Uploaded image for project: 'Policy Framework'
  1. Policy Framework
  2. POLICY-507

Review security issues: policy-engine

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: High High
    • Beijing Release
    • None
    • None

      The following security issues have been identified by Nexus IQ Server (tool used by LF) on 2017-12-23. See the attached report - RED Security issues.

      1. swagger-ui - not used anywhere. Not sure how it is detecting this.
      2. collections - pulled in from several other dependencies
      3. springcore - will upgrade to 2.3.3-RELEASE
      4. io.springfox - will upgrade to 2.8.0
      5. xstream - will upgrade 1.4.10
      6. jackson-databind - will upgrade to 2.9.3
      7. commons-fileupload - will upgrade to 1.3.3
      8. maven-model - will upgrade to 3.3.9
      9. maven-invoker - will upgrade to 3.0.0

      Lucene-query-parser is pulled in from elastic search dependency - I think this is disabled

      License issues with: org.owasp.esapi:esapi:jar:2.1.0.1 --> this pulls in xalan, beanutils, xerces

      EELF will have to fix qos logback

      Portal SDK will have to upgrade:

      • bouncy castle
        *

            pdragosh pdragosh
            katel34 katel34
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: