Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 6.1.0Report Generated On : Wed, 3 Mar 2021 21:10:17 +0100Dependencies Scanned : 34 (32 unique)Vulnerable Dependencies : 5 Vulnerabilities Found : 39Vulnerabilities Suppressed : 0... NVD CVE Checked : 2021-03-03T18:17:15NVD CVE Modified : 2021-03-03T16:02:16VersionCheckOn : 2021-03-03T08:29:07Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies XML-APIS-2.5.0.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/XML-APIS/XML-APIS/2.5.0/XML-APIS-2.5.0.jarMD5: d96b62c9d7c2a81efd1986b59582e4e1SHA1: 5f3baec73262ebebc87a457fb24012bedb6f0ca6SHA256: 00e7ff4fb2f424bb3c6031b6e7ad03c2badf7af08c1798c8ede6a5d7b7843520Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor pom groupid XML-APIS Highest Vendor pom artifactid XML-APIS Low Vendor manifest: javax/xml/parsers/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor jar package name apache Highest Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/transform/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor jar package name xml Highest Vendor file name XML-APIS High Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Product jar package name sax Highest Product pom groupid XML-APIS Highest Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.transform Medium Product jar package name xmlcommons Highest Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product jar package name javax Highest Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product jar package name dom Highest Product jar package name version Highest Product jar package name w3c Highest Product jar package name xml Highest Product jar package name transform Highest Product pom artifactid XML-APIS Highest Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product jar package name apache Highest Product jar package name document Highest Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 2 Core Medium Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium Product file name XML-APIS High Version file version 2.5.0 High Version pom version 2.5.0 Highest
XMLEditor-2.2.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/XMLEditor/XMLEditor/2.2/XMLEditor-2.2.jarMD5: 4a4a0b6d61460d738a469ad200809624SHA1: 0b6ed34aa9b29b3e093ede285d08f6bce7128504SHA256: a84c1f3cdd1d38bdea7fa1513c152b50957eef17bc7d42f585d2c2dc31b9663dReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid XMLEditor Low Vendor jar package name xmleditor Highest Vendor jar package name fg Low Vendor pom groupid XMLEditor Highest Vendor file name XMLEditor High Product pom artifactid XMLEditor Highest Product jar package name xmleditor Highest Product pom groupid XMLEditor Highest Product file name XMLEditor High Version pom version 2.2 Highest Version file version 2.2 High
Xerces-2.5.0.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/Xerces/Xerces/2.5.0/Xerces-2.5.0.jarMD5: 17c7b058d32d6df45456e1728a299ba1SHA1: c0468bac6d11a07ffc69506003cfedc0ce54e172SHA256: d1ff701c93fdd4838b95ccef54b83b3f2f9200052fe34fe8b82a0fbabfc1a72cReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor jar package name xerces Highest Vendor pom artifactid Xerces Low Vendor manifest: org/apache/xerces/impl/Version Implementation-Vendor Apache Software Foundation Medium Vendor jar package name apache Highest Vendor manifest: javax/xml/parsers/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor pom groupid Xerces Highest Vendor file name Xerces High Vendor manifest: javax/xml/transform/ Implementation-Vendor Sun Microsystems Inc. Medium Vendor manifest: org.apache.xerces.xni/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Product jar package name impl Highest Product jar package name parsers Highest Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product jar package name xni Highest Product jar package name dom Highest Product jar package name version Highest Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product jar package name w3c Highest Product jar package name xml Highest Product manifest: org.apache.xerces.xni/ Specification-Title Xerces Native Interface Medium Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product pom artifactid Xerces Highest Product jar package name xerces Highest Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product manifest: org.apache.xerces.xni/ Implementation-Title org.apache.xerces.xni Medium Product jar package name apache Highest Product pom groupid Xerces Highest Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product file name Xerces High Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 2 Core Medium Product manifest: org/apache/xerces/impl/Version Implementation-Title org.apache.xerces.impl.Version Medium Version file version 2.5.0 High Version manifest: org/apache/xerces/impl/Version Implementation-Version 2.5.0 Medium Version pom version 2.5.0 Highest
commons-beanutils-1.9.4.jarDescription:
Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar
MD5: 07dc532ee316fe1f2f0323e9bd2f8df4
SHA1: d52b9abcd97f38c81342bb7e7ae1eee9b73cba51
SHA256: 7d938c81789028045c08c065e94be75fc280527620d5bd62b519d5838532368a
