Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1304-1

Опубликовано: 16 апр. 2024
Источник: suse-cvrf

Описание

Security update for eclipse, maven-surefire, tycho

This update for eclipse, maven-surefire, tycho fixes the following issues:

eclipse received the following security fix:

  • CVE-2023-4218: Fixed a bug where parsing files with xml content laeds to XXE attacks. (bsc#1216992)

maven-sunfire was updated from version 2.22.0 to 2.22.2:

  • Changes in version 2.22.2:

    • Bugs fixed:

      • Fixed JUnit Runner that writes to System.out corrupts Surefire’s STDOUT when using JUnit’s Vintage Engine
  • Changes in version 2.22.1:

    • Bugs fixed:

      • Fixed Surefire unable to run testng suites in parallel
      • Fixed Git wrongly considering PNG files as changed when there is no change
      • Fixed the surefire XSD published on maven site lacking of some rerun element
      • Fixed XML Report elements rerunError, rerunFailure, flakyFailure, flakyError
      • Fixed overriding platform version through project/plugin dependencies
      • Fixed mixed up characters in standard output
      • Logs in Parallel Tests are mixed up when forkMode=never or forkCount=0
      • MIME type for javascript is now officially application/javascript
    • Improvements:

      • Elapsed time in XML Report should satisfy pattern in XSD.
      • Fix old test resources TEST-*.xml in favor of continuing with SUREFIRE-1550
      • Nil element “failureMessage” in failsafe-summary.xml should have self closed tag
      • Removed obsolete module surefire-setup-integration-tests
      • Support Java 11
      • Surefire should support parameterized reportsDirectory
    • Dependency upgrades:

      • Upgraded maven-plugins parent to version 32
      • Upgraded maven-plugins parent to version 33

tycho received the following bug fixes:

  • Fixed build against maven-surefire 2.22.1 and newer
  • Fixed build against newer plexus-compiler
  • Fixed issues with plexus-archiver 4.4.0 and newer
  • Require explicitely artifacts that will not be required automatically any more

Список пакетов

SUSE Enterprise Storage 7.1
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Module for Development Tools 15 SP5
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Module for Package Hub 15 SP5
eclipse-contributor-tools-4.15-150200.4.16.4
eclipse-emf-core-2.22.0-150200.4.9.3
eclipse-emf-core-bootstrap-2.22.0-150200.4.9.3
eclipse-equinox-osgi-4.15-150200.4.16.4
eclipse-equinox-osgi-bootstrap-4.15-150200.4.16.5
eclipse-pde-4.15-150200.4.16.4
eclipse-pde-bootstrap-4.15-150200.4.16.5
eclipse-platform-4.15-150200.4.16.4
eclipse-platform-bootstrap-4.15-150200.4.16.5
eclipse-swt-4.15-150200.4.16.4
eclipse-swt-bootstrap-4.15-150200.4.16.5
SUSE Linux Enterprise Server 15 SP2-LTSS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Server 15 SP3-LTSS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Server 15 SP4-LTSS
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
openSUSE Leap 15.5
eclipse-contributor-tools-4.15-150200.4.16.4
eclipse-emf-core-2.22.0-150200.4.9.3
eclipse-emf-core-bootstrap-2.22.0-150200.4.9.3
eclipse-emf-runtime-2.22.0-150200.4.9.3
eclipse-emf-sdk-2.22.0-150200.4.9.3
eclipse-emf-xsd-2.22.0-150200.4.9.3
eclipse-equinox-osgi-4.15-150200.4.16.4
eclipse-equinox-osgi-bootstrap-4.15-150200.4.16.5
eclipse-jdt-4.15-150200.4.16.4
eclipse-jdt-bootstrap-4.15-150200.4.16.5
eclipse-p2-discovery-4.15-150200.4.16.4
eclipse-p2-discovery-bootstrap-4.15-150200.4.16.5
eclipse-pde-4.15-150200.4.16.4
eclipse-pde-bootstrap-4.15-150200.4.16.5
eclipse-platform-4.15-150200.4.16.4
eclipse-platform-bootstrap-4.15-150200.4.16.5
eclipse-swt-4.15-150200.4.16.4
eclipse-swt-bootstrap-4.15-150200.4.16.5
maven-failsafe-plugin-2.22.2-150200.3.9.9.1
maven-failsafe-plugin-bootstrap-2.22.2-150200.3.9.9.1
maven-surefire-2.22.2-150200.3.9.9.1
maven-surefire-javadoc-2.22.2-150200.3.9.9.1
maven-surefire-plugin-2.22.2-150200.3.9.9.1
maven-surefire-plugin-bootstrap-2.22.2-150200.3.9.9.1
maven-surefire-plugins-javadoc-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit5-2.22.2-150200.3.9.9.1
maven-surefire-provider-junit5-javadoc-2.22.2-150200.3.9.9.1
maven-surefire-provider-testng-2.22.2-150200.3.9.9.1
maven-surefire-report-parser-2.22.2-150200.3.9.9.1
maven-surefire-report-plugin-2.22.2-150200.3.9.9.1
maven-surefire-report-plugin-bootstrap-2.22.2-150200.3.9.9.1
tycho-1.6.0-150200.4.9.5
tycho-bootstrap-1.6.0-150200.4.9.2
tycho-javadoc-1.6.0-150200.4.9.5

Описание

In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).


Затронутые продукты
SUSE Enterprise Storage 7.1:maven-surefire-2.22.2-150200.3.9.9.1
SUSE Enterprise Storage 7.1:maven-surefire-plugin-2.22.2-150200.3.9.9.1
SUSE Enterprise Storage 7.1:maven-surefire-provider-junit-2.22.2-150200.3.9.9.1
SUSE Enterprise Storage 7.1:maven-surefire-provider-testng-2.22.2-150200.3.9.9.1

Ссылки
Уязвимость SUSE-SU-2024:1304-1