Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 18 Current »

NOTE: This page is copy of /wiki/spaces/SV/pages/16094118 report

The tables contain the recommended package version upgrades for outdated direct dependencies with Critical or Severe vulnerabilities identified by NexusIQ. These packages must be upgraded by M2/M3 or a request for a waiver must be requested from SECCOM and the TSC.

  • Priority 1 recommendations have at least one Critical vulnerability.
  • Priority 2 recommendations contain at least one Severe vulnerability, and no Critical vulnerabilities.
  • There are four status values:
    • OPEN - required upgrade identified
    • IN PROGRESS - project working on the upgrade
    • COMPLETE - package has been upgraded to the recommended version
    • WAIVER - project granted a waiver for the upgrade because of technical or resource constraints

When the upgrade of the package is complete change the status in the table to COMPLETE.

If a waiver is granted, change the status to WAIVER.

When the status of all direct dependency replacements is COMPLETE or WAIVER , the Jira ticket should be closed.

so-adapters-so-etsi-sol003-adapter

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1

This is indirect dependency coming from the o-parent. 


The version 2.14.2 is updated and available in Master branch   

COMPLETE

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

 
As per our analysis 1.33 version not supported it required Spring Boot 3.0.0 version. So 
we try update it 1.31 version its working so we push the code changes.

 
 The version 1.31 is updated and available in Master branch 

so-libs

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. 

 
The version 
2.14.2 is updated and available in Master branch 

so

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1


This is indirect dependency coming from the o-parent.


The version 2.14.2 is updated and available in Master branch   

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.9.82.14.1
Same as above

COMPLETE

1com.google.protobuf : protobuf-java : 3.10.04.0.0-rc-2

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.
 
This dependancy is excluded in SO pom.xml therefor no impact, require no change in SO

COMPLETE

1com.h2database : h2 : 1.4.2000.16.4

We dont use this code in the production and is only built for testing code.

 
1) As per analysis the recommend version is lowest which is not available in Maven dependency.
2) We update the latest version 2.1.214 and its work i.e. code build successfully. Reference link:  https://mvnrepository.com/artifact/com.h2database/h2

 
The version 2.1.214 is updated and available in Master branch 

OPEN

1org.apache.tomcat : tomcat-catalina : 9.0.459.0.37.1

This needs further analysis and We are facing resource issue at the moment, request a waiver.

 
We are not able to find this dependency.

COMPLETE

1org.json : json : 2014010720220924


The change would bring in a major testing to be performed across the projects and we have a resource crunch. 


The version 2.14.2 is updated and available in Master branch   

COMPLETE

1org.json : json : 2016021220220924

The change would bring in a major testing to be performed across the projects and we have a resource crunch. 


The version 2.14.2 is updated and available in Master branch   

OPEN

1org.springframework : spring-web : 5.2.14.RELEASE6.0.2

 
Spring Framework 6 requires Java 17 

COMPLETE

1

org.springframework.data : spring-data-rest-hal-browser : 3.3.9.RELEASE

3.3.9.RELEASE

change is pushed

 
The version 3.3.9.RELEASE is updated and available in Master branch 

COMPLETE

1org.springframework.security : spring-security-web : 5.4.63.0.11-oss


This needs further analysis and We are facing resource issue at the moment, request a waiver.
 
1) As per our analysis the recommended version 3.0.11-oss  is not related to Spring-Security-Web. It is related to AJSC Archetype Parent which is not used in our SO Project (atleast we did not find it).
2) Therefore we can update the latest version of spring-security-web version 6.1.2 and its work i.e. code build successfully. Reference links https://mvnrepository.com/artifact/com.att.ajsc/ajsc-archetype-parent/3.0.11-oss  
and  https://mvnrepository.com/artifact/org.springframework.security/spring-security-web/6.1.2

 
The version 6.1.2 is updated and available in Master branch 

COMPLETE

1org.yaml : snakeyaml : 1.261.33


This needs further analysis and We are facing resource issue at the moment, request a waiver.

 
As per our analysis 1.33 version not supported it required Spring Boot 3.0.0 version. So 
we try update it 1.31 version its working so we push the code changes.

 
The version 1.31 is updated and available in Master branch 
 

COMPLETE

2org.glassfish.jersey.core : jersey-common : 2.22.1

 change is pushed

 
The version is updated and available in Master branch 

COMPLETE

2org.glassfish.jersey.core : jersey-common : 2.30.1

 change is pushed

 
The version is updated and available in Master branch 

OPEN

2org.springframework : spring-webmvc : 5.2.12.RELEASE6.0.2

 
Spring Framework 6 requires Java 17 

so-so-admin-cockpit

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch


The version 2.14.2 is updated and available in Master branch   

so-so-etsi-nfvo

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch.


The version 2.14.2 is updated and available in Master branch   

COMPLETE

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

 
As per our analysis 1.33 version not supported it required Spring Boot 3.0.0 version. So 
we try update it 1.31 version its working so we push the code changes.

 
The version 1.31 is updated and available in Master branch 
 

  • No labels