Casablanca MUSIC Security/Vulnerability Report

This table represents the known exploitable and non-exploitable vulnerabilities in third party packages used in the project.



Repository

Code

Group

Impact Analysis

Action

Repository

Code

Group

Impact Analysis

Action

music

CVE-2017-7525

org.codehaus.jackson

False Positive. This is a dependency by the core library for our RESTful service(jersey-json) and our cassandra-unit library. We do not use Jackson directly and do not use createBeanDeserializer() function which has the vulnerability. We were unable to find any reference to this Vulnerability from jersey-json or cassandra-unit.

MUSIC-48: Deal with jackson-mapper-asl security vulnerabilityClosed



music

CVE-2018-7489

com.fasterxml.jackson.core

False Positive. This is a dependency of Swagger Jersey Jaxrs library. We do not use Jackson directly and do not use createBeanDeserializer() function which has the vulnerability. To our knowledge we cannot find any reference of swagger jersey using this.

MUSIC-49: Deal with jackson-databind issueClosed

music

SONATYPE-2018-0469

org.apache.zookeeper : zookeeper : 3.4.11

This has been removed in the Dublin release



music

SONATYPE-2017-0356

io.netty

This has been removed in the Dublin release