-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
log4j dependency has critical vulnerability CVE-2021-44228 #53
Comments
@daniel-beck until when can we expect a fix? I think, this is the dependency:
|
I'm not a maintainer, you're going to have to ask them. |
jfyi: I wrote a Support-Ticket (SUPPORT-45549) for this issue. Maybe that's speed up the fix. |
Hi everyone! I'm one of the maintainers of this repository. We are aware of this issue and working on a fix. The pull request and the release will happen in the next few days, before the end of this week. We will update this thread as soon as we have any updates. |
#53 XRAYJENKINS-132 Bump version dependencies
Hi everyone, We are ready to deploy the new version as soon as the accounts.jenkins.io is back online in order for us to reset our credentials. Around 2 months ago all passwords in the Jenkins ecosystem were revoked something that I, unfortunately, didn't notice at the time. According to this thread of some other developers with the same problem, the Jenkins' security team is still investigating the impact of the log4j vulnerability. Maybe @daniel-beck may have more information regarding when they expect to have the accounts.jenkins.io operational. Meanwhile, in case you don't want to wait for the official release, you are free to manually download and install the release candidate (2.5.2) from the official Jenkins build I'm going to keep this thread open and up-to-date with the most recent information. |
@Russell616 I'll check with the infra team. |
As mentioned by @rhutchison |
I will update again the log4j dependency, I will let you all know when the new release candidate is available to be downloaded |
You can download the latest build (2.5.2.1) using log4j 2.16.0 from the Jenkins build |
Thank you for the support and quick remediation Result: (file:/C:/Program%20Files%20(x86)/Jenkins/plugins/xray-connector/WEB-INF/lib/log4j-core-2.16.0.jar ) |
@Russell616 it looks like https://accounts.jenkins.io/ is once again available. Could we get an ETA for this release? Thanks! |
(Looks like the error page gets cached so might need a reload. That's annoying. I poked infra folks about it for the future.) |
The ETA is now 😄 We just released the version 2.5.2.1 in the Jenkins maven repo. For all of you, who want to install manually the plugin, you can use the release git tag. In a few hours, the new release will be available to download in the plugins page in your own Jenkins instances (there is a delay between the time of the release and the and the time when ths version is avaible to download via UI) I will keep this issue open until we make sure that the plugin is displayed in the Jenkins index page |
Already installed in our dev environment. Thank you! |
Usually less than 5 minutes, just remember to query for updates. plugins.jenkins.io is a lot slower. |
Thanks @Russell616 ! |
See https://issues.jenkins.io/browse/JENKINS-67353
The text was updated successfully, but these errors were encountered: