[MS-39466] fix high vulnerabilities in azure and core
Reference Issues:
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/issues/81 https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/issues/80 https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/issues/56 https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/issues/47
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/35714
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/35708
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/35688
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/34041
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/34015
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/33998
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/30851
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/30848
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/22046
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/22044
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/16575
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/16574
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/16573
- https://community.opengroup.org/osdu/platform/system/reference/crs-catalog-service/-/security/vulnerabilities/16572
Changes:
- update os-core-common-spring6 to
0.27.0-rc1
- update core-lib-azure-spring6 to
0.27.0-rc2
- update spring-boot to
3.2.5
to remediate spring-web vulnerability - remove unused
cobertura-maven-plugin
to remediate transitive dependencies - plexus-utils, xercesImpl, maven-core, apache.velocity, jdom
mvn dependency:tree
before changes for crs-catalog-service:
[INFO] | | +- org.springframework.boot:spring-boot-starter-json:jar:3.2.4:compile
[INFO] | | +- org.springframework.boot:spring-boot-starter-tomcat:jar:3.2.4:compile
[INFO] | | | +- org.apache.tomcat.embed:tomcat-embed-core:jar:10.1.19:compile
[INFO] | | | \- org.apache.tomcat.embed:tomcat-embed-websocket:jar:10.1.19:compile
[INFO] | | \- org.springframework:spring-web:jar:6.1.5:compile
mvn dependency:tree
after changes for crs-catalog-service:
[INFO] | | \- org.springframework:spring-webmvc:jar:6.1.6:compile
[INFO] | | +- org.springframework:spring-aop:jar:6.1.6:compile
[INFO] | | +- org.springframework:spring-beans:jar:6.1.6:compile
[INFO] | | +- org.springframework:spring-context:jar:6.1.6:compile
[INFO] | | | \- io.micrometer:micrometer-observation:jar:1.12.5:compile
[INFO] | | | \- io.micrometer:micrometer-commons:jar:1.12.5:compile
[INFO] | | +- org.springframework:spring-core:jar:6.1.6:compile
[INFO] | | | \- org.springframework:spring-jcl:jar:6.1.6:compile
[INFO] | | +- org.springframework:spring-expression:jar:6.1.6:compile
[INFO] | | \- org.springframework:spring-web:jar:6.1.6:compile
Edited by VidyaDharani Lokam