Openbravo Issue Tracking System - Retail Modules
View Issue Details
0049251Retail ModulesWeb POS Hardware Managerpublic2022-05-06 13:482022-05-25 10:20
adrianromero 
jonae 
highmajorhave not tried
closedfixed 
5
 
 
approved
OBPS
No
0049251: Security issue in lib4j dependency in Ingenico Oman payment integration plugin
The hardware manager plugin for the Ingenico Oman payment plugin uses old library versions that have important security issues

https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/tree/master/lib [^]

* log4j-api
* log4j-core
* commons-lang
* jscc

All these versions must be upgraded to the latest available version. This upgrade must be done in coordination with the integration provider as they are libraries that depends on the integration provider library. It is not a direct Openbravo dependency.

Also a new /legal folder must be included with all the licence details of the third party libraries.
In description
No tags attached.
Issue History
2022-05-06 13:48adrianromeroNew Issue
2022-05-06 13:48adrianromeroAssigned To => jonae
2022-05-06 13:48adrianromeroOBNetwork customer => OBPS
2022-05-06 13:48adrianromeroTriggers an Emergency Pack => No
2022-05-06 14:01shuehnerIssue Monitored: shuehner
2022-05-24 10:11hgbotMerge Request Status => open
2022-05-24 10:11hgbotNote Added: 0137670
2022-05-24 10:11hgbotNote Added: 0137671
2022-05-24 22:40hgbotNote Added: 0137690
2022-05-24 22:40hgbotNote Added: 0137691
2022-05-24 22:44hgbotNote Added: 0137692
2022-05-24 22:44hgbotNote Added: 0137693
2022-05-24 22:47hgbotNote Added: 0137694
2022-05-24 22:47hgbotNote Added: 0137695
2022-05-25 09:48hgbotNote Added: 0137711
2022-05-25 09:48hgbotNote Added: 0137712
2022-05-25 10:20hgbotMerge Request Statusopen => approved
2022-05-25 10:20hgbotResolutionopen => fixed
2022-05-25 10:20hgbotStatusnew => closed
2022-05-25 10:20hgbotNote Added: 0137715
2022-05-25 10:20hgbotNote Added: 0137716
2022-05-25 10:20hgbotNote Added: 0137717
2022-05-25 10:20hgbotNote Added: 0137718

Notes
(0137670)
hgbot   
2022-05-24 10:11   
Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137671)
hgbot   
2022-05-24 10:11   
Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137690)
hgbot   
2022-05-24 22:40   
Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137691)
hgbot   
2022-05-24 22:40   
Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137692)
hgbot   
2022-05-24 22:44   
Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137693)
hgbot   
2022-05-24 22:44   
Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137694)
hgbot   
2022-05-24 22:47   
Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137695)
hgbot   
2022-05-24 22:47   
Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137711)
hgbot   
2022-05-25 09:48   
Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137712)
hgbot   
2022-05-25 09:48   
Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137715)
hgbot   
2022-05-25 10:20   
Directly closing issue as related merge request is already approved.

Repository: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman [^]
Changeset: 4dd8ba119b9d399034bfc361c282ba28be5ac5b8
Author: Jon Alegría <jon.alegria@openbravo.com>
Date: 25-05-2022 08:20:50
URL: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/commit/4dd8ba119b9d399034bfc361c282ba28be5ac5b8 [^]

Fixes ISSUE-49251: Adding new libraries fixing the security issues in log4j. Adding license text.

---
A legal/Licensing.txt
A lib/commons-lang3-3.12.0.jar
A lib/jssc-2.9.4.jar
A lib/log4j-api-2.17.2.jar
A lib/log4j-core-2.17.2.jar
A lib/slf4j-simple-1.7.25.jar
M lib/SgInterfaceLibrary.jar
M lib/SgSyncEcrInterfaceLibrary.jar
R lib/commons-lang3-3.6.jar
R lib/jssc-2.8.0.jar
R lib/log4j-api-2.13.3.jar
R lib/log4j-core-2.13.3.jar
---
(0137716)
hgbot   
2022-05-25 10:20   
Merge request merged: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137717)
hgbot   
2022-05-25 10:20   
Merge request merged: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137718)
hgbot   
2022-05-25 10:20   
Directly closing issue as related merge request is already approved.

Repository: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman [^]
Changeset: 4dd8ba119b9d399034bfc361c282ba28be5ac5b8
Author: Jon Alegría <jon.alegria@openbravo.com>
Date: 25-05-2022 08:20:50
URL: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/commit/4dd8ba119b9d399034bfc361c282ba28be5ac5b8 [^]

Fixes ISSUE-49251: Adding new libraries fixing the security issues in log4j. Adding license text.

---
A legal/Licensing.txt
A lib/commons-lang3-3.12.0.jar
A lib/jssc-2.9.4.jar
A lib/log4j-api-2.17.2.jar
A lib/log4j-core-2.17.2.jar
A lib/slf4j-simple-1.7.25.jar
M lib/SgInterfaceLibrary.jar
M lib/SgSyncEcrInterfaceLibrary.jar
R lib/commons-lang3-3.6.jar
R lib/jssc-2.8.0.jar
R lib/log4j-api-2.13.3.jar
R lib/log4j-core-2.13.3.jar
---