Fix vulnerability issue: upgrade org.apache.tomcat.embed.tomcat-embed-core to 8.5.42 75/93275/1
authorPrudence Au <prudence.au@amdocs.com>
Sun, 11 Aug 2019 20:41:07 +0000 (16:41 -0400)
committerPrudence Au <prudence.au@amdocs.com>
Sun, 11 Aug 2019 20:42:56 +0000 (16:42 -0400)
Issue-ID: LOG-1066
Signed-off-by: Prudence Au <prudence.au@amdocs.com>
Change-Id: I9ede69b718fe177abdd7e56ceb430fd3a7d3ec70

reference/logging-slf4j-demo/pom.xml

index e3989e0..c10f570 100644 (file)
@@ -16,7 +16,7 @@
              spring-expression 4.3.14 goes to 4.3.17 under 1.5.15
              1.5.17 ups jackson-databind from 2.8.11.2 - but we will likely need 2.9+
          -->
-        <springframework.boot.version>2.0.3.RELEASE</springframework.boot.version>
+        <springframework.boot.version>1.5.22.RELEASE</springframework.boot.version>
         <spring.version>5.1.2.RELEASE</spring.version>
         <logback.version>1.2.3</logback.version>
     </properties>
                 <version>${springframework.boot.version}</version>
                 <type>pom</type>
                 <scope>import</scope>
+                <exclusions>
+                    <exclusion>
+                        <groupId>org.apache.tomcat.embed</groupId>
+                        <artifactId>tomcat-embed-websocket</artifactId>
+                    </exclusion>
+                </exclusions>
             </dependency>
             <dependency>
                 <groupId>org.apache.commons</groupId>