A248 opened a new issue, #1038: URL: https://github.com/apache/maven-enforcer/issues/1038
### Affected version 3.6.3 ### Bug description bannedRepositories says that it checks all repositories in the current session context. However, repositories can be drawn in if they are declared by dependencies, and these repositories aren't checked by Maven Enforcer. Thus, the current build can download artifacts from unintended repositories -- subverting the enforcement of the bannedRepositories rule -- if those repositories were declared in the POMs of dependencies. Here is a reproducer: https://github.com/A248/enforcer-bannedrepo-bypass Running the reproducer we can see the following output in the build of `consumer`. The "sneaky" repository still gets used. This is despite that the consumer uses "bannedRepositories" to enforce a whitelist of repositories. ``` [INFO] -----------< org.libertybans.enforcer:repo-bypass-consumer >------------ [INFO] Building repo-bypass-consumer 1.0.0-SNAPSHOT [INFO] --------------------------------[ jar ]--------------------------------- Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.pom Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.pom (8.2 kB at 15 kB/s) Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/enforcer/enforcer/3.6.3/enforcer-3.6.3.pom Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/enforcer/enforcer/3.6.3/enforcer-3.6.3.pom (10 kB at 197 kB/s) Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/48/maven-parent-48.pom Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/maven-parent/48/maven-parent-48.pom (50 kB at 291 kB/s) Downloading from central: https://repo.maven.apache.org/maven2/org/apache/apache/38/apache-38.pom Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/apache/38/apache-38.pom (26 kB at 492 kB/s) Downloading from central: https://repo.maven.apache.org/maven2/org/junit/junit-bom/5.14.4/junit-bom-5.14.4.pom Downloaded from central: https://repo.maven.apache.org/maven2/org/junit/junit-bom/5.14.4/junit-bom-5.14.4.pom (5.7 kB at 126 kB/s) Downloading from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.jar Downloaded from central: https://repo.maven.apache.org/maven2/org/apache/maven/plugins/maven-enforcer-plugin/3.6.3/maven-enforcer-plugin-3.6.3.jar (40 kB at 216 kB/s) Downloading from sonatype-snapshots: https://central.sonatype.com/repository/maven-snapshots/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom Downloading from central: https://repo.maven.apache.org/maven2/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom Downloading from sneaky: https://dl.google.com/android/maven2/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom Downloaded from sneaky: https://dl.google.com/android/maven2/androidx/annotation/annotation/1.11.0/annotation-1.11.0.pom ``` This could be considered a security vulnerability depending on the security policy of the organization. At the very least it contradicts the intention of the bannedRepositories rule, which is to control the repositories allowed to be accessed during the build sequence. Note: This seems to happen when the dependency POM declares a dependency on an artifact that only exists in the remote repository. In the reproducer, this is the androidx.annotations artifact. When the consumer POM needs to download androidx.annotations, it uses the repository declared by the dependency POM. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
