[#MS39389] fix: remediate high vulnerabilities for [core & azure] module
Change Details:
- Remediate High vulnerabilities in [Core & Azure] modules
- Cleanup unused
cobertura-maven-plugin
which has more vulnerabilities associated. SinceJaCoCo
already available to coverage report generation.
Core Module
- [spring-web]
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/35747
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/34920
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/34659
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ entitlements-v2-core ---
[INFO] org.opengroup.osdu.entitlements.v2:entitlements-v2-core:jar:0.27.0-SNAPSHOT
[INFO] \- org.springframework.boot:spring-boot-starter-web:jar:3.2.5:compile
[INFO] \- org.springframework:spring-web:jar:6.1.6:compile
- [spring-security-core]
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/35535
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/34922
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ entitlements-v2-core ---
[INFO] org.opengroup.osdu.entitlements.v2:entitlements-v2-core:jar:0.27.0-SNAPSHOT
[INFO] \- org.springframework.boot:spring-boot-starter-security:jar:3.2.5:compile
[INFO] \- org.springframework.security:spring-security-config:jar:6.2.4:compile
[INFO] \- org.springframework.security:spring-security-core:jar:6.2.4:compile
- [commons-beanutils]
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/29853
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/29842
- [org.apache.velocity/velocity]
- [xerces/xercesImpl]
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/29838
- https://community.opengroup.org/osdu/platform/security-and-compliance/entitlements/-/security/vulnerabilities/29836
- [jdom]
- [org.mortbay.jetty/jetty]
Azure Module
- [spring-web]
[INFO] --- maven-dependency-plugin:2.8:tree (default-cli) @ entitlements-v2-azure ---
[INFO] org.opengroup.osdu.entitlements.v2:entitlements-v2-azure:jar:0.27.0-SNAPSHOT
[INFO] \- org.springframework.boot:spring-boot-starter-web:jar:3.1.11:compile
[INFO] \- org.springframework:spring-web:jar:6.0.19:compile
Edited by Thulasi Dass Subramanian