-
Component Upgrade
-
Resolution: Done
-
Major
-
None
-
None
-
Undefined
Pick up the fix to https://nvd.nist.gov/vuln/detail/CVE-2021-30129
I haven't carefully looked at the CVE but at a glance it doesn't sound particularly relevant to WildFly's use of MINA SSHD. But it's High Severity in general so it's good to eliminate component versions with such things.
Unfortunately local testing shows a simple update fails because our JGit integration is not compatible. We need a JGit release with https://bugs.eclipse.org/bugs/show_bug.cgi?id=574220 fixed.
I don't know if Elytron testing or testing of the upgrade in full WF would show other issues.
Changes in 2.7.0: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310849&version=12349400
- is cloned by
-
JBEAP-22493 (7.4.z) Upgrade Apache MINA SSHD from 2.4.0.redhat-00001 to 2.7.0.redhat-00001 (fixes CVE-2021-30129)
- Closed
-
JBEAP-22494 (7.4.z) Upgrade eclipse jgit from 5.10.0.202012080955-r-redhat-00001 to 5.13.0.202109080827-r-redhat-00001
- Closed
- is duplicated by
-
WFLY-15196 Request to update org.apache.sshd:sshd-* to 2.7.0 to eliminate CVE-2021-30129
- Resolved
- relates to
-
ELY-2200 Update org.apache.sshd:sshd-common:2.3.0 to 2.7.0 to eliminate CVE-2021-30129
- Resolved