Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-5303

Upgrade Acegi Security to the latest Spring Security release

    • Icon: Task Task
    • Resolution: Fixed
    • Icon: Blocker Blocker
    • core
    • 2.266

      Please upgrade Acegi Security to the latest Spring Security release. Acegi Security it's old and deprecated.

          [JENKINS-5303] Upgrade Acegi Security to the latest Spring Security release

          nicusorb created issue -

          Alan Harder added a comment -

          FYI, as per this discussion such an upgrade was rejected by Kohsuke. The work done towards this upgrade was archived here:
          https://svn.dev.java.net/svn/hudson/branches/springframework2
          Likely only if lots of people vote for this issue will an upgrade be done.

          Alan Harder added a comment - FYI, as per this discussion such an upgrade was rejected by Kohsuke. The work done towards this upgrade was archived here: https://svn.dev.java.net/svn/hudson/branches/springframework2 Likely only if lots of people vote for this issue will an upgrade be done.
          Alan Harder made changes -
          Component/s New: security [ 15508 ]
          Jesse Glick made changes -
          Link New: This issue is blocking JENKINS-14520 [ JENKINS-14520 ]
          Kanstantsin Shautsou made changes -
          Assignee New: Kohsuke Kawaguchi [ kohsuke ]
          Oleg Nenashev made changes -
          Component/s New: core [ 15593 ]
          Component/s Original: security [ 15508 ]
          Labels New: security

          Rob Winch added a comment -

          Acegi Security's last commit was over 7 years ago. There have been many CVE's reported and fixed within the maintained versions of Spring Security. For this reason I believe this issue should be considered a high priority.

          Note that it appears that the Hudson team has already updated to Spring Security 3.2.x.

          Rob Winch added a comment - Acegi Security's last commit was over 7 years ago. There have been many CVE's reported and fixed within the maintained versions of Spring Security. For this reason I believe this issue should be considered a high priority. Note that it appears that the Hudson team has already updated to Spring Security 3.2.x.
          Kanstantsin Shautsou made changes -
          Labels Original: security New: 2.0 security
          Kanstantsin Shautsou made changes -
          Priority Original: Major [ 3 ] New: Blocker [ 1 ]

          In 2015 it's Blocker. Jenkins ships acegi-security released in 2008.

          Kanstantsin Shautsou added a comment - In 2015 it's Blocker. Jenkins ships acegi-security released in 2008.

            jglick Jesse Glick
            nicusorb nicusorb
            Votes:
            22 Vote for this issue
            Watchers:
            21 Start watching this issue

              Created:
              Updated:
              Resolved: