Re: using cocoon 2.1 in the long-term, security concerns
Leszek Gawron <[email protected]> Fri, 30 Jul 2021 10:35:08 +0200
| Newsgroups | gmane.text.xml.cocoon.user |
|---|---|
| Message-ID | <CAM3qyxL4jPX1SjqeqpMpeTf3JSOECC5PbSw70R4LjRik0PzxtA@mail.gmail.com> |
--000000000000860e8105c8531972 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable I am sorry for not reading the thread to the last message. Maybe a release then? On Tue, Jul 20, 2021 at 12:39 PM Gabriel Gruber <[email protected]= > wrote: > Hi Vincent, > > > > We at Workflow are also still using Cocoon 2.2 as part of our main produc= t > and are running it with Java 11 and Tomcat 9 on Windows and Linux OSes. = In > the past we did not see any major problem with cocoon which were not > solvable. From a security perspective maybe the biggest thread was a > directory traversal opportunity if you would use ResourceReader cocoon > component in the wrong way allowing users to use the /.. in > URL/request-parameters being forwarded to the path of the resource to be > read in order to traverse the directory of the deployment. > > > > Latest Cocoon 2.2 trunk is also compatible with Spring 4.x by the way. > > > > Cheers, > > Gabriel Gruber > > www.workflow.at > > > > > > *Von:* Vincent Neyt <[email protected]> > *Gesendet:* Dienstag, 20. Juli 2021 12:28 > *An:* [email protected] > *Betreff:* Re: using cocoon 2.1 in the long-term, security concerns > > > > Thank you very much Warrell, C=C3=A9dric, Greg and Chris. > > > > I'm happy to hear that you believe Cocoon poses a very low security risk > as long as Tomcat and Java are up to date, and that Cocoon should continu= e > to work well with future versions of T & J as long as the dependency > libraries in Cocoon are updated. (At least until Tomcat 9 is no longer > supported.) > > > > best wishes, > > Vincent > > > > > > > > > > > > On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz < > [email protected]> wrote: > > Vincent, > > On 7/19/21 08:03, Vincent Neyt wrote: > > Hi Cocoon users, > > > > I'd like to ask your opinion on the long-term security risks of running > > Cocoon on a server. The colleague responsible for the servers at my > > university is inquiring if the software I'm using for my website is up > > to date and is concerned that I'm using outdated software that could in > > the future pose a security risk. > > > > I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13 > > without many problems. But I'm concerned about the long-term, and > > wondering if it would perhaps be better to reprogram the website I've > > been working on for 10 years into eXist DB (which would be a huge time > > investment). I like cocoon very much and would love to continue using i= t > > if it's possible. > > > > I'm curious to hear your thoughts about using Cocoon 2.1 for the long > > term: will it still work well inside future versions of servlet > > containers like Tomcat? What about the java dependencies? And will > > cocoon 2.1 continue to put out updates when security risks are > identified? > > I, like you, have been running Cocoon 2.1.x for years and would like to > continue to rely on it for some important functions at $work. > > I don't see any reason it wouldn't run on current and future Tomcat > versions. There are a few "current" versions of Tomcat, and the only one > I would expect to have some issues would be the Tomcat 10.x series, > which implement the "Jakarta EE" specifications instead of the "Java EE" > specifications. For the most part, these specifications are simply > package-renamed versions of the original Java EE specs. So, for example, > javax.servlet.whatever becomes jakarta.servlet.whatever and so on. > > Tomcat has a migration tool which can migrate a binary web application > (e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if > that tool works on a webapp which is Cocoon itself and/or > Cocoon-bundled-with-your-application. > > I'm a Tomcat committer and if there are any problems, we could work > together to make sure Cocoon has plenty of life left in it. > > With the semi-recent release of Cocoon 2.2, are there members of the > community who would be interested in converting the project into a > Jakarta EE-based project? There is no particular rush, and most of the > conversion can be done essentially with a single sed script. But working > that into the build process so you can say "build me a Java EE-based > Cocoon" versus "build me a Jakarta EE-based Cocoon" would be really > beneficial moving into the future. > > [As a Cocoon user, I'd love to know what is necessary to upgrade from > Cocoon 2.1 to 2.2. We have an ant-based build process for our > application which starts with a pre-built cocoon.war and customizes it > with everything we need. So if e.g. Maven can build Cocoon into a WAR > file, I might be all set.] > > -chris > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > --000000000000860e8105c8531972 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">I am sorry for not reading the thread to the last message.= Maybe a release then?=C2=A0</div><br><div class=3D"gmail_quote"><div dir= =3D"ltr" class=3D"gmail_attr">On Tue, Jul 20, 2021 at 12:39 PM Gabriel Grub= er <<a href=3D"mailto:[email protected]">gabriel.gruber@workflo= w.at</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"mar= gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1= ex"> <div lang=3D"DE-AT" style=3D"overflow-wrap: break-word;"> <div class=3D"gmail-m_3433114795894122082WordSection1"> <p class=3D"MsoNormal"><span>Hi Vincent,<u></u><u></u></span></p> <p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB">We at Workflow are also still u= sing Cocoon 2.2 as part of our main product and are running it with Java 11= and Tomcat 9 on Windows and Linux OSes.=C2=A0 In the past we did not see a= ny major problem with cocoon which were not solvable. From a security perspective m= aybe the biggest thread was a directory traversal opportunity if you would = use ResourceReader cocoon component in the wrong way allowing users to use = the =C2=A0/.. in URL/request-parameters =C2=A0being forwarded to the path of the resource to be read in order to t= raverse the directory of the deployment.