This template is intended to be used to document the outcome of the impact analysis related to the known vulnerability reported by Nexus-IQ (CLM tab in Jenkins). Nexus-IQ can identify the known vulnerabilities contained in the components use by onap components.
This table will be presented to TSC at Code Freeze milestone (M4) to the TSC.
It is recommended to first update to the latest version of the third party components available. In case the latest third party components still reports some vulnerabilities, you must provide an impact analysis as illustrated in the example below.
The following table is addressing 2 different scenarios:
- Confirmation of a vulnerability including an action
- False Positive
The information related to Repository, Group, Artifact, Version and Problem Code are extracted from the CLM report (see the below screenshot)
Repository | Group | Impact Analysis | Action |
---|---|---|---|
policy/common | com.fasterxml.jackson.core | False Positive - we are not using the Jackson code in the manner that exposes the vulnerability. | Request exception or false positive |
policy/common | javax.servlet | False Positive - the license is CCDL-1.1 | Request exception |
policy/common | javax.jms | This is a license issue that is brought in due to inclusion of DMaap client. We will investigate the latest version of Dmaap client available for Casablanca. | Request exception |
policy/common | org.json | This is a license issue that is brought in due to inclusion of Cambria client. We will investigate the latest version of Cambrian client available for Casablanca. | Request exception |
policy/drools-applications | com.fasterxml.jackson.core | False Positive - flagged due to inclusion of policy/drools-pdp | Request exception |
policy/drools-applications | javax.jms | False Positive - flagged due to inclusion of policy/common | Request exception |
policy/common | org.json | False Positive - flagged due to inclusion of policy/common | Request exception |
policy/drools-applications | com.att.research.xacml | False positive - MIT license should be acceptable | Request exception |
policy/drools-applications | xacml-apis | False positive - Apache 2.0 license should be acceptable | Request exception |
policy/engine | com.sword-group.bizdock.lib | Flagged due to inclusion of ONAP Portal SDK | |
policy/engine | org.apache.tomcat | The declared and effective license are Apache 2.0, the CLM is incorrectly reporting a problem. | False Positive |
policy/engine | com.fasterxml.jackson.core | False positive The code is not using jackson in the manner described in the vulnerability. There are too many lines to list here. | Request exception |
policy/engine | org.springframework | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | angular.js angular.min.js | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | moment moment | Flagged due to inclusion of ONAP Portal SDK | Request exception |
policy/engine | commons-beanutils | Flagged due to inclusion of ONAP Portal SDK | Request exception |
Sample of CLM Report