Uploaded image for project: 'Vnfsdk'
  1. Vnfsdk
  2. VNFSDK-370

Fix VNFSDK Validation vulnerabilities

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Medium Medium
    • El Alto Release
    • None
    • None

      2019/04/17: https://nexus-iq.wl.linuxfoundation.org/assets/index.html#/reports/onap-vnfsdk-validation/4b6ffbd82974412fa989de9d2d63d704 
      CVE-2018-7489:  com.fasterxml.jackson.core : jackson-databind : 2.9.4 jackson-databind-2.9.4.jar
      currently we are working on using the Gson as the Alternative of jackson.
      CVE-2013-2035: jline : jline : 2.6 jline-2.6.jar
       jline is used during the mvn test phase and is not used while vnfsdk service is running.  we will try to investigate this that how to update this into a newer version.
       

            mkr1481 mkr1481
            g310497 g310497
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: