Update vulnerable dependencies 51/127451/10
authorvasraz <vasyl.razinkov@est.tech>
Thu, 3 Mar 2022 11:38:39 +0000 (11:38 +0000)
committerVasyl Razinkov <vasyl.razinkov@est.tech>
Thu, 3 Mar 2022 14:34:04 +0000 (14:34 +0000)
Change-Id: Id1098d2e0aceb3fb507e32994925d36f23ad8517
Signed-off-by: Vasyl Razinkov <vasyl.razinkov@est.tech>
Issue-ID: SDC-3895

asdctool/src/main/java/org/openecomp/sdc/asdctool/App.java
catalog-be/pom.xml
catalog-be/src/main/docker/backend/Dockerfile
catalog-fe/pom.xml
catalog-fe/sdc-frontend/Dockerfile
common/onap-common-configuration-management/onap-configuration-management-core/pom.xml
integration-tests/pom.xml
openecomp-be/dist/sdc-onboard-backend-docker/artifacts/Dockerfile
pom.xml
utils/webseal-simulator/sdc-simulator/Dockerfile

index db541a8..2f7aa0a 100644 (file)
@@ -22,6 +22,7 @@ package org.openecomp.sdc.asdctool;
 import org.eclipse.jetty.server.Server;
 import org.eclipse.jetty.servlet.ServletContextHandler;
 import org.eclipse.jetty.servlet.ServletHolder;
+import org.glassfish.jersey.servlet.ServletContainer;
 
 /**
  * Hello world!
@@ -34,7 +35,7 @@ public class App {
         context.setContextPath("/asdctool");
         Server jettyServer = new Server(Integer.valueOf(asdcToolPort));
         jettyServer.setHandler(context);
-        ServletHolder jerseyServlet = context.addServlet(org.glassfish.jersey.servlet.ServletContainer.class, "/*");
+        ServletHolder jerseyServlet = context.addServlet(ServletContainer.class.getName(), "/*");
         jerseyServlet.setInitOrder(0);
 
         // Tells the Jersey Servlet which REST service/class to load.
@@ -59,4 +60,3 @@ public class App {
         }
     }
 }
-
index 8bf5515..8cddf17 100644 (file)
             <artifactId>esapi</artifactId>
             <version>${org.owasp.esapi.version}</version>
             <exclusions>
-                <exclusion>
-                    <groupId>xerces</groupId>
-                    <artifactId>xercesImpl</artifactId>
-                </exclusion>
                 <exclusion>
                     <groupId>log4j</groupId>
                     <artifactId>log4j</artifactId>
                 </exclusion>
+                <exclusion>
+                    <groupId>commons-io</groupId>
+                    <artifactId>commons-io</artifactId>
+                </exclusion>
                 <exclusion>
                     <groupId>commons-fileupload</groupId>
                     <artifactId>commons-fileupload</artifactId>
                     <groupId>xml-apis</groupId>
                     <artifactId>xml-apis</artifactId>
                 </exclusion>
+                <exclusion>
+                    <groupId>xerces</groupId>
+                    <artifactId>xercesImpl</artifactId>
+                </exclusion>
             </exclusions>
         </dependency>
         <dependency>
index 5e49f57..9026955 100644 (file)
@@ -26,7 +26,7 @@ RUN mkdir $JETTY_FOLDER && chown onap:onap $JETTY_FOLDER
 USER onap
 
 #Download jetty
-RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty.version}/jetty-distribution-${jetty.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
+RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty-distribution.version}/jetty-distribution-${jetty-distribution.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
         tar xvz -C $JETTY_FOLDER -f $JETTY_FOLDER/jetty.tar.gz --strip 1 && \
         rm -rf $JETTY_FOLDER/jetty.tar.gz
 
index b1acef9..e7d6fe6 100644 (file)
                     <groupId>xml-apis</groupId>
                     <artifactId>xml-apis</artifactId>
                 </exclusion>
+                <exclusion>
+                    <groupId>xerces</groupId>
+                    <artifactId>xercesImpl</artifactId>
+                </exclusion>
             </exclusions>
         </dependency>
         <dependency>
index 005e5c9..d0978a9 100644 (file)
@@ -26,7 +26,7 @@ RUN mkdir $JETTY_FOLDER && chown onap:onap $JETTY_FOLDER
 USER onap
 
 #Download jetty
-RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty.version}/jetty-distribution-${jetty.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
+RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty-distribution.version}/jetty-distribution-${jetty-distribution.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
         tar xvz -C $JETTY_FOLDER -f $JETTY_FOLDER/jetty.tar.gz --strip 1 && \
         rm -rf $JETTY_FOLDER/jetty.tar.gz
 RUN sed -i 's/"jetty"/"onap"/g' $JETTY_FOLDER/etc/jetty-setuid.xml
index 02d96fd..f72b776 100755 (executable)
@@ -89,7 +89,7 @@
     <dependency>
       <groupId>io.github.classgraph</groupId>
       <artifactId>classgraph</artifactId>
-      <version>4.8.112</version>
+      <version>4.8.137</version>
     </dependency>
     <dependency>
       <groupId>com.virtlink.commons</groupId>
index 31abb03..a2d03a5 100644 (file)
@@ -333,8 +333,12 @@ limitations under the License.
             <scope>test</scope>
             <exclusions>
                 <exclusion>
-                    <artifactId>log4j</artifactId>
                     <groupId>log4j</groupId>
+                    <artifactId>log4j</artifactId>
+                </exclusion>
+                <exclusion>
+                    <groupId>org.owasp.esapi</groupId>
+                    <artifactId>esapi</artifactId>
                 </exclusion>
             </exclusions>
         </dependency>
index 012ebee..aa9929c 100644 (file)
@@ -27,7 +27,7 @@ RUN mkdir $JETTY_FOLDER && chown onap:onap $JETTY_FOLDER
 USER onap
 
 #Download jetty
-RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty.version}/jetty-distribution-${jetty.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
+RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty-distribution.version}/jetty-distribution-${jetty-distribution.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
         tar xvz -C $JETTY_FOLDER -f $JETTY_FOLDER/jetty.tar.gz --strip 1 && \
         rm -rf $JETTY_FOLDER/jetty.tar.gz
 RUN sed -i 's/"jetty"/"onap"/g' $JETTY_FOLDER/etc/jetty-setuid.xml
diff --git a/pom.xml b/pom.xml
index 57affb7..72d407d 100644 (file)
--- a/pom.xml
+++ b/pom.xml
@@ -47,7 +47,7 @@ Modifications copyright (c) 2018-2019 Nokia
         <lang3.version>3.10</lang3.version>
         <guava.version>30.1-jre</guava.version>
         <janusgraph.version>0.3.3</janusgraph.version>
-        <spring.version>5.3.9</spring.version>
+        <spring.version>5.3.13</spring.version>
         <jersey-bom.version>2.34</jersey-bom.version>
         <netty.version>4.1.68.Final</netty.version>
         <servlet-api.version>4.0.1</servlet-api.version>
@@ -74,7 +74,8 @@ Modifications copyright (c) 2018-2019 Nokia
         <javax.validation.version>2.0.1.Final</javax.validation.version>
         <javax.servlet.version>${servlet-api.version}</javax.servlet.version>
 
-        <jetty.version>9.4.41.v20210516</jetty.version>
+        <jetty.version>9.4.45.v20220203</jetty.version>
+        <jetty-distribution.version>9.4.45.v20220203</jetty-distribution.version>
         <cxf.version>3.4.4</cxf.version>
 
         <org.owasp.esapi.version>2.2.0.0</org.owasp.esapi.version>
@@ -100,7 +101,7 @@ Modifications copyright (c) 2018-2019 Nokia
 
         <!-- Logging start -->
         <!-- logback -->
-        <logback.version>1.2.7</logback.version>
+        <logback.version>1.2.10</logback.version>
         <slf4j-api.version>1.7.25</slf4j-api.version>
         <commons-codec>1.15</commons-codec>
         <commons-logging>1.2</commons-logging>
index 7406cda..6497ff8 100644 (file)
@@ -26,7 +26,7 @@ RUN mkdir $JETTY_FOLDER && chown onap:onap $JETTY_FOLDER
 USER onap
 
 #Download jetty
-RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty.version}/jetty-distribution-${jetty.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
+RUN wget https://repo1.maven.org/maven2/org/eclipse/jetty/jetty-distribution/${jetty-distribution.version}/jetty-distribution-${jetty-distribution.version}.tar.gz -O $JETTY_FOLDER/jetty.tar.gz && \
         tar xvz -C $JETTY_FOLDER -f $JETTY_FOLDER/jetty.tar.gz --strip 1 && \
         rm -rf $JETTY_FOLDER/jetty.tar.gz
 RUN sed -i 's/"jetty"/"onap"/g' $JETTY_FOLDER/etc/jetty-setuid.xml