[JIRA] (JENKINS-16161) Can't Install Plugin - - Malicious Code - FTP Download deleted

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

[JIRA] (JENKINS-16161) Can't Install Plugin - - Malicious Code - FTP Download deleted

JIRA noreply@jenkins-ci.org
Issue Type: Bug Bug
Affects Versions: current
Assignee: Ulli Hafner
Components: pmd
Created: 18/Dec/12 2:42 PM
Description:

Getting this error when trying to install plugin:
PMD Plugin
Failure -
hudson.util.IOException2: Failed to download from http://updates.jenkins-ci.org/download/plugins/pmd/3.33/pmd.hpi
at hudson.model.UpdateCenter$UpdateCenterConfiguration.download(UpdateCenter.java:741)
at hudson.model.UpdateCenter$DownloadJob._run(UpdateCenter.java:1078)
at hudson.model.UpdateCenter$InstallationJob._run(UpdateCenter.java:1240)
at hudson.model.UpdateCenter$DownloadJob.run(UpdateCenter.java:1056)
at java.util.concurrent.Executors$RunnableAdapter.call(Unknown Source)
at java.util.concurrent.FutureTask$Sync.innerRun(Unknown Source)
at java.util.concurrent.FutureTask.run(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.runTask(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
Caused by: java.io.IOException: Inconsistent file length: expected 7867436 but only got 4716722
at hudson.model.UpdateCenter$UpdateCenterConfiguration.download(UpdateCenter.java:736)
... 9 more

THEN tried to go to the FTP URL and got this error:

Restricted URL

A malicious code was detected in your web traffic:

Item: http://mirror.xmission.com/jenkins/plugins/pmd/3.33/pmd.hpi
Action: deleted

Infection detail:

– File: pmd.hpi, malicious code name: Exceed_Compression_Ratio_Limit
The uncleanable file was deleted.

Environment: WinXP
with Jenkins 1.493 and 1.494
Project: Jenkins
Priority: Critical Critical
Reporter: Damien Saunders
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira
Reply | Threaded
Open this post in threaded view
|

[JIRA] (JENKINS-16161) Can't Install Plugin - - Malicious Code - FTP Download deleted

JIRA noreply@jenkins-ci.org
Ulli Hafner resolved Bug JENKINS-16161 as Not A Defect

I don't think that this is a defect that I can fix. There is something broken in the mirror that hosts the artifact. (Or a proxy that sits in between).

Change By: Ulli Hafner (21/Dec/12 10:30 AM)
Status: Open Resolved
Resolution: Not A Defect
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira