Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0052255Openbravo ERPA. Platformpublic2023-04-26 13:342023-11-21 09:13
kousalya_r 
kousalya_r 
normalmajorhave not tried
closedno change required 
5
 
 
Core
No
0052255: Request to provide valid version for jettison-1.3-patched.jar
Please provide us a valid version to replace the jar jettison-1.3-patched.jar that China has reported the vulnerability.
China has requested version 1.5.4
No tags attached.
depends on design defect 0037151 acknowledged Triage Platform Base upgrade/replace JSON library 
depends on defect 0037135 closed alostale OOM parsing corrupted JSON 
Not all the children of this issue are yet resolved or closed.
Issue History
2023-04-26 13:34kousalya_rNew Issue
2023-04-26 13:34kousalya_rAssigned To => Triage Platform Base
2023-04-26 13:34kousalya_rModules => Core
2023-04-26 13:34kousalya_rTriggers an Emergency Pack => No
2023-04-26 13:35kousalya_rSummaryjettison-1.3-patched.jar => Request to provide valid version for jettison-1.3-patched.jar
2023-04-26 13:37kousalya_rDescription Updatedbug_revision_view_page.php?rev_id=25964#r25964
2023-04-26 13:38kousalya_rRelationship addeddepends on 0037151
2023-04-26 13:39kousalya_rRelationship addeddepends on 0037135
2023-04-26 13:41kousalya_rSteps to Reproduce Updatedbug_revision_view_page.php?rev_id=25966#r25966
2023-05-15 11:08AugustoMauchAssigned ToTriage Platform Base => kousalya_r
2023-05-15 11:08AugustoMauchStatusnew => feedback
2023-11-20 17:41AugustoMauchNote Added: 0157374
2023-11-21 09:13AugustoMauchNote Added: 0157398
2023-11-21 09:13AugustoMauchStatusfeedback => closed
2023-11-21 09:13AugustoMauchResolutionopen => no change required

Notes
(0157374)
AugustoMauch   
2023-11-20 17:41   
Kousalya, that upgrade of that library is very complex, see [1]. Could you share with me via chat the details of the vulnerability? To see if we are really exposed to it, and if so, if there are other ways of avoiding the vulnerability other than upgrading the library.

[1] https://issues.openbravo.com/view.php?id=51132 [^]
(0157398)
AugustoMauch   
2023-11-21 09:13   
It has been confirmed that the current version does not have the vulnerability that the client was concerned about