From ca685bb55cd192ab58c62663a31f5292697a4182 Mon Sep 17 00:00:00 2001 From: vasraz Date: Thu, 11 Jun 2020 17:05:29 +0100 Subject: [PATCH] Fix Critical security vulnerability com.fasterxml.jackson.core : jackson-databind : 2.9.9 Change-Id: I81af7879cb1fbcd158177a3dc220b704ff2f3388 Signed-off-by: Vasyl Razinkov Issue-ID: SDC-3111 --- asdctool/pom.xml | 44 ++++++++++-- catalog-be/pom.xml | 79 +++++++++++++++++++--- catalog-dao/pom.xml | 6 ++ catalog-fe/pom.xml | 7 +- catalog-model/pom.xml | 25 ++++++- common-app-api/pom.xml | 12 ++++ common-be/pom.xml | 25 ++++++- .../onap-configuration-management-core/pom.xml | 6 ++ common/onap-tosca-datatype/pom.xml | 11 +++ onboarding/pom.xml | 7 +- .../backend/openecomp-sdc-security-util/pom.xml | 13 +++- openecomp-be/lib/openecomp-common-lib/pom.xml | 6 ++ pom.xml | 4 +- test-apis-ci/pom.xml | 7 +- ui-ci/pom.xml | 26 ++++++- utils/DmaapPublisher/pom.xml | 5 -- 16 files changed, 252 insertions(+), 31 deletions(-) diff --git a/asdctool/pom.xml b/asdctool/pom.xml index b685620bab..76cd7b4840 100644 --- a/asdctool/pom.xml +++ b/asdctool/pom.xml @@ -48,19 +48,34 @@ ${project.version} compile + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + org.openecomp.sdc.be catalog-dao ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + org.openecomp.sdc.be catalog-model ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -73,6 +88,10 @@ classes + + com.fasterxml.jackson.core + jackson-core + org.openecomp.ecompsdkos epsdk-fw @@ -296,7 +315,12 @@ com.fasterxml.jackson.core jackson-databind ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -390,7 +414,12 @@ com.fasterxml.jackson.dataformat jackson-dataformat-yaml ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -437,7 +466,12 @@ de.ruedigermoeller fst 2.47 - compile + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/catalog-be/pom.xml b/catalog-be/pom.xml index 7f34e15c56..47650bd8c7 100644 --- a/catalog-be/pom.xml +++ b/catalog-be/pom.xml @@ -37,18 +37,33 @@ + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + com.fasterxml.jackson.dataformat jackson-dataformat-yaml ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + com.fasterxml.jackson.core jackson-databind ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -63,6 +78,12 @@ io.swagger.core.v3 swagger-jaxrs2 ${swagger.version} + + + com.fasterxml.jackson.core + jackson-core + + io.swagger.core.v3 @@ -75,7 +96,12 @@ org.openecomp.sdc common-app-api ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -95,14 +121,24 @@ org.openecomp.sdc.be catalog-dao ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + org.openecomp.sdc.be catalog-model ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -141,7 +177,12 @@ org.glassfish.jersey.media jersey-media-json-jackson ${jersey-bom.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -510,6 +551,10 @@ com.att.aft dme2 + + com.fasterxml.jackson.core + jackson-core + @@ -672,6 +717,12 @@ org.onap.sdc.common onap-tosca-datatype ${project.version} + + + com.fasterxml.jackson.core + jackson-core + + org.apache.commons @@ -688,11 +739,17 @@ security-util-lib ${security.util.lib.version} - - org.openecomp.sdc.core - openecomp-tosca-lib - ${project.version} - + + org.openecomp.sdc.core + openecomp-tosca-lib + ${project.version} + + + com.fasterxml.jackson.core + jackson-core + + + diff --git a/catalog-dao/pom.xml b/catalog-dao/pom.xml index ba2ec97c3b..06cb1e81a0 100644 --- a/catalog-dao/pom.xml +++ b/catalog-dao/pom.xml @@ -128,6 +128,12 @@ Modifications copyright (c) 2018 Nokia com.fasterxml.jackson.core jackson-databind ${jackson.version} + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/catalog-fe/pom.xml b/catalog-fe/pom.xml index 3781bb59e3..60353a8ec3 100644 --- a/catalog-fe/pom.xml +++ b/catalog-fe/pom.xml @@ -135,7 +135,12 @@ com.fasterxml.jackson.core jackson-databind ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/catalog-model/pom.xml b/catalog-model/pom.xml index 051313602f..98e8c24d26 100644 --- a/catalog-model/pom.xml +++ b/catalog-model/pom.xml @@ -28,6 +28,11 @@ ${junitJupiter.version} test + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + @@ -35,6 +40,12 @@ common-app-api ${project.version} provided + + + com.fasterxml.jackson.core + jackson-core + + @@ -70,6 +81,12 @@ catalog-dao ${project.version} provided + + + com.fasterxml.jackson.core + jackson-core + + @@ -315,7 +332,13 @@ org.openecomp.sdc.core openecomp-tosca-lib ${project.version} - + + + com.fasterxml.jackson.core + jackson-core + + + diff --git a/common-app-api/pom.xml