This table represents the known exploitable and non-exploitable vulnerabilities in third party packages used in the project.


Note : the shaded lines in the table below are vulnerabilities inherited from the OpenDaylight Oxygen distribution, on which much of CCSDK is based.  These vulnerabilities will be reported as CVEs to the OpenDaylight project so they can address them.

RepositoryGroupImpact AnalysisAction
ccsdk/appsch.qos.logback

Need to upgrade version to 1.2.0

Plan to upgrade version to 1.2.0, where feasible
ccsdk/apps, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/pluginsch.qos.logback

Need to upgrade version to 1.2.0

Plan to upgrade version to 1.2.0, where feasible
ccsdk/apps, ccsdk/distribution, ccsdk/sli/pluginscom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/parentcom.fasterxml.jackson.coreFixed in version 2.8.6Plan to upgrade to version >= 2.8.6
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorscom.fasterxml.jackson.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorscom.fasterxml.jackson.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/featurescom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/sli/northboundcom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorscom.fasterxml.jackson.coreNo non-vulnerable version of Jackson existsNeed to rewrite code to avoid Jackson
ccsdk/parentcom.fasterxml.jackson.coreFixed in version 2.8.8.1Plan to upgrade to version >= 2.8.8.1
ccsdk/apps, ccsdk/distribution, ccsdk/sli/adaptorscom.fasterxml.jackson.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.fasterxml.jackson.dataformatNeed to upgrade to version 2.7.4 or higherPlan to upgrade to version >= 2.7.8
ccsdk/distributioncom.fasterxml.jackson.dataformatNeed to upgrade to version 2.7.8 or higherPlan to upgrade to version >= 2.7.8
ccsdk/distributioncom.flozano.sendgridInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/sli/northboundcom.google.guavaNeed to upgrade to version 23.6.1 or greaterPlan to upgrade to version 23.6.1 or higher
ccsdk/appscom.google.guavaNeed to upgrade to version 23.6.1 or greaterPlan to upgrade to version 23.6.1 or higher
ccsdk/distributioncom.google.guavaInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.google.guavaInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.h2databaseInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncom.h2databaseInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appscom.h2databaseNo non-vulnerable version existsNeed to find replacement
ccsdk/appscom.h2databaseNo non-vulnerable version existsNeed to find replacement
ccsdk/distributioncom.jcraftInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/sli/adaptorscom.sun.mailNeed to upgrade to version 1.5.3 or greaterPlan to upgrade to version >= 1.5.3
ccsdk/distributioncommons-beanutilsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-beanutilsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-codecInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/sli/pluginscommons-collectionsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-collectionsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-fileuploadInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-fileuploadInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributioncommons-fileuploadInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distribution, ccsdk/sli/pluginsdom4jNeed to upgrade to version 2.1.1 or higherNeed to upgrade to version 2.1.1 or higher
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionio.nettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/featuresjavax.mailInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionjavax.mailInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/sli/adaptorsjavax.mailInherited from OpenDaylightMust be updated to 1.4.5 to be consistent with ODL
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionnet.sf.ehcacheInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.activemqInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.activemqInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.faces.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hadoopInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.hbaseInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptorsorg.apahe.httpcomponentsInherited from OpenDaylightMust be fixed in upstream OpenDaylight

ccsdk/apps, ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/core, ccsdk/sli/northbound, ccsdk/sli/plugins

org.apache.karaf.jaasNeed to upgrade to version 4.5.3 or higherPlan to upgrade to version >= 4.5.3
ccsdk/apps, ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/core, ccsdk/sli/northbound, ccsdk/sli/pliuginsorg.apache.karaf.jaasNeed to upgrade to version 4.3.6 or higherPlan to upgrade to version >= 4.5.3
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.apache.karaf.webconsoleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.myfaces.coreInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.servicemix.bundlesInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.shiroInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.shiroInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.28 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.23 or laterPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.28 or higherPlan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version > 8.5.16Plan to upgrade version >= 8.5.32
ccsdk/appsorg.apache.tomcat.embedNeed to upgrade to version 8.5.32 or higherPlan to upgrade version >= 8.5.32
ccsdk/distributionorg.apache.zookeeperInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.apache.zookeeperInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.bouncycastleInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.codehaus.jacksonInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.codehaus.jacksonInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.dom4jInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jettyInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jetty.aggregateInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.eclipse.jetty.aggregateInherited from OpenDaylightMust be fixed in upstream OpenDaylight

ccsdk/apps, ccsdk/distribution

org.hibernateNeed to upgrade to version 5.3.6.Final or laterPlan to upgrade to version >= 5.3.6.Final
ccsdk/distributionorg.infinispanInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.infinispanInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jboss.narayana.osgiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.jgroupsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appsorg.liquibaseFalse positive?
CVE refers to jQuery, not liquibase.
Unknown - inadequate information in tool
ccsdk/appsorg.liquibase

False positive?

CVE refers to bootstrap, not liquibase

Unknown - inadequate information in tool
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.tipiInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.ops4j.pax.webInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionorg.postgresqlInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.17
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.17 or higherPlan to upgrade to version >= 4.3.17
ccsdk/parentorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.17
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.17 or higherPlan to upgrade to version >= 4.3.17
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/pluginsorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.17
ccsdk/distribution, ccsdk/features, ccsdk/sli/adaptors, ccsdk/sli/pluginsorg.springframeworkNeed to upgrade to version 4.3.17 or higherPlan to upgrade to version >= 4.3.17
ccsdk/parentorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/parentorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/distribution, ccsdk/featuresorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.18
ccsdk/distribution, ccsdk/featuresorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.18 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframeworkNeed to upgrade to version 4.3.15 or higherPlan to upgrade to version >= 4.3.18
ccsdk/appsorg.springframework.bootNeed to upgrade to version 1.5.10 or highrerPlan to upgrade to version >= 1.5.10
ccsdk/appsorg.springframework.dataNeed to upgrade to version 1.3.10 or higherPlan to upgrade version >= 1.3.12
ccsdk/appsorg.springframework.dataNeed to upgrade to version 1.3.11 or higherPlan to upgrade version >= 1.3.12
ccsdk/appsorg.springframework.dataNeed to upgrade to version 1.3.12 or higherPlan to upgrade version >= 1.3.12
ccsdk/distributionangularInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionangularInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionangularInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionangularInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionangularInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionangularInherited from OpenDaylightMust be fixed in upstream OpenDaylight

ccsdk/apps, ccsdk/distribution

angularjsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangularjsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangularjsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangularjsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangularjsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangularjsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-materialInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-materialInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-sanitizeInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-sanitizeInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-sanitizeInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-sanitizeInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionangular-sanitizeInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionblInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributiondeep-extendInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionhandlebarsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/apps, ccsdk/distributionjqueryInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionjqueryInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionjqueryInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionjqueryInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionjqueryInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionlodash-amdInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionminimatchInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionqsInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionrequestInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionrequestInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionsemverInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributionshell-quoteInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributiontough-cookieInherited from OpenDaylightMust be fixed in upstream OpenDaylight
ccsdk/distributiontough-cookieInherited from OpenDaylightMust be fixed in upstream OpenDaylight