<u></u><u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB">Latest Cocoon 2.2 trunk is also= compatible with Spring 4.x by the way.<u></u><u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB">Cheers,<u></u><u></u></span></p= > <p class=3D"MsoNormal"><span lang=3D"EN-GB">Gabriel Gruber<u></u><u></u></s= pan></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB"><a href=3D"http://www.workflow.= at" target=3D"_blank">www.workflow.at</a><u></u><u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p> <div style=3D"border-right:none;border-bottom:none;border-left:none;border-= top:1pt solid rgb(225,225,225);padding:3pt 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"DE">Von:</span></b><span lang=3D"DE= "> Vincent Neyt <<a href=3D"mailto:[email protected]" target=3D"_bl= ank">[email protected]</a>> <br> <b>Gesendet:</b> Dienstag, 20. Juli 2021 12:28<br> <b>An:</b> <a href=3D"mailto:[email protected]" target=3D"_blank">use= [email protected]</a><br> <b>Betreff:</b> Re: using cocoon 2.1 in the long-term, security concerns<u>= </u><u></u></span></p> </div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div> <p class=3D"MsoNormal">Thank you very much Warrell, C=C3=A9dric, Greg and C= hris.<u></u><u></u></p> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">I'm happy to hear that you believe Cocoon poses = a very low security risk as long as Tomcat and Java are up to date, and tha= t Cocoon should continue to work well with future versions of T & J as = long as the dependency libraries in Cocoon are updated. (At least until Tomcat 9 is no longer supported.)<u></u><u></= u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">best wishes,<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">Vincent<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> </div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div> <div> <p class=3D"MsoNormal">On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz = <<a href=3D"mailto:[email protected]" target=3D"_blank">chris= @christopherschultz.net</a>> wrote:<u></u><u></u></p> </div> <blockquote style=3D"border-top:none;border-right:none;border-bottom:none;b= order-left:1pt solid rgb(204,204,204);padding:0cm 0cm 0cm 6pt;margin-left:4= .8pt;margin-right:0cm"> <p class=3D"MsoNormal" style=3D"margin-bottom:12pt">Vincent,<br> <br> On 7/19/21 08:03, Vincent Neyt wrote:<br> > Hi Cocoon users,<br> > <br> > I'd like to ask your opinion on the long-term security risks of ru= nning <br> > Cocoon on a server. The colleague responsible for the servers at my <b= r> > university is inquiring if the software I'm using for my website i= s up <br> > to date and is concerned that I'm using outdated software that cou= ld in <br> > the future pose a security risk.<br> > <br> > I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13 = <br> > without many problems. But I'm concerned about the long-term, and = <br> > wondering if it would perhaps be better to reprogram the website I'= ;ve <br> > been working on for 10 years into eXist DB (which would be a huge time= <br> > investment). I like cocoon very=C2=A0much and would love to continue u= sing it <br> > if it's possible.<br> > <br> > I'm curious to hear your thoughts about using Cocoon 2.1 for the l= ong <br> > term: will it still work well inside future versions of servlet <br> > containers like Tomcat? What about the java dependencies? And will <br= > > cocoon 2.1 continue to put out updates when security risks are identif= ied?<br> <br> I, like you, have been running Cocoon 2.1.x for years and would like to <br= > continue to rely on it for some important functions at $work.<br> <br> I don't see any reason it wouldn't run on current and future Tomcat= <br> versions. There are a few "current" versions of Tomcat, and the o= nly one <br> I would expect to have some issues would be the Tomcat 10.x series, <br> which implement the "Jakarta EE" specifications instead of the &q= uot;Java EE" <br> specifications. For the most part, these specifications are simply <br> package-renamed versions of the original Java EE specs. So, for example, <b= r> javax.servlet.whatever becomes jakarta.servlet.whatever and so on.<br> <br> Tomcat has a migration tool which can migrate a binary web application <br> (e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if <br= > that tool works on a webapp which is Cocoon itself and/or <br> Cocoon-bundled-with-your-application.<br> <br> I'm a Tomcat committer and if there are any problems, we could work <br= > together to make sure Cocoon has plenty of life left in it.<br> <br> With the semi-recent release of Cocoon 2.2, are there members of the <br> community who would be interested in converting the project into a <br> Jakarta EE-based project? There is no particular rush, and most of the <br> conversion can be done essentially with a single sed script. But working <b= r> that into the build process so you can say "build me a Java EE-based <= br> Cocoon" versus "build me a Jakarta EE-based Cocoon" would be= really <br> beneficial moving into the future.<br> <br> [As a Cocoon user, I'd love to know what is necessary to upgrade from <= br> Cocoon 2.1 to 2.2. We have an ant-based build process for our <br> application which starts with a pre-built cocoon.war and customizes it <br> with everything we need. So if e.g. Maven can build Cocoon into a WAR <br> file, I might be all set.]<br> <br> -chris<br> <br> ---------------------------------------------------------------------<br> To unsubscribe, e-mail: <a href=3D"mailto:[email protected]= rg" target=3D"_blank"> [email protected]</a><br> For additional commands, e-mail: <a href=3D"mailto:[email protected]= .org" target=3D"_blank"> [email protected]</a><u></u><u></u></p> </blockquote> </div> </div> </div> </blockquote></div> --000000000000860e8105c8531972--