audit-log-plugin icon indicating copy to clipboard operation
audit-log-plugin copied to clipboard

New plugin release with log4j v2.17.1

Open DemiurgeKH3 opened this issue 3 years ago • 11 comments

Hello, is it possible to generate a new version for audit-log plugin which uses log4j v2.17.1 because of this CVE: CVE-2021-45105 ?

DemiurgeKH3 avatar Jan 05 '22 07:01 DemiurgeKH3

@daniel-beck can you use your superpowers again? I haven't gotten around to enabling CD here yet.

jvz avatar Jan 05 '22 22:01 jvz

Sorry, that's quite a bit of hassle to not mess up accidentally, and IIUC the new vulnerability is far less severe (and in fact fairly unlikely to be exploitable anywhere). I think you're just a password reset away from being able to release yourself?

daniel-beck avatar Jan 05 '22 23:01 daniel-beck

I already reset my password. Back when I tried to release from Maven, I got 403 errors or something like that. I could try again at some point, though. And you're right, the latest CVEs aren't even really applicable to this plugin.

jvz avatar Jan 06 '22 00:01 jvz

If a snapshot deploy works, authentication works. What's left is confirming coordinates and user name in https://github.com/jenkins-infra/repository-permissions-updater/blob/master/permissions/plugin-audit-log.yml are correct (and a mismatch in the former wouldn't allow CD either).

daniel-beck avatar Jan 06 '22 14:01 daniel-beck

Any news on the release of the version of audit log ?

DemiurgeKH3 avatar Jan 12 '22 07:01 DemiurgeKH3

@daniel-beck @jvz Any news on the release of the version of audit log ?

DemiurgeKH3 avatar Jan 27 '22 11:01 DemiurgeKH3

I haven't had a chance to reset my deployment settings yet.

jvz avatar Jan 27 '22 20:01 jvz

I'm waiting too :) https://github.com/jenkinsci/audit-log-plugin/pull/87/commits/37efd33bb1af9f836c56c18f4388b3ebbcdc6774

sunilkhokalay avatar Mar 11 '22 11:03 sunilkhokalay

Hi, Any idea when this is going to get fixed ?

smarlaku820 avatar Aug 24 '22 17:08 smarlaku820

@daniel-beck @jvz any news about that ticket ? When a Nessus scan is done on a machine where Jenkins is installed with this plugin, an error is raised because the plugin uses log4j v2.16.0. v2.17.1 is needed now

DemiurgeKH3 avatar Dec 16 '22 13:12 DemiurgeKH3

Waiting for this update.

amrithdas avatar Mar 15 '24 16:03 amrithdas