Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Grouper's use of Apache Struts

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Grouper's use of Apache Struts


Chronological Thread 
  • From: Baron Fujimoto <>
  • To: "Hyzer, Chris" <>, Grouper Users <>
  • Subject: Re: [grouper-users] Grouper's use of Apache Struts
  • Date: Fri, 13 Oct 2017 13:41:48 -1000
  • Ironport-phdr: 9a23:ATg6OBGfhZqUjvtuLXwwbZ1GYnF86YWxBRYc798ds5kLTJ7yoMiwAkXT6L1XgUPTWs2DsrQf2rqQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDmwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VC+85Kl3VhDnlCYHNyY48G7JjMxwkLlbqw+lqxBm3oLYfJ2ZOP94c6zTZ9MaQXdKUNhXWSJPH4iwa5IDAuoEMetesoLzpUYBrQGmCAeiBO3h1CJGiHz43aI1z+suDAPJ0wI7EtISrHjZtsn5OLsIXOyryqTD0DXNb+lR2Tf48IXFbwouoeuLXbJ2bMHfyVQvFwHEjlWVrozlIzSV3fkKvmeA9eVgT+Wvi2g8pgFxuDeuyN0jiojIho4P1F/L6Dh5zZ8zKNalRkB7ZtukH4FRtyGcL4Z2RMIiQ3p0uCogxb0GvoC7cDAQx5Q/3RHQd/yHfJaS7hLkTuaRLi90hHxldb6lmxmy9k2gx+vhXce3yFZHtjRJn9jQun0P0hHT5MuKReBh8kqk1juDyxzf5f9BLE8oiabWK5ssz7sumpcdv0nPBjL6lFv1gaOMa0kp+PWk5/76brn8uJORMZJ/hBvkPaQ0gMO/BPw1MggQUGif/uSxzLjj8lf4QLVOl/E2iqbZvIzDKcUUuKK0DQFY3pws6xa4CDem39AYkmcdIF1ZfxKHipDlO1DIIP/mEfeym0qgnTZ3y/3EO7DhDJbAIWPfnLrkcrtx91JQxxQ2wN9D+55ZCrQMLfftVkL/utHUFho5PBa1w+bjBtV9zIQeWWeXD6CCKqzSq1iI5uQ0LumMfoAUtizyK/kk5/L0k3A2hEIdcbGz3ZQLcHC4AuhmI0KBbHrjmNcBFnoKvhIgQ+zwkVGCTCVTaGioX6In/Tw7DIOmDZzfRoC2nrCNxia7HptKZm9YEFCMF2nnd5maV/sWdi2dP9JhwXQ4Uu3ra54z2Avq/CT60bt8ZKKA/yYYpIDuzvB0/OaViAk/8zoyAsiAhSXFYHtzg3sFXXcLx61lugQpxU2EzLB1mblFDtFJ/NtIVBs3L5jR07Y8BtzvDFHvZNCMHXyvWNKgSR8sTNM0xMMJKxJ3Es+liDjD1jWjAr5TmrCWUs9nupnA1mT8cp4ug03N07Ms2hx/GpZC

Apologies for possibly beating a dead horse, but can anyone confirm that
Grouper is using the features available in BeanUtils 1.9.2 to mitigate
CVE-2014-0114?

Without positive confirmation, we'll probably have to firewall off our
Grouper to limit exposure, which we'd obviously rather avoid if
unnecessary.

It doesn't seem like anyone else seems particularly concerned about this
that we've noticed. Are we overreacting?

Aloha,
-baron

On Wed, Sep 27, 2017 at 07:41:13PM +0000, Baron Fujimoto wrote:
>Mahalo for the responses. For clarification, does the use of beanutils
>1.9.2 which provides for the suppression of properties, including "class"
>mean that this vulnerability is actually mitigated in Grouper?
>
>It actually seems a little ambiguous, since the BEANUTILS-463 issue
>indicates that the issue is addressable in BeanUtils 1.9.2, but
>CVE-2014-0114 implicates beanutils versions "through 1.9.2". I'm assuming
>the BEANUTILS-463 is correct and that the CVE-2014-0114 advisory could be
>more clearly or accurately worded, but confirmation would be helpful.
>
>Thanks also for the roadmap/timeline for Grouper's plans for Struts going
>forward.
>
>On Wed, Sep 27, 2017 at 03:36:52PM +0000, Hyzer, Chris wrote:
>>Yes 1.2.4
>>Yes the manifest is a reliable way to get the version
>>We use beanutils 1.9.2: https://issues.apache.org/jira/browse/BEANUTILS-463
>>Struts is only in UI, not WS
>>We are trying to get struts out of Grouper by the end of the calendar
>>year...
>>
>>Thanks
>>Chris
>>
>>-----Original Message-----
>>From:
>>
>>
>>[mailto:]
>> On Behalf Of Baron Fujimoto
>>Sent: Tuesday, September 26, 2017 11:05 PM
>>To: Grouper Users
>><>
>>Subject: [grouper-users] Grouper's use of Apache Struts
>>
>>Due to the recent high profile Equifax breach attributed to
>>vulnerabilities in Apache Struts, use of Struts within our organization
>>has come under scrutiny. It would help us to address concerns if these
>>questions could be answered.
>>
>>It's our understanding that Grouper is not subject to recently announced
>>vulnerabilities in Struts, e.g. CVE-2017-5638
>><https://nvd.nist.gov/vuln/detail/CVE-2017-5638>, because they apply to
>>older version of Struts 2, whereas Grouper uses Struts v1.
>>
>>How can you tell specifically which version of Struts is being used in a
>>Grouper deployment? I dug this out of the UI's struts.jar MANIFEST:
>>
>>Specification-Title: Struts Framework
>>Specification-Vendor: The Apache Software Foundation
>>Specification-Version: 1.2.4
>>
>>Is this a reliable way to get the version information?
>>
>>Is the only place Grouper uses Struts in the UI? Not, say, by the WS?
>>
>>The assumed non-vulnerablity to CVE-2017-5638 notwithstanding, it was
>>brought to our attention that Struts 1 is implicated in CVE-2014-0114
>><https://nvd.nist.gov/vuln/detail/CVE-2014-0114>. Our Google-fu failed to
>>turn up anything about this in the Grouper context. Has this risk been
>>assessed for Grouper?
>>
>>If called for, would the mitigation strategy described here work with
>>Grouper, or is there perhaps a fly in the ointment?
>><https://devcentral.f5.com/articles/mitigating-the-apache-struts-classloader-manipulation-vulnerabilities-using-asm>
>>
>>It's also been pointed out to us that Struts 1 itself was EOL as of
>>2013-04. Per their announcement, should a major security problem or a
>>serious bug reported for Struts 1, no new releases or fixes fixes may be
>>expected. <https://struts.apache.org/struts1eol-announcement.html>
>>
>>Given this, what is Grouper's future with regard to its use of Struts?

--
Baron Fujimoto
<>
:: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum



Archive powered by MHonArc 2.6.19.

Top of Page