Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

distributionRequest Integration team to upgrade guava
RepositoryGroupImpact AnalysisAction
policy/commoncom.fasterxml.jackson.coreFalse Positive - we are not using the Jackson code in the manner that exposes the vulnerability.Request exception
policy/commonjavax.jms

This is a license issue that is brought in due to inclusion of DMaap client.

Request exceptioncom.fasterxml.jackson.datatype

False Positive - we are not using any DurationDeserializer or InstantDeserializer

policy/commonorg.json

This is a license issue that is brought in due to inclusion of Cambria client.

Request exception






policy/

common
org.checkerframework

This is a license issue that is brought in from google.guava

There is an MIT license associated with it.

Request Integration team to upgrade guava

or

LF to override

drools-pdp

policy/drools-applications

policy/distribution

policy/engine


com.fasterxml.jackson.core

False Positive - flagged due to inclusion inheritance of policy/common

Request exception

policy/drools-applications

javax.jmsThis is a license issue that is brought in due to inclusion of DMaap client.Request exception

pdp

policy/drools-applications

org.jsonThis is a license issue that is brought in due to inclusion of Cambria client.
Request exception
policy/drools-applicationscom.att.research.xacmlFalse positive - MIT license should be acceptableRequest exception or LF to override
policy/drools-applicationsorg.checkerframeworkThis is a license issue that is brought in from google.guavaRequest Integration team to upgrade guava
policy/drools-applicationsxml-apisFalse positive - Apache 2.0 license should be acceptableRequest LF to select correct license

policy/distribution

policy/engine

policy/drools-pdpcom.fasterxml.jackson.coredatatypeFalse Positive - flagged due to inclusion inheritance of policy/common

Request exception

policy/drools-pdp

javax.jmsThis is a license issue that is brought in due to inclusion of DMaap client.Request exception
policy/drools-pdporg.jsonThis is a license issue that is brought in due to inclusion of Cambria client.

Request exception





policy/drools-pdpdom4j

This is both a security /and a license issue due to Drools v6.5.0.Final including and using this dependency.

Upgrading to 7.x version would not clear this issue and would result in multiple other license exceptions that are not clearable.

Request exception
policy/drools-pdpjsoup

This is a security issue due to Drools v6.5.0.Final including this dependency.

Upgrading to 7.x version would not clear this issue and would result in multiple other new license exceptions that are not clearable.

Request exception
policy/drools-pdpant

This is a security issue due to Drools v6.5.0.Final including this dependency.

Upgrading to 7.x version would clear this issue, but would then consequently result in multiple other new license exceptions that are not clearable.

Request exception




policy/droolsapex-pdporg.checkerframework.codehaus.jackson.jackson-mapper-asl

This

is a license issue that is brought in from google.guava
Request Integration team to upgrade guava

dependency is pulled in by org.apache.avro. We are using the latest version of Avro.

We are using Avro to deserialize events. Avro uses jackson-mapper-asl for its Json decoding. The schema for the events we are decoding is controlled in policy models and prevents executable code being specified. Therefore this vulnerability cannot be exploited

policy/drools-pdpjboss.jta

This is a license issue - LGPL. JBoss has a newer set of transaction code which has the same license issue.

This feature is unused in ONAP and is disabled.

Request exception

policy/droolsapex-pdphibernate-core

This is a license issue - LGPL

This feature is unused in ONAP and is disabled.

Request exception
policy/drools-pdphibernate-commons-annotations

This is a license issue - LGPL

This feature is unused in ONAP and is disabled.

Request exception
policy/drools-pdpmariadbFalse positive - BSD3 license

Request LF to select correct license.

NOTE: LF requested ONAP to move to mariadb in Amsterdam release.

org.python.jython-standalone.2.7.1

This dependency brings in the Jython (Python) interpreter for executing scripts written in Python under the control of Apex.

There are two vulnerabilities, both concerning adding extra modules to the Python libraries on a host running Python scripts under Jython.

  • The setup.py and build_py.py files allow extra python packages to be installed on the host during the startup of Jython. This mechanism uses the setuptools mechanism to install those packages. That mechanism does not enforce path traversal restrictions, allowing malicious packages to access protected areas on the host.
  • Jython uses packages installed with the python pip utility. Pip is vulnerable to Path Traversal attacks, malicious packages installed with pip can access protected areas on the host

The solution is to warn developers not to install malicious extra Python packages.

Request Exception

The apex-pdp documentation for the Jython plugin is updated to warn developers that they must ensure that extra python packages they add at install time with PIP or using the setup.py/build_py.py mechanisms must be checked and certified by them as not being malicious.


policy/apex-pdpdom4j

This dependency is pulled in by hibernate-core. We are using the latest release of Hibernate.

The XML schema of incoming events is controlled in Apex and arbitrary code even if it was injected cannot be executed.

Request exception

Image AddedPOLICY-1510 - Investigate Apex dom4j OPEN

policy/apex-pdporg.apache.zookeeper

Liam Fallon - can you take a quick look at the impact?

Request exception




policy/enginecommons-fileuploadpolicy/enginecom.sword-group.bizdock.libFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/engineorg.apache.tomcat The declared and effective license are Apache 2.0, the CLM is incorrectly reporting a problem.bootstrapFlagged due to inclusion of ONAP Portal SDKRequest exceptionRequest LF to select correct license.
policy/enginecom.fasterxml.jackson.core

False positive

The code is not using jackson in the manner described in the vulnerability.There are too many lines to list here

Request exception
policy/engineorg.springframeworkOne version is flagged due to inclusion of ONAP Portal SDK.

Request exception

policy/engineorg.springframeworkWe will upgrade other versions not related to ONAP Portal SDK. Possible together, needs investigation.
policy/enginebouncycastleFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/enginecom.mchangeFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/engine

angularjs

angular

angular.min.js

angular-ui-grid.min.js

angular-sanitize

Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

moment

moment

ng-formio-gridFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/enginecommonswicket-beanutilsutilFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/distributioncom.fasterxml.jackson.coreengine

moment


moment

2 separate issues:

1) Flagged due to inclusion of ONAP SDC Portal SDK

Request exception

policy/enginexerces2) Flagged due to inclusion of policy/commonONAP Portal SDKRequest exception
policy/enginecommons-beanutilsFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/distributionengineorg.springframeworkesapiFlagged due to inclusion of ONAP Portal SDKRequest exception
policy/distributionenginejavax.jmsantisamyFlagged This is a license issue that is brought in due to inclusion of DMaap client.ONAP Portal SDKRequest exception
policy/distributionengineorg.jsonjqueryFlagged This is a license issue that is brought in due to inclusion of Cambria client.ONAP Portal SDKRequest exception
policy/org.checkerframeworkThis is a license issue that is brought in from google.guavaenginecommons-fileuploadFlagged due to inclusion of ONAP Portal SDKRequest exception




policy/distributionorg.dspace.xmlui.xmlThis is a license issue that is a false positive - it is Apache 2.0springframeworkFlagged due to inheritance from policy/engine which has dependency on ONAP Portal SDKRequest exceptionRequest LF to select correct license.


Sample of CLM Report