Anonymous | Login
Project:
RSS
  
News | My View | View Issues | Roadmap | Summary

View Issue DetailsJump to Notes ] Issue History ] Print ]
ID
0049251
TypeCategorySeverityReproducibilityDate SubmittedLast Update
defect[Retail Modules] Web POS Hardware Managermajorhave not tried2022-05-06 13:482022-05-25 10:20
ReporteradrianromeroView Statuspublic 
Assigned Tojonae 
PriorityhighResolutionfixedFixed in Version
StatusclosedFix in branchFixed in SCM revision
ProjectionnoneETAnoneTarget Version
OSAnyDatabaseAnyJava version
OS VersionDatabase versionAnt version
Product VersionSCM revision 
Merge Request Statusapproved
Review Assigned To
OBNetwork customerOBPS
Support ticket
Regression level
Regression date
Regression introduced in release
Regression introduced by commit
Triggers an Emergency PackNo
Summary

0049251: Security issue in lib4j dependency in Ingenico Oman payment integration plugin

DescriptionThe hardware manager plugin for the Ingenico Oman payment plugin uses old library versions that have important security issues

https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/tree/master/lib [^]

* log4j-api
* log4j-core
* commons-lang
* jscc

All these versions must be upgraded to the latest available version. This upgrade must be done in coordination with the integration provider as they are libraries that depends on the integration provider library. It is not a direct Openbravo dependency.

Also a new /legal folder must be included with all the licence details of the third party libraries.
Steps To ReproduceIn description
TagsNo tags attached.
Attached Files

- Relationships Relation Graph ] Dependency Graph ]

-  Notes
(0137670)
hgbot (developer)
2022-05-24 10:11

Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137671)
hgbot (developer)
2022-05-24 10:11

Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137690)
hgbot (developer)
2022-05-24 22:40

Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137691)
hgbot (developer)
2022-05-24 22:40

Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/4 [^]
(0137692)
hgbot (developer)
2022-05-24 22:44

Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137693)
hgbot (developer)
2022-05-24 22:44

Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137694)
hgbot (developer)
2022-05-24 22:47

Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137695)
hgbot (developer)
2022-05-24 22:47

Merge request closed: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/5 [^]
(0137711)
hgbot (developer)
2022-05-25 09:48

Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137712)
hgbot (developer)
2022-05-25 09:48

Merge Request created: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137715)
hgbot (developer)
2022-05-25 10:20

Directly closing issue as related merge request is already approved.

Repository: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman [^]
Changeset: 4dd8ba119b9d399034bfc361c282ba28be5ac5b8
Author: Jon Alegría <jon.alegria@openbravo.com>
Date: 25-05-2022 08:20:50
URL: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/commit/4dd8ba119b9d399034bfc361c282ba28be5ac5b8 [^]

Fixes ISSUE-49251: Adding new libraries fixing the security issues in log4j. Adding license text.

---
A legal/Licensing.txt
A lib/commons-lang3-3.12.0.jar
A lib/jssc-2.9.4.jar
A lib/log4j-api-2.17.2.jar
A lib/log4j-core-2.17.2.jar
A lib/slf4j-simple-1.7.25.jar
M lib/SgInterfaceLibrary.jar
M lib/SgSyncEcrInterfaceLibrary.jar
R lib/commons-lang3-3.6.jar
R lib/jssc-2.8.0.jar
R lib/log4j-api-2.13.3.jar
R lib/log4j-core-2.13.3.jar
---
(0137716)
hgbot (developer)
2022-05-25 10:20

Merge request merged: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137717)
hgbot (developer)
2022-05-25 10:20

Merge request merged: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/merge_requests/7 [^]
(0137718)
hgbot (developer)
2022-05-25 10:20

Directly closing issue as related merge request is already approved.

Repository: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman [^]
Changeset: 4dd8ba119b9d399034bfc361c282ba28be5ac5b8
Author: Jon Alegría <jon.alegria@openbravo.com>
Date: 25-05-2022 08:20:50
URL: https://gitlab.com/openbravo/product/pmods/hwmanager-ingenicooman/-/commit/4dd8ba119b9d399034bfc361c282ba28be5ac5b8 [^]

Fixes ISSUE-49251: Adding new libraries fixing the security issues in log4j. Adding license text.

---
A legal/Licensing.txt
A lib/commons-lang3-3.12.0.jar
A lib/jssc-2.9.4.jar
A lib/log4j-api-2.17.2.jar
A lib/log4j-core-2.17.2.jar
A lib/slf4j-simple-1.7.25.jar
M lib/SgInterfaceLibrary.jar
M lib/SgSyncEcrInterfaceLibrary.jar
R lib/commons-lang3-3.6.jar
R lib/jssc-2.8.0.jar
R lib/log4j-api-2.13.3.jar
R lib/log4j-core-2.13.3.jar
---

- Issue History
Date Modified Username Field Change
2022-05-06 13:48 adrianromero New Issue
2022-05-06 13:48 adrianromero Assigned To => jonae
2022-05-06 13:48 adrianromero OBNetwork customer => OBPS
2022-05-06 13:48 adrianromero Triggers an Emergency Pack => No
2022-05-06 14:01 shuehner Issue Monitored: shuehner
2022-05-24 10:11 hgbot Merge Request Status => open
2022-05-24 10:11 hgbot Note Added: 0137670
2022-05-24 10:11 hgbot Note Added: 0137671
2022-05-24 22:40 hgbot Note Added: 0137690
2022-05-24 22:40 hgbot Note Added: 0137691
2022-05-24 22:44 hgbot Note Added: 0137692
2022-05-24 22:44 hgbot Note Added: 0137693
2022-05-24 22:47 hgbot Note Added: 0137694
2022-05-24 22:47 hgbot Note Added: 0137695
2022-05-25 09:48 hgbot Note Added: 0137711
2022-05-25 09:48 hgbot Note Added: 0137712
2022-05-25 10:20 hgbot Merge Request Status open => approved
2022-05-25 10:20 hgbot Resolution open => fixed
2022-05-25 10:20 hgbot Status new => closed
2022-05-25 10:20 hgbot Note Added: 0137715
2022-05-25 10:20 hgbot Note Added: 0137716
2022-05-25 10:20 hgbot Note Added: 0137717
2022-05-25 10:20 hgbot Note Added: 0137718


Copyright © 2000 - 2009 MantisBT Group
Powered by Mantis Bugtracker