<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 19:08:45 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[AAA-143] Severe security and license analysis issuess in jackson-databind and jackson-dataformat-xml on Nexus IQ server CLM Job</title>
                <link>https://jira.opendaylight.org/browse/AAA-143</link>
                <project id="10102" key="AAA">aaa</project>
                    <description>&lt;p&gt;Several projects (originally raised in private email among committers of genius, then seen by me on infrautils, now raised by An Ho on &lt;a href=&quot;https://lists.opendaylight.org/pipermail/release/2017-August/011985.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.opendaylight.org/pipermail/release/2017-August/011985.html&lt;/a&gt; for daexim) have hit a Severe License analysis issues in jackson-dataformat-xml on Nexus IQ server CLM Job, seen e.g. here: &lt;a href=&quot;https://clm.opendaylight.org/assets/index.html#/reports/daexim/d3d1cd100d6a4443a997ad713f474c35&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://clm.opendaylight.org/assets/index.html#/reports/daexim/d3d1cd100d6a4443a997ad713f474c35&lt;/a&gt;, due to what it thinks is a &quot;Apache-2.0, LGPL-2.1, No Source License&quot; on component com.fasterxml.jackson.dataformat : jackson-dataformat-xml : 2.3.2.&lt;/p&gt;

&lt;p&gt;Stephen Kitt (skitt) in private email dixit, quote: &quot;Likewise, there&#8217;s a security issue with Jackson (again, I haven&#8217;t checked in detail), and we pull that in via AAA and/or odlparent, so it&#8217;s not Genius&#8217;s concern either.&quot;&lt;/p&gt;

&lt;p&gt;Let&apos;s track looking into what going on there in this bug.&lt;/p&gt;

&lt;p&gt;I&apos;m not sure which project needs to do something about this - let&apos;s start with AAA?  (Folks from AAA, of course, please move this bug to another project appropriately, if jackson-dataformat-xml isn&apos;t inherited by all this other projects from you?)&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="22394">AAA-143</key>
            <summary>Severe security and license analysis issuess in jackson-databind and jackson-dataformat-xml on Nexus IQ server CLM Job</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="1" iconUrl="https://jira.opendaylight.org/images/icons/priorities/blocker.svg">Highest</priority>
                        <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10000">Done</resolution>
                                        <assignee username="rgoulding">Ryan Goulding</assignee>
                                    <reporter username="vorburger">Michael Vorburger</reporter>
                        <labels>
                    </labels>
                <created>Tue, 15 Aug 2017 09:52:58 +0000</created>
                <updated>Thu, 21 Mar 2019 11:56:49 +0000</updated>
                            <resolved>Tue, 22 May 2018 13:15:08 +0000</resolved>
                                                    <fixVersion>Fluorine</fixVersion>
                                    <component>General</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>4</watches>
                                                                                                                <comments>
                            <comment id="42443" author="vorburger" created="Tue, 15 Aug 2017 10:06:51 +0000"  >&lt;p&gt;Further to the license issue (above), there is also a Security High alert on jackson-databinding, and a Medium on com.fasterxml.jackson.dataformat (same one as license), which we should also aim to resolve under this issue.&lt;/p&gt;</comment>
                            <comment id="60979" author="rgoulding" created="Wed, 7 Feb 2018 18:52:58 +0000"  >&lt;p&gt;Will target fixing this in Oxygen-SR1 with complete removal of jackson.&#160; Not going to attempt to fix this until we are done releasing Oxygen.&lt;/p&gt;</comment>
                            <comment id="62762" author="opendaylight.release" created="Thu, 3 May 2018 10:06:41 +0000"  >&lt;p&gt;Since the bug is unassigned I&apos;m currently assigning it to you.&lt;/p&gt;

&lt;p&gt;Please assign to the relevant person.&#160;&lt;/p&gt;</comment>
                            <comment id="62789" author="vorburger" created="Thu, 3 May 2018 12:06:42 +0000"  >&lt;p&gt;Hello &lt;a href=&quot;https://jira.opendaylight.org/secure/ViewProfile.jspa?name=opendaylight.release&quot; class=&quot;user-hover&quot; rel=&quot;opendaylight.release&quot;&gt;opendaylight.release&lt;/a&gt; who (human) are you?&lt;/p&gt;</comment>
                            <comment id="63049" author="rgoulding" created="Tue, 22 May 2018 13:14:44 +0000"  >&lt;p&gt;&lt;a href=&quot;https://git.opendaylight.org/gerrit/#/c/70055/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org/gerrit/#/c/70055/&lt;/a&gt;&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>8992</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=8992]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i024d3:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>