Fix security issues 51/40651/1
authorSonsino, Ofir (os0695) <os0695@intl.att.com>
Tue, 3 Apr 2018 07:53:27 +0000 (10:53 +0300)
committerSonsino, Ofir (os0695) <os0695@intl.att.com>
Tue, 3 Apr 2018 07:53:27 +0000 (10:53 +0300)
Change-Id: I9d003e30920e7cb57143743f260e4ae2a8ba52d6
Issue-ID: VID-149
Signed-off-by: Sonsino, Ofir (os0695) <os0695@intl.att.com>
epsdk-app-onap/pom.xml
pom.xml
vid-app-common/pom.xml

index 646c017..e5b88ba 100755 (executable)
@@ -18,7 +18,7 @@
                <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>\r
                <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>\r
                <epsdk.version>2.1.0</epsdk.version>\r
-               <springframework.version>4.2.4.RELEASE</springframework.version>\r
+               <springframework.version>4.2.9.RELEASE</springframework.version>\r
                <hibernate.version>4.3.11.Final</hibernate.version>\r
                <!-- Skip assembling the zip; assemble via mvn -Dskipassembly=false .. -->\r
                <skipassembly>true</skipassembly>\r
                        <artifactId>epsdk-app-common</artifactId>\r
                        <version>${epsdk.version}</version>\r
                        <type>jar</type>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>commons-fileupload</groupId>\r
+                                       <artifactId>commons-fileupload</artifactId>\r
+                               </exclusion>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
+               </dependency>\r
+               <!--Upgrade fileupload version-->\r
+               <dependency>\r
+                       <groupId>commons-fileupload</groupId>\r
+                       <artifactId>commons-fileupload</artifactId>\r
+                       <version>1.3.3</version>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.vid</groupId>\r
                        <artifactId>vid-app-common</artifactId>\r
                        <version>${project.version}</version>\r
                        <type>war</type>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.vid</groupId>\r
                        <groupId>org.onap.portal.sdk</groupId>\r
                        <artifactId>epsdk-core</artifactId>\r
                        <version>${epsdk.version}</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.portal.sdk</groupId>\r
                        <artifactId>epsdk-analytics</artifactId>\r
                        <version>${epsdk.version}</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.onap.portal.sdk</groupId>\r
                        <artifactId>epsdk-workflow</artifactId>\r
                        <version>${epsdk.version}</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>com.att.eelf</groupId>\r
                        <groupId>com.fasterxml.jackson.core</groupId>\r
                        <artifactId>jackson-databind</artifactId>\r
                        <version>2.6.7.1</version>\r
+                       <exclusions>\r
+                               <exclusion>\r
+                                       <groupId>com.fasterxml.jackson.core</groupId>\r
+                                       <artifactId>jackson-core</artifactId>\r
+                               </exclusion>\r
+                       </exclusions>\r
                </dependency>\r
                <dependency>\r
                        <groupId>com.mchange</groupId>\r
                        <artifactId>junit</artifactId>\r
                        <version>4.12</version>\r
                </dependency>\r
-               <!-- Elastic Search -->\r
-               <dependency>\r
-                       <groupId>org.elasticsearch</groupId>\r
-                       <artifactId>elasticsearch</artifactId>\r
-                       <version>2.2.0</version>\r
-               </dependency>\r
                <dependency>\r
                        <groupId>org.json</groupId>\r
                        <artifactId>json</artifactId>\r
diff --git a/pom.xml b/pom.xml
index e4dd40c..231d2cf 100644 (file)
--- a/pom.xml
+++ b/pom.xml
                        <artifactId>commons-fileupload</artifactId>\r
                        <version>1.3.3</version>\r
                </dependency>\r
-               <dependency>\r
-                       <groupId>org.bouncycastle</groupId>\r
-                       <artifactId>bcprov-jdk16</artifactId>\r
-                       <version>1.46</version>\r
-               </dependency>\r
-               <dependency>\r
-                       <groupId>xalan</groupId>\r
-                       <artifactId>xalan</artifactId>\r
-                       <version>2.7.2</version>\r
-               </dependency>\r
                <dependency>\r
                        <groupId>org.apache.poi</groupId>\r
                        <artifactId>poi</artifactId>\r
-                       <version>3.15</version>\r
-               </dependency>\r
-               <dependency>\r
-                       <groupId>com.thoughtworks.xstream</groupId>\r
-                       <artifactId>xstream</artifactId>\r
-                       <version>1.4.10</version>\r
+                       <version>3.17</version>\r
                </dependency>\r
                <dependency>\r
                        <groupId>org.apache.httpcomponents</groupId>\r
                        <artifactId>httpclient</artifactId>\r
                        <version>4.5.3</version>\r
                </dependency>\r
-               <dependency>\r
-                       <groupId>com.fasterxml.jackson.core</groupId>\r
-                       <artifactId>jackson-core</artifactId>\r
-                       <version>2.8.6</version>\r
-               </dependency>\r
-               <dependency>\r
-                       <groupId>xerces</groupId>\r
-                       <artifactId>xercesImpl</artifactId>\r
-                       <version>2.11.0.SP5</version>\r
-               </dependency>\r
        </dependencies>\r
        <version>1.2.1-SNAPSHOT</version>\r
 </project>\r
index de0e0d2..7a48522 100755 (executable)
@@ -19,7 +19,7 @@
                <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>\r
                <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>\r
                <epsdk.version>2.1.0</epsdk.version>\r
-               <springframework.version>4.2.4.RELEASE</springframework.version>\r
+               <springframework.version>4.2.9.RELEASE</springframework.version>\r
                <hibernate.version>4.3.11.Final</hibernate.version>\r
                <!-- Skip assembling the zip by default -->\r
                <skipassembly>true</skipassembly>\r
                <dependency>\r
                        <groupId>com.fasterxml.jackson.core</groupId>\r
                        <artifactId>jackson-core</artifactId>\r
-                       <version>2.6.3</version>\r
+                       <version>2.8.6</version>\r
                </dependency>\r
                <dependency>\r
                        <groupId>com.fasterxml.jackson.core</groupId>\r