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom url https://commons.apache.org/proper/commons-beanutils/ Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2019-07-28 22:14:44+0000 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid commons-beanutils Low Vendor pom name Apache Commons BeanUtils High Vendor jar package name commons Highest Vendor Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor Manifest implementation-url https://commons.apache.org/proper/commons-beanutils/ Low Vendor jar package name apache Highest Vendor pom groupid commons-beanutils Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor file name commons-beanutils High Vendor jar package name beanutils Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils/ Low Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2019-07-28 22:14:44+0000 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom url https://commons.apache.org/proper/commons-beanutils/ Medium Product pom name Apache Commons BeanUtils High Product jar package name commons Highest Product Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Product pom parent-artifactid commons-parent Medium Product Manifest specification-title Apache Commons BeanUtils Medium Product pom artifactid commons-beanutils Highest Product Manifest Implementation-Title Apache Commons BeanUtils High Product pom parent-groupid org.apache.commons Medium Product Manifest implementation-url https://commons.apache.org/proper/commons-beanutils/ Low Product jar package name apache Highest Product Manifest Bundle-Name Apache Commons BeanUtils Medium Product pom groupid commons-beanutils Highest Product file name commons-beanutils High Product jar package name beanutils Highest Version file version 1.9.4 High Version Manifest Bundle-Version 1.9.4 High Version pom parent-version 1.9.4 Low Version Manifest Implementation-Version 1.9.4 High Version pom version 1.9.4 Highest
commons-collections-3.2.2.jarDescription:
Types that extend and augment the Java Collections Framework. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
SHA256: eeeae917917144a68a741d4c0dff66aa5c5c5fd85593ff217bced3fc8ca783b8
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium Vendor jar package name commons Highest Vendor pom groupid commons-collections Highest Vendor pom artifactid commons-collections Low Vendor jar package name collections Highest Vendor pom name Apache Commons Collections High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low Vendor pom parent-artifactid commons-parent Low Vendor Manifest implementation-url http://commons.apache.org/collections/ Low Vendor file name commons-collections High Vendor jar package name apache Highest Vendor pom url http://commons.apache.org/collections/ Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low Product pom artifactid commons-collections Highest Product Manifest bundle-docurl http://commons.apache.org/collections/ Low Product pom url http://commons.apache.org/collections/ Medium Product Manifest bundle-symbolicname org.apache.commons.collections Medium Product jar package name commons Highest Product pom groupid commons-collections Highest Product Manifest Bundle-Name Apache Commons Collections Medium Product pom parent-artifactid commons-parent Medium Product jar package name collections Highest Product pom name Apache Commons Collections High Product Manifest Implementation-Title Apache Commons Collections High Product pom parent-groupid org.apache.commons Medium Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low Product Manifest specification-title Apache Commons Collections Medium Product Manifest implementation-url http://commons.apache.org/collections/ Low Product file name commons-collections High Product jar package name apache Highest Version file version 3.2.2 High Version pom version 3.2.2 Highest Version Manifest Implementation-Version 3.2.2 High Version Manifest Bundle-Version 3.2.2 High Version pom parent-version 3.2.2 Low
commons-compress-1.20.jarDescription:
Apache Commons Compress software defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
lzma, xz, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/apache/commons/commons-compress/1.20/commons-compress-1.20.jar
MD5: 3f7237fb56029591b5bdd2698c196220
SHA1: b8df472b31e1f17c232d2ad78ceb1c84e00c641b
SHA256: 0aeb625c948c697ea7b205156e112363b59ed5e2551212cd4e460bdb72c7c06e
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Vendor jar package name commons Highest Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest implementation-url https://commons.apache.org/proper/commons-compress/ Low Vendor pom parent-artifactid commons-parent Low Vendor pom groupid apache.commons Highest Vendor jar package name compress Highest Vendor Manifest implementation-build UNKNOWN@rf7503adfbad8b44eb079d564f2784aeaa034647c; 2020-02-05 05:01:35+0000 Low Vendor pom groupid org.apache.commons Highest Vendor pom artifactid commons-compress Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor jar package name apache Highest Vendor pom name Apache Commons Compress High Vendor file name commons-compress High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product pom artifactid commons-compress Highest Product Manifest specification-title Apache Commons Compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest automatic-module-name org.apache.commons.compress Medium Product jar package name commons Highest Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Product Manifest Implementation-Title Apache Commons Compress High Product pom parent-groupid org.apache.commons Medium Product Manifest implementation-url https://commons.apache.org/proper/commons-compress/ Low Product pom groupid apache.commons Highest Product jar package name compress Highest Product Manifest implementation-build UNKNOWN@rf7503adfbad8b44eb079d564f2784aeaa034647c; 2020-02-05 05:01:35+0000 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product jar package name apache Highest Product pom name Apache Commons Compress High Product file name commons-compress High Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Version file version 1.20 High Version pom parent-version 1.20 Low Version pom version 1.20 Highest Version Manifest Implementation-Version 1.20 High
commons-daemon-1.2.4.jarDescription:
Apache Commons Daemon software is a set of utilities and Java support
classes for running Java applications as server processes. These are
commonly known as 'daemon' processes in Unix terminology (hence the
name). On Windows they are called 'services'.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-daemon/commons-daemon/1.2.4/commons-daemon-1.2.4.jar
MD5: 3b09311652913abfa26325b07ad35b14
SHA1: d60046797e74222fc6df647ffb9ab32946615264
SHA256: e9ca86791491454eb065475ded6f1d9669a6a015fd0f179ae0a92b20b8e0a71c
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name support Highest Vendor Manifest implementation-build master@r0373c020f233236ca7acf4fa4ceef31e27b7cb70; 2021-01-18 16:50:29+0000 Low Vendor pom name Apache Commons Daemon High Vendor Manifest bundle-symbolicname org.apache.commons.commons-daemon Medium Vendor jar package name commons Highest Vendor pom groupid commons-daemon Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-daemon/ Low Vendor file name commons-daemon High Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid commons-daemon Low Vendor pom url https://commons.apache.org/proper/commons-daemon/ Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor jar package name daemon Highest Product Manifest Bundle-Name Apache Commons Daemon Medium Product Manifest build-jdk-spec 1.8 Low Product jar package name support Highest Product Manifest implementation-build master@r0373c020f233236ca7acf4fa4ceef31e27b7cb70; 2021-01-18 16:50:29+0000 Low Product pom name Apache Commons Daemon High Product Manifest bundle-symbolicname org.apache.commons.commons-daemon Medium Product jar package name commons Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-daemon/ Low Product pom groupid commons-daemon Highest Product pom parent-artifactid commons-parent Medium Product file name commons-daemon High Product Manifest Implementation-Title Apache Commons Daemon High Product pom parent-groupid org.apache.commons Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid commons-daemon Highest Product jar package name apache Highest Product pom url https://commons.apache.org/proper/commons-daemon/ Medium Product Manifest specification-title Apache Commons Daemon Medium Product jar package name daemon Highest Version pom version 1.2.4 Highest Version Manifest Implementation-Version 1.2.4 High Version Manifest Bundle-Version 1.2.4 High Version pom parent-version 1.2.4 Low Version file version 1.2.4 High
commons-dbcp-1.4.jarDescription:
Commons Database Connection Pooling License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
SHA256: a6e2d83551d0e5b59aa942359f3010d35e79365e6552ad3dbaa6776e4851e4f6
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://commons.apache.org/dbcp/ Highest Vendor Manifest bundle-docurl http://commons.apache.org/dbcp/ Low Vendor jar package name commons Highest Vendor jar package name dbcp Highest Vendor file name commons-dbcp High Vendor Manifest bundle-symbolicname org.apache.commons.dbcp Medium Vendor pom parent-groupid org.apache.commons Medium Vendor pom groupid commons-dbcp Highest Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-dbcp Low Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom name Commons DBCP High Product Manifest bundle-docurl http://commons.apache.org/dbcp/ Low Product pom url http://commons.apache.org/dbcp/ Medium Product jar package name commons Highest Product pom parent-artifactid commons-parent Medium Product jar package name dbcp Highest Product file name commons-dbcp High Product Manifest bundle-symbolicname org.apache.commons.dbcp Medium Product Manifest Implementation-Title Commons DBCP High Product pom parent-groupid org.apache.commons Medium Product pom groupid commons-dbcp Highest Product Manifest specification-title Commons DBCP Medium Product jar package name apache Highest Product Manifest Bundle-Name Commons DBCP Medium Product pom artifactid commons-dbcp Highest Product pom name Commons DBCP High Version Manifest Implementation-Version 1.4 High Version Manifest Bundle-Version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest Version file version 1.4 High
commons-io-2.6.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar
MD5: 467c2a1f64319c99b5faf03fc78572af
SHA1: 815893df5f31da2ece4040fe0a12fd44b577afaf
SHA256: f877d304660ac2a142f3865badfc971dec7ed73c747c7f8d5d2f5139ca736513
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid commons-io Highest Vendor file name commons-io High Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor jar package name commons Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Vendor pom artifactid commons-io Low Vendor pom url http://commons.apache.org/proper/commons-io/ Highest Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor jar package name io Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor jar package name apache Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor Manifest Implementation-Vendor-Id commons-io Medium Vendor pom name Apache Commons IO High Product Manifest Bundle-Name Apache Commons IO Medium Product file name commons-io High Product pom groupid commons-io Highest Product pom url http://commons.apache.org/proper/commons-io/ Medium Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest specification-title Apache Commons IO Medium Product jar package name commons Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product Manifest Implementation-Title Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom artifactid commons-io Highest Product pom parent-groupid org.apache.commons Medium Product jar package name io Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product jar package name apache Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Product Manifest bundle-symbolicname org.apache.commons.io Medium Product pom name Apache Commons IO High Version pom version 2.6 Highest Version file version 2.6 High Version Manifest Implementation-Version 2.6 High Version pom parent-version 2.6 Low
commons-logging-1.2.jarDescription:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256: daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor pom name Apache Commons Logging High Vendor pom parent-groupid org.apache.commons Medium Vendor file name commons-logging High Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-logging Low Vendor pom groupid commons-logging Highest Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Vendor jar package name apache Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Vendor Manifest Implementation-Vendor-Id org.apache Medium Product pom artifactid commons-logging Highest Product Manifest Bundle-Name Apache Commons Logging Medium Product Manifest bundle-symbolicname org.apache.commons.logging Medium Product jar package name commons Highest Product jar package name logging Highest Product pom name Apache Commons Logging High Product pom url http://commons.apache.org/proper/commons-logging/ Medium Product pom parent-artifactid commons-parent Medium Product Manifest specification-title Apache Commons Logging Medium Product pom parent-groupid org.apache.commons Medium Product file name commons-logging High Product pom groupid commons-logging Highest Product Manifest Implementation-Title Apache Commons Logging High Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Product jar package name apache Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Version pom parent-version 1.2 Low Version Manifest Implementation-Version 1.2 High Version file version 1.2 High Version pom version 1.2 Highest
commons-pool-1.6.jarDescription:
Commons Object Pooling Library License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
SHA256: 46c42b4a38dc6b2db53a9ee5c92c63db103665d56694e2cfce2c95d51a6860cc
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name pool Highest Vendor pom url http://commons.apache.org/pool/ Highest Vendor pom name Commons Pool High Vendor jar package name commons Highest Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom parent-artifactid commons-parent Low Vendor pom artifactid commons-pool Low Vendor pom groupid commons-pool Highest Vendor file name commons-pool High Vendor jar package name apache Highest Vendor Manifest bundle-symbolicname org.apache.commons.pool Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/pool/ Low Product Manifest Bundle-Name Commons Pool Medium Product jar package name pool Highest Product pom artifactid commons-pool Highest Product pom name Commons Pool High Product jar package name commons Highest Product pom parent-artifactid commons-parent Medium Product Manifest specification-title Commons Pool Medium Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low Product pom url http://commons.apache.org/pool/ Medium Product pom parent-groupid org.apache.commons Medium Product pom groupid commons-pool Highest Product file name commons-pool High Product jar package name apache Highest Product Manifest bundle-symbolicname org.apache.commons.pool Medium Product Manifest Implementation-Title Commons Pool High Product Manifest bundle-docurl http://commons.apache.org/pool/ Low Version pom parent-version 1.6 Low Version pom version 1.6 Highest Version Manifest Implementation-Version 1.6 High Version file version 1.6 High
dom4j-2.0.3.jarDescription:
flexible XML framework for Java License:
BSD 3-clause New License: https://github.com/dom4j/dom4j/blob/master/LICENSE File Path: /home/frederic/.m2/repository/org/dom4j/dom4j/2.0.3/dom4j-2.0.3.jar
MD5: e52772ce926518c4b58ce7084cb365f1
SHA1: 486bf7f9c368f621e616b9a3532253f23665a104
SHA256: b9ee0981b983ff71605c63cae5c12e0e5facb030bc1c1cd586447e28afc2876e
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.dom4j Highest Vendor pom artifactid dom4j Low Vendor file name dom4j High Vendor pom url http://dom4j.github.io/ Highest Vendor pom groupid dom4j Highest Vendor pom name dom4j High Vendor jar package name dom4j Highest Vendor jar package name dom4j Low Product pom artifactid dom4j Highest Product file name dom4j High Product pom url http://dom4j.github.io/ Medium Product pom groupid dom4j Highest Product pom name dom4j High Product jar package name dom4j Highest Version pom version 2.0.3 Highest Version file version 2.0.3 High
guava-20.0.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/google/guava/guava/20.0/guava-20.0.jar
MD5: f32a8a2524620dbecc9f6bf6a20c293f
SHA1: 89507701249388e1ed5ddcf8c41f4ce1be7831ef
SHA256: 36a666e3b71ae7f0f0dca23654b67e086e6c93d192f60ba5dfd5519db6c288c8
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor file name guava High Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom parent-groupid com.google.guava Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid guava Low Vendor pom groupid google.guava Highest Vendor pom parent-artifactid guava-parent Low Vendor jar package name google Highest Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor pom name Guava: Google Core Libraries for Java High Vendor pom groupid com.google.guava Highest Product file name guava High Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom groupid google.guava Highest Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product jar package name google Highest Product Manifest bundle-docurl https://github.com/google/guava/ Low Product pom parent-artifactid guava-parent Medium Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Version pom version 20.0 Highest Version file version 20.0 High
Published Vulnerabilities CVE-2018-10237 suppress
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MLIST - [activemq-gitbox] 20190530 [GitHub] [activemq-artemis] brusdev opened a new pull request #2687: ARTEMIS-2359 Upgrade to Guava 24.1 MLIST - [activemq-issues] 20190516 [jira] [Created] (AMQ-7208) Security Issue related to Guava 18.0 MLIST - [activemq-issues] 20190820 [jira] [Created] (AMQ-7279) Security Vulnerabilities in Libraries - jackson-databind-2.9.8.jar, tomcat-servlet-api-8.0.53.jar, tomcat-websocket-api-8.0.53.jar, zookeeper-3.4.6.jar, guava-18.0.jar, jetty-all-9.2.26.v20180806.jar, scala-library-2.11.0.jar MLIST - [cassandra-commits] 20190612 [jira] [Assigned] (CASSANDRA-14760) CVE-2018-10237 Security vulnerability in 3.11.3 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] davidkarlsen opened a new pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200211 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] andrei-ivanov commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [drill-dev] 20191017 Dependencies used by Drill contain known vulnerabilities MLIST - [drill-dev] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [drill-issues] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [flink-dev] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [flink-dev] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200814 [jira] [Commented] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20210212 [jira] [Closed] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-user] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [hadoop-common-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [hadoop-common-dev] 20200623 Update guava to 27.0-jre in hadoop branch-2.10 MLIST - [hadoop-hdfs-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [kafka-users] 20200413 CVEs for the dependency software guava and rocksdbjni of Kafka MLIST - [lucene-issues] 20201022 [jira] [Created] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Resolved] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Updated] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [maven-issues] 20210122 [GitHub] [maven-indexer] akurtakov opened a new pull request #75: Remove guava dependency from indexer-core MLIST - [pulsar-commits] 20190416 [GitHub] [pulsar] one70six opened a new issue #4057: Security Vulnerabilities - Black Duck Scan - Pulsar v.2.3.1 MLIST - [syncope-dev] 20200423 Re: Time to cut 2.1.6 / 2.0.15? N/A - N/A OSSINDEX - [CVE-2018-10237] Deserialization of Untrusted Data REDHAT - RHSA-2018:2423 REDHAT - RHSA-2018:2424 REDHAT - RHSA-2018:2425 REDHAT - RHSA-2018:2428 REDHAT - RHSA-2018:2598 REDHAT - RHSA-2018:2643 REDHAT - RHSA-2018:2740 REDHAT - RHSA-2018:2741 REDHAT - RHSA-2018:2742 REDHAT - RHSA-2018:2743 REDHAT - RHSA-2018:2927 REDHAT - RHSA-2019:2858 REDHAT - RHSA-2019:3149 SECTRACK - 1041707 Vulnerable Software & Versions: (show all )
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
h2-1.4.191.jarDescription:
H2 Database Engine License:
MPL 2.0, and EPL 1.0: http://h2database.com/html/license.html File Path: /home/frederic/.m2/repository/com/h2database/h2/1.4.191/h2-1.4.191.jar
MD5: dda3c5e5615f0e29a9bc6b14d20fb0c2
SHA1: dec3540178ea889b2871b0ed56db14bbec9cfdfc
SHA256: e21ea665b74ec0115344b5afda5ec70ea27b528c3f103524e74c9854b1c4a284
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest implementation-url http://www.h2database.com Low Vendor pom groupid h2database Highest Vendor pom artifactid h2 Low Vendor Manifest bundle-category jdbc Low Vendor jar package name database Highest Vendor pom name H2 Database Engine High Vendor file name h2 High Vendor jar package name h2 Highest Vendor Manifest bundle-symbolicname org.h2 Medium Vendor jar package name engine Highest Vendor pom groupid com.h2database Highest Vendor pom url http://www.h2database.com Highest Product Manifest implementation-url http://www.h2database.com Low Product pom groupid h2database Highest Product Manifest Implementation-Title H2 Database Engine High Product Manifest bundle-category jdbc Low Product pom url http://www.h2database.com Medium Product jar package name database Highest Product jar package name jdbc Highest Product pom name H2 Database Engine High Product file name h2 High Product Manifest Bundle-Name H2 Database Engine Medium Product jar package name h2 Highest Product pom artifactid h2 Highest Product Manifest bundle-symbolicname org.h2 Medium Product jar package name engine Highest Version pom version 1.4.191 Highest Version Manifest Bundle-Version 1.4.191 High Version file version 1.4.191 High Version Manifest Implementation-Version 1.4.191 High
h2-1.4.191.jar: data.zip: table.jsFile Path: /home/frederic/.m2/repository/com/h2database/h2/1.4.191/h2-1.4.191.jar/org/h2/util/data.zip/org/h2/server/web/res/table.jsMD5: a914a66de53dcdeb39684f1ce8ce8527SHA1: c41ef5fb193ac25622f4e129470339aec24d731aSHA256: 8c5b079b38e94718bb58a71b0e310bad6c1004670a19c1bc0f63b32fdd81134aReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence
h2-1.4.191.jar: data.zip: tree.jsFile Path: /home/frederic/.m2/repository/com/h2database/h2/1.4.191/h2-1.4.191.jar/org/h2/util/data.zip/org/h2/server/web/res/tree.jsMD5: 495277155635a72b0c69f987d938b6e1SHA1: 446cad47e33a62baf330ee5200646b5ccb9c0df9SHA256: 14c797bd700570c38e8af1aa50ecea205a385be466ec9431e46dbe586ce7a61cReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence
jackson-core-2.7.9.jarDescription:
Core Jackson abstractions, basic JSON streaming API implementation License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.7.9/jackson-core-2.7.9.jar
MD5: f5d0dfe03814113d792e75e885699640
SHA1: 09b530cec4fd2eb841ab8e79f19fc7cf0ec487b2
SHA256: bd90721420bb899a974ed09a107fef42ca8cc7c8e055762f6c81576132e5bbc5
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest implementation-build-date 2017-02-04 19:18:13+0000 Low Vendor jar package name jackson Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor pom artifactid jackson-core Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom groupid fasterxml.jackson.core Highest Vendor pom url FasterXML/jackson-core Highest Vendor pom name Jackson-core High Vendor jar package name json Highest Vendor jar package name fasterxml Highest Vendor jar package name core Highest Vendor pom parent-artifactid jackson-parent Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest specification-vendor FasterXML Low Product file name jackson-core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Implementation-Title Jackson-core High Product Manifest implementation-build-date 2017-02-04 19:18:13+0000 Low Product jar package name jackson Highest Product pom parent-groupid com.fasterxml.jackson Medium Product hint analyzer product modules Highest Product jar package name version Highest Product pom groupid fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom url FasterXML/jackson-core High Product hint analyzer product java8 Highest Product jar package name json Highest Product jar package name fasterxml Highest Product Manifest Bundle-Name Jackson-core Medium Product Manifest specification-title Jackson-core Medium Product jar package name core Highest Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product pom parent-artifactid jackson-parent Medium Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product jar package name filter Highest Product pom artifactid jackson-core Highest Version pom parent-version 2.7.9 Low Version file version 2.7.9 High Version pom version 2.7.9 Highest Version Manifest Implementation-Version 2.7.9 High Version Manifest Bundle-Version 2.7.9 High
Related Dependencies jackson-annotations-2.7.9.jarFile Path: /home/frederic/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.7.9/jackson-annotations-2.7.9.jar MD5: 6e9df0fc4856924a1e4a51da36f37b31 SHA1: eb356e825cb73da42f7c902a3fe0276fe32b26c8 SHA256: f9a9a3db99c35324a97b6c3bc95941a0892a9da935a02620d431f7534040bf4f pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.7.9 Published Vulnerabilities CVE-2018-1000873 suppress
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jackson-databind-2.7.9.6.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.7.9.6/jackson-databind-2.7.9.6.jar
MD5: 56c7443cccf36b6bc6eb661a4d128762
SHA1: 562ce1931544a1ae4a3d0e8523c2068fea4198fa
SHA256: 368c7a722e45d8bbbbbfad953f4999c383ecab5bf366fa85ed4115534e377a43
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name jackson Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor Manifest implementation-build-date 2019-07-26 05:00:34+0000 Low Vendor pom groupid fasterxml.jackson.core Highest Vendor jar package name databind Highest Vendor file name jackson-databind High Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor jar package name fasterxml Highest Vendor pom artifactid jackson-databind Low Vendor pom parent-artifactid jackson-parent Low Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low Vendor pom url http://github.com/FasterXML/jackson Highest Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest specification-vendor FasterXML Low Vendor pom name jackson-databind High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Bundle-Name jackson-databind Medium Product jar package name jackson Highest Product pom parent-groupid com.fasterxml.jackson Medium Product pom url http://github.com/FasterXML/jackson Medium Product hint analyzer product modules Highest Product Manifest implementation-build-date 2019-07-26 05:00:34+0000 Low Product pom groupid fasterxml.jackson.core Highest Product jar package name databind Highest Product file name jackson-databind High Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product hint analyzer product java8 Highest Product Manifest Implementation-Title jackson-databind High Product jar package name fasterxml Highest Product Manifest specification-title jackson-databind Medium Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low Product pom parent-artifactid jackson-parent Medium Product pom artifactid jackson-databind Highest Product pom name jackson-databind High Version file version 2.7.9.6 High Version pom version 2.7.9.6 Highest Version pom parent-version 2.7.9.6 Low Version Manifest Bundle-Version 2.7.9.6 High Version Manifest Implementation-Version 2.7.9.6 High
