[ https://issues.apache.org/jira/browse/FLINK-4732?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15545403#comment-15545403 ]
ASF GitHub Bot commented on FLINK-4732: --------------------------------------- Github user mxm commented on the issue: https://github.com/apache/flink/pull/2586 Merged to `master` and `release-1.1`. @uce I also like the symbolic link. I contacted the maintainer of the plugin because it wouldn't be hard to fix this nowadays with Java 7+ which supports the creation of symbolic links. I think the lack of this was the reason why the author chose to download a binary. However, I don't know why he didn't simply ship it with the jar which should have been possible. > Maven junction plugin security threat > ------------------------------------- > > Key: FLINK-4732 > URL: https://issues.apache.org/jira/browse/FLINK-4732 > Project: Flink > Issue Type: Bug > Components: Build System > Reporter: Maximilian Michels > Assignee: Maximilian Michels > Priority: Critical > Fix For: 1.2.0, 1.1.3 > > > We use the Maven Junction plugin > http://pyx4j.com/pyx4j-maven-plugins/maven-junction-plugin/introduction.html > to create a symbolic link to the build directory. On Windows, the plugin > downloads an executable from the author's homepage which may be modified by > an attacker. The plugin has not been updated since 2007 and the maintainer > has not shown interest to fix the issue. > I propose to remove the plugin while this security threat persists. -- This message was sent by Atlassian JIRA (v6.3.4#6332)