Re: using cocoon 2.1 in the long-term, security concerns

Leszek Gawron <[email protected]> Fri, 30 Jul 2021 10:35:08 +0200
Newsgroups gmane.text.xml.cocoon.user
Message-ID <CAM3qyxL4jPX1SjqeqpMpeTf3JSOECC5PbSw70R4LjRik0PzxtA@mail.gmail.com>
--000000000000860e8105c8531972
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I am sorry for not reading the thread to the last message. Maybe a release
then?

On Tue, Jul 20, 2021 at 12:39 PM Gabriel Gruber <[email protected]=
>
wrote:

> Hi Vincent,
>
>
>
> We at Workflow are also still using Cocoon 2.2 as part of our main produc=
t
> and are running it with Java 11 and Tomcat 9 on Windows and Linux OSes.  =
In
> the past we did not see any major problem with cocoon which were not
> solvable. From a security perspective maybe the biggest thread was a
> directory traversal opportunity if you would use ResourceReader cocoon
> component in the wrong way allowing users to use the  /.. in
> URL/request-parameters  being forwarded to the path of the resource to be
> read in order to traverse the directory of the deployment.
>
>
>
> Latest Cocoon 2.2 trunk is also compatible with Spring 4.x by the way.
>
>
>
> Cheers,
>
> Gabriel Gruber
>
> www.workflow.at
>
>
>
>
>
> *Von:* Vincent Neyt <[email protected]>
> *Gesendet:* Dienstag, 20. Juli 2021 12:28
> *An:* [email protected]
> *Betreff:* Re: using cocoon 2.1 in the long-term, security concerns
>
>
>
> Thank you very much Warrell, C=C3=A9dric, Greg and Chris.
>
>
>
> I'm happy to hear that you believe Cocoon poses a very low security risk
> as long as Tomcat and Java are up to date, and that Cocoon should continu=
e
> to work well with future versions of T & J as long as the dependency
> libraries in Cocoon are updated. (At least until Tomcat 9 is no longer
> supported.)
>
>
>
> best wishes,
>
> Vincent
>
>
>
>
>
>
>
>
>
>
>
> On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz <
> [email protected]> wrote:
>
> Vincent,
>
> On 7/19/21 08:03, Vincent Neyt wrote:
> > Hi Cocoon users,
> >
> > I'd like to ask your opinion on the long-term security risks of running
> > Cocoon on a server. The colleague responsible for the servers at my
> > university is inquiring if the software I'm using for my website is up
> > to date and is concerned that I'm using outdated software that could in
> > the future pose a security risk.
> >
> > I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13
> > without many problems. But I'm concerned about the long-term, and
> > wondering if it would perhaps be better to reprogram the website I've
> > been working on for 10 years into eXist DB (which would be a huge time
> > investment). I like cocoon very much and would love to continue using i=
t
> > if it's possible.
> >
> > I'm curious to hear your thoughts about using Cocoon 2.1 for the long
> > term: will it still work well inside future versions of servlet
> > containers like Tomcat? What about the java dependencies? And will
> > cocoon 2.1 continue to put out updates when security risks are
> identified?
>
> I, like you, have been running Cocoon 2.1.x for years and would like to
> continue to rely on it for some important functions at $work.
>
> I don't see any reason it wouldn't run on current and future Tomcat
> versions. There are a few "current" versions of Tomcat, and the only one
> I would expect to have some issues would be the Tomcat 10.x series,
> which implement the "Jakarta EE" specifications instead of the "Java EE"
> specifications. For the most part, these specifications are simply
> package-renamed versions of the original Java EE specs. So, for example,
> javax.servlet.whatever becomes jakarta.servlet.whatever and so on.
>
> Tomcat has a migration tool which can migrate a binary web application
> (e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if
> that tool works on a webapp which is Cocoon itself and/or
> Cocoon-bundled-with-your-application.
>
> I'm a Tomcat committer and if there are any problems, we could work
> together to make sure Cocoon has plenty of life left in it.
>
> With the semi-recent release of Cocoon 2.2, are there members of the
> community who would be interested in converting the project into a
> Jakarta EE-based project? There is no particular rush, and most of the
> conversion can be done essentially with a single sed script. But working
> that into the build process so you can say "build me a Java EE-based
> Cocoon" versus "build me a Jakarta EE-based Cocoon" would be really
> beneficial moving into the future.
>
> [As a Cocoon user, I'd love to know what is necessary to upgrade from
> Cocoon 2.1 to 2.2. We have an ant-based build process for our
> application which starts with a pre-built cocoon.war and customizes it
> with everything we need. So if e.g. Maven can build Cocoon into a WAR
> file, I might be all set.]
>
> -chris
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--000000000000860e8105c8531972
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">I am sorry for not reading the thread to the last message.=
 Maybe a release then?=C2=A0</div><br><div class=3D"gmail_quote"><div dir=
=3D"ltr" class=3D"gmail_attr">On Tue, Jul 20, 2021 at 12:39 PM Gabriel Grub=
er &lt;<a href=3D"mailto:[email protected]">gabriel.gruber@workflo=
w.at</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"mar=
gin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1=
ex">





<div lang=3D"DE-AT" style=3D"overflow-wrap: break-word;">
<div class=3D"gmail-m_3433114795894122082WordSection1">
<p class=3D"MsoNormal"><span>Hi Vincent,<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">We at Workflow are also still u=
sing Cocoon 2.2 as part of our main product and are running it with Java 11=
 and Tomcat 9 on Windows and Linux OSes.=C2=A0 In the past we did not see a=
ny major
 problem with cocoon which were not solvable. From a security perspective m=
aybe the biggest thread was a directory traversal opportunity if you would =
use ResourceReader cocoon component in the wrong way allowing users to use =
the =C2=A0/.. in URL/request-parameters
 =C2=A0being forwarded to the path of the resource to be read in order to t=
raverse the directory of the deployment.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">Latest Cocoon 2.2 trunk is also=
 compatible with Spring 4.x by the way.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">Cheers,<u></u><u></u></span></p=
>
<p class=3D"MsoNormal"><span lang=3D"EN-GB">Gabriel Gruber<u></u><u></u></s=
pan></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><a href=3D"http://www.workflow.=
at" target=3D"_blank">www.workflow.at</a><u></u><u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-GB"><u></u>=C2=A0<u></u></span></p>
<div style=3D"border-right:none;border-bottom:none;border-left:none;border-=
top:1pt solid rgb(225,225,225);padding:3pt 0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"DE">Von:</span></b><span lang=3D"DE=
"> Vincent Neyt &lt;<a href=3D"mailto:[email protected]" target=3D"_bl=
ank">[email protected]</a>&gt;
<br>
<b>Gesendet:</b> Dienstag, 20. Juli 2021 12:28<br>
<b>An:</b> <a href=3D"mailto:[email protected]" target=3D"_blank">use=
[email protected]</a><br>
<b>Betreff:</b> Re: using cocoon 2.1 in the long-term, security concerns<u>=
</u><u></u></span></p>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<p class=3D"MsoNormal">Thank you very much Warrell, C=C3=A9dric, Greg and C=
hris.<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">I&#39;m happy to hear that you believe Cocoon poses =
a very low security risk as long as Tomcat and Java are up to date, and tha=
t Cocoon should continue to work well with future versions of T &amp; J as =
long as the dependency libraries in Cocoon
 are updated. (At least until Tomcat 9 is no longer supported.)<u></u><u></=
u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">best wishes,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Vincent<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<div>
<p class=3D"MsoNormal">On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz =
&lt;<a href=3D"mailto:[email protected]" target=3D"_blank">chris=
@christopherschultz.net</a>&gt; wrote:<u></u><u></u></p>
</div>
<blockquote style=3D"border-top:none;border-right:none;border-bottom:none;b=
order-left:1pt solid rgb(204,204,204);padding:0cm 0cm 0cm 6pt;margin-left:4=
.8pt;margin-right:0cm">
<p class=3D"MsoNormal" style=3D"margin-bottom:12pt">Vincent,<br>
<br>
On 7/19/21 08:03, Vincent Neyt wrote:<br>
&gt; Hi Cocoon users,<br>
&gt; <br>
&gt; I&#39;d like to ask your opinion on the long-term security risks of ru=
nning <br>
&gt; Cocoon on a server. The colleague responsible for the servers at my <b=
r>
&gt; university is inquiring if the software I&#39;m using for my website i=
s up <br>
&gt; to date and is concerned that I&#39;m using outdated software that cou=
ld in <br>
&gt; the future pose a security risk.<br>
&gt; <br>
&gt; I&#39;m using cocoon 2.1.11, which I could probably upgrade to 2.1.13 =
<br>
&gt; without many problems. But I&#39;m concerned about the long-term, and =
<br>
&gt; wondering if it would perhaps be better to reprogram the website I&#39=
;ve <br>
&gt; been working on for 10 years into eXist DB (which would be a huge time=
 <br>
&gt; investment). I like cocoon very=C2=A0much and would love to continue u=
sing it <br>
&gt; if it&#39;s possible.<br>
&gt; <br>
&gt; I&#39;m curious to hear your thoughts about using Cocoon 2.1 for the l=
ong <br>
&gt; term: will it still work well inside future versions of servlet <br>
&gt; containers like Tomcat? What about the java dependencies? And will <br=
>
&gt; cocoon 2.1 continue to put out updates when security risks are identif=
ied?<br>
<br>
I, like you, have been running Cocoon 2.1.x for years and would like to <br=
>
continue to rely on it for some important functions at $work.<br>
<br>
I don&#39;t see any reason it wouldn&#39;t run on current and future Tomcat=
 <br>
versions. There are a few &quot;current&quot; versions of Tomcat, and the o=
nly one <br>
I would expect to have some issues would be the Tomcat 10.x series, <br>
which implement the &quot;Jakarta EE&quot; specifications instead of the &q=
uot;Java EE&quot; <br>
specifications. For the most part, these specifications are simply <br>
package-renamed versions of the original Java EE specs. So, for example, <b=
r>
javax.servlet.whatever becomes jakarta.servlet.whatever and so on.<br>
<br>
Tomcat has a migration tool which can migrate a binary web application <br>
(e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if <br=
>
that tool works on a webapp which is Cocoon itself and/or <br>
Cocoon-bundled-with-your-application.<br>
<br>
I&#39;m a Tomcat committer and if there are any problems, we could work <br=
>
together to make sure Cocoon has plenty of life left in it.<br>
<br>
With the semi-recent release of Cocoon 2.2, are there members of the <br>
community who would be interested in converting the project into a <br>
Jakarta EE-based project? There is no particular rush, and most of the <br>
conversion can be done essentially with a single sed script. But working <b=
r>
that into the build process so you can say &quot;build me a Java EE-based <=
br>
Cocoon&quot; versus &quot;build me a Jakarta EE-based Cocoon&quot; would be=
 really <br>
beneficial moving into the future.<br>
<br>
[As a Cocoon user, I&#39;d love to know what is necessary to upgrade from <=
br>
Cocoon 2.1 to 2.2. We have an ant-based build process for our <br>
application which starts with a pre-built cocoon.war and customizes it <br>
with everything we need. So if e.g. Maven can build Cocoon into a WAR <br>
file, I might be all set.]<br>
<br>
-chris<br>
<br>
---------------------------------------------------------------------<br>
To unsubscribe, e-mail: <a href=3D"mailto:[email protected]=
rg" target=3D"_blank">
[email protected]</a><br>
For additional commands, e-mail: <a href=3D"mailto:[email protected]=
.org" target=3D"_blank">
[email protected]</a><u></u><u></u></p>
</blockquote>
</div>
</div>
</div>

</blockquote></div>

--000000000000860e8105c8531972--