Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

org.apache.commons.jxpath_1.3.0.v200911051830.jar (Apache Commons JXPath Vulnerability) #291

Closed
akapoor12 opened this issue Dec 8, 2022 · 4 comments

Comments

@akapoor12
Copy link

As we know there is already CVE assigned to this issue.

CVE-2022-41852: Apache Commons JXPatch is vulnerable to a remote code execution attack.

I would like to know when we can expect new JAR from eclipse side to resolve this CVE reported globally.

Thanks
Akash

@mickaelistria
Copy link
Contributor

I don't think any of the contributors is working on this topic and is likely to fix it soon. Some ideas have been discussed (mainly eclipse-platform/eclipse.platform.ui#423 ), but the chance of seeing those implemented soon are relatively low. Moreover, independently of Eclipse project, the JXPath project itself doesn't seem to have released a fix for that CVE; so there is no available easy fix path.
Do you think you could contribute a fix?

@merks
Copy link
Contributor

merks commented Dec 9, 2022

Here it is marked as rejected:

https://nvd.nist.gov/vuln/detail/CVE-2022-41852

If the following produces a new version, we will use that:

apache/commons-jxpath#26

That would be the place to ask "when can we expect a new jar"?

Given that this library is used purely to access the workbench model representation, there is no actual risk of it using arbitrary XPaths from an untrusted source.

@HannesWell
Copy link
Member

Duplicate of eclipse-platform/eclipse.platform.ui#423

@HannesWell
Copy link
Member

Let's close this as this is a duplicate and continue any discussion in eclipse-platform/eclipse.platform.ui#423.

@HannesWell HannesWell closed this as not planned Won't fix, can't repro, duplicate, stale Sep 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants