...
The information related to Repository and Group are extracted from the CLM report.
Repository | Group | Impact Analysis | Action |
---|---|---|---|
vid | angular.min.js angular.js | False Positive VID UI templates are static, and not user-generated in any way. Its source is in ONAP Portal SDK | False positive |
vid | bouncycastle | No fix is available for this vulnerability; Its source is in ONAP Portal SDK | Request exception |
vid | com.fasterxml.jackson.core | False positive VID doesn't use createBeanDeserializer() function in the BeanDeserializerFactory class | False positive |
vid | com.thoughtworks.xstream | Its source is in ONAP Portal SDK | Request exception |
vid | commons-beanutils | No fix is available for this vulnerability; Its source is in ONAP Portal SDK | Request exception |
vid | commons-fileupload | Its source is in ONAP Portal SDK | Request exception |
vid | commons-httpclient | False positive VID doesn't use the problematic line: readRawLine of HttpParser class No fix is available for this vulnerability | False positive |
vid | javax.servlet | No fix is available for this vulnerability (since 1.2); Its source is in ONAP Portal SDK | Request exception |
vid | moment | No fix is available for this vulnerability; Its source is in ONAP Portal SDK | Request exception |
vid | org.apache.httpcomponents | False positive VID uses this library just for selenium tests automation, meaning no production code affected. Its source also is in ONAP Portal SDK | False positive |
vid | org.apache.lucene | No fix is available for this vulnerability; Its source is in ONAP Portal SDK | Request exception |
vid | org.bouncycastle | No fix is available for this vulnerability; Its source is in ONAP Portal SDK | Request exception |
vid | org.codehaus.jackson | False positive VID doesn't use the problematic function createBeanDeserializer in the BeanDeserializerFactory class No fix is available for this vulnerability | False positive |
vid | xalan | Its source is in ONAP Portal SDK | Request exception |
vid | xerces | Its source is in ONAP Portal SDK | Request exception |
vid | org.hibernate | Its source is in ONAP Portal SDK | Request exception |
vid | org.beanshell | Its source is in ONAP Portal SDK | Request exception |
vid | commons-collections | Its source is in ONAP Portal SDK | Request exception |
vid | org.apache.poi | Its source is in ONAP Portal SDK | Request exception |
vid | org.apache.poi | Its source is in ONAP Portal SDK | Request exception |
vid | org.eclipse.jetty | False positive VID doesn't use the check function in Password.java file | False positive |