-
Bug
-
Resolution: Done
-
Highest
-
Istanbul Release
-
None
Sonarcloud identified the following security bugs in your project and, as agreed by the TSC, should be fixed within the Istanbul release. Any not finished in Istanbul must be fixed within the Jakarta release. Follow each of the URLs for details on each each bug, along with recommended fixes.
The verification URL for these issues will be <https://sonarcloud.io/organizations/onap/issues?resolved=false&sonarsourceSecurity=xxe&projects=onap_appc>.
If any of the links below fail, please find your code on the master list found at <https://sonarcloud.io/organizations/onap/issues?resolved=false&sonarsourceSecurity=xxe>.
Project: onap_appc
Component: onap_appc:appc-adapters/appc-netconf-adapter/appc-netconf-adapter-bundle/src/main/java/org/onap/appc/adapter/netconf/VNFOperationalStateValidatorImpl.java
Message: Disable access to external entities in XML parsing.
Severity: BLOCKER
Line: 84
Effort: 15min
Creation-Date: 2017-02-11T00:01:38+0100
URL: https://sonarcloud.io/project/issues?id=onap_appc&issues=AXfYukqvylV6v2eEg2KM&open=AXfYukqvylV6v2eEg2KM
Project: onap_appc
Component: onap_appc:appc-config/appc-config-adaptor/provider/src/main/java/org/onap/appc/ccadaptor/ConfigComponentAdaptor.java
Message: Disable access to external entities in XML parsing.
Severity: BLOCKER
Line: 1029
Effort: 15min
Creation-Date: 2019-07-06T04:16:41+0200
URL: https://sonarcloud.io/project/issues?id=onap_appc&issues=AW6lYVmDgYcRdnXY2UXS&open=AW6lYVmDgYcRdnXY2UXS
Project: onap_appc
Component: onap_appc:appc-config/appc-config-adaptor/provider/src/main/java/org/onap/appc/ccadaptor/ConfigComponentAdaptor.java
Message: Disable access to external entities in XML parsing.
Severity: BLOCKER
Line: 1034
Effort: 15min
Creation-Date: 2019-07-06T04:16:41+0200
URL: https://sonarcloud.io/project/issues?id=onap_appc&issues=AXDJhV137NPLvZRIh3OH&open=AXDJhV137NPLvZRIh3OH
Project: onap_appc
Component: onap_appc:appc-config/appc-config-generator/provider/src/main/java/org/onap/sdnc/config/generator/transform/XSLTTransformerNode.java
Message: Disable access to external entities in XML parsing.
Severity: BLOCKER
Line: 97
Effort: 15min
Creation-Date: 2018-02-26T20:11:11+0100
URL: https://sonarcloud.io/project/issues?id=onap_appc&issues=AXDJhWSx7NPLvZRIh3OJ&open=AXDJhWSx7NPLvZRIh3OJ
- clones
-
CCSDK-3317 fix CRITICAL xxe (XML External Entity) issues identified in sonarcloud
- Closed
- is cloned by
-
CCSDK-3318 fix CRITICAL xxe (XML External Entity) issues identified in sonarcloud
- Closed
- relates to
-
REQ-443 CONTINUATION OF BEST PRACTICES BADGING SCORE IMPROVEMENTS FOR SILVER LEVEL
- In Progress