Uploaded image for project: 'Service Design and Creation'
  1. Service Design and Creation
  2. SDC-3495

fix CRITICAL weak-cryptography issues identified in sonarcloud

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: High High
    • Istanbul Release
    • Honolulu Release
    • None

      Sonarcloud identified the following security bugs in your project and, as agreed by the TSC, should be fixed within the Honolulu release. Any not finished in Honolulu must be fixed within the Istanbul release. Follow each of the URLs for details on each each bug, along with recommended fixes.

       
      If any of the links below fail, please find your code on the master list found at <https://sonarcloud.io/organizations/onap/issues?resolved=false&sonarsourceSecurity=weak-cryptography>.
       

      https://sonarcloud.io/project/issues?id=onap_clamp&issues=AXUZwZGvABzwvbI_x8XB&open=AXUZwZGvABzwvbI_x8XB

      Project: onap_sdc
      Component: onap_sdc:openecomp-be/api/openecomp-sdc-rest-webapp/vendor-software-products-rest/vnf-repository-rest-services/src/main/java/org/openecomp/sdcrests/vsp/rest/services/VnfPackageRepositoryImpl.java
      Message: Enable server certificate validation on this SSL/TLS connection.
      Severity: CRITICAL
      Line: 83
      Effort: 5min
      Creation-Date: 2020-10-12T00:09:13+0200
      URL: https://sonarcloud.io/project/issues?id=onap_sdc&issues=AXUZwZGvABzwvbI_x8W_&open=AXUZwZGvABzwvbI_x8W_

      Project: onap_sdc
      Component: onap_sdc:openecomp-be/api/openecomp-sdc-rest-webapp/vendor-software-products-rest/vnf-repository-rest-services/src/main/java/org/openecomp/sdcrests/vsp/rest/services/VnfPackageRepositoryImpl.java
      Message: Enable server certificate validation on this SSL/TLS connection.
      Severity: CRITICAL
      Line: 84
      Effort: 5min
      Creation-Date: 2020-10-12T00:09:13+0200
      URL: https://sonarcloud.io/project/issues?id=onap_sdc&issues=AXUZwZGvABzwvbI_x8XA&open=AXUZwZGvABzwvbI_x8XA

      Project: onap_sdc
      Component: onap_sdc:openecomp-be/api/openecomp-sdc-rest-webapp/vendor-software-products-rest/vnf-repository-rest-services/src/main/java/org/openecomp/sdcrests/vsp/rest/services/VnfPackageRepositoryImpl.java
      Message: Enable server hostname verification on this SSL/TLS connection.
      Severity: CRITICAL
      Line: 90
      Effort: 5min
      Creation-Date: 2020-10-12T00:09:13+0200
      URL: https://sonarcloud.io/project/issues?id=onap_sdc&issues=AXUZwZGvABzwvbI_x8XB&open=AXUZwZGvABzwvbI_x8XB

       

            xuegao xuegao
            tonylhansen tonylhansen
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: