Skip to content

Patch Ecoscanner CVEs (jackson-databind, commons-io) - cut 1.0.5.2 - #51

Merged
agrasth merged 1 commit into
bamboo-9.xfrom
bamboo-9.x-fix-cves
Aug 18, 2026
Merged

agrasth merged 1 commit into
bamboo-9.xfrom
bamboo-9.x-fix-cves

Conversation

@agrasth

@agrasth agrasth commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Summary

Patches three Atlassian Ecoscanner-flagged vulnerabilities in the bundled dependency tree of 1.0.5.1. All three are P2-Severe with an Atlassian-imposed remediation date of Nov 6, 2026 (AMS-62407 / AMS-62408 / AMS-62409). Bumps plugin version to 1.0.5.2.

CVEs addressed

CVE Package From To Notes
CVE-2026-54512 (GHSA-j3rv-43j4-c7qm) jackson-databind 2.17.2 2.18.8 PolymorphicTypeValidator bypass via generic type parameters
CVE-2026-54513 (GHSA-rmj7-2vxq-3g9f) jackson-databind 2.17.2 2.18.8 array subtype allowlist bypass in BasicPolymorphicTypeValidator
CVE-2024-47554 (GHSA-78wr-2p64-hpwj) commons-io 2.11.0 (bundled transitively) not bundled; runtime uses Bamboo's commons-io-2.15.1 XmlStreamReader DoS

Changes

  • Bump jackson-core, jackson-databind from 2.17.2 → 2.18.8 in pom.xml (direct deps).
  • Add explicit jackson-annotations at 2.18.8 — the transitive 2.14.1 was version-skewed against the 2.17.2 core/databind.
  • Exclude commons-io from the four build-info-* / file-specs-java transitive edges — AMPS's banned-dependencies enforcer forbids bundling it, and Bamboo 9.6.x ships commons-io-2.15.1 in the runtime classpath.
  • Bump plugin version to 1.0.5.2.

Verification

  • mvn clean test package — 9/9 tests passing, validate-banned-dependencies passes.
  • Bundled META-INF/lib/ inspected — jackson-core-2.18.8.jar, jackson-databind-2.18.8.jar, jackson-annotations-2.18.8.jar, no commons-io-*.jar present.
  • Bamboo 9.6.13 confirmed to ship commons-io-2.15.1 in WEB-INF/lib, so runtime resolution works.
  • Re-upload to Marketplace after merge — vulnerability tickets should auto-close on next Ecoscanner pass.

Base branch

Targets bamboo-9.x (the 9.x maintenance line). Not applicable to main — that already scopes Jackson as provided, and commons-io transitives are provided there too, so those CVEs don't apply to the 10.x line's bundled artifact.

Bump the compile-scope Jackson stack to 2.18.8 (jackson-core,
jackson-databind, jackson-annotations) to close both PolymorphicTypeValidator
bypass CVEs flagged by Atlassian Ecoscanner:

  - jackson-databind@2.17.2 -> CVE-2026-54512 (GHSA-j3rv-43j4-c7qm)
    PolymorphicTypeValidator bypass via generic type parameters
  - jackson-databind@2.17.2 -> CVE-2026-54513 (GHSA-rmj7-2vxq-3g9f)
    array subtype allowlist bypass in BasicPolymorphicTypeValidator
    Both fixed in jackson-databind 2.18.8.

Also pin jackson-annotations at 2.18.8; the transitive 2.14.1 was
version-skewed against the 2.17.2 core/databind.

For CVE-2024-47554 (Apache Commons IO XmlStreamReader DoS), the
vulnerable commons-io 2.11.0 came in transitively through build-info-*.
Bamboo 9.6.x ships commons-io 2.15.1 (post-fix) in the runtime
classpath, and AMPS's banned-dependencies enforcer bans commons-io
from plugin bundles for exactly this reason. Excluding it from the
build-info-* transitive graph so the runtime version is used.

Version bumped to 1.0.5.2. mvn clean test: 9/9 passing.
@agrasth
agrasth force-pushed the bamboo-9.x-fix-cves branch from 03a7003 to b66311d Compare August 18, 2026 09:32
@agrasth
agrasth merged commit dc64555 into bamboo-9.x Aug 18, 2026
7 checks passed
@agrasth
agrasth deleted the bamboo-9.x-fix-cves branch August 18, 2026 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant