Jason Ryan
09/09/2022, 8:34 PMfelix-cache
folder? More specifically I'm getting some lit up with some vulnerabilities that I was hoping to (and almost did) avoid with box-light in this folder: /root/.CommandBox/engine/cfml/cli/lucee-server/felix-cache/bundle56/version0.0/bundle.jar
bdw429s
09/09/2022, 9:13 PMbdw429s
09/09/2022, 9:14 PMbdw429s
09/09/2022, 9:14 PMbdw429s
09/09/2022, 9:15 PMJason Ryan
09/09/2022, 9:17 PMbdw429s
09/09/2022, 9:19 PMbdw429s
09/09/2022, 9:19 PMJason Ryan
09/09/2022, 9:19 PMJason Ryan
09/09/2022, 9:19 PMbdw429s
09/09/2022, 9:19 PMJason Ryan
09/09/2022, 9:20 PMJason Ryan
09/09/2022, 9:21 PMbdw429s
09/09/2022, 9:21 PMbdw429s
09/09/2022, 9:22 PMbdw429s
09/09/2022, 9:22 PMJason Ryan
09/09/2022, 9:22 PMbdw429s
09/09/2022, 9:22 PMbdw429s
09/09/2022, 9:23 PMJason Ryan
09/09/2022, 9:23 PMJason Ryan
09/09/2022, 9:23 PMbdw429s
09/09/2022, 9:23 PMbdw429s
09/09/2022, 9:24 PMBundle (jar)
under Info
Jason Ryan
09/09/2022, 9:24 PMJason Ryan
09/09/2022, 9:24 PMJason Ryan
09/09/2022, 9:29 PMbundle56
.jar like the vulnerability scanner was (turns out I'm manually copying that in through java sdk includes in app.cfc)bdw429s
09/09/2022, 9:29 PMbdw429s
09/09/2022, 9:29 PMMETA-INF/MANIFEST.MF
bdw429s
09/09/2022, 9:29 PMbdw429s
09/09/2022, 9:30 PMJason Ryan
09/09/2022, 9:30 PMbundle56/version0.0/bundle.jar
?bdw429s
09/09/2022, 9:30 PMbdw429s
09/09/2022, 9:30 PMbdw429s
09/09/2022, 9:30 PMbdw429s
09/09/2022, 9:31 PMbdw429s
09/09/2022, 9:32 PMJason Ryan
09/09/2022, 9:32 PMJason Ryan
09/09/2022, 9:32 PMbdw429s
09/09/2022, 9:32 PMJason Ryan
09/09/2022, 9:33 PMbdw429s
09/09/2022, 9:33 PMbdw429s
09/09/2022, 9:33 PMbdw429s
09/09/2022, 9:33 PMbdw429s
09/09/2022, 9:34 PMJason Ryan
09/09/2022, 9:35 PMbdw429s
09/09/2022, 9:36 PMbdw429s
09/09/2022, 9:37 PMbdw429s
09/09/2022, 9:38 PMorg.apache.commons.Collections
bdw429s
09/09/2022, 9:38 PMbdw429s
09/09/2022, 9:39 PMbdw429s
09/09/2022, 9:39 PMbdw429s
09/09/2022, 9:40 PMbdw429s
09/09/2022, 9:40 PMbdw429s
09/09/2022, 9:40 PMcom.fasterxml.jackson.core:jackson-databind
Jason Ryan
09/09/2022, 9:41 PMbdw429s
09/09/2022, 9:42 PMJason Ryan
09/09/2022, 9:42 PM/root/.CommandBox/engine/cfml/cli/lucee-server/felix-cache/bundle56/version0.0/bundle.jar
and setn over the manifestbdw429s
09/09/2022, 9:42 PMJul 17, 2014
bdw429s
09/09/2022, 9:43 PMThis was the bundle that I unzippedNo, it wasn't. I'm betting that server was restarted since the scan, the felix cache was deleted and re-created with different jars getting the same name
bdw429s
09/09/2022, 9:43 PMJason Ryan
09/09/2022, 9:45 PMJason Ryan
09/09/2022, 9:45 PMbdw429s
09/09/2022, 9:46 PMJason Ryan
09/09/2022, 9:46 PMbdw429s
09/09/2022, 9:46 PMJason Ryan
09/09/2022, 9:46 PMbdw429s
09/09/2022, 9:46 PMJason Ryan
09/09/2022, 9:46 PMJason Ryan
09/09/2022, 9:46 PMbdw429s
09/09/2022, 9:46 PMbdw429s
09/09/2022, 9:47 PMJason Ryan
09/09/2022, 9:48 PMJason Ryan
09/09/2022, 9:49 PMbdw429s
09/09/2022, 9:51 PMbdw429s
09/09/2022, 9:51 PMJason Ryan
09/09/2022, 9:51 PMbdw429s
09/10/2022, 1:55 AMbdw429s
09/10/2022, 1:58 AMJason Ryan
09/12/2022, 6:56 PMroot/.CommandBox/engine/cfml/cli/lucee-server/bundles/*org-lucee-ehcache-2-10-3.jar*
. Turns out it's coming from the installation of HibernateORMEngine v3.5.5.84
bdw429s
09/12/2022, 6:57 PMJason Ryan
09/12/2022, 6:58 PMbdw429s
09/12/2022, 6:58 PMorg.lucee
even though it's ehcache-- that's one of those repackaged bundles Lucee makesJason Ryan
09/12/2022, 6:58 PMbdw429s
09/12/2022, 6:59 PMbdw429s
09/12/2022, 6:59 PMbdw429s
09/12/2022, 7:00 PMbdw429s
09/12/2022, 7:01 PMbdw429s
09/12/2022, 7:02 PMcom.fasterxml.jackson.core
was reported as the vulnerable package, but I don't see any class files with that path anywhere in the ehcache jarbdw429s
09/12/2022, 7:03 PMJason Ryan
09/12/2022, 7:03 PMJason Ryan
09/12/2022, 7:03 PMbdw429s
09/12/2022, 7:04 PMbdw429s
09/12/2022, 7:04 PMJason Ryan
09/12/2022, 7:04 PMbdw429s
09/12/2022, 7:05 PMJason Ryan
09/12/2022, 7:08 PMJason Ryan
09/12/2022, 7:10 PMbdw429s
09/12/2022, 7:13 PMbdw429s
09/12/2022, 7:14 PMJason Ryan
09/12/2022, 7:15 PMbdw429s
09/12/2022, 7:15 PMbdw429s
09/12/2022, 7:16 PMJason Ryan
09/12/2022, 7:18 PMJason Ryan
09/12/2022, 7:19 PMbdw429s
09/12/2022, 7:19 PM2.10.3
of net.sf.ehcache:ehcache
is from 2016bdw429s
09/12/2022, 7:19 PMbdw429s
09/12/2022, 7:20 PMbdw429s
09/12/2022, 7:20 PMbdw429s
09/12/2022, 7:21 PMnet.sf.ehcache
and the 3.x series changed to org.ehcache
so it's likely a non-trivial amount of work to update Lucee as there are breaking changes in the API for sureJason Ryan
09/12/2022, 7:23 PM