Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

RepositoryGroupImpact AnalysisAction
vid

angular.min.js

angular.js

False Positive

VID UI templates are static, and not user-generated in any way.

Its source is in ONAP Portal SDK

False positiveRequest exception

vidbouncycastle No fix is available for this vulnerability;

Its source is in ONAP Portal SDK

Request exception


vidcom.fasterxml.jackson.core

False positive

VID doesn't use createBeanDeserializer() function in the BeanDeserializerFactory class

False positive

vidcom.thoughtworks.xstreamcommons-beanutils

No fix is available for this vulnerability;

Its source is in ONAP Portal SDK

Request exception


vidcommons-beanutilsmoment

No fix is available for this vulnerability;

Its source is in ONAP Portal SDK

Request exception

vidcommons-fileuploadorg.apache.httpcomponents

Its source is in ONAP Portal SDK

Request exception

vidcommons-httpclientorg.codehaus.jackson

False positive

VID doesn't use the problematic line: readRawLine of HttpParser function createBeanDeserializer in the BeanDeserializerFactory class

No fix is available for this vulnerability

False positive

vidjavax.servletNo fix is available for this vulnerability (since 1.2);xercesIts source is in ONAP Portal SDK

Request exception

vidmomentNo fix is available for this vulnerability;org.hibernateIts source is in ONAP Portal SDK

Request exception

vidorg.apacheeclipse.httpcomponentsjetty

False positive

VID uses this library just for selenium tests automation, meaning no production code affected.doesn't use the check function in Password.java file

False positive
vidcom.google.guavaIts source also is in ONAP Portal SDKFalse positiveRequest exception
vidorg.apache.luceneNo fix is available for this vulnerability;commons-codec Its source is in ONAP Portal SDKRequest exception
vidorg.bouncycastleNo fix is available for this vulnerability;dom4jIts source is in ONAP Portal SDKRequest exception
vidorg.codehaus.jackson

False positive

VID doesn't use the problematic function createBeanDeserializer in the BeanDeserializerFactory class

No fix is available for this vulnerability

False positive

vidxalan jquery

Under investigation

Jira Legacy
serverSystem Jira
serverId4733707d-2057-3a0f-ae5e-4fd8aff50176
keyVID-309


vidorg.apache.wicketIts source is in ONAP Portal SDKRequest exception
vidxercesorg.springframework Its source is in ONAP Portal SDKRequest exception
vidorg.hibernatespringframework Its source is in ONAP Portal SDKRequest exception
vidorg.beanshellspringframework Its source is in ONAP Portal SDKRequest exception
vidcommons-collectionsorg.springframework Its source is in ONAP Portal SDKRequest exception
vidorg org.apacheowasp.poiesapi Its source is in ONAP Portal SDKRequest exception
vidorg.apacheowasp.poiantisamyIts source is in ONAP Portal SDKRequest exception
???vidorg.eclipse.jetty

False positive

VID doesn't use the check function in Password.java file

False positive

Under investigation

Jira Legacy
serverSystem Jira
serverId4733707d-2057-3a0f-ae5e-4fd8aff50176
keyVID-309