The library commons-io contains a vulnerability in all released versions. The correction is planned for 2.7, but unreleased yet. To prevent any issue with this library, please ensure you are not using FileNameUtils.normalize and post your analysis here.

      Ticket to follow the vulnerability:

      https://issues.apache.org/jira/browse/IO-559

      Although the plugin may not use the dependency the way it's exploitable, it's better to avoid the buggy dependency in order to:

      Thank you.

      by Ramón León

          [JENKINS-61511] Outdated/vulnerable dependency (commons-io)

          Don McCasland added a comment -

          Don McCasland added a comment - https://github.com/jenkinsci/google-storage-plugin/pull/113

          Thanks donmccasland - Do we have a timeline for release?

          Jeremy Hartley added a comment - Thanks donmccasland - Do we have a timeline for release?

            donmccasland Don McCasland
            foundation_security_members CloudBees Foundation Security
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: