[ 
https://issues.apache.org/jira/browse/FLINK-4732?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15545403#comment-15545403
 ] 

ASF GitHub Bot commented on FLINK-4732:
---------------------------------------

Github user mxm commented on the issue:

    https://github.com/apache/flink/pull/2586
  
    Merged to `master` and `release-1.1`.
    
    @uce I also like the symbolic link. I contacted the maintainer of the 
plugin because it wouldn't be hard to fix this nowadays with Java 7+ which 
supports the creation of symbolic links. I think the lack of this was the 
reason why the author chose to download a binary. However, I don't know why he 
didn't simply ship it with the jar which should have been possible.
    
      


> Maven junction plugin security threat
> -------------------------------------
>
>                 Key: FLINK-4732
>                 URL: https://issues.apache.org/jira/browse/FLINK-4732
>             Project: Flink
>          Issue Type: Bug
>          Components: Build System
>            Reporter: Maximilian Michels
>            Assignee: Maximilian Michels
>            Priority: Critical
>             Fix For: 1.2.0, 1.1.3
>
>
> We use the Maven Junction plugin 
> http://pyx4j.com/pyx4j-maven-plugins/maven-junction-plugin/introduction.html 
> to create a symbolic link to the build directory. On Windows, the plugin 
> downloads an executable from the author's homepage which may be modified by 
> an attacker. The plugin has not been updated since 2007 and the maintainer 
> has not shown interest to fix the issue.
> I propose to remove the plugin while this security threat persists.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Reply via email to