Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.java > #12322

Re: libspring-java support

Path csiph.com!newsfeed.xs4all.nl!newsfeed9.news.xs4all.nl!bofh.it!news.nic.it!robomod
From Markus Koschany <apo@debian.org>
Newsgroups linux.debian.maint.java
Subject Re: libspring-java support
Date Sat, 04 Dec 2021 00:00:02 +0100
Message-ID <DqpH3-1cX-3@gated-at.bofh.it> (permalink)
References <DqpH4-1cX-5@gated-at.bofh.it>
X-Original-To Sylvain Beucler <beuc@beuc.net>, Debian LTS <debian-lts@lists.debian.org>
X-Mailbox-Line From debian-java-request@lists.debian.org Fri Dec 3 22:50:50 2021
Old-Return-Path <apo@debian.org>
X-Amavis-Spam-Status No, score=-11.263 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, FOURLA=0.1, LDO_WHITELIST=-5, PGPSIGNATURE=-5, SARE_MSGID_LONG40=0.637] autolearn=unavailable autolearn_force=no
X-Policyd-Weight using cached result; rate: -4.6
Content-Type multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="=-Sw7QzVv422EkrncAyaHA"
MIME-Version 1.0
Authentication-Results ORIGINATING; auth=pass smtp.auth=apo@gambaru.de smtp.mailfrom=apo@debian.org
X-Mailing-List <debian-java@lists.debian.org> archive/latest/22953
List-ID <debian-java.lists.debian.org>
List-URL <https://lists.debian.org/debian-java/>
List-Archive https://lists.debian.org/msgid-search/f588e081494c592ece8912dc5e62420fe5d9f941.camel@debian.org
Approved robomod@news.nic.it
Lines 94
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Cc debian-java <debian-java@lists.debian.org>
X-Original-Date Fri, 03 Dec 2021 23:50:32 +0100
X-Original-Message-ID <f588e081494c592ece8912dc5e62420fe5d9f941.camel@debian.org>
X-Original-References <e00e8e48-b76e-4982-897e-a4a317974b82@beuc.net>
Xref csiph.com linux.debian.maint.java:12322

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi Sylvain,

Am Freitag, dem 03.12.2021 um 14:28 +0100 schrieb Sylvain Beucler:
> Hi,
> 
> This year I worked on libspring-java twice for LTS&ELTS. In both case 
> upstream provided limited information for the CVEs, and for 5 of them 
> we're unable to determine the fixes.
> https://deb.freexian.com/extended-lts/tracker/source-package/libspring-java
> 
> Upstream declined to provide information to identify the fixes (which in 
> turn would allow us to determine whether stretch and jessie are 
> affected, and backport the fixes if needed).
> https://github.com/spring-projects/spring-framework/issues/26821
> https://github.com/spring-projects/spring-framework/issues/27647
> 
> They made clear that they wouldn't provide this information even if 
> paid, confirming they apply a security-by-obscurity strategy similar to 
> Oracle's.
> 
> I exchanged with the Debian security team after they witnessed the last 
> exchanges above, and 2 weeks ago they concluded the latest CVE was minor 
> and no action was needed right now. I insisted about the other, prior 
> unfixable CVEs (1/4 impacting buster) but they haven't answered yet.
> 
> I think we're not in capacity to offer further security support for 
> libspring-java for LTS and ELTS, but I'd like to hear from other team 
> members, especially if they work in the Java team (Markus?) - what do 
> you think?
> 
> Cheers!
> Sylvain Beucler
> Debian LTS Team
> 

I have made similar experiences like you when I contacted upstream and asked
for more information about previous CVE. I agree with you that their policy
makes future security support for us nearly impossible. Currently the main
purpose of libspring-java is to build other software from source. We don't ship
any application or web project that depends on Spring and exposes users to the
currently unfixed CVE which means the current status of all CVE in
Stretch/Buster/Bullseye (no-dsa/minor) is correct. It is also very unlikely
that Java developers who use Spring/Spring Boot for their web applications
depend on one of our Debian packages. 

In my opinion it is OK to ignore the currently known CVE. I would support
adding libspring-java to the list of unsupported packages because of the lack
of upstream support. We, as the Java team, should make this clear by mentioning
libspring-java in the next release notes for Debian 12.

Regards,

Markus

Back to linux.debian.maint.java | Previous | NextNext in thread | Find similar


Thread

Re: libspring-java support Markus Koschany <apo@debian.org> - 2021-12-04 00:00 +0100
  Re: libspring-java support Sylvain Beucler <beuc@beuc.net> - 2022-04-01 12:10 +0200
    Re: libspring-java support Holger Levsen <holger@layer-acht.org> - 2022-04-02 14:40 +0200
  Re: libspring-java support Emilio Pozuelo Monfort <pochu@debian.org> - 2022-04-01 12:10 +0200

csiph-web