Security Vulnerability in pom.xml fix 09/97309/1
authorDominik Mizyn <d.mizyn@samsung.com>
Fri, 18 Oct 2019 12:43:07 +0000 (14:43 +0200)
committerDominik Mizyn <d.mizyn@samsung.com>
Fri, 18 Oct 2019 12:43:22 +0000 (14:43 +0200)
Security Vulnerability in pom.xml fix

Issue-ID: PORTAL-772
Change-Id: I6b0932122b101411b06d371e757918875529b87d
Signed-off-by: Dominik Mizyn <d.mizyn@samsung.com>
12 files changed:
ecomp-sdk/epsdk-aaf/pom.xml
ecomp-sdk/epsdk-analytics/pom.xml
ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/system/DbUtils.java
ecomp-sdk/epsdk-app-common/pom.xml
ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java
ecomp-sdk/epsdk-app-os/pom.xml
ecomp-sdk/epsdk-core/pom.xml
ecomp-sdk/epsdk-domain/pom.xml
ecomp-sdk/epsdk-fw/pom.xml
ecomp-sdk/epsdk-logger/pom.xml
ecomp-sdk/epsdk-music/pom.xml
ecomp-sdk/epsdk-workflow/pom.xml

index 9d10e9b..036b5e4 100644 (file)
@@ -19,7 +19,7 @@
 
        <properties>
                <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
-               <springframework.version>4.2.0.RELEASE</springframework.version>
+               <springframework.version>4.3.20.RELEASE</springframework.version>
        </properties>
        <dependencies>
                <!-- internal -->
                <dependency>
                        <groupId>org.springframework.boot</groupId>
                        <artifactId>spring-boot-starter</artifactId>
-                       <version>1.3.0.RELEASE</version>
+                       <version>1.3.1.RELEASE</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>org.slf4j</groupId>
index dcffc4c..26821de 100644 (file)
@@ -45,7 +45,7 @@
                <dependency>
                        <groupId>com.fasterxml.jackson.core</groupId>
                        <artifactId>jackson-databind</artifactId>
-                       <version>2.8.10</version>
+                       <version>2.8.11.4</version>
                </dependency>
                <!-- Raptor required Libraries -->
                <!-- for static charts -->
                <dependency>
                        <groupId>org.apache.poi</groupId>
                        <artifactId>poi-scratchpad</artifactId>
-                       <version>3.14</version>
+                       <version>3.17</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>commons-logging</groupId>
index 67acdf9..d528dc6 100644 (file)
@@ -45,7 +45,6 @@ import java.sql.SQLException;
 import java.sql.Statement;
 import java.sql.Types;
 import javax.sql.DataSource;
-import org.apache.commons.lang3.StringUtils;
 import org.onap.portalsdk.analytics.error.RaptorException;
 import org.onap.portalsdk.analytics.error.ReportSQLException;
 import org.onap.portalsdk.analytics.model.runtime.ReportRuntime;
@@ -213,7 +212,7 @@ public class DbUtils {
         try (final Connection con = getConnection();) {
             if (con != null) {
                 try (final PreparedStatement preparedStatement = con.prepareStatement(sql);) {
-                    if (StringUtils.isNotBlank(reportID)) {
+                    if (!reportID.isEmpty()) {
                         preparedStatement.setString(1, reportID);
                         preparedStatement.setString(2, reportName);
                     } else {
index 473c942..2d0bf37 100644 (file)
                <dependency>
                        <groupId>com.att.eelf</groupId>
                        <artifactId>eelf-core</artifactId>
-                       <version>1.0.0</version>
+                       <version>1.0.0-oss</version>
                </dependency>
                <!-- Mapper -->
                <dependency>
                <dependency>
                        <groupId>com.mchange</groupId>
                        <artifactId>c3p0</artifactId>
-                       <version>0.9.5.3</version>
+                       <version>0.9.5.4</version>
                </dependency>
                <dependency>
                        <groupId>io.searchbox</groupId>
                        <artifactId>jest</artifactId>
-                       <version>2.0.0</version>
+                       <version>5.3.4</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>commons-logging</groupId>
                <dependency>
                        <groupId>org.elasticsearch</groupId>
                        <artifactId>elasticsearch</artifactId>
-                       <version>7.1.1</version>
+                       <version>7.2.1</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>org.apache.lucene</groupId>
        <dependency>
                <groupId>org.owasp.esapi</groupId>
                <artifactId>esapi</artifactId>
-               <version>2.1.0.1</version>
+               <version>2.2.0.0</version>
            <exclusions>
                <exclusion>
                <groupId>commons-beanutils</groupId>
                <dependency>
                <groupId>commons-beanutils</groupId>
                <artifactId>commons-beanutils</artifactId>
-               <version>1.9.3</version>
+               <version>1.9.4</version>
                </dependency>
                <dependency>
                        <groupId>org.apache.httpcomponents</groupId>
                <dependency>
                <groupId>xerces</groupId>
                <artifactId>xercesImpl</artifactId>
-               <version>2.11.0.SP5</version>
+               <version>2.12.0</version>
                </dependency>
                <dependency>
                <groupId>commons-collections</groupId>
index 69807a1..c964712 100644 (file)
@@ -43,8 +43,8 @@ import java.util.concurrent.locks.Lock;
 import java.util.concurrent.locks.ReentrantLock;
 import java.util.regex.Pattern;
 import org.apache.commons.lang.NotImplementedException;
+import org.apache.commons.lang.StringEscapeUtils;
 import org.apache.commons.lang.StringUtils;
-import org.apache.commons.lang3.StringEscapeUtils;
 import org.onap.portalsdk.core.logging.logic.EELFLoggerDelegate;
 import org.onap.portalsdk.core.util.SystemProperties;
 import org.owasp.esapi.ESAPI;
@@ -132,7 +132,7 @@ public class SecurityXssValidator {
 
       if (StringUtils.isNotBlank(value)) {
 
-        value = StringEscapeUtils.escapeHtml4(value);
+        value = StringEscapeUtils.escapeHtml(value);
 
         value = ESAPI.encoder().canonicalize(value);
 
index cfdcb24..5269091 100644 (file)
                <dependency>
                        <groupId>com.att.eelf</groupId>
                        <artifactId>eelf-core</artifactId>
-                       <version>1.0.0</version>
+                       <version>1.0.0-oss</version>
                </dependency>
                <!-- Mapper -->
                <dependency>
                <dependency>
                        <groupId>com.mchange</groupId>
                        <artifactId>c3p0</artifactId>
-                       <version>0.9.5.2</version>
+                       <version>0.9.5.4</version>
                </dependency>
                <dependency>
                        <groupId>io.searchbox</groupId>
                        <artifactId>jest</artifactId>
-                       <version>2.0.0</version>
+                       <version>5.3.2</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>commons-logging</groupId>
                <dependency>
                        <groupId>org.elasticsearch</groupId>
                        <artifactId>elasticsearch</artifactId>
-                       <version>2.2.0</version>
+                       <version>6.8.2</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>org.apache.lucene</groupId>
index be08cc3..565867d 100644 (file)
                <dependency>
                        <groupId>org.hibernate</groupId>
                        <artifactId>hibernate-validator</artifactId>
-                       <version>5.1.3.Final</version>
+                       <version>5.2.1.Final</version>
                </dependency>
                <!-- Servlet+JSP+JSTL -->
                <dependency>
                <dependency>
                        <groupId>com.mchange</groupId>
                        <artifactId>c3p0</artifactId>
-                       <version>0.9.5.3</version>
+                       <version>0.9.5.4</version>
                </dependency>
                <!-- Apache Tiles -->
                <dependency>
                <dependency>
                        <groupId>com.fasterxml.jackson.core</groupId>
                        <artifactId>jackson-databind</artifactId>
-                       <version>2.8.10</version>
+                       <version>2.8.11.4</version>
                </dependency>
                <!-- Use Mariadb connector -->
                <dependency>
                <dependency>
                        <groupId>org.apache.tomcat</groupId>
                        <artifactId>tomcat-websocket</artifactId>
-                       <version>8.0.28</version>
+                       <version>8.0.52</version>
                        <scope>provided</scope>
                </dependency>
 
                <dependency>
                        <groupId>org.elasticsearch</groupId>
                        <artifactId>elasticsearch</artifactId>
-                       <version>2.2.0</version>
+                       <version>6.8.2</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>org.apache.lucene</groupId>
                <dependency>
                        <groupId>io.searchbox</groupId>
                        <artifactId>jest</artifactId>
-                       <version>2.0.0</version>
+                       <version>5.3.2</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>commons-logging</groupId>
                <dependency>
                        <groupId>com.att.eelf</groupId>
                        <artifactId>eelf-core</artifactId>
-                       <version>1.0.0</version>
+                       <version>1.0.0-oss</version>
                </dependency>
 
        <dependency>
                <groupId>org.owasp.esapi</groupId>
                <artifactId>esapi</artifactId>
-               <version>2.1.0.1</version>
+               <version>2.2.0.0</version>
                <exclusions>
                        <exclusion>
                                <groupId>commons-beanutils</groupId>
                <dependency>
                        <groupId>com.thoughtworks.xstream</groupId>
                        <artifactId>xstream</artifactId>
-                       <version>1.4.10</version>
+                       <version>1.4.11</version>
                </dependency>
                <dependency>
                        <groupId>org.apache.wicket</groupId>
                <dependency>
                        <groupId>commons-beanutils</groupId>
                        <artifactId>commons-beanutils</artifactId>
-                       <version>1.9.2</version>
+                       <version>1.9.4</version>
                </dependency>
                <dependency>
                        <groupId>org.apache.poi</groupId>
index 327e51d..f1b554e 100644 (file)
@@ -33,7 +33,7 @@
                <dependency>
                        <groupId>com.fasterxml.jackson.core</groupId>
                        <artifactId>jackson-databind</artifactId>
-                       <version>2.8.10</version>
+                       <version>2.8.11.4</version>
                </dependency>
                <dependency>
                        <groupId>org.mockito</groupId>
index 6c2b283..1c29cea 100644 (file)
@@ -17,7 +17,7 @@
 
        <!-- properties are inherited from parent -->
        <properties>
-               <resteasy.version>3.0.18.Final</resteasy.version>
+               <resteasy.version>3.1.0.Final</resteasy.version>
                <powermock.version>1.7.4</powermock.version>
        </properties>
        <!-- repositories are inherited from parent -->
                <dependency>
                        <groupId>com.fasterxml.jackson.core</groupId>
                        <artifactId>jackson-databind</artifactId>
-                       <version>2.8.10</version>
+                       <version>2.8.11.3</version>
                </dependency>
                <dependency>
                        <groupId>org.owasp.esapi</groupId>
                        <artifactId>esapi</artifactId>
-                       <version>2.1.0.1</version>
+                       <version>2.2.0.0</version>
                        <exclusions>
                                <exclusion>
                                        <groupId>log4j</groupId>
index 3f0f7df..b7e0b64 100644 (file)
@@ -17,7 +17,7 @@
        <dependency>
                        <groupId>com.att.eelf</groupId>
                        <artifactId>eelf-core</artifactId>
-                       <version>1.0.0</version>
+                       <version>1.0.0-oss</version>
                </dependency>
                <dependency>
                        <groupId>javax.servlet</groupId>
index 5c442a9..cfbc41c 100644 (file)
@@ -18,7 +18,7 @@
 
        <properties>
                <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
-               <springframework.version>4.2.3.RELEASE</springframework.version>
+               <springframework.version>4.3.20.RELEASE</springframework.version>
                <jersey1.version>1.19.4</jersey1.version>
                <jaxrs.version>2.0.1</jaxrs.version>
                <cassandra.version>3.0.0</cassandra.version>
index 707e1fb..f08b65f 100644 (file)
@@ -40,7 +40,7 @@
                <dependency>
                        <groupId>com.fasterxml.jackson.core</groupId>
                        <artifactId>jackson-databind</artifactId>
-                       <version>2.8.10</version>
+                       <version>2.8.11.4</version>
                </dependency>
                <dependency>
                        <groupId>javax.servlet</groupId>
@@ -55,7 +55,7 @@
                <dependency>
                        <groupId>org.hibernate</groupId>
                        <artifactId>hibernate-validator</artifactId>
-                       <version>5.1.3.Final</version>
+                       <version>5.2.1.Final</version>
                </dependency>
                <dependency>
                        <groupId>org.json</groupId>