Fixed security vulnerability 53/110553/1
authorjitendra007 <jitendra.sharma1@huawei.com>
Fri, 24 Jul 2020 13:05:06 +0000 (18:35 +0530)
committerjitendra007 <jitendra.sharma1@huawei.com>
Fri, 24 Jul 2020 13:07:54 +0000 (18:37 +0530)
Issue-ID: CLI-299

Signed-off-by: jitendra007 <jitendra.sharma1@huawei.com>
Change-Id: I634c42dfce01192e65b1102147953156e5828421

framework/pom.xml
grpc/pom.xml
profiles/http/pom.xml

index 9878cd8..cd9d90e 100644 (file)
@@ -74,7 +74,7 @@
         <dependency>
             <groupId>commons-codec</groupId>
             <artifactId>commons-codec</artifactId>
-            <version>1.13</version>
+            <version>1.14</version>
         </dependency>
         <dependency>
             <groupId>org.apache.commons</groupId>
index 0055d2b..cd31b2e 100644 (file)
         <groupId>io.netty</groupId>
         <artifactId>netty-codec-http2</artifactId>
         <version>4.1.46.Final</version>
+        <exclusions>
+            <exclusion>
+                <groupId>io.netty</groupId>
+                <artifactId>netty-codec-http</artifactId>
+            </exclusion>
+            <exclusion>
+                <groupId>io.netty</groupId>
+                <artifactId>netty-handler</artifactId>
+            </exclusion>
+        </exclusions>
     </dependency>
-      
-    <dependency>
+      <dependency>
+          <groupId>io.netty</groupId>
+          <artifactId>netty-codec-http</artifactId>
+          <version>4.1.48.Final</version>
+      </dependency>
+      <dependency>
+          <groupId>io.netty</groupId>
+          <artifactId>netty-handler</artifactId>
+          <version>4.1.19.Final</version>
+      </dependency>
+
+      <dependency>
       <groupId>io.grpc</groupId>
       <artifactId>grpc-protobuf</artifactId>
       <version>${grpc.version}</version>
index 0458941..3dee45c 100644 (file)
@@ -63,7 +63,7 @@ Excluded commons-codec vulnerable version and added invulnerable version
       <dependency>
           <groupId>commons-codec</groupId>
           <artifactId>commons-codec</artifactId>
-          <version>1.13</version>
+          <version>1.14</version>
       </dependency>
         <dependency>
           <groupId>org.apache.httpcomponents</groupId>