This table represents the known exploitable and non-exploitable vulnerabilities in third party packages used in the project.


RepositoryGroupImpact AnalysisAction
sdnc/apps, sdnc/oamch.qos.logbackMost likely false positive, since this vulnerability only applies to remote socket connections, which do not apply (since we do not log to remote server). However, should be addressed anyway.

Tracked in issue SDNC-596 - Getting issue details... STATUS

sdnc/oamcom.fasterxmlShould be upgraded to jackson-databind version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/oamcom.fasterxmlShould be upgraded to jackson-databind version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.core

Fixed in version 2.8.6

Tracked in issue SDNC-597 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.coreFixed in version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.coreFixed in version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.coreFixed in version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.coreThere is no non-vulnerable version, but there is a documented workaround.

Tracked in issue SDNC-599 - Getting issue details... STATUS

sdnc/northboundcom.fasterxml.jackson.coreFixed in version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/oamcom.fasterxml.jackson.coreThere is no non-vulnerable version, but there is a documented workaround.

Tracked in issue SDNC-599 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.coreThere is no non-vulnerable version, but there is a documented workaround.

Tracked in issue SDNC-599 - Getting issue details... STATUS

sdnc/appscom.fasterxml.jackson.datatypeFixed in version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/northboundcom.fasterxml.jackson.datatypeFixed in version 2.9.8

Tracked in issue SDNC-598 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundcom.google.guavaFixed in version 23.6.1

Tracked in issue SDNC-600 - Getting issue details... STATUS

sdnc/oamdom4jFixed in version 2.1.1

Tracked in issue SDNC-651 - Getting issue details... STATUS

sdnc/oamjavax.servletFixed in version 1.2.3

Tracked in issue SDNC-651 - Getting issue details... STATUS

sdnc/northboundjavax.mailFixed in version 1.5.3

Tracked in issue SDNC-604 - Getting issue details... STATUS

sdnc/northbound, sdnc/oamorg.apache.karaf.jaasInherited from OpenDaylight Fluorine releaseMust be fixed in upstream OpenDaylight
sdnc/northbound, sdnc/oamorg.apache.karaf.jaasInherited from OpenDaylight Fluorine releaseMust be fixed in upstream OpenDaylight
sdnc/northbound, sdnc/oamorg.apache.karaf.jaasInherited from OpenDaylight Fluorine releaseMust be fixed in upstream OpenDaylight
sdnc/northbound, sdnc/oamorg.apache.karaf.jaasInherited from OpenDaylight Fluorine releaseMust be fixed in upstream OpenDaylight
sdnc/northbound, sdnn/oamorg.apache.karaf.shellInherited from OpenDaylight Fluorine releaseMust be fixed in upstream OpenDaylight
sdnc/northbound, sdnn/oamorg.apache.karaf.shellInherited from OpenDaylight Fluorine releaseMust be fixed in upstream OpenDaylight
sdnc/oamorg.apache.logging.log4jFixed in version 2.8.2

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.apache.tomcat.embedUpgrade to version 8.5.32

Tracked in issue SDNC-610 - Getting issue details... STATUS

sdnc/oamorg.codehaus.jacksonThere is no non-vulnerable version, but there is a documented workaround.

Tracked in issue SDNC-599 - Getting issue details... STATUS

sdnc/oamorg.hibernateUpgrade to version 5.3.6.Final or above

Tracked in issue SDNC-611 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundorg.springframeworkFixed in version 4.3.15.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundorg.springframeworkFixed in version 4.3.15.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundorg.springframeworkFixed in version 4.3.15.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundorg.springframeworkFixed in version 4.3.20.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundorg.springframeworkFixed in version 4.3.18.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/apps, sdnc/northboundorg.springframeworkFixed in version 4.3.18.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/oamorg.springframeworkFixed in version 4.3.20.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/oamorg.springframeworkFixed in version 4.3.18.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/oamorg.springframeworkFixed in version 4.3.18.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/oamorg.springframeworkFixed in version 4.3.18.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/oamorg.springframeworkFixed in version 4.3.18.RELEASE

Tracked in issue SDNC-601 - Getting issue details... STATUS

sdnc/oamorg.springframework.dataFixed in version 1.13.11

Tracked in issue SDNC-612 - Getting issue details... STATUS

sdnc/oamorg.springframework.dataFixed in version 1.13.12

Tracked in issue SDNC-612 - Getting issue details... STATUS

sdnc/oamorg.springframework.dataFixed in version 1.13.10

Tracked in issue SDNC-612 - Getting issue details... STATUS

sdnc/oamorg.webjarsFixed in version 4.0.0 and above

Tracked in issue SDNC-613 - Getting issue details... STATUS

sdnc/oamorg.webjarsFixed in version 3.4.0 and above

Tracked in issue SDNC-613 - Getting issue details... STATUS

sdnc/oamorg.webjarsFixed in version 3.4.0 and above

Tracked in issue SDNC-613 - Getting issue details... STATUS

sdnc/oamorg.webjarsFixed in version 4.1.2 and above

Tracked in issue SDNC-613 - Getting issue details... STATUS

sdnc/oamorg.webjarsFixed in jQuery version 3.0.0

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/oamorg.webjarsFixed in jQuery version 3.0.0

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/oambootstrapFixed in version 4.1.2

Tracked in issue SDNC-605 - Getting issue details... STATUS

sdnc/oambootstrapFixed in version 4.1.2

Tracked in issue SDNC-605 - Getting issue details... STATUS

sdnc/oambootstrapFixed in version 4.1.2

Tracked in issue SDNC-605 - Getting issue details... STATUS

sdnc/oambootstrapFixed in version 4.1.2

Tracked in issue SDNC-605 - Getting issue details... STATUS

sdnc/oambootstrap-tableNeeds further research - problem description is poor, as usual with these (says to upgrade to version that does not have vulnerability without stating what version that might be)

Tracked in issue SDNC-605 - Getting issue details... STATUS

sdnc/appshandlebarsWorkaround is to ensure "handlebars" (double braces - e.g {{ hello there }}) are inside single quotes (e.g. '{{hello there}}')

Tracked in issue SDNC-602 - Getting issue details... STATUS

sdnc/oamjqueryFixed in jQuery version 3.0.0

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/oamjqueryFixed in jQuery version 3.0.0

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/oamjqueryFixed in jQuery version 3.0.0

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/oamjqueryFixed in jQuery version 3.0.0

Tracked in issue SDNC-608 - Getting issue details... STATUS

sdnc/appsuikitAppears to have been fixed in 2016, but unclear what version. This is a recurrent theme in SONATYPE vulnerabilities - the problem description generally says "upgrade to a version that does not have this vulnerability" without specifying that version - only a link to the change in GitHub, which does not tell you what version it applies to.

Tracked in issue SDNC-603 - Getting issue details... STATUS