This table represents the known exploitable and non-exploitable vulnerabilities in third party packages used in the project.

RepositoryGroupImpact AnalysisAction
musicorg.codehaus.jacksonThis is a dependency by the core library for our RESTful service(jersey-json) and our cassandra-unit library. We do not use Jackson directly and do not use createBeanDeserializer() function which has the vulnerability. We were unable to find any reference to this Vulnerability from jersey-json or cassandra-unit.

MUSIC-48 - Getting issue details... STATUS


musiccom.fasterxml.jackson.core

This is a dependency of Swagger Jersey Jaxrs library. We do not use Jackson directly and do not use createBeanDeserializer() function which has the vulnerability. To our knowledge we cannot find any reference of swagger jersey using this.

MUSIC-49 - Getting issue details... STATUS

musicorg.apache.zookeeperThis is no longer a problem in the latest version of MUSIC. This shows up in the music jar which is still being used by Portal based on an older version. We have raised an issue with the team asking them to move to the latest version.

MUSIC-362 - Getting issue details... STATUS

musiccom.google.guavaThis is no longer a problem in the latest version of MUSIC. This shows up in the music jar which is still being used by Portal based on an older version. We have raised an issue with the team asking them to move to the latest version.

MUSIC-362 - Getting issue details... STATUS

musicio.nettyThis is no longer a problem in the latest version of MUSIC. This shows up in the music jar which is still being used by Portal based on an older version. We have raised an issue with the team asking them to move to the latest version.

MUSIC-362 - Getting issue details... STATUS