Fix security issues
[vid.git] / epsdk-app-onap / pom.xml
index 646c017..e5b88ba 100755 (executable)
@@ -18,7 +18,7 @@
                <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>\r
                <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>\r
                <epsdk.version>2.1.0</epsdk.version>\r
-               <springframework.version>4.2.4.RELEASE</springframework.version>\r
+               <springframework.version>4.2.9.RELEASE</springframework.version>\r
                <hibernate.version>4.3.11.Final</hibernate.version>\r
                <!-- Skip assembling the zip; assemble via mvn -Dskipassembly=false .. -->\r
                <skipassembly>true</skipassembly>\r
                        <artifactId>epsdk-app-common</artifactId>\r
                        <version>${epsdk.version}</version>\r
                        <type>jar</type>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>commons-fileupload</groupId>\r
+                                       <artifactId>commons-fileupload</artifactId>\r
+                               </exclusion>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
+               </dependency>\r
+               <!--Upgrade fileupload version-->\r
+               <dependency>\r
+                       <groupId>commons-fileupload</groupId>\r
+                       <artifactId>commons-fileupload</artifactId>\r
+                       <version>1.3.3</version>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.vid</groupId>\r
                        <artifactId>vid-app-common</artifactId>\r
                        <version>${project.version}</version>\r
                        <type>war</type>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.vid</groupId>\r
                        <groupId>org.onap.portal.sdk</groupId>\r
                        <artifactId>epsdk-core</artifactId>\r
                        <version>${epsdk.version}</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.portal.sdk</groupId>\r
                        <artifactId>epsdk-analytics</artifactId>\r
                        <version>${epsdk.version}</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.portal.sdk</groupId>\r
                        <artifactId>epsdk-workflow</artifactId>\r
                        <version>${epsdk.version}</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>com.att.eelf</groupId>\r
                        <groupId>com.fasterxml.jackson.core</groupId>\r
                        <artifactId>jackson-databind</artifactId>\r
                        <version>2.6.7.1</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>com.mchange</groupId>\r
                        <artifactId>junit</artifactId>\r
                        <version>4.12</version>\r
                </dependency>\r
-               <!-- Elastic Search -->\r
-               <dependency>\r
-                       <groupId>org.elasticsearch</groupId>\r
-                       <artifactId>elasticsearch</artifactId>\r
-                       <version>2.2.0</version>\r
-               </dependency>\r
                <dependency>\r
                        <groupId>org.json</groupId>\r
                        <artifactId>json</artifactId>\r