b/common-app-api/pom.xml index 210a9b25a6..323bcf822b 100644 --- a/common-app-api/pom.xml +++ b/common-app-api/pom.xml @@ -113,6 +113,12 @@ jersey-media-json-jackson ${jersey-bom.version} provided + + + com.fasterxml.jackson.core + jackson-annotations + + @@ -142,6 +148,12 @@ jackson-databind ${jackson.version} provided + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/common-be/pom.xml b/common-be/pom.xml index f08154f707..2005537798 100644 --- a/common-be/pom.xml +++ b/common-be/pom.xml @@ -28,12 +28,23 @@ test + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + + org.openecomp.sdc common-app-api ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -68,6 +79,12 @@ jackson-databind ${jackson.version} provided + + + com.fasterxml.jackson.core + jackson-core + + @@ -104,6 +121,12 @@ org.onap.sdc.common onap-tosca-datatype ${tosca.datatype.version} + + + com.fasterxml.jackson.core + jackson-core + + org.onap.sdc.sdc-tosca diff --git a/common/onap-common-configuration-management/onap-configuration-management-core/pom.xml b/common/onap-common-configuration-management/onap-configuration-management-core/pom.xml index eed797829e..1583aa90d0 100755 --- a/common/onap-common-configuration-management/onap-configuration-management-core/pom.xml +++ b/common/onap-common-configuration-management/onap-configuration-management-core/pom.xml @@ -48,6 +48,12 @@ com.fasterxml.jackson.core jackson-databind + + + com.fasterxml.jackson.core + jackson-core + + com.fasterxml.jackson.dataformat diff --git a/common/onap-tosca-datatype/pom.xml b/common/onap-tosca-datatype/pom.xml index 6292c561c1..91b4202b09 100644 --- a/common/onap-tosca-datatype/pom.xml +++ b/common/onap-tosca-datatype/pom.xml @@ -59,10 +59,21 @@ commons-beanutils ${commons-beanutils} + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + com.fasterxml.jackson.core jackson-databind ${jackson.version} + + + com.fasterxml.jackson.core + jackson-core + + org.mockito diff --git a/onboarding/pom.xml b/onboarding/pom.xml index 7d3f967638..c86cca4ef8 100644 --- a/onboarding/pom.xml +++ b/onboarding/pom.xml @@ -91,7 +91,6 @@ 3.0.1-b04 1 2.5 - 2.9.9 ${jackson.version} ${jackson.version} 1.58 @@ -236,6 +235,12 @@ com.fasterxml.jackson.core jackson-databind ${jackson.version} + + + com.fasterxml.jackson.core + jackson-core + + com.fasterxml.jackson.dataformat diff --git a/openecomp-be/backend/openecomp-sdc-security-util/pom.xml b/openecomp-be/backend/openecomp-sdc-security-util/pom.xml index d9370ac6af..9d0c33ee63 100644 --- a/openecomp-be/backend/openecomp-sdc-security-util/pom.xml +++ b/openecomp-be/backend/openecomp-sdc-security-util/pom.xml @@ -37,10 +37,21 @@ 4.7 + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + com.fasterxml.jackson.core jackson-databind - 2.9.9 + ${jackson.version} + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/openecomp-be/lib/openecomp-common-lib/pom.xml b/openecomp-be/lib/openecomp-common-lib/pom.xml index 5a4e78698c..647675f840 100644 --- a/openecomp-be/lib/openecomp-common-lib/pom.xml +++ b/openecomp-be/lib/openecomp-common-lib/pom.xml @@ -54,6 +54,12 @@ com.fasterxml.jackson.core jackson-databind + + + com.fasterxml.jackson.core + jackson-core + + com.amdocs.zusammen diff --git a/pom.xml b/pom.xml index 798ab3aabc..6b04d6f89e 100644 --- a/pom.xml +++ b/pom.xml @@ -67,8 +67,8 @@ Modifications copyright (c) 2018-2019 Nokia 9.4.18.v20190429 - 2.9.9 - 2.9.9 + 2.10.0 + ${jackson.version} 1.9.13 2.1.1 diff --git a/test-apis-ci/pom.xml b/test-apis-ci/pom.xml index 1613c476f6..cfe1ac99ed 100644 --- a/test-apis-ci/pom.xml +++ b/test-apis-ci/pom.xml @@ -306,7 +306,12 @@ com.fasterxml.jackson.core jackson-databind ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/ui-ci/pom.xml b/ui-ci/pom.xml index da09985cca..4c24d2d5d5 100644 --- a/ui-ci/pom.xml +++ b/ui-ci/pom.xml @@ -86,11 +86,22 @@ compile + + com.fasterxml.jackson.core + jackson-core + ${jackson.version} + + org.openecomp.sdc test-apis-ci ${project.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -175,7 +186,12 @@ com.fasterxml.jackson.core jackson-databind ${jackson.version} - compile + + + com.fasterxml.jackson.core + jackson-core + + @@ -261,6 +277,12 @@ to browsermob-core --> browsermob-core 2.1.4 + + + com.fasterxml.jackson.core + jackson-core + + diff --git a/utils/DmaapPublisher/pom.xml b/utils/DmaapPublisher/pom.xml index b2b013e2a2..1a8cf652c2 100644 --- a/utils/DmaapPublisher/pom.xml +++ b/utils/DmaapPublisher/pom.xml @@ -6,11 +6,6 @@ dmaap-publisher 1.0.0 - - - 2.8.6 - - -- 2.16.6