diff --git a/CHANGELOG.md b/CHANGELOG.md index 2b6f92f0..9f6a8b00 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,8 +7,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## 0.2.12 ### Added - Added summary for the open api paths -- + ### Fixed +- Fixed CVE-2022-44729| CWE-918 Third-Party Components vulnerability. ## 0.2.11-M1 ### Added diff --git a/DEPENDENCIES b/DEPENDENCIES index 74af82f5..bfdd7985 100644 --- a/DEPENDENCIES +++ b/DEPENDENCIES @@ -83,7 +83,7 @@ maven/mavencentral/jakarta.activation/jakarta.activation-api/2.1.2, EPL-2.0 OR B maven/mavencentral/jakarta.annotation/jakarta.annotation-api/2.1.1, EPL-2.0 OR GPL-2.0-only with Classpath-exception-2.0, approved, ee4j.ca maven/mavencentral/jakarta.servlet/jakarta.servlet-api/5.0.0, EPL-2.0 OR GPL-2.0-only with Classpath-exception-2.0, approved, ee4j.servlet maven/mavencentral/jakarta.transaction/jakarta.transaction-api/2.0.1, EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0, approved, #7697 -maven/mavencentral/jakarta.validation/jakarta.validation-api/3.0.2, Apache-2.0, approved, clearlydefined +maven/mavencentral/jakarta.validation/jakarta.validation-api/3.0.2, Apache-2.0, approved, ee4j.validation maven/mavencentral/jakarta.websocket/jakarta.websocket-api/2.1.1, EPL-2.0 OR GPL-2.0-only with Classpath-exception-2.0, approved, ee4j.websocket maven/mavencentral/jakarta.websocket/jakarta.websocket-client-api/2.1.1, EPL-2.0 OR GPL-2.0-only with Classpath-exception-2.0, approved, ee4j.websocket maven/mavencentral/jakarta.xml.bind/jakarta.xml.bind-api/4.0.0, BSD-3-Clause, approved, ee4j.jaxb @@ -134,34 +134,15 @@ maven/mavencentral/org.apache.maven.shared/maven-shared-utils/3.3.3, Apache-2.0, maven/mavencentral/org.apache.maven/maven-artifact/3.6.3, Apache-2.0, approved, clearlydefined maven/mavencentral/org.apache.maven/maven-model/3.6.3, Apache-2.0, approved, clearlydefined maven/mavencentral/org.apache.maven/maven-plugin-api/3.6.3, Apache-2.0, approved, clearlydefined -maven/mavencentral/org.apache.poi/poi-ooxml-schemas/4.1.2, , approved, #2132 +maven/mavencentral/org.apache.poi/poi-ooxml-schemas/4.1.2, Apache-2.0 AND BSD-3-Clause AND EPL-1.0 AND MIT, approved, #2132 maven/mavencentral/org.apache.poi/poi-ooxml/4.1.2, Apache-2.0 AND MIT AND BSD-3-Clause AND EPL-1.0, approved, CQ22906 maven/mavencentral/org.apache.poi/poi/4.1.2, Apache-2.0 AND MIT AND BSD-3-Clause AND EPL-1.0, approved, CQ22907 maven/mavencentral/org.apache.thrift/libthrift/0.17.0, Apache-2.0, approved, #6543 maven/mavencentral/org.apache.tomcat.embed/tomcat-embed-el/10.1.11, Apache-2.0, approved, #6997 maven/mavencentral/org.apache.velocity/velocity-engine-core/2.3, Apache-2.0, approved, #2478 maven/mavencentral/org.apache.xmlbeans/xmlbeans/3.1.0, Apache-2.0, approved, clearlydefined -maven/mavencentral/org.apache.xmlgraphics/batik-anim/1.16, Apache-2.0, approved, #4275 -maven/mavencentral/org.apache.xmlgraphics/batik-awt-util/1.16, Apache-2.0, approved, #4271 -maven/mavencentral/org.apache.xmlgraphics/batik-bridge/1.16, Apache-2.0, approved, #4288 -maven/mavencentral/org.apache.xmlgraphics/batik-codec/1.16, Apache-2.0, approved, #4274 -maven/mavencentral/org.apache.xmlgraphics/batik-constants/1.16, Apache-2.0, approved, #4276 -maven/mavencentral/org.apache.xmlgraphics/batik-css/1.16, Apache-2.0, approved, #4289 -maven/mavencentral/org.apache.xmlgraphics/batik-dom/1.16, Apache-2.0 AND W3C, approved, #4277 -maven/mavencentral/org.apache.xmlgraphics/batik-ext/1.16, Apache-2.0 AND W3C, approved, #4286 -maven/mavencentral/org.apache.xmlgraphics/batik-gvt/1.16, Apache-2.0, approved, #4272 -maven/mavencentral/org.apache.xmlgraphics/batik-i18n/1.16, Apache-2.0, approved, #4282 -maven/mavencentral/org.apache.xmlgraphics/batik-parser/1.16, Apache-2.0, approved, #4273 maven/mavencentral/org.apache.xmlgraphics/batik-rasterizer/1.16, Apache-2.0, approved, clearlydefined -maven/mavencentral/org.apache.xmlgraphics/batik-script/1.16, Apache-2.0, approved, #4278 maven/mavencentral/org.apache.xmlgraphics/batik-shared-resources/1.16, Apache-2.0, approved, #4290 -maven/mavencentral/org.apache.xmlgraphics/batik-svg-dom/1.16, Apache-2.0 AND W3C, approved, #4280 -maven/mavencentral/org.apache.xmlgraphics/batik-svggen/1.16, Apache-2.0, approved, #4287 -maven/mavencentral/org.apache.xmlgraphics/batik-svgrasterizer/1.16, Apache-2.0, approved, clearlydefined -maven/mavencentral/org.apache.xmlgraphics/batik-transcoder/1.16, Apache-2.0, approved, #4283 -maven/mavencentral/org.apache.xmlgraphics/batik-util/1.16, Apache-2.0, approved, #4279 -maven/mavencentral/org.apache.xmlgraphics/batik-xml/1.16, Apache-2.0, approved, #4281 -maven/mavencentral/org.apache.xmlgraphics/xmlgraphics-commons/2.7, Apache-2.0, approved, #3367 maven/mavencentral/org.checkerframework/checker-qual/3.33.0, MIT, approved, clearlydefined maven/mavencentral/org.codehaus.plexus/plexus-classworlds/2.6.0, Apache-2.0 AND Plexus, approved, CQ22821 maven/mavencentral/org.codehaus.plexus/plexus-component-annotations/1.5.5, Apache-2.0, approved, CQ4581 @@ -223,7 +204,7 @@ maven/mavencentral/org.graalvm.js/js-scriptengine/22.3.1, UPL-1.0, approved, #43 maven/mavencentral/org.graalvm.sdk/graal-sdk/22.3.1, UPL-1.0, approved, #4345 maven/mavencentral/org.hibernate.validator/hibernate-validator/8.0.1.Final, Apache-2.0, approved, clearlydefined maven/mavencentral/org.jboss.forge.roaster/roaster-api/2.28.0.Final, EPL-1.0, approved, #9791 -maven/mavencentral/org.jboss.forge.roaster/roaster-jdt/2.28.0.Final, , approved, #9790 +maven/mavencentral/org.jboss.forge.roaster/roaster-jdt/2.28.0.Final, EPL-2.0 AND Apache-2.0 AND (EPL-2.0 OR Apache-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0 OR GPL-2.0-only WITH OpenJDK-assembly-exception-1.0), approved, #9790 maven/mavencentral/org.jboss.logging/jboss-logging/3.5.3.Final, Apache-2.0, approved, #9471 maven/mavencentral/org.jeasy/easy-random-core/5.0.0, MIT, approved, clearlydefined maven/mavencentral/org.mapstruct/mapstruct/1.5.3.Final, Apache-2.0, approved, #6277 @@ -236,7 +217,7 @@ maven/mavencentral/org.projectlombok/lombok/1.18.22, MIT AND LicenseRef-Public-D maven/mavencentral/org.slf4j/jcl-over-slf4j/2.0.7, Apache-2.0, approved, clearlydefined maven/mavencentral/org.slf4j/jul-to-slf4j/2.0.7, MIT, approved, #7698 maven/mavencentral/org.slf4j/slf4j-api/2.0.7, MIT, approved, #5915 -maven/mavencentral/org.slf4j/slf4j-simple/2.0.7, MIT, approved, clearlydefined +maven/mavencentral/org.slf4j/slf4j-simple/2.0.7, MIT, approved, #10372 maven/mavencentral/org.springdoc/springdoc-openapi-starter-common/2.0.2, Apache-2.0, approved, #5920 maven/mavencentral/org.springdoc/springdoc-openapi-starter-webmvc-api/2.0.2, Apache-2.0, approved, #5950 maven/mavencentral/org.springdoc/springdoc-openapi-starter-webmvc-ui/2.0.2, Apache-2.0, approved, #5923 @@ -271,6 +252,4 @@ maven/mavencentral/org.topbraid/shacl/1.3.1, Apache-2.0, approved, clearlydefine maven/mavencentral/org.webjars.npm/viz.js-graphviz-java/2.1.3, MIT, approved, clearlydefined maven/mavencentral/org.webjars/swagger-ui/4.15.5, Apache-2.0 AND MIT, approved, #5921 maven/mavencentral/org.webjars/webjars-locator-core/0.52, MIT, approved, clearlydefined -maven/mavencentral/org.yaml/snakeyaml/2.0, Apache-2.0 AND (Apache-2.0 OR BSD-3-Clause OR EPL-1.0 OR GPL-2.0-or-later OR LGPL-2.1-or-later), approved, #7275 -maven/mavencentral/xml-apis/xml-apis-ext/1.3.04, Apache-2.0, approved, CQ1448 -maven/mavencentral/xml-apis/xml-apis/1.4.01, Apache-2.0 OR LicenseRef-Public-Domain OR W3C, approved, CQ9621 \ No newline at end of file +maven/mavencentral/org.yaml/snakeyaml/2.0, Apache-2.0 AND (Apache-2.0 OR BSD-3-Clause OR EPL-1.0 OR GPL-2.0-or-later OR LGPL-2.1-or-later), approved, #7275 \ No newline at end of file diff --git a/backend/pom.xml b/backend/pom.xml index add3813a..2b8e06e2 100644 --- a/backend/pom.xml +++ b/backend/pom.xml @@ -107,6 +107,18 @@ org.webjars.npm viz.js-graphviz-java + + org.apache.xmlgraphics + batik-bridge + + + org.apache.xmlgraphics + batik-transcoder + + + org.apache.xmlgraphics + batik-svgrasterizer +