Published Vulnerabilities CVE-2017-15095 (OSSINDEX) suppress
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2017-17485 (OSSINDEX) suppress
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2018-1000873 suppress
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-14540 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-14893 (OSSINDEX) suppress
A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-16335 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-16942 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-16943 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-17267 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-17531 (OSSINDEX) suppress
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload. CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2019-20330 suppress
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-10672 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-10673 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-10968 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-10969 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-11111 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11112 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11113 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11619 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-11620 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly). CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14060 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14061 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14062 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-14195 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-24616 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-24750 (OSSINDEX) suppress
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration. CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.fasterxml.jackson.core:jackson-databind:2.7.9.6:*:*:*:*:*:*:* CVE-2020-35490 suppress
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-35491 suppress
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-8840 suppress
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-9546 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config). CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20200904-0006/ MISC - https://github.com/FasterXML/jackson-databind/issues/2631 MISC - https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E MISC - https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2020.html MLIST - [debian-lts-announce] 20200305 [SECURITY] [DLA 2135-1] jackson-databind security update MLIST - [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12 MLIST - [zookeeper-dev] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200308 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200430 [jira] [Resolved] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 OSSINDEX - [CVE-2020-9546] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... Vulnerable Software & Versions: (show all )
CVE-2020-9547 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap). CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20200904-0006/ MISC - https://github.com/FasterXML/jackson-databind/issues/2634 MISC - https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab@%3Cnotifications.zookeeper.apache.org%3E MISC - https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428@%3Cnotifications.zookeeper.apache.org%3E MISC - https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2020.html MLIST - [debian-lts-announce] 20200305 [SECURITY] [DLA 2135-1] jackson-databind security update MLIST - [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12 MLIST - [zookeeper-dev] 20200307 Build failed in Jenkins: PreCommit-ZOOKEEPER-github-pr-build-maven #1898 MLIST - [zookeeper-dev] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200308 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200430 [jira] [Resolved] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 OSSINDEX - [CVE-2020-9547] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... Vulnerable Software & Versions: (show all )
CVE-2020-9548 suppress
