From 98794615f346c753a94fa5f63f7cbc67792af4c1 Mon Sep 17 00:00:00 2001 From: Amichai Hemli Date: Mon, 16 Sep 2019 10:53:47 +0300 Subject: [PATCH] Upgrade FasterXML/Jackson to version 2.9.9.3 FasterXML jackson-databind versions 2.x through 2.9.9.1 are vulnerable. we will use 2.9.9.3 for jackson-databind only Issue-ID: VID-640 Signed-off-by: Amichai Hemli Change-Id: I537cb83ad787522b75fdee59ffabb51def747096 --- epsdk-app-onap/pom.xml | 3 ++- vid-app-common/pom.xml | 3 ++- vid-automation/pom.xml | 3 ++- vid-ext-services-simulator/pom.xml | 5 +++-- vid-webpack-master/pom.xml | 1 - 5 files changed, 9 insertions(+), 6 deletions(-) diff --git a/epsdk-app-onap/pom.xml b/epsdk-app-onap/pom.xml index 5cab377c8..f9b55f0e6 100755 --- a/epsdk-app-onap/pom.xml +++ b/epsdk-app-onap/pom.xml @@ -26,6 +26,7 @@ UTF-8 2.5.0 2.9.9 + 2.9.9.3 5.1.9.RELEASE 4.3.11.Final 2.9.9 + 2.9.9.3 2.29 2.22.1 3.141.59 @@ -617,7 +618,7 @@ com.fasterxml.jackson.core jackson-databind - ${jackson.version} + ${jackson.databind.version} com.fasterxml.jackson.module diff --git a/vid-automation/pom.xml b/vid-automation/pom.xml index 81ec4a6d8..6f2ae22c2 100644 --- a/vid-automation/pom.xml +++ b/vid-automation/pom.xml @@ -9,6 +9,7 @@ 5.1.9.RELEASE 2.29 2.9.9 + 2.9.9.3 1.8.10 3.6.0 2.12.0 @@ -161,7 +162,7 @@ com.fasterxml.jackson.core jackson-databind - ${jackson.version} + ${jackson.databind.version} commons-beanutils diff --git a/vid-ext-services-simulator/pom.xml b/vid-ext-services-simulator/pom.xml index 8cb3c37b8..b3179cf5e 100644 --- a/vid-ext-services-simulator/pom.xml +++ b/vid-ext-services-simulator/pom.xml @@ -14,7 +14,8 @@ UTF-8 5.1.9.RELEASE 5.3.4.Final - 2.9.8 + 2.9.9 + 2.9.9.3 true @@ -142,7 +143,7 @@ com.fasterxml.jackson.core jackson-databind - ${jackson.version} + ${jackson.databind.version} javax.xml.bind diff --git a/vid-webpack-master/pom.xml b/vid-webpack-master/pom.xml index f54142854..9e7dd0da6 100644 --- a/vid-webpack-master/pom.xml +++ b/vid-webpack-master/pom.xml @@ -18,7 +18,6 @@ UTF-8 - true -- 2.16.6