Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update org.dom4j in kettle-core and kettle-engine (v2.1.1 has critical vulnerability) #5570

Closed
mariusssi opened this issue Mar 30, 2024 · 2 comments

Comments

@mariusssi
Copy link

mariusssi commented Mar 30, 2024

dom4j is still version 2.1.1 in both the engine and core packages. And this has a critical CVE, CVE-2020-10683 , we need to fix.
Could you please upgrade to 2.1.3 or 2.1.4 ?
Actually in pom there's no explicit version set when included, so I couldn't find where it comes from.
I did try to force the version with reuploading the changed poms and jars of core+engine in my own repo, but it didn't work, I still got 2.1.1 in it.

Affects latest 9.3 and 9.5 too: 9.3.0.6-786, 9.5.2.0-273

@mariusssi mariusssi changed the title Update dom4jin kettle-core and kettle-engine ( 2.1.1 has critical vulnerability) Update org.dom4j in kettle-core and kettle-engine (v2.1.1 has critical vulnerability) Mar 30, 2024
@mariusssi
Copy link
Author

mariusssi commented Mar 30, 2024

If upgrade is not possible, there is a mitigation mentioned in that CVE page, I believe like this: https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
Please clarify if this is already done, this file looks promising. Comes from PPP-3506

@smmribeiro
Copy link
Contributor

smmribeiro commented Feb 3, 2025

Thank you @mariusssi.
I'm closing this issue as the dom4j upgrade from 2.1.1 to 2.1.4 was done under PPP-4538. This change was made available as part of our 10.1 release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants