This template is intended to be used to document the outcome of the impact analysis related to the known vulnerability reported by Nexus-IQ (CLM tab in Jenkins).  Nexus-IQ can identify the known vulnerabilities contained in the components use by ONAP components.

This table will be presented to the TSC at Code Freeze milestone (M4).

It is recommended to first update to the latest version of the third party components available. In case the latest third party components still reports some vulnerabilities, you must provide an impact analysis as illustrated in the example below.

In the case where you have nested third party components (a third party component embedding another third party component) and there is NO CVE number for the upstream third party component (meaning the third party component you are embedding), it is recommended to open a vulnerability issue on the upstream third party component.

The following table is addressing 2 different scenarios:

  • Confirmation of a vulnerability including an action
  • False Positive

The information related to Repository and Group are extracted from the CLM report.

RepositoryGroupImpact AnalysisAction
vid

angular.min.js

angular.js

Its source is in ONAP Portal SDK

Request exception

vidbouncycastle

Its source is in ONAP Portal SDK

Request exception


vidcom.fasterxml.jackson.core

False positive

VID doesn't use createBeanDeserializer() function in the BeanDeserializerFactory class

False positive

vidcommons-beanutils

No fix is available for this vulnerability;

Its source is in ONAP Portal SDK

Request exception


vidmoment

No fix is available for this vulnerability;

Its source is in ONAP Portal SDK

Request exception

vidorg.apache.httpcomponents

Its source is in ONAP Portal SDK

Request exception

vidorg.codehaus.jackson

False positive

VID doesn't use the problematic function createBeanDeserializer in the BeanDeserializerFactory class

No fix is available for this vulnerability

False positive

vidxercesIts source is in ONAP Portal SDK

Request exception

vidorg.hibernateIts source is in ONAP Portal SDK

Request exception

vidorg.eclipse.jetty

False positive

VID doesn't use the check function in Password.java file

False positive
vidcom.google.guavaIts source is in ONAP Portal SDKRequest exception
vidcommons-codec Its source is in ONAP Portal SDKRequest exception
viddom4jIts source is in ONAP Portal SDKRequest exception
vid jquery

Under investigation VID-309 - Getting issue details... STATUS


vidorg.apache.wicketIts source is in ONAP Portal SDKRequest exception
vidorg.springframework Its source is in ONAP Portal SDKRequest exception
vidorg.springframework Its source is in ONAP Portal SDKRequest exception
vidorg.springframework Its source is in ONAP Portal SDKRequest exception
vidorg.springframework Its source is in ONAP Portal SDKRequest exception
vid org.owasp.esapi Its source is in ONAP Portal SDKRequest exception
vidorg.owasp.antisamyIts source is in ONAP Portal SDKRequest exception
vidorg.eclipse.jetty

Under investigation VID-309 - Getting issue details... STATUS