Log4J exploit in XRay-Jenkins Plugin

CQ December 13, 2021

Hello team.

How exposed is the plugin and does it need to be patched?   Our team disabled it to prevent problems over the weekend, but would be great to know if we can re-enable it.

 

Thanks

Chris

2 answers

1 accepted

0 votes
Answer accepted
Rogério Paiva - Xray Xporter
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 17, 2021

Hi @CQ and @Jeff Smith 

The Jenkins plugin has been updated to remove the vulnerability and those updates are now available as follows:
  • Xray for JIRA Jenkins Plugin
    Available on the Jenkins Plugin Manager
    Instructions

 Please check the full information here.

Thank you.

Kind regards,
Rogerio Paiva [Xray Support Team]

Jeff Smith December 20, 2021

Hi Rogerio,

I appreciate the response and letting us know about the update. However, it has come to our attention that there are also log4j vulnerabilities with version 2.16 and that 2.17 is now available. Have you investigated whether or not the plugin needs another log4j update?

Regards,

Jeff

Jeff Smith December 20, 2021

Hi again Rogerio,

I just found my answer here: https://github.com/jenkinsci/xray-connector-plugin/issues/57

The new plugin (2.5.3) was released a few hours ago.

Thanks again,

Jeff

0 votes
Jeff Smith December 15, 2021

We are also interested in knowing when this will be patched.

 

Jeff Smith

Systems/QA Engineer 

MedImpact Inc

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events