialization in SimpleGeneratorHostKeyProvider

Jenkins core does not reference the SimpleGeneratorHostKeyProvider class.

It is referenced from sshd plugin at
https://github.com/jenkinsci/sshd-plugin/blob/251d59011530b4d3a4db4a3e6ee8f076c61c3bfe/src/main/java/org/jenkinsci/main/modules/sshd/SSHD.java#L162

Users can upgrade the plugin themselves during installation but it is
easier if we bundle the updated plugin version with new releases rather
than requiring that the user perform the update.

(cherry picked from commit 31974d3)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug For changelog: Minor bug. Will be listed after features ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback
Projects
None yet
3 participants