You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@ignite.apache.org by "Ignite TC Bot (Jira)" <ji...@apache.org> on 2021/12/21 08:58:00 UTC
[jira] [Commented] (IGNITE-13464) Ignite-rest-http includes vulnerable dependencies
[ https://issues.apache.org/jira/browse/IGNITE-13464?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17463072#comment-17463072 ]
Ignite TC Bot commented on IGNITE-13464:
----------------------------------------
{panel:title=Branch: [pull/9676/head] Base: [master] : No blockers found!|borderStyle=dashed|borderColor=#ccc|titleBGColor=#D6F7C1}{panel}
{panel:title=Branch: [pull/9676/head] Base: [master] : No new tests found!|borderStyle=dashed|borderColor=#ccc|titleBGColor=#F7D6C1}{panel}
[TeamCity *--> Run :: All* Results|https://ci2.ignite.apache.org/viewLog.html?buildId=6240843&buildTypeId=IgniteTests24Java8_RunAll]
> Ignite-rest-http includes vulnerable dependencies
> -------------------------------------------------
>
> Key: IGNITE-13464
> URL: https://issues.apache.org/jira/browse/IGNITE-13464
> Project: Ignite
> Issue Type: Bug
> Components: rest
> Affects Versions: 2.9, 2.8.1
> Reporter: Stephen Darlington
> Assignee: Sergei Ryzhov
> Priority: Blocker
> Fix For: 2.12
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The ignite-rest-http module includes a [vulnerable version|https://nvd.nist.gov/vuln/detail/CVE-2019-17571] of the log4j library. It also appears to include slf4j. Why does the REST API include its own logging libraries?
> This was spotted in 2.8.1 but still appears to be an issue in master and 2.9.
> More here:
> http://apache-ignite-users.70518.x6.nabble.com/critical-security-vulnerability-for-opt-ignite-apache-ignite-libs-optional-ignite-rest-http-log4j-1-r-td34031.html
--
This message was sent by Atlassian Jira
(v8.20.1#820001)