Uploaded image for project: 'Service Design and Creation'
  1. Service Design and Creation
  2. SDC-1714

fix security vilation CVE-2016-6814

XMLWordPrintable

      LF CLM report identified a vulnerability in the flowing dependency:

      group: org.codehaus.groovy

      Artifact: groovy

      this dependency was identified in:

       

      Dependency org.codehaus.groovy:groovy:jar:2.4.7 located at Module org.openecomp.sdc.onboarding:notifications-fe:war:1.3.0-SNAPSHOT

      Dependency org.codehaus.groovy:groovy:jar:2.4.7 located at Module org.openecomp.sdc.onboarding:onboarding-be:war:1.3.0-SNAPSHOT
       

      the closest version with a fix is 2.4.8

      it looks like in a lot of places we use groovy all dependency which brings a lot of things that may not be needed consider replacing with groovy jar or groovy-all-minimale

       

       

       

       

       

            vempo vempo
            ml636r ml636r
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: