Re: using cocoon 2.1 in the long-term, security concerns

Gabriel Gruber <[email protected]> Fri, 30 Jul 2021 11:37:09 +0000
Newsgroups gmane.text.xml.cocoon.user
Message-ID <DBAPR02MB6343BB43DAAF840FC7399B7D9FEC9@DBAPR02MB6343.eurprd02.prod.outlook.com>
--_000_DBAPR02MB6343BB43DAAF840FC7399B7D9FEC9DBAPR02MB6343eurp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Hi Leszak,

Yeah, a release would be nice =96 Fix version 2.2.1 was stated in this tick=
et https://issues.apache.org/jira/browse/COCOON-2347

But was never released though=85
Cheers,
Gabriel

From: Leszek Gawron <[email protected]>
Date: Friday, 30. July 2021 at 10:35
To: [email protected] <[email protected]>
Subject: Re: using cocoon 2.1 in the long-term, security concerns
I am sorry for not reading the thread to the last message. Maybe a release =
then?

On Tue, Jul 20, 2021 at 12:39 PM Gabriel Gruber <[email protected]=
<mailto:[email protected]>> wrote:
Hi Vincent,

We at Workflow are also still using Cocoon 2.2 as part of our main product =
and are running it with Java 11 and Tomcat 9 on Windows and Linux OSes.  In=
 the past we did not see any major problem with cocoon which were not solva=
ble. From a security perspective maybe the biggest thread was a directory t=
raversal opportunity if you would use ResourceReader cocoon component in th=
e wrong way allowing users to use the  /.. in URL/request-parameters  being=
 forwarded to the path of the resource to be read in order to traverse the =
directory of the deployment.

Latest Cocoon 2.2 trunk is also compatible with Spring 4.x by the way.

Cheers,
Gabriel Gruber
www.workflow.at<http://www.workflow.at>


Von: Vincent Neyt <[email protected]<mailto:[email protected]>>
Gesendet: Dienstag, 20. Juli 2021 12:28
An: [email protected]<mailto:[email protected]>
Betreff: Re: using cocoon 2.1 in the long-term, security concerns

Thank you very much Warrell, C=E9dric, Greg and Chris.

I'm happy to hear that you believe Cocoon poses a very low security risk as=
 long as Tomcat and Java are up to date, and that Cocoon should continue to=
 work well with future versions of T & J as long as the dependency librarie=
s in Cocoon are updated. (At least until Tomcat 9 is no longer supported.)

best wishes,
Vincent





On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz <chris@christopherschul=
tz.net<mailto:[email protected]>> wrote:
Vincent,

On 7/19/21 08:03, Vincent Neyt wrote:
> Hi Cocoon users,
>
> I'd like to ask your opinion on the long-term security risks of running
> Cocoon on a server. The colleague responsible for the servers at my
> university is inquiring if the software I'm using for my website is up
> to date and is concerned that I'm using outdated software that could in
> the future pose a security risk.
>
> I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13
> without many problems. But I'm concerned about the long-term, and
> wondering if it would perhaps be better to reprogram the website I've
> been working on for 10 years into eXist DB (which would be a huge time
> investment). I like cocoon very much and would love to continue using it
> if it's possible.
>
> I'm curious to hear your thoughts about using Cocoon 2.1 for the long
> term: will it still work well inside future versions of servlet
> containers like Tomcat? What about the java dependencies? And will
> cocoon 2.1 continue to put out updates when security risks are identified=
?

I, like you, have been running Cocoon 2.1.x for years and would like to
continue to rely on it for some important functions at $work.

I don't see any reason it wouldn't run on current and future Tomcat
versions. There are a few "current" versions of Tomcat, and the only one
I would expect to have some issues would be the Tomcat 10.x series,
which implement the "Jakarta EE" specifications instead of the "Java EE"
specifications. For the most part, these specifications are simply
package-renamed versions of the original Java EE specs. So, for example,
javax.servlet.whatever becomes jakarta.servlet.whatever and so on.

Tomcat has a migration tool which can migrate a binary web application
(e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if
that tool works on a webapp which is Cocoon itself and/or
Cocoon-bundled-with-your-application.

I'm a Tomcat committer and if there are any problems, we could work
together to make sure Cocoon has plenty of life left in it.

With the semi-recent release of Cocoon 2.2, are there members of the
community who would be interested in converting the project into a
Jakarta EE-based project? There is no particular rush, and most of the
conversion can be done essentially with a single sed script. But working
that into the build process so you can say "build me a Java EE-based
Cocoon" versus "build me a Jakarta EE-based Cocoon" would be really
beneficial moving into the future.

[As a Cocoon user, I'd love to know what is necessary to upgrade from
Cocoon 2.1 to 2.2. We have an ant-based build process for our
application which starts with a pre-built cocoon.war and customizes it
with everything we need. So if e.g. Maven can build Cocoon into a WAR
file, I might be all set.]

-chris

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]<mailto:users-un=
[email protected]>
For additional commands, e-mail: [email protected]<mailto:users-=
[email protected]>

--_000_DBAPR02MB6343BB43DAAF840FC7399B7D9FEC9DBAPR02MB6343eurp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.com/of=
fice/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style>
</head>
<body lang=3D"en-AT" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea=
k-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span lang=3D"DE-AT" style=3D"mso-fareast-language:E=
N-US">Hi Leszak,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"DE-AT" style=3D"mso-fareast-language:E=
N-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"mso-fareast-language:E=
N-US">Yeah, a release would be nice =96 Fix version 2.2.1 was stated in thi=
s ticket
<a href=3D"https://issues.apache.org/jira/browse/COCOON-2347">https://issue=
s.apache.org/jira/browse/COCOON-2347</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"mso-fareast-language:E=
N-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"mso-fareast-language:E=
N-US">But was never released though=85<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"mso-fareast-language:E=
N-US">Cheers,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"mso-fareast-language:E=
N-US">Gabriel<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US"><o:p>&nbs=
p;</o:p></span></p>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><b><span style=3D"fon=
t-size:12.0pt;color:black">From:
</span></b><span style=3D"font-size:12.0pt;color:black">Leszek Gawron &lt;o=
[email protected]&gt;<br>
<b>Date: </b>Friday, 30. July 2021 at 10:35<br>
<b>To: </b>[email protected] &lt;[email protected]&gt;<br>
<b>Subject: </b>Re: using cocoon 2.1 in the long-term, security concerns<o:=
p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal">I am sorry for not reading the thread to the last me=
ssage. Maybe a release then?&nbsp;<o:p></o:p></p>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div>
<p class=3D"MsoNormal">On Tue, Jul 20, 2021 at 12:39 PM Gabriel Gruber &lt;=
<a href=3D"mailto:[email protected]">[email protected]</a=
>&gt; wrote:<o:p></o:p></p>
</div>
<blockquote style=3D"border:none;border-left:solid #CCCCCC 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">Hi Vincent,<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">We at Workflow are also still using Cocoon 2.=
2 as part of our main product and are running it with Java 11 and Tomcat 9 =
on Windows and Linux OSes.&nbsp; In the past
 we did not see any major problem with cocoon which were not solvable. From=
 a security perspective maybe the biggest thread was a directory traversal =
opportunity if you would use ResourceReader cocoon component in the wrong w=
ay allowing users to use the &nbsp;/..
 in URL/request-parameters &nbsp;being forwarded to the path of the resourc=
e to be read in order to traverse the directory of the deployment.</span><s=
pan lang=3D"DE-AT"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">&nbsp;</span><span lang=3D"DE-AT"><o:p></o:p>=
</span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">Latest Cocoon 2.2 trunk is also compatible wi=
th Spring 4.x by the way.</span><span lang=3D"DE-AT"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">&nbsp;</span><span lang=3D"DE-AT"><o:p></o:p>=
</span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">Cheers,</span><span lang=3D"DE-AT"><o:p></o:p=
></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">Gabriel Gruber</span><span lang=3D"DE-AT"><o:=
p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB"><a href=3D"http://www.workflow.at" target=3D"=
_blank">www.workflow.at</a></span><span lang=3D"DE-AT"><o:p></o:p></span></=
p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">&nbsp;</span><span lang=3D"DE-AT"><o:p></o:p>=
</span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"EN-GB">&nbsp;</span><span lang=3D"DE-AT"><o:p></o:p>=
</span></p>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><b><span lang=3D"DE">Von:</span></b><span lang=3D"DE"> Vincent Ney=
t &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">vincent.n=
[email protected]</a>&gt;
<br>
<b>Gesendet:</b> Dienstag, 20. Juli 2021 12:28<br>
<b>An:</b> <a href=3D"mailto:[email protected]" target=3D"_blank">use=
[email protected]</a><br>
<b>Betreff:</b> Re: using cocoon 2.1 in the long-term, security concerns</s=
pan><span lang=3D"DE-AT"><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">Thank you very much Warrell, C=E9dric, Greg a=
nd Chris.<o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">I'm happy to hear that you believe Cocoon pos=
es a very low security risk as long as Tomcat and Java are up to date, and =
that Cocoon should continue to work well
 with future versions of T &amp; J as long as the dependency libraries in C=
ocoon are updated. (At least until Tomcat 9 is no longer supported.)<o:p></=
o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">best wishes,<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">Vincent<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">&nbsp;<o:p></o:p></span></p>
<div>
<div>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span lang=3D"DE-AT">On Mon, Jul 19, 2021 at 6:35 PM Christopher S=
chultz &lt;<a href=3D"mailto:[email protected]" target=3D"_blank=
">[email protected]</a>&gt; wrote:<o:p></o:p></span></p>
</div>
<blockquote style=3D"border:none;border-left:solid #CCCCCC 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-=
bottom:5.0pt">
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;margin-bottom:12.0p=
t"><span lang=3D"DE-AT">Vincent,<br>
<br>
On 7/19/21 08:03, Vincent Neyt wrote:<br>
&gt; Hi Cocoon users,<br>
&gt; <br>
&gt; I'd like to ask your opinion on the long-term security risks of runnin=
g <br>
&gt; Cocoon on a server. The colleague responsible for the servers at my <b=
r>
&gt; university is inquiring if the software I'm using for my website is up=
 <br>
&gt; to date and is concerned that I'm using outdated software that could i=
n <br>
&gt; the future pose a security risk.<br>
&gt; <br>
&gt; I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13 <br>
&gt; without many problems. But I'm concerned about the long-term, and <br>
&gt; wondering if it would perhaps be better to reprogram the website I've =
<br>
&gt; been working on for 10 years into eXist DB (which would be a huge time=
 <br>
&gt; investment). I like cocoon very&nbsp;much and would love to continue u=
sing it <br>
&gt; if it's possible.<br>
&gt; <br>
&gt; I'm curious to hear your thoughts about using Cocoon 2.1 for the long =
<br>
&gt; term: will it still work well inside future versions of servlet <br>
&gt; containers like Tomcat? What about the java dependencies? And will <br=
>
&gt; cocoon 2.1 continue to put out updates when security risks are identif=
ied?<br>
<br>
I, like you, have been running Cocoon 2.1.x for years and would like to <br=
>
continue to rely on it for some important functions at $work.<br>
<br>
I don't see any reason it wouldn't run on current and future Tomcat <br>
versions. There are a few &quot;current&quot; versions of Tomcat, and the o=
nly one <br>
I would expect to have some issues would be the Tomcat 10.x series, <br>
which implement the &quot;Jakarta EE&quot; specifications instead of the &q=
uot;Java EE&quot; <br>
specifications. For the most part, these specifications are simply <br>
package-renamed versions of the original Java EE specs. So, for example, <b=
r>
javax.servlet.whatever becomes jakarta.servlet.whatever and so on.<br>
<br>
Tomcat has a migration tool which can migrate a binary web application <br>
(e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if <br=
>
that tool works on a webapp which is Cocoon itself and/or <br>
Cocoon-bundled-with-your-application.<br>
<br>
I'm a Tomcat committer and if there are any problems, we could work <br>
together to make sure Cocoon has plenty of life left in it.<br>
<br>
With the semi-recent release of Cocoon 2.2, are there members of the <br>
community who would be interested in converting the project into a <br>
Jakarta EE-based project? There is no particular rush, and most of the <br>
conversion can be done essentially with a single sed script. But working <b=
r>
that into the build process so you can say &quot;build me a Java EE-based <=
br>
Cocoon&quot; versus &quot;build me a Jakarta EE-based Cocoon&quot; would be=
 really <br>
beneficial moving into the future.<br>
<br>
[As a Cocoon user, I'd love to know what is necessary to upgrade from <br>
Cocoon 2.1 to 2.2. We have an ant-based build process for our <br>
application which starts with a pre-built cocoon.war and customizes it <br>
with everything we need. So if e.g. Maven can build Cocoon into a WAR <br>
file, I might be all set.]<br>
<br>
-chris<br>
<br>
---------------------------------------------------------------------<br>
To unsubscribe, e-mail: <a href=3D"mailto:[email protected]=
rg" target=3D"_blank">
[email protected]</a><br>
For additional commands, e-mail: <a href=3D"mailto:[email protected]=
.org" target=3D"_blank">
[email protected]</a><o:p></o:p></span></p>
</blockquote>
</div>
</div>
</div>
</blockquote>
</div>
</div>
</body>
</html>

--_000_DBAPR02MB6343BB43DAAF840FC7399B7D9FEC9DBAPR02MB6343eurp_--