Fix critical security issues 79/63979/1
authorromaingimbert <romain.gimbert@orange.com>
Fri, 31 Aug 2018 12:01:39 +0000 (14:01 +0200)
committerromaingimbert <romain.gimbert@orange.com>
Fri, 31 Aug 2018 12:01:39 +0000 (14:01 +0200)
-change pom dependencies version

Change-Id: I053f46b33aeb61e10e390af039dcf19c8247b651
Issue-ID: EXTAPI-126
Signed-off-by: romaingimbert <romain.gimbert@orange.com>
pom.xml

diff --git a/pom.xml b/pom.xml
index 8c849e3..e7768ff 100644 (file)
--- a/pom.xml
+++ b/pom.xml
                                        <groupId>ch.qos.logback</groupId>
                                        <artifactId>logback-classic</artifactId>
                                </exclusion>
+                               <exclusion>
+                                       <groupId>org.apache.tomcat.embed</groupId>
+                                       <artifactId>tomcat-embed-core</artifactId>
+                               </exclusion>
                        </exclusions>
                </dependency>
 
+               <dependency>
+                       <groupId>org.apache.tomcat.embed</groupId>
+                       <artifactId>tomcat-embed-core</artifactId>
+                       <version>8.5.33</version>
+               </dependency>
+
                <dependency>
                        <groupId>ch.qos.logback</groupId>
                        <artifactId>logback-classic</artifactId>
                <dependency>
                        <groupId>org.springframework.boot</groupId>
                        <artifactId>spring-boot-starter-data-jpa</artifactId>
+      <exclusions>
+        <exclusion>
+                                       <groupId>org.springframework.data</groupId>
+                                       <artifactId>spring-data-commons</artifactId>
+        </exclusion>
+      </exclusions>
                </dependency>
 
-        <dependency>
-            <groupId>org.springframework.boot</groupId>
-            <artifactId>spring-boot-starter-aop</artifactId>
-        </dependency>
+               <dependency>
+                       <groupId>org.springframework.data</groupId>
+                       <artifactId>spring-data-commons</artifactId>
+                       <version>1.13.14.RELEASE</version>
+               </dependency>
+
+               <dependency>
+                               <groupId>org.springframework.boot</groupId>
+                               <artifactId>spring-boot-starter-aop</artifactId>
+               </dependency>
 
                <dependency>
                        <groupId>org.apache.commons</groupId>
                <dependency>
                        <groupId>commons-beanutils</groupId>
                        <artifactId>commons-beanutils</artifactId>
-                       <version>1.9.3</version>
+                       <version>1.9.0</version>
                </dependency>
 
                <dependency>
                <dependency>
                        <groupId>com.fasterxml.jackson.dataformat</groupId>
                        <artifactId>jackson-dataformat-yaml</artifactId>
-                       <version>2.8.11</version>
+                       <version>2.9.6</version>
                </dependency>
 
                <!-- jolt -->