Fix Security Vulnerabilities for TCAgen2 43/122743/2
authorsumithra <sumithra.s69@wipro.com>
Tue, 20 Jul 2021 12:08:00 +0000 (12:08 +0000)
committerSumithra S <sumithra.s69@wipro.com>
Wed, 21 Jul 2021 05:51:52 +0000 (05:51 +0000)
Issue-ID: DCAEGEN2-2803
Signed-off-by: Sumithra <sumithra.s69@wipro.com>
Change-Id: I972695de49590c265b68078fd26b8a08ac6a972d

dcae-analytics/dcae-analytics-tca-web/pom.xml
dcae-analytics/dcae-analytics-web/pom.xml

index d6421e2..0a1b994 100644 (file)
@@ -4,6 +4,7 @@
   ~ Copyright (c) 2018-2020 AT&T Intellectual Property. All rights reserved.
   ~ Copyright (c) 2021 Samsung Electronics. All rights reserved.
   ~ Copyright (c) 2021 Nokia Intellectual Property. All rights reserved.
+  ~ Copyright (c) 2021 Wipro Limited.
   ~ ================================================================================
   ~ Modifications Copyright (C) 2019 IBM
   ~ ================================================================================
@@ -42,8 +43,9 @@
     <description>Contains Web related code for TCA</description>
 
     <properties>
-        <main.basedir>${project.parent.basedir}</main.basedir>
-        <docker.image.name>onap/${project.groupId}.${project.artifactId}</docker.image.name>
+           <main.basedir>${project.parent.basedir}</main.basedir>
+           <undertow-core.version>2.2.7.Final</undertow-core.version>
+           <docker.image.name>onap/${project.groupId}.${project.artifactId}</docker.image.name>
     <maven.build.timestamp.format>yyyyMMdd'T'HHmmss</maven.build.timestamp.format>
     </properties>
 
@@ -67,7 +69,7 @@
             <exclusions>
                 <exclusion>
                     <groupId>io.undertow</groupId>
-                    <artifactId>undertow-core</artifactId>
+                   <artifactId>undertow-core</artifactId>
               </exclusion>
             </exclusions>
         </dependency>
         <!-- https://mvnrepository.com/artifact/io.undertow/undertow-core -->
         <dependency>
             <groupId>io.undertow</groupId>
-            <artifactId>undertow-core</artifactId>
+           <artifactId>undertow-core</artifactId>
+           <version>${undertow-core.version}</version>
         </dependency>
 
     </dependencies>
index ef90b03..5d79faf 100644 (file)
@@ -4,6 +4,7 @@
   ~ Copyright (c) 2018-2019 AT&T Intellectual Property. All rights reserved.
   ~ Copyright (c) 2021 Samsung Electronics. All rights reserved.
   ~ Copyright (c) 2021 Nokia Intellectual Property. All rights reserved.
+  ~ Copyright (c) 2021 Wipro Limited.
   ~ ================================================================================
   ~ Licensed under the Apache License, Version 2.0 (the "License");
   ~ you may not use this file except in compliance with the License.
@@ -40,7 +41,9 @@
     <description>Contains common web code for all DCAE Analytics Modules</description>
 
     <properties>
-        <main.basedir>${project.parent.basedir}</main.basedir>
+           <main.basedir>${project.parent.basedir}</main.basedir>
+           <undertow-core.version>2.2.7.Final</undertow-core.version>
+           <httpclient.version>4.5.13</httpclient.version>
     </properties>
 
 
             <exclusions>
                 <exclusion>
                     <groupId>org.springframework.boot</groupId>
-                    <artifactId>spring-boot-starter-tomcat</artifactId>
+                   <artifactId>spring-boot-starter-tomcat</artifactId>
                 </exclusion>
                 <exclusion>
                     <groupId>io.undertow</groupId>
-                    <artifactId>undertow-core</artifactId>
+                   <artifactId>undertow-core</artifactId>
                 </exclusion>
             </exclusions>
         </dependency>
@@ -86,7 +89,7 @@
             <exclusions>
                 <exclusion>
                     <groupId>io.undertow</groupId>
-                    <artifactId>undertow-websockets-jsr</artifactId>
+                   <artifactId>undertow-websockets-jsr</artifactId>
                 </exclusion>
             </exclusions>
         </dependency>
         <!-- APACHE HTTP CLIENT -->
         <dependency>
             <groupId>org.apache.httpcomponents</groupId>
-            <artifactId>httpclient</artifactId>
+           <artifactId>httpclient</artifactId>
+           <version>${httpclient.version}</version>
         </dependency>
 
         <!-- UTILITIES -->
          <!-- https://mvnrepository.com/artifact/io.undertow/undertow-core -->
         <dependency>
             <groupId>io.undertow</groupId>
-            <artifactId>undertow-core</artifactId>
+           <artifactId>undertow-core</artifactId>
+           <version>${undertow-core.version}</version>
         </dependency>
 
     </dependencies>