← All tasks
javaOpenFeign/feign #1389Not a task: not reproduced

Update Jackson, fix version of jackson-databind in core; update guava

envgap__OpenFeign__feign-1389

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
78b6c68373ca2a22d68cb8b73343c8e27e1ef9e0
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

OpenFeign/feign #1389 · read the original issue
* First: in `core` the `jackson-databind` dependency uses `jackson.version` instead of `jackson.databind.version`, see line 63 https://github.com/OpenFeign/feign/blob/b53a53591b7de1f2c301ad332f7b8a88a7b6fbce/core/pom.xml#L63

* Second: jackson-databind 2.10.0.pr3 has critical issue [CVE-2020-25649](https://ossindex.sonatype.org/vulnerability/f582b4ea-ef28-4d6e-93ad-15034025df21?component-type=maven&component-name=com.fasterxml.jackson.core.jackson-databind&utm_source=ossindex-client&utm_medium=integration&utm_content=1.1.1). I run `ossindex-maven-plugin` and it shows: _A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity._



I propose not only fix version of jackson-databind but increase all jackson's versions to last stable **2.12.3**. And looks like we could remove explicit `jackson.databind.version` from `core`, `jackson` and `jackson-jaxb` as it is defined in `dependencyManagement` of `parent`.



Then I have found another issue: for `guava` [CVE-2020-8908](https://ossindex.sonatype.org/vulnerability/8e973be2-4220-410d-a4cb-2de7a755bdbe?component-type=maven&component-name=com.google.guava.guava&utm_source=ossindex-client&utm_medium=integration&utm_content=1.1.1): _A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked `@Deprecated` in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured._



This issue is related `feign-hystrix`, `feign-ribbon`, `feign-apt-test-generator` and `feign-googlehttpclient`. I have update `guava` to **30.1.1-jre** in `feign-hystrix`, `feign-ribbon`, `feign-apt-test-generator`, and `google-http-client` to **1.39.2**: the build was OK.



The `ossindex-maven-plugin` has not shown any other issues.





Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]