A248 opened a new issue, #1038:
URL: https://github.com/apache/maven-enforcer/issues/1038

   ### Affected version
   
   3.6.3
   
   ### Bug description
   
   bannedRepositories says that it checks all repositories in the current 
session context. However, repositories can be drawn in if they are declared by 
dependencies, and these repositories aren't checked by Maven Enforcer.
   
   Thus, the current build can download artifacts from unintended repositories 
-- subverting the enforcement of the bannedRepositories rule -- if those 
repositories were declared in the POMs of dependencies.
   
   Here is a reproducer: https://github.com/A248/enforcer-bannedrepo-bypass
   
   Running the reproducer we can see the following output in the build of 
`consumer`. The "sneaky" repository still gets used. This is despite that the 
consumer uses "bannedRepositories" to enforce a whitelist of repositories.
   ```
   [INFO] -----------< org.libertybans.enforcer:repo-bypass-consumer 
>------------
   [INFO] Building repo-bypass-consumer 1.0.0-SNAPSHOT
   [INFO] --------------------------------[ jar 
]---------------------------------
   Downloading from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.pom
   Downloaded from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.pom
 (8.2 kB at 15 kB/s)
   Downloading from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/enforcer/enforcer/3.6.3/enforcer-3.6.3.pom
   Downloaded from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/enforcer/enforcer/3.6.3/enforcer-3.6.3.pom
 (10 kB at 197 kB/s)
   Downloading from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/48/maven-parent-48.pom
   Downloaded from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/48/maven-parent-48.pom
 (50 kB at 291 kB/s)
   Downloading from central: 
https://repo.maven.apache.org/maven2/org/apache/apache/38/apache-38.pom
   Downloaded from central: 
https://repo.maven.apache.org/maven2/org/apache/apache/38/apache-38.pom (26 kB 
at 492 kB/s)
   Downloading from central: 
https://repo.maven.apache.org/maven2/org/junit/junit-bom/5.14.4/junit-bom-5.14.4.pom
   Downloaded from central: 
https://repo.maven.apache.org/maven2/org/junit/junit-bom/5.14.4/junit-bom-5.14.4.pom
 (5.7 kB at 126 kB/s)
   Downloading from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.jar
   Downloaded from central: 
https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.jar
 (40 kB at 216 kB/s)
   Downloading from sonatype-snapshots: 
https://central.sonatype.com/repository/maven-snapshots/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom
   Downloading from central: 
https://repo.maven.apache.org/maven2/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom
   Downloading from sneaky: 
https://dl.google.com/android/maven2/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom
   Downloaded from sneaky: 
https://dl.google.com/android/maven2/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom
 
   ```
   
   This could be considered a security vulnerability depending on the security 
policy of the organization. At the very least it contradicts the intention of 
the bannedRepositories rule, which is to control the repositories allowed to be 
accessed during the build sequence.
   
   Note: This seems to happen when the dependency POM declares a dependency on 
an artifact that only exists in the remote repository. In the reproducer, this 
is the androidx.annotations artifact. When the consumer POM needs to download 
androidx.annotations, it uses the repository declared by the dependency POM.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to