You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 12 Next »

This template is intended to be used to document the outcome of the impact analysis related to the known vulnerability reported by Nexus-IQ (CLM tab in Jenkins).  Nexus-IQ can identify the known vulnerabilities contained in the components use by onap components.

This table will be presented to TSC at Code Freeze milestone (M4) to the TSC.

It is recommended to first update to the latest version of the third party components available. In case the latest third party components still reports some vulnerabilities, you must provide an impact analysis as illustrated in the example below.


The following table is addressing 2 different scenarios:

  • Confirmation of a vulnerability including an action
  • False Positive

The information related to Repository, Group, Artifact, Version and Problem Code are extracted from the CLM report (see the below screenshot)


RepositoryGroupImpact AnalysisAction
policy/commoncom.fasterxml.jackson.core

False Positive - we are not using the Jackson code in the manner that exposes the vulnerability.

Request exception or false positive


policy/common

javax.jms

This is a license issue that is brought in due to inclusion of DMaap client.

Request exception
policy/commonorg.json

This is a license issue that is brought in due to inclusion of Cambria client.

Request exception
policy/commonorg.checkerframeworkThis is a license issue that is brought in from google.guavaRequest Integration team to upgrade guava
policy/drools-applicationscom.fasterxml.jackson.core

False Positive - flagged due to inclusion of policy/common

Request exception

policy/drools-applications

javax.jmsThis is a license issue that is brought in due to inclusion of DMaap client.Request exception
policy/drools-applicationsorg.jsonThis is a license issue that is brought in due to inclusion of Cambria client.
Request exception
policy/drools-applicationscom.att.research.xacmlFalse positive - MIT license should be acceptableRequest exception
policy/drools-applicationsorg.checkerframeworkThis is a license issue that is brought in from google.guavaRequest Integration team to upgrade guava
policy/drools-applicationsxml-apisFalse positive - Apache 2.0 license should be acceptableRequest LF to select correct license
policy/drools-pdpcom.fasterxml.jackson.core

False Positive - flagged due to inclusion of policy/common

Request exception

policy/drools-pdp

javax.jmsThis is a license issue that is brought in due to inclusion of DMaap client.Request exception
policy/drools-pdporg.jsonThis is a license issue that is brought in due to inclusion of Cambria client.Request exception
policy/drools-pdpdom4jThis is a security/license issue due to Drools v6.5.0.Final
policy/drools-pdpjsoupThis is a security issue due to Drools v6.5.0.Final
policy/drools-pdpantThis is a security issue due to Drools v6.5.0.Final
















policy/engine

com.sword-group.bizdock.lib

Flagged due to inclusion of ONAP Portal SDK
policy/engineorg.apache.tomcat The declared and effective license are Apache 2.0, the CLM is incorrectly reporting a problem.False Positive
policy/enginecom.fasterxml.jackson.core

False positive

The code is not using jackson in the manner described in the vulnerability.

There are too many lines to list here.

Request exception
policy/engineorg.springframeworkFlagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

angular.js

angular.min.js


Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

moment


moment

Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/enginecommons-beanutilsFlagged due to inclusion of ONAP Portal SDKRequest exception




policy/distributioncom.fasterxml.jackson.core

2 separate issues:

1) Flagged due to inclusion of ONAP SDC SDK

2) Flagged due to inclusion of policy/common

Request exception

policy/distribution

javax.jms

This is a license issue that is brought in due to inclusion of DMaap client.

Request exception
policy/distributionorg.json

This is a license issue that is brought in due to inclusion of Cambria client.

Request exception
policy/distributionorg.checkerframeworkThis is a license issue that is brought in from google.guavaRequest Integration team to upgrade guava





Sample of CLM Report



  • No labels