From 208a99d6f8a557ec8d78ce914e5e58c61fb432a5 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 14 Apr 2023 17:15:35 +0000 Subject: [PATCH] fix: EIDAS-Sources-2.6.0-MDSL/EIDAS-Parent/pom.xml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-5422217 --- EIDAS-Sources-2.6.0-MDSL/EIDAS-Parent/pom.xml | 1794 ++++++++--------- 1 file changed, 897 insertions(+), 897 deletions(-) diff --git a/EIDAS-Sources-2.6.0-MDSL/EIDAS-Parent/pom.xml b/EIDAS-Sources-2.6.0-MDSL/EIDAS-Parent/pom.xml index 17f5294f..c2ea6f86 100644 --- a/EIDAS-Sources-2.6.0-MDSL/EIDAS-Parent/pom.xml +++ b/EIDAS-Sources-2.6.0-MDSL/EIDAS-Parent/pom.xml @@ -1,900 +1,900 @@ - + - 4.0.0 - eu.eidas - eidas-parent - pom - eIDAS Node Parent - 2.6.0 - - The EIDAS-Parent provides artifacts versions for Eidas Node components. - - - - EIDASParent - EidasNode - UTF-8 - war - jar - ${maven.build.timestamp} - - 11 - - 0.5.2 - 0.5.1 - - - 4.3.18.RELEASE - 0.3.9 - 1.5.5 - 4.2.0 - 4.2.0 - 2.2.3 - 8.0.0 - 3.0.1 - 2.3.3 - 2.3.3 - 1.1.4 - 2.0 - 1.2.6 - 6.0.53 - 1.7.10 - 1.2.9 - 3.7.0 - 4.12 - 1.3 - 1.15 - 3.2.2 - 2.4 - 2.6 - 1.1.3 - 4.5.13 - 4.4.9 - 3.1 - 1.70 - 1.2.3 - 1.4.0 - 2.6 - 1.2.17 - 2.3 - 1.5 - 1.2.2 - 2.3.34 - 7.4.2 - ${vaadin.version} - 1.0.0.beta1 - 0.0.5.RELEASE - 9.2.3.v20140905 - 28.1-jre - 3.0.1 - 57.1 - - - 2.8.1 - 3.8.0 - 2.19.1 - 3.2.0 - 2.7 - 2.4 - 0.8.7 - 1.5 - 2.1.2 - 2.5.2 - 2.6.1 - 3.1.2 - 2.5.0 - - - - - - - eu.eidas - SimpleProtocol - 0.0.4-SNAPSHOT - - - eu.eidas - eidas-commons - ${project.version} - - - eu.eidas - eidas-light-commons - ${project.version} - - - eu.eidas - eidas-encryption - ${project.version} - - - eu.eidas - eidas-saml-engine - ${project.version} - - - eu.eidas - eidas-updater - ${project.version} - - - eu.eidas - eidas-saml-metadata - ${project.version} - - - eu.eidas - eidas-specific-connector - ${project.version} - - - eu.eidas - eidas-specific-proxyservice - ${project.version} - - - eu.eidas - eidas-specific-communication-definition - ${project.version} - - - eu.eidas - eidas-jcache-dev - ${project.version} - - - eu.eidas - eidas-jcache-dev-node - ${project.version} - - - eu.eidas - eidas-jcache-dev-specific-communication - ${project.version} - - - eu.eidas - eidas-jcache-ignite - ${project.version} - - - eu.eidas - eidas-jcache-ignite-node - ${project.version} - - - eu.eidas - eidas-jcache-ignite-specific-communication - ${project.version} - - - eu.eidas - eidas-node - ${project.version} - - - eu.eidas - eidas-sp - ${project.version} - - - eu.eidas - eidas-idp - ${project.version} - - - - - javax.servlet - javax.servlet-api - ${servlet.version} - provided - - - org.glassfish.web - jakarta.servlet.jsp.jstl - ${jstl.version} - runtime - - - - - javax.servlet - jsp-api - ${jsp.api} - provided - - - org.apache.tomcat - jasper-el - ${jasper.version} - - - - - org.apache.struts - struts2-core - ${struts.version} - - - - - org.springframework - spring-core - ${spring.version} - - - commons-logging - commons-logging - - - - - org.springframework - spring-beans - ${spring.version} - - - org.springframework - spring-context - ${spring.version} - - - org.springframework - spring-context-support - ${spring.version} - - - org.springframework - spring-web - ${spring.version} - - - - - - jakarta.xml.bind - jakarta.xml.bind-api - ${jaxb.api.version} - - - org.glassfish.jaxb - jaxb-runtime - ${jaxb.runtime.version} - - - org.glassfish - javax.json - ${json.runtime.version} - - - xalan - xalan - ${xalan.version} - - - - org.opensaml - opensaml-core - ${opensaml.version} - - - commons-codec - commons-codec - - - commons-collections - commons-collections - - - commons-lang - commons-lang - - - commons-logging - commons-logging - - - javax.servlet - servlet-api - - - joda-time - joda-time - - - junit - junit - - - log4j - log4j - - - org.apache.velocity - velocity - - - org.bouncycastle - bcprov-jdk15on - - - org.slf4j - slf4j-api - - - org.slf4j - jcl-over-slf4j - - - org.slf4j - log4j-over-slf4j - - - org.slf4j - jul-to-slf4j - - - org.springframework - spring-test - - - - - org.opensaml - opensaml-saml-api - ${opensaml.version} - - - org.opensaml - opensaml-saml-impl - ${opensaml.version} - - - org.opensaml - opensaml-security-api - ${opensaml.version} - - - org.bouncycastle - bcprov-jdk15on - - - org.bouncycastle - bcpkix-jdk15on - - - - - org.opensaml - opensaml-security-impl - ${opensaml.version} - - - net.shibboleth.utilities - java-support - ${shibboleth.xmlsupport.version} - - - org.opensaml - opensaml-xmlsec-api - - - org.bouncycastle - bcprov-jdk15on - - - ${opensaml.version} - - - org.opensaml - opensaml-xmlsec-impl - - - org.bouncycastle - bcprov-jdk15on - - - ${opensaml.version} - - - - org.apache.santuario - xmlsec - ${xmlsec.version} - - - - - org.slf4j - slf4j-api - ${slf4j.version} - - - org.slf4j - jcl-over-slf4j - ${slf4j.version} - - - org.slf4j - log4j-over-slf4j - ${slf4j.version} - - - org.slf4j - jul-to-slf4j - ${slf4j.version} - - - org.slf4j - slf4j-simple - ${slf4j.version} - - - org.slf4j - slf4j-log4j12 - ${slf4j.version} - - - commons-logging - commons-logging - ${commons.logging} - - - log4j - log4j - ${log4j.version} - - - javax.jms - jms - - - com.sun.jdmk - jmxtools - - - com.sun.jmx - jmxri - - - mail - javax.mail - - - - - ch.qos.logback - logback-classic - ${logback.version} - - - org.slf4j - slf4j-api - - - - - - - commons-codec - commons-codec - ${commons.codec} - - - commons-collections - commons-collections - ${commons.collections} - - - org.apache.httpcomponents - httpclient - ${commons.httpclient} - - - commons-logging - commons-logging - - - commons-codec - commons-codec - - - - - org.apache.httpcomponents - httpcore - ${commons.httpcore} - - - commons-logging - commons-logging - - - - - commons-io - commons-io - ${commons.io} - - - commons-lang - commons-lang - ${commons.lang} - - - - - joda-time - joda-time - ${joda.time.version} - - - org.owasp.encoder - encoder - ${owasp.version} - - - org.owasp.encoder - encoder-jsp - ${owasp.version} - - - com.google.guava - guava - ${guava.version} - - - com.google.code.findbugs - jsr305 - ${jsr305.version} - provided - - - - - org.bouncycastle - bcprov-jdk15on - ${bouncycastle.version} - - - - - com.ibm.icu - icu4j - ${icu4j.version} - - - - - junit - junit - ${junit.version} - test - - - org.hamcrest - hamcrest-all - ${hamcrest.version} - test - - - org.mockito - mockito-core - ${mockito.version} - test - - - xmlunit - xmlunit - ${xmlunit.version} - test - - - org.springframework - spring-test - ${spring.version} - test - - - - - - - - commons-collections - commons-collections - - - commons-io - commons-io - - - commons-lang - commons-lang - - - com.google.guava - guava - - - com.google.code.findbugs - jsr305 - - - - - junit - junit - - - hamcrest-core - org.hamcrest - - - - - org.hamcrest - hamcrest-all - - - org.mockito - mockito-core - - - hamcrest-core - org.hamcrest - - - - - xmlunit - xmlunit - - - - - - - - - com.orctom.mojo - was-maven-plugin - 1.0.8 - - c:/pgm/wlp - ${proj.name} - localhost - server01 - node01 - default_host - true - - - - - org.apache.tomcat.maven - tomcat7-maven-plugin - 2.2 - - http://localhost:8080/manager/text - tomcat - /${proj.name} - admin - admin - - - - org.apache.maven.plugins - maven-war-plugin - ${war.plugin.version} - - - - ${project.basedir}/src/main/webapp/WEB-INF - true - WEB-INF - - **/web.xml - - - - - - - org.apache.maven.plugins - maven-source-plugin - ${source.plugin.version} - - - attach-sources - verify - - jar-no-fork - - - - - - org.jacoco - jacoco-maven-plugin - ${jacoco.plugin.version} - - - default-prepare-agent - - prepare-agent - - - - default-report - - report - - - HTML,XML - - - - - - org.codehaus.mojo - jaxb2-maven-plugin - ${jaxb.plugin.version} - - - org.apache.maven.plugins - maven-resources-plugin - ${resources.plugin.version} - - - org.apache.maven.plugins - maven-jar-plugin - ${maven.jar.plugin.version} - - - - - - - org.apache.maven.plugins - maven-compiler-plugin - ${compile.plugin.version} - - ${java.version} - ${java.version} - - - - org.apache.maven.plugins - maven-surefire-plugin - ${surefire.plugin.version} - - false - - - - org.apache.maven.plugins - maven-javadoc-plugin - ${javadoc.plugin.version} - - true - --add-exports java.base/sun.security.rsa=ALL-UNNAMED - - - - - - ../EIDAS-Light-Commons - ../EIDAS-Commons - ../EIDAS-Encryption - ../EIDAS-Metadata - - - ../EIDAS-JCache-Dev - ../EIDAS-JCache-Dev-Node - - - - - NodeOnly - - true - - - ../EIDAS-SAMLEngine - ../EIDAS-UPDATER - ../EIDAS-Node - - - - DemoToolsOnly - - false - - - ../EIDAS-SimpleProtocol - ../EIDAS-SpecificProxyService - ../EIDAS-SpecificConnector - ../EIDAS-SP - ../EIDAS-IdP-1.0 - - - - nodeJcacheIgnite - - true - - - ../EIDAS-JCache-Ignite - ../EIDAS-JCache-Ignite-Node - - - - nodeJcacheDev - - true - - - ../EIDAS-JCache-Dev - ../EIDAS-JCache-Dev-Node - - - - specificCommunicationJcacheIgnite - - true - - - ../EIDAS-JCache-Ignite - ../EIDAS-JCache-Ignite-Specific-Communication - - - - specificCommunicationJcacheDev - - false - - specificJar - - - - ../EIDAS-JCache-Dev - ../EIDAS-JCache-Dev-Specific-Communication - - - + http://maven.apache.org/maven-v4_0_0.xsd"> + 4.0.0 + eu.eidas + eidas-parent + pom + eIDAS Node Parent + 2.6.0 + + The EIDAS-Parent provides artifacts versions for Eidas Node components. + + + + EIDASParent + EidasNode + UTF-8 + war + jar + ${maven.build.timestamp} + + 11 + + 0.5.2 + 0.5.1 + + + 5.0.0.RELEASE + 0.3.9 + 1.5.5 + 4.2.0 + 4.2.0 + 2.2.3 + 8.0.0 + 3.0.1 + 2.3.3 + 2.3.3 + 1.1.4 + 2.0 + 1.2.6 + 6.0.53 + 1.7.10 + 1.2.9 + 3.7.0 + 4.12 + 1.3 + 1.15 + 3.2.2 + 2.4 + 2.6 + 1.1.3 + 4.5.13 + 4.4.9 + 3.1 + 1.70 + 1.2.3 + 1.4.0 + 2.6 + 1.2.17 + 2.3 + 1.5 + 1.2.2 + 2.3.34 + 7.4.2 + ${vaadin.version} + 1.0.0.beta1 + 0.0.5.RELEASE + 9.2.3.v20140905 + 28.1-jre + 3.0.1 + 57.1 + + + 2.8.1 + 3.8.0 + 2.19.1 + 3.2.0 + 2.7 + 2.4 + 0.8.7 + 1.5 + 2.1.2 + 2.5.2 + 2.6.1 + 3.1.2 + 2.5.0 + + + + + + + eu.eidas + SimpleProtocol + 0.0.4-SNAPSHOT + + + eu.eidas + eidas-commons + ${project.version} + + + eu.eidas + eidas-light-commons + ${project.version} + + + eu.eidas + eidas-encryption + ${project.version} + + + eu.eidas + eidas-saml-engine + ${project.version} + + + eu.eidas + eidas-updater + ${project.version} + + + eu.eidas + eidas-saml-metadata + ${project.version} + + + eu.eidas + eidas-specific-connector + ${project.version} + + + eu.eidas + eidas-specific-proxyservice + ${project.version} + + + eu.eidas + eidas-specific-communication-definition + ${project.version} + + + eu.eidas + eidas-jcache-dev + ${project.version} + + + eu.eidas + eidas-jcache-dev-node + ${project.version} + + + eu.eidas + eidas-jcache-dev-specific-communication + ${project.version} + + + eu.eidas + eidas-jcache-ignite + ${project.version} + + + eu.eidas + eidas-jcache-ignite-node + ${project.version} + + + eu.eidas + eidas-jcache-ignite-specific-communication + ${project.version} + + + eu.eidas + eidas-node + ${project.version} + + + eu.eidas + eidas-sp + ${project.version} + + + eu.eidas + eidas-idp + ${project.version} + + + + + javax.servlet + javax.servlet-api + ${servlet.version} + provided + + + org.glassfish.web + jakarta.servlet.jsp.jstl + ${jstl.version} + runtime + + + + + javax.servlet + jsp-api + ${jsp.api} + provided + + + org.apache.tomcat + jasper-el + ${jasper.version} + + + + + org.apache.struts + struts2-core + ${struts.version} + + + + + org.springframework + spring-core + ${spring.version} + + + commons-logging + commons-logging + + + + + org.springframework + spring-beans + ${spring.version} + + + org.springframework + spring-context + ${spring.version} + + + org.springframework + spring-context-support + ${spring.version} + + + org.springframework + spring-web + ${spring.version} + + + + + + jakarta.xml.bind + jakarta.xml.bind-api + ${jaxb.api.version} + + + org.glassfish.jaxb + jaxb-runtime + ${jaxb.runtime.version} + + + org.glassfish + javax.json + ${json.runtime.version} + + + xalan + xalan + ${xalan.version} + + + + org.opensaml + opensaml-core + ${opensaml.version} + + + commons-codec + commons-codec + + + commons-collections + commons-collections + + + commons-lang + commons-lang + + + commons-logging + commons-logging + + + javax.servlet + servlet-api + + + joda-time + joda-time + + + junit + junit + + + log4j + log4j + + + org.apache.velocity + velocity + + + org.bouncycastle + bcprov-jdk15on + + + org.slf4j + slf4j-api + + + org.slf4j + jcl-over-slf4j + + + org.slf4j + log4j-over-slf4j + + + org.slf4j + jul-to-slf4j + + + org.springframework + spring-test + + + + + org.opensaml + opensaml-saml-api + ${opensaml.version} + + + org.opensaml + opensaml-saml-impl + ${opensaml.version} + + + org.opensaml + opensaml-security-api + ${opensaml.version} + + + org.bouncycastle + bcprov-jdk15on + + + org.bouncycastle + bcpkix-jdk15on + + + + + org.opensaml + opensaml-security-impl + ${opensaml.version} + + + net.shibboleth.utilities + java-support + ${shibboleth.xmlsupport.version} + + + org.opensaml + opensaml-xmlsec-api + + + org.bouncycastle + bcprov-jdk15on + + + ${opensaml.version} + + + org.opensaml + opensaml-xmlsec-impl + + + org.bouncycastle + bcprov-jdk15on + + + ${opensaml.version} + + + + org.apache.santuario + xmlsec + ${xmlsec.version} + + + + + org.slf4j + slf4j-api + ${slf4j.version} + + + org.slf4j + jcl-over-slf4j + ${slf4j.version} + + + org.slf4j + log4j-over-slf4j + ${slf4j.version} + + + org.slf4j + jul-to-slf4j + ${slf4j.version} + + + org.slf4j + slf4j-simple + ${slf4j.version} + + + org.slf4j + slf4j-log4j12 + ${slf4j.version} + + + commons-logging + commons-logging + ${commons.logging} + + + log4j + log4j + ${log4j.version} + + + javax.jms + jms + + + com.sun.jdmk + jmxtools + + + com.sun.jmx + jmxri + + + mail + javax.mail + + + + + ch.qos.logback + logback-classic + ${logback.version} + + + org.slf4j + slf4j-api + + + + + + + commons-codec + commons-codec + ${commons.codec} + + + commons-collections + commons-collections + ${commons.collections} + + + org.apache.httpcomponents + httpclient + ${commons.httpclient} + + + commons-logging + commons-logging + + + commons-codec + commons-codec + + + + + org.apache.httpcomponents + httpcore + ${commons.httpcore} + + + commons-logging + commons-logging + + + + + commons-io + commons-io + ${commons.io} + + + commons-lang + commons-lang + ${commons.lang} + + + + + joda-time + joda-time + ${joda.time.version} + + + org.owasp.encoder + encoder + ${owasp.version} + + + org.owasp.encoder + encoder-jsp + ${owasp.version} + + + com.google.guava + guava + ${guava.version} + + + com.google.code.findbugs + jsr305 + ${jsr305.version} + provided + + + + + org.bouncycastle + bcprov-jdk15on + ${bouncycastle.version} + + + + + com.ibm.icu + icu4j + ${icu4j.version} + + + + + junit + junit + ${junit.version} + test + + + org.hamcrest + hamcrest-all + ${hamcrest.version} + test + + + org.mockito + mockito-core + ${mockito.version} + test + + + xmlunit + xmlunit + ${xmlunit.version} + test + + + org.springframework + spring-test + ${spring.version} + test + + + + + + + + commons-collections + commons-collections + + + commons-io + commons-io + + + commons-lang + commons-lang + + + com.google.guava + guava + + + com.google.code.findbugs + jsr305 + + + + + junit + junit + + + hamcrest-core + org.hamcrest + + + + + org.hamcrest + hamcrest-all + + + org.mockito + mockito-core + + + hamcrest-core + org.hamcrest + + + + + xmlunit + xmlunit + + + + + + + + + com.orctom.mojo + was-maven-plugin + 1.0.8 + + c:/pgm/wlp + ${proj.name} + localhost + server01 + node01 + default_host + true + + + + + org.apache.tomcat.maven + tomcat7-maven-plugin + 2.2 + + http://localhost:8080/manager/text + tomcat + /${proj.name} + admin + admin + + + + org.apache.maven.plugins + maven-war-plugin + ${war.plugin.version} + + + + ${project.basedir}/src/main/webapp/WEB-INF + true + WEB-INF + + **/web.xml + + + + + + + org.apache.maven.plugins + maven-source-plugin + ${source.plugin.version} + + + attach-sources + verify + + jar-no-fork + + + + + + org.jacoco + jacoco-maven-plugin + ${jacoco.plugin.version} + + + default-prepare-agent + + prepare-agent + + + + default-report + + report + + + HTML,XML + + + + + + org.codehaus.mojo + jaxb2-maven-plugin + ${jaxb.plugin.version} + + + org.apache.maven.plugins + maven-resources-plugin + ${resources.plugin.version} + + + org.apache.maven.plugins + maven-jar-plugin + ${maven.jar.plugin.version} + + + + + + + org.apache.maven.plugins + maven-compiler-plugin + ${compile.plugin.version} + + ${java.version} + ${java.version} + + + + org.apache.maven.plugins + maven-surefire-plugin + ${surefire.plugin.version} + + false + + + + org.apache.maven.plugins + maven-javadoc-plugin + ${javadoc.plugin.version} + + true + --add-exports java.base/sun.security.rsa=ALL-UNNAMED + + + + + + ../EIDAS-Light-Commons + ../EIDAS-Commons + ../EIDAS-Encryption + ../EIDAS-Metadata + + + ../EIDAS-JCache-Dev + ../EIDAS-JCache-Dev-Node + + + + + NodeOnly + + true + + + ../EIDAS-SAMLEngine + ../EIDAS-UPDATER + ../EIDAS-Node + + + + DemoToolsOnly + + false + + + ../EIDAS-SimpleProtocol + ../EIDAS-SpecificProxyService + ../EIDAS-SpecificConnector + ../EIDAS-SP + ../EIDAS-IdP-1.0 + + + + nodeJcacheIgnite + + true + + + ../EIDAS-JCache-Ignite + ../EIDAS-JCache-Ignite-Node + + + + nodeJcacheDev + + true + + + ../EIDAS-JCache-Dev + ../EIDAS-JCache-Dev-Node + + + + specificCommunicationJcacheIgnite + + true + + + ../EIDAS-JCache-Ignite + ../EIDAS-JCache-Ignite-Specific-Communication + + + + specificCommunicationJcacheDev + + false + + specificJar + + + + ../EIDAS-JCache-Dev + ../EIDAS-JCache-Dev-Specific-Communication + + +