Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-69026

Latest Plugins Versions having Securities Vulnerabilities issues involved

      Hello Team,

            We are using following plugins with its latest versions. But there are security vulnerabilities involved on these plugin's latest versions and there is no fix available as of now. We needed these plugins but  \We are concerned about these plugins version issues. So , can you please provide any fix on these version or please suggest how to handle this case.

      Plugins List

       

      Thanks,

      Sudhir

          [JENKINS-69026] Latest Plugins Versions having Securities Vulnerabilities issues involved

          Sudhir Nikhade created issue -
          Sudhir Nikhade made changes -
          Description Original: Hello Team,

                We are using following plugins with its latest versions. But as we can see, there are security vulnerabilities involved in these latest plugins as well. We needed these plugins but  We are concerned about these plugins versions issues. So , can you please provide any fix on these version or please suggest how to handle this case.

           

          *Plugins List:*

          global-build-stats plugin (global-build-stats): 244.v27c8a_2e50a_34

          Maven Metadata Plugin for Jenkins CI server (maven-metadata-plugin): 2.2

          Performance Plugin (performance): 3.20

          Release Helper Plugin (release-helper): 1.3.3

          build-metrics (build-metrics): 1.3

           

          Thanks,

          Sudhir
          New: Hello Team,

                We are using following plugins with its latest versions. But there are security vulnerabilities involved on these plugin's latest versions and there is no fix available as of now. We needed these plugins but  \We are concerned about these plugins version issues. So , can you please provide any fix on these version or please suggest how to handle this case.

           

          *Plugins List:*

          global-build-stats plugin (global-build-stats): 244.v27c8a_2e50a_34

          Maven Metadata Plugin for Jenkins CI server (maven-metadata-plugin): 2.2

          Performance Plugin (performance): 3.20

          Release Helper Plugin (release-helper): 1.3.3

          build-metrics (build-metrics): 1.3

           

          Thanks,

          Sudhir

          Mark Symons added a comment - - edited

          A fix for SECURITY-2394 (CVE-2021-21701) was merged on 7th April for performance-plugin and just needs to be released.

          See:  [SECURITY-2394] Prevent XXE  in Github

           

          Mark Symons added a comment - - edited A fix for SECURITY-2394 ( CVE-2021-21701 ) was merged on 7th April for performance-plugin and just needs to be released. See:   [SECURITY-2394] Prevent XXE   in Github  
          Mark Symons made changes -
          Remote Link New: This issue links to "Merged Fix for SECURITY-2394 (Web Link)" [ 28002 ]

          Jan Duris added a comment -

          Hello guys, is there a plan to release this fix in near future? A lot of people are waiting for fix of that vulnerability

          Jan Duris added a comment - Hello guys, is there a plan to release this fix in near future? A lot of people are waiting for fix of that vulnerability

          Hemanth SD added a comment -

          Hi guys, It will be great if we can get the new release with the vulnerability fix. community will use the performance trend feature which is really helpful in pipeline integration.

          Hemanth SD added a comment - Hi guys, It will be great if we can get the new release with the vulnerability fix. community will use the performance trend feature which is really helpful in pipeline integration.

          Hello , Do you have any update on it Please?

          Sudhir Nikhade added a comment - Hello , Do you have any update on it Please?
          Mark Symons made changes -
          Attachment New: SECURITY-2394-Still=alerting.png [ 59928 ]

          Mark Symons added a comment -

          Release v916.v0f63142e4c07 (3rd February 2023) incorporates the fix for SECURITY-2394

          However, on 5th February the there are still warnings displayed on jenkins site and within Jenkins itself.

          What can bedone to address this?

           

          Mark Symons added a comment - Release v916.v0f63142e4c07 (3rd February 2023) incorporates the fix for SECURITY-2394 However, on 5th February the there are still warnings displayed on jenkins site and within Jenkins itself. What can bedone to address this?  

          msymons Like mentioned in https://github.com/jenkinsci/performance-plugin/pull/205 there's a PR pending (jenkins-infra/update-center2#683) which will take care of removing the warning.

          Alexander Straube added a comment - msymons Like mentioned in https://github.com/jenkinsci/performance-plugin/pull/205 there's a PR pending ( jenkins-infra/update-center2#683 ) which will take care of removing the warning.

            ydubreuil Yoann Dubreuil
            snikhade Sudhir Nikhade
            Votes:
            5 Vote for this issue
            Watchers:
            14 Start watching this issue

              Created:
              Updated: