Uploaded image for project: 'Service Design and Creation'
  1. Service Design and Creation
  2. SDC-1715

fix security vilation CVE-2015-3253

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Medium Medium
    • Casablanca Release
    • None
    • Onboarding
    • None

      LF CLM report identified a vulnerability in the flowing dependency:

      group: org.codehaus.groovy

      Artifact: groovy

      this dependency was identified in:

      Dependency org.codehaus.groovy:groovy:jar:2.4.1 located at Module org.openecomp.sdc.be:catalog-dao:jar:1.3.0-SNAPSHOT

      Dependency org.codehaus.groovy:groovy:jar:2.4.1 located at Module org.openecomp.sdc.be:catalog-model:jar:1.3.0-SNAPSHOT

      Dependency org.codehaus.groovy:groovy:jar:2.4.1 located at Module org.openecomp.sdc:asdctool:jar:1.3.0-SNAPSHOT

      Dependency org.codehaus.groovy:groovy:jar:2.4.1 located at Module org.openecomp.sdc:catalog-be:war:1.3.0-SNAPSHOT

      Dependency org.codehaus.groovy:groovy:jar:2.4.1 located at Module org.openecomp.sdc:test-apis-ci:jar:1.3.0-SNAPSHOT

      Dependency org.codehaus.groovy:groovy:jar:2.4.1 located at Module org.openecomp.sdc:ui-ci:jar:1.3.0-SNAPSHOT
       

      the closest version with a fix is 2.4.8

      it looks like in a lot of places we use groovy all dependency which brings a lot of things that may not be needed consider replacing with groovy jar or groovy-all-minimal

       

      reopened need to fix the issue with the indy dependency that is still showen in the clm report

       

       

       

       

       

            tgitelman tgitelman
            ml636r ml636r
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - 4 hours
                4h
                Remaining:
                Remaining Estimate - 4 hours
                4h
                Logged:
                Time Spent - Not Specified
                Not Specified