Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-66889

SECURITY issue - plugin contains virus!!!

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not A Defect
    • Icon: Blocker Blocker
    • durable-task-plugin
    • None
    • jenkins 3.303.2
      durable task plugin 1.39

      We are working in an air-gapped environment, in order to use plugins in our internal environment we must scan them with anti viruses.

      both BitDefender and AvAware found the following virus in the latest durable task plugin (1.39):

      Java.Trojan.GenericGBA.30673

      it is fond in the WEB-INF/lib/durable-task.jar file.

      specifically, in org/jenkinsci/plugins/durabletask/PowershellScript.class

      please fix it ASAP, as this is causing us major security problems in our network.

       

      linked to https://issues.jenkins.io/browse/SECURITY-2534

            Unassigned Unassigned
            amidar Amit Dar
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: