Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

RepositoryGroupImpact AnalysisAction
ccsdk/appsch.qos.logback

Need to upgrade version to 1.2.0

Plan to upgrade version to 1.2.0, where feasible
ccsdk/apps, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/pluginsch.qos.logback

Need to upgrade version to 1.2.0

Plan to upgrade version to 1.2.0, where feasible
ccsdk/apps, ccsdk/distribution, ccsdk/sli/pluginscom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/parentcom.fasterxml.jackson.coreFixed in version 2.8.6Plan to upgrade to version >= 2.8.6
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorscom.fasterxml.jackson.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorscom.fasterxml.jackson.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/featurescom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/sli/northboundcom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorscom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/parentcom.fasterxml.jackson.coreFixed in version 2.8.8.1Plan to upgrade to version >= 2.8.8.1
ccsdk/apps, ccsdk/distribution, ccsdk/sli/adaptorscom.fasterxml.jackson.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.fasterxml.jackson.dataformatNeed to upgrade to version 2.7.4 or higherPlan to upgrade to version >= 2.7.8
ccsdk/distributioncom.fasterxml.jackson.dataformatNeed to upgrade to version 2.7.8 or higherPlan to upgrade to version >= 2.7.8
ccsdk/distributioncom.flozano.sendgridInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/sli/northboundcom.google.guavaNeed to upgrade to version 23.6.1 or greaterPlan to upgrade to version 23.6.1 or higher
ccsdk/appscom.google.guavaNeed to upgrade to version 23.6.1 or greaterPlan to upgrade to version 23.6.1 or higher
ccsdk/distributioncom.google.guavaInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.google.guavaInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.h2databaseInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.h2databaseInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appscom.h2databaseNo non-vulnerable version existsNeed to find replacement
ccsdk/appscom.h2databaseNo non-vulnerable version existsNeed to find replacement
ccsdk/distributioncom.jcraftInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/sli/adaptorscom.sun.mailNeed to upgrade to version 1.5.3 or greaterPlan to upgrade to version >= 1.5.3
ccsdk/distributioncommons-beanutilsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-beanutilsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-codecInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/sli/pluginscommons-collectionsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-collectionsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-fileuploadInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-fileuploadInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-fileuploadInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distribution, ccsdk/sli/pluginsdom4jNeed to upgrade to version 2.1.1 or higherNeed to upgrade to version 2.1.1 or higher
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/featuresjavax.mailInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionjavax.mailInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/sli/adaptorsjavax.mailInherited from OpenDaylightMust be updated to 1.4.5 to be consistent with ODL
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.activemqInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.activemqInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.faces.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hbaseInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorsorg.apahe.httpcomponentsInherited from OpenDaylightMust be fixed in upstream OpenDaylight

ccsdk/apps, ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/core, ccsdk/sli/northbound, ccsdk/sli/plugins

org.apache.karaf.jaasNeed to upgrade to version 4.5.3 or higherPlan to upgrade to version >= 4.5.3
ccsdk/apps, ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/core, ccsdk/sli/northbound, ccsdk/sli/pliuginsorg.apache.karaf.jaasNeed to upgrade to version 4.3.6 or higherPlan to upgrade to version >= 4.5.3
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.myfaces.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.shiroInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.shiroInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.28 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.23 or laterPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.28 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version > 8.5.16Plan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/distributionorg.apache.zookeeperInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.zookeeperInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.codehaus.jacksonInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.codehaus.jacksonInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.dom4jInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jetty.aggregateInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jetty.aggregateInherited from OpenDaylightMust be fixed in upstream OpenDaylight

ccsdk/apps, ccsdk/distribution

org.hibernateNeed to upgrade to version 5.3.6.Final or laterPlan to upgrade to version >= 5.3.6.Final
ccsdk/distributionorg.infinispanInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.infinispanInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jgroupsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appsorg.liquibaseFalse positive?
CVE refers to jQuery, not liquibase.
Unknown - inadequate information in tool
ccsdk/appsorg.liquibase

False positive?

CVE refers to bootstrap, not liquibase

Unknown - inadequate information in tool
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.webInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.postgresqlInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.17
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.17 or higherPlan to upgrade to version >= 4.3.17
ccsdk/parentorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.17
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.17 or higherPlan to upgrade to version >= 4.3.17
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/pluginsorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.17
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/pluginsorg.springframeworkNeed to upgrade to version 4.3.17 or higherPlan to upgrade to version >= 4.3.17
ccsdk/parentorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/parentorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/distribution, ccsdk/featuresorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.18
ccsdk/distribution, ccsdk/featuresorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframework.bootNeed to upgrade to version 1.5.10 or highrerPlan to upgrade to version >= 1.5.10
ccsdk/appsorg.springframework.dataNeed to upgrade to version 1.3.10 or higherPlan to upgrade version >= 1.3.12
ccsdk/appsorg.springframework.dataNeed to upgrade to version 1.3.11 or higherPlan to upgrade version >= 1.3.12
ccsdk/appsorg.springframework.dataNeed to upgrade to version 1.3.12 or higherPlan to upgrade version >= 1.3.12
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight

ccsdk/apps, ccsdk/distribution

N/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionN/AInherited from OpenDaylightMust be fixed in upstream OpenDaylight

Sample of CLM Report

Security-Vulnerability ThreadImage Removed