From eae3e8b357d96bff29ce0b3086aed388754feaf2 Mon Sep 17 00:00:00 2001 From: Dominik Mizyn Date: Fri, 18 Oct 2019 14:43:07 +0200 Subject: Security Vulnerability in pom.xml fix Security Vulnerability in pom.xml fix Issue-ID: PORTAL-772 Change-Id: I6b0932122b101411b06d371e757918875529b87d Signed-off-by: Dominik Mizyn --- ecomp-sdk/epsdk-aaf/pom.xml | 4 ++-- ecomp-sdk/epsdk-analytics/pom.xml | 4 ++-- .../org/onap/portalsdk/analytics/system/DbUtils.java | 3 +-- ecomp-sdk/epsdk-app-common/pom.xml | 14 +++++++------- .../onap/portalapp/util/SecurityXssValidator.java | 4 ++-- ecomp-sdk/epsdk-app-os/pom.xml | 8 ++++---- ecomp-sdk/epsdk-core/pom.xml | 20 ++++++++++---------- ecomp-sdk/epsdk-domain/pom.xml | 2 +- ecomp-sdk/epsdk-fw/pom.xml | 6 +++--- ecomp-sdk/epsdk-logger/pom.xml | 2 +- ecomp-sdk/epsdk-music/pom.xml | 2 +- ecomp-sdk/epsdk-workflow/pom.xml | 4 ++-- 12 files changed, 36 insertions(+), 37 deletions(-) diff --git a/ecomp-sdk/epsdk-aaf/pom.xml b/ecomp-sdk/epsdk-aaf/pom.xml index 9d10e9bb..036b5e4a 100644 --- a/ecomp-sdk/epsdk-aaf/pom.xml +++ b/ecomp-sdk/epsdk-aaf/pom.xml @@ -19,7 +19,7 @@ UTF-8 - 4.2.0.RELEASE + 4.3.20.RELEASE @@ -108,7 +108,7 @@ org.springframework.boot spring-boot-starter - 1.3.0.RELEASE + 1.3.1.RELEASE org.slf4j diff --git a/ecomp-sdk/epsdk-analytics/pom.xml b/ecomp-sdk/epsdk-analytics/pom.xml index dcffc4ce..26821ded 100644 --- a/ecomp-sdk/epsdk-analytics/pom.xml +++ b/ecomp-sdk/epsdk-analytics/pom.xml @@ -45,7 +45,7 @@ com.fasterxml.jackson.core jackson-databind - 2.8.10 + 2.8.11.4 @@ -146,7 +146,7 @@ org.apache.poi poi-scratchpad - 3.14 + 3.17 commons-logging diff --git a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/system/DbUtils.java b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/system/DbUtils.java index 67acdf9e..d528dc6d 100644 --- a/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/system/DbUtils.java +++ b/ecomp-sdk/epsdk-analytics/src/main/java/org/onap/portalsdk/analytics/system/DbUtils.java @@ -45,7 +45,6 @@ import java.sql.SQLException; import java.sql.Statement; import java.sql.Types; import javax.sql.DataSource; -import org.apache.commons.lang3.StringUtils; import org.onap.portalsdk.analytics.error.RaptorException; import org.onap.portalsdk.analytics.error.ReportSQLException; import org.onap.portalsdk.analytics.model.runtime.ReportRuntime; @@ -213,7 +212,7 @@ public class DbUtils { try (final Connection con = getConnection();) { if (con != null) { try (final PreparedStatement preparedStatement = con.prepareStatement(sql);) { - if (StringUtils.isNotBlank(reportID)) { + if (!reportID.isEmpty()) { preparedStatement.setString(1, reportID); preparedStatement.setString(2, reportName); } else { diff --git a/ecomp-sdk/epsdk-app-common/pom.xml b/ecomp-sdk/epsdk-app-common/pom.xml index 473c942a..2d0bf371 100644 --- a/ecomp-sdk/epsdk-app-common/pom.xml +++ b/ecomp-sdk/epsdk-app-common/pom.xml @@ -128,7 +128,7 @@ com.att.eelf eelf-core - 1.0.0 + 1.0.0-oss @@ -149,12 +149,12 @@ com.mchange c3p0 - 0.9.5.3 + 0.9.5.4 io.searchbox jest - 2.0.0 + 5.3.4 commons-logging @@ -176,7 +176,7 @@ org.elasticsearch elasticsearch - 7.1.1 + 7.2.1 org.apache.lucene @@ -246,7 +246,7 @@ org.owasp.esapi esapi - 2.1.0.1 + 2.2.0.0 commons-beanutils @@ -346,7 +346,7 @@ commons-beanutils commons-beanutils - 1.9.3 + 1.9.4 org.apache.httpcomponents @@ -361,7 +361,7 @@ xerces xercesImpl - 2.11.0.SP5 + 2.12.0 commons-collections diff --git a/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java b/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java index 69807a1c..c964712d 100644 --- a/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java +++ b/ecomp-sdk/epsdk-app-common/src/main/java/org/onap/portalapp/util/SecurityXssValidator.java @@ -43,8 +43,8 @@ import java.util.concurrent.locks.Lock; import java.util.concurrent.locks.ReentrantLock; import java.util.regex.Pattern; import org.apache.commons.lang.NotImplementedException; +import org.apache.commons.lang.StringEscapeUtils; import org.apache.commons.lang.StringUtils; -import org.apache.commons.lang3.StringEscapeUtils; import org.onap.portalsdk.core.logging.logic.EELFLoggerDelegate; import org.onap.portalsdk.core.util.SystemProperties; import org.owasp.esapi.ESAPI; @@ -132,7 +132,7 @@ public class SecurityXssValidator { if (StringUtils.isNotBlank(value)) { - value = StringEscapeUtils.escapeHtml4(value); + value = StringEscapeUtils.escapeHtml(value); value = ESAPI.encoder().canonicalize(value); diff --git a/ecomp-sdk/epsdk-app-os/pom.xml b/ecomp-sdk/epsdk-app-os/pom.xml index cfdcb244..52690916 100644 --- a/ecomp-sdk/epsdk-app-os/pom.xml +++ b/ecomp-sdk/epsdk-app-os/pom.xml @@ -423,7 +423,7 @@ com.att.eelf eelf-core - 1.0.0 + 1.0.0-oss @@ -444,12 +444,12 @@ com.mchange c3p0 - 0.9.5.2 + 0.9.5.4 io.searchbox jest - 2.0.0 + 5.3.2 commons-logging @@ -471,7 +471,7 @@ org.elasticsearch elasticsearch - 2.2.0 + 6.8.2 org.apache.lucene diff --git a/ecomp-sdk/epsdk-core/pom.xml b/ecomp-sdk/epsdk-core/pom.xml index be08cc3e..565867dd 100644 --- a/ecomp-sdk/epsdk-core/pom.xml +++ b/ecomp-sdk/epsdk-core/pom.xml @@ -185,7 +185,7 @@ org.hibernate hibernate-validator - 5.1.3.Final + 5.2.1.Final @@ -228,7 +228,7 @@ com.mchange c3p0 - 0.9.5.3 + 0.9.5.4 @@ -261,7 +261,7 @@ com.fasterxml.jackson.core jackson-databind - 2.8.10 + 2.8.11.4 @@ -285,7 +285,7 @@ org.apache.tomcat tomcat-websocket - 8.0.28 + 8.0.52 provided @@ -344,7 +344,7 @@ org.elasticsearch elasticsearch - 2.2.0 + 6.8.2 org.apache.lucene @@ -355,7 +355,7 @@ io.searchbox jest - 2.0.0 + 5.3.2 commons-logging @@ -367,13 +367,13 @@ com.att.eelf eelf-core - 1.0.0 + 1.0.0-oss org.owasp.esapi esapi - 2.1.0.1 + 2.2.0.0 commons-beanutils @@ -434,7 +434,7 @@ com.thoughtworks.xstream xstream - 1.4.10 + 1.4.11 org.apache.wicket @@ -459,7 +459,7 @@ commons-beanutils commons-beanutils - 1.9.2 + 1.9.4 org.apache.poi diff --git a/ecomp-sdk/epsdk-domain/pom.xml b/ecomp-sdk/epsdk-domain/pom.xml index 327e51de..f1b554e3 100644 --- a/ecomp-sdk/epsdk-domain/pom.xml +++ b/ecomp-sdk/epsdk-domain/pom.xml @@ -33,7 +33,7 @@ com.fasterxml.jackson.core jackson-databind - 2.8.10 + 2.8.11.4 org.mockito diff --git a/ecomp-sdk/epsdk-fw/pom.xml b/ecomp-sdk/epsdk-fw/pom.xml index 6c2b283c..1c29ceab 100644 --- a/ecomp-sdk/epsdk-fw/pom.xml +++ b/ecomp-sdk/epsdk-fw/pom.xml @@ -17,7 +17,7 @@ - 3.0.18.Final + 3.1.0.Final 1.7.4 @@ -108,12 +108,12 @@ com.fasterxml.jackson.core jackson-databind - 2.8.10 + 2.8.11.3 org.owasp.esapi esapi - 2.1.0.1 + 2.2.0.0 log4j diff --git a/ecomp-sdk/epsdk-logger/pom.xml b/ecomp-sdk/epsdk-logger/pom.xml index 3f0f7df0..b7e0b644 100644 --- a/ecomp-sdk/epsdk-logger/pom.xml +++ b/ecomp-sdk/epsdk-logger/pom.xml @@ -17,7 +17,7 @@ com.att.eelf eelf-core - 1.0.0 + 1.0.0-oss javax.servlet diff --git a/ecomp-sdk/epsdk-music/pom.xml b/ecomp-sdk/epsdk-music/pom.xml index 5c442a91..cfbc41c1 100644 --- a/ecomp-sdk/epsdk-music/pom.xml +++ b/ecomp-sdk/epsdk-music/pom.xml @@ -18,7 +18,7 @@ UTF-8 - 4.2.3.RELEASE + 4.3.20.RELEASE 1.19.4 2.0.1 3.0.0 diff --git a/ecomp-sdk/epsdk-workflow/pom.xml b/ecomp-sdk/epsdk-workflow/pom.xml index 707e1fb1..f08b65f8 100644 --- a/ecomp-sdk/epsdk-workflow/pom.xml +++ b/ecomp-sdk/epsdk-workflow/pom.xml @@ -40,7 +40,7 @@ com.fasterxml.jackson.core jackson-databind - 2.8.10 + 2.8.11.4 javax.servlet @@ -55,7 +55,7 @@ org.hibernate hibernate-validator - 5.1.3.Final + 5.2.1.Final org.json -- cgit 1.2.3-korg