-
Bug
-
Resolution: Fixed
-
Minor
-
2.492 (upcoming)
The Apache MINA core library has reported CVE-2024-52046, an issue for MINA users that use ioBuffer.getObject(). Jenkins is not affected by the issue, but software composition analysis tools will report it as a vulnerability and we'll spend time explaining that Jenkins is not vulnerable.
Let's backport the change from PR-10096 to the stable-2.479 line so that it can be part of Jenkins 2.479.3
This is an exception to the policy that we only backport to an LTS after a change has been merged to the Jenkins weekly release. I think this exception should be approved so that we reduce the amount of time that the Jenkins security team must spend explaining that Jenkins is not vulnerable to this issue. It is simpler to include the updated library plugin than to spend time during January to explain why this is not an issue.
timja and wfollonier should probably both confirm that they approve this exception, either through this issue report or in the backporting pull request.
krisstern I can provide the backporting pull request.