Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY-2394] Prevent XXE #205

Merged
merged 1 commit into from Apr 7, 2022
Merged

Conversation

a-st
Copy link
Contributor

@a-st a-st commented Apr 7, 2022

Potential fix for XXE vulnerability in Performance Plugin (SECURITY-2394 / CVE-2021-21701)

@artem-fedorov artem-fedorov merged commit b0b4e74 into jenkinsci:master Apr 7, 2022
@michal-sujkowski
Copy link

@artem-fedorov When do you plan to make a release with that fix?

@rpionke
Copy link
Member

rpionke commented Jul 1, 2022

@daniel-beck can you file a release to get this security fix released?

@daniel-beck
Copy link
Member

I am not a maintainer, never have been.

@rpionke
Copy link
Member

rpionke commented Jul 4, 2022

I know, but you created a security fix related release in the past. So i thought you can do it again.

@michal-sujkowski
Copy link

Any update on releasing this?

@zdenek-jonas
Copy link

I am waiting for the release too. Please do it.

@msymons
Copy link

msymons commented Jul 26, 2022

A JIRA issue has been logged requesting that this fix be released... JENKINS-69026

@gonchik
Copy link

gonchik commented Aug 8, 2022

+1
I am waiting for the release too. Please do it.

@faandg
Copy link

faandg commented Dec 26, 2022

@basil this CVE was patched 8 months ago but people are still waiting for a release...
Is this something you can do please? Or notify someone who can?

@basil
Copy link
Member

basil commented Dec 26, 2022

I am not a maintainer of this plugin. See this page.

@NathanAZaks
Copy link

@artem-fedorov @manolo Hi Artem and Manuel, I saw you were maintainers on Jenkins.io. Could you please create a new release for this which includes the XXE fix? Thanks!

@msymons
Copy link

msymons commented Feb 5, 2023

@a-st , thank you very much for talking care of the release that addreses the vulnerability. However, as I have documented on JENKINS-69026, Jenkins is still warning that the vulnerability is still present.

SECURITY-2394-Still=alerting

@a-st
Copy link
Contributor Author

a-st commented Feb 5, 2023

@msymons You're welcome! There's a PR pending (jenkins-infra/update-center2#683) which will take care of removing the warning.

@a-st a-st deleted the SECURITY-2394 branch February 6, 2023 07:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet