This template is intended to be used to document the outcome of the impact analysis related to the known vulnerability reported by Nexus-IQ (CLM tab in Jenkins). Nexus-IQ can identify the known vulnerabilities contained in the components use by onap components.
This table will be presented to TSC at Code Freeze milestone (M4) to the TSC.
It is recommended to first update to the latest version of the third party components available. In case the latest third party components still reports some vulnerabilities, you must provide an impact analysis as illustrated in the example below.
The following table is addressing 2 different scenarios:
- Confirmation of a vulnerability including an action
- False Positive
The information related to Repository, Group, Artifact, Version and Problem Code are extracted from the CLM report (see the below screenshot)
Repository | Group | Impact Analysis | Action |
---|---|---|---|
policy/common | com.fasterxml.jackson.core | False Positive - we are not using the Jackson code in the manner that exposes the vulnerability. | Request exception |
policy/common | javax.jms | This is a license issue that is brought in due to inclusion of DMaap client. | Request exception |
policy/common | org.json | This is a license issue that is brought in due to inclusion of Cambria client. | Request exception |
policy/common | org.checkerframework | This is a license issue that is brought in from google.guava | Request Integration team to upgrade guava |
policy/drools-applications | com.fasterxml.jackson.core | False Positive - flagged due to inclusion of policy/common | Request exception |
policy/drools-applications | javax.jms | This is a license issue that is brought in due to inclusion of DMaap client. | Request exception |
policy/drools-applications | org.json | This is a license issue that is brought in due to inclusion of Cambria client. | Request exception |
policy/drools-applications | com.att.research.xacml | False positive - MIT license should be acceptable | Request exception |
policy/drools-applications | org.checkerframework | This is a license issue that is brought in from google.guava | Request Integration team to upgrade guava |
policy/drools-applications | xml-apis | False positive - Apache 2.0 license should be acceptable | Request LF to select correct license |
policy/drools-pdp | com.fasterxml.jackson.core | False Positive - flagged due to inclusion of policy/common | Request exception |
policy/drools-pdp | javax.jms | This is a license issue that is brought in due to inclusion of DMaap client. | Request exception |
policy/drools-pdp | org.json | This is a license issue that is brought in due to inclusion of Cambria client. | Request exception |
policy/drools-pdp | dom4j | This is a security/license issue due to Drools v6.5.0.Final Upgrading to 7.x version would not clear this issue and would result in multiple other license exceptions that are not clearable. | Request exception |
policy/drools-pdp | jsoup | This is a security issue due to Drools v6.5.0.Final Upgrading to 7.x version would not clear this issue and would result in multiple other license exceptions that are not clearable. | Request exception |
policy/drools-pdp | ant | This is a security issue due to Drools v6.5.0.Final Upgrading to 7.x version would clear this issue, but would result in multiple other license exceptions that are not clearable. | Request exception |
policy/drools-pdp | org.checkerframework | This is a license issue that is brought in from google.guava | Request Integration team to upgrade guava |
policy/drools-pdp | jboss.jta | This is a license issue - LGPL. JBoss has a newer set of transaction code which has the same license issue. This feature is unused in ONAP and is disabled. | Request exception |
policy/drools-pdp | hibernate-core | This is a license issue - LGPL This feature is unused in ONAP and is disabled. | Request exception |
policy/drools-pdp | hibernate-commons-annotations | This is a license issue - LGPL This feature is unused in ONAP and is disabled. | Request exception |
policy/drools-pdp | mariadb | False positive - BSD3 license | Request LF to select correct license. NOTE: LF requested ONAP to move to mariadb in Amsterdam release. |
policy/engine | com.sword-group.bizdock.lib | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | org.apache.tomcat | The declared and effective license are Apache 2.0, the CLM is incorrectly reporting a problem. | Request LF to select correct license. |
policy/engine | com.fasterxml.jackson.core | False positive The code is not using jackson in the manner described in the vulnerability. There are too many lines to list here. | Request exception |
policy/engine | org.springframework | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | angular.js angular.min.js | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | moment moment | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | commons-beanutils | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/distribution | com.fasterxml.jackson.core | 2 separate issues: 1) Flagged due to inclusion of ONAP SDC SDK 2) Flagged due to inclusion of policy/common | Request exception |
policy/distribution | org.springframework | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/distribution | javax.jms | This is a license issue that is brought in due to inclusion of DMaap client. | Request exception |
policy/distribution | org.json | This is a license issue that is brought in due to inclusion of Cambria client. | Request exception |
policy/distribution | org.checkerframework | This is a license issue that is brought in from google.guava | Request Integration team to upgrade guava |
policy/distribution | org.dspace.xmlui.xml | This is a license issue that is a false positive - it is Apache 2.0 | Request LF to select correct license. |
Sample of CLM Report