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core). CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20200904-0006/ MISC - https://github.com/FasterXML/jackson-databind/issues/2634 MISC - https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2020.html MLIST - [debian-lts-announce] 20200305 [SECURITY] [DLA 2135-1] jackson-databind security update MLIST - [geode-issues] 20200831 [jira] [Created] (GEODE-8471) Dependency security issues in geode-core-1.12 MLIST - [zookeeper-dev] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Created] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200307 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200308 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Commented] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200319 [jira] [Updated] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 MLIST - [zookeeper-issues] 20200430 [jira] [Resolved] (ZOOKEEPER-3750) update jackson-databind to address CVE-2020-9547, CVE-2020-9548, CVE-2020-9546 OSSINDEX - [CVE-2020-9548] FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee... Vulnerable Software & Versions: (show all )
jackson-dataformat-smile-2.7.9.jarDescription:
Support for reading and writing Smile ("binary JSON")
encoded data using Jackson abstractions (streaming API, data binding,
tree model)
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-smile/2.7.9/jackson-dataformat-smile-2.7.9.jar
MD5: eb20c11444c0aeb464a7302930ec18e0
SHA1: 3aef8d360e5bb6f8044964ba831f5cd53a663fe3
SHA256: 8df9cfc493a3e3c6c0d5eacf019ca06b2fae7f97eac4a7efdbab6694ba1dc643
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-dataformat-smile High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-smile Medium Vendor jar package name jackson Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url http://github.com/FasterXML/jackson-dataformat-smile Highest Vendor pom groupid com.fasterxml.jackson.dataformat Highest Vendor pom name Jackson-dataformat-Smile High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor jar package name fasterxml Highest Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson-dataformat-smile Low Vendor jar package name dataformat Highest Vendor pom parent-artifactid jackson-parent Low Vendor pom groupid fasterxml.jackson.dataformat Highest Vendor Manifest implementation-build-date 2017-02-04 21:35:17+0000 Low Vendor Manifest specification-vendor FasterXML Low Vendor jar package name smile Highest Vendor pom artifactid jackson-dataformat-smile Low Product file name jackson-dataformat-smile High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Implementation-Title Jackson-dataformat-Smile High Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-smile Medium Product jar package name jackson Highest Product pom parent-groupid com.fasterxml.jackson Medium Product Manifest Bundle-Name Jackson-dataformat-Smile Medium Product pom name Jackson-dataformat-Smile High Product jar package name fasterxml Highest Product Manifest bundle-docurl http://github.com/FasterXML/jackson-dataformat-smile Low Product pom url http://github.com/FasterXML/jackson-dataformat-smile Medium Product jar package name dataformat Highest Product Manifest specification-title Jackson-dataformat-Smile Medium Product pom artifactid jackson-dataformat-smile Highest Product pom groupid fasterxml.jackson.dataformat Highest Product pom parent-artifactid jackson-parent Medium Product Manifest implementation-build-date 2017-02-04 21:35:17+0000 Low Product jar package name smile Highest Version pom parent-version 2.7.9 Low Version file version 2.7.9 High Version pom version 2.7.9 Highest Version Manifest Implementation-Version 2.7.9 High Version Manifest Bundle-Version 2.7.9 High
javax.ws.rs-api-2.0.1.jarDescription:
Java API for RESTful Web Services (JAX-RS) License:
CDDL 1.1: http://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/frederic/.m2/repository/javax/ws/rs/javax.ws.rs-api/2.0.1/javax.ws.rs-api-2.0.1.jar
MD5: edcd111cf4d3ba8ac8e1f326efc37a17
SHA1: 104e9c2b5583cfcfeac0402316221648d6d8ea6b
SHA256: 38607d626f2288d8fbc1b1f8a62c369e63806d9a313ac7cbc5f9d6c94f4b466d
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor jar package name rs Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom name javax.ws.rs-api High Vendor jar package name javax Highest Vendor pom url http://jax-rs-spec.java.net Highest Vendor Manifest extension-name javax.ws.rs Medium Vendor pom parent-groupid net.java Medium Vendor pom groupid javax.ws.rs Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor file name javax.ws.rs-api High Vendor jar package name ws Highest Vendor pom parent-artifactid jvnet-parent Low Vendor pom organization url http://www.oracle.com/ Medium Vendor pom artifactid javax.ws.rs-api Low Vendor pom organization name Oracle Corporation High Vendor Manifest bundle-symbolicname javax.ws.rs-api Medium Product pom url http://jax-rs-spec.java.net Medium Product jar package name rs Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom parent-artifactid jvnet-parent Medium Product pom artifactid javax.ws.rs-api Highest Product pom name javax.ws.rs-api High Product jar package name javax Highest Product hint analyzer product web services Medium Product Manifest Bundle-Name javax.ws.rs-api Medium Product Manifest extension-name javax.ws.rs Medium Product pom parent-groupid net.java Medium Product Manifest bundle-docurl http://www.oracle.com/ Low Product pom groupid javax.ws.rs Highest Product pom organization name Oracle Corporation Low Product file name javax.ws.rs-api High Product jar package name ws Highest Product pom organization url http://www.oracle.com/ Low Product Manifest bundle-symbolicname javax.ws.rs-api Medium Version Manifest Implementation-Version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version file version 2.0.1 High Version pom version 2.0.1 Highest
jaxen-1.2.0.jarDescription:
Jaxen is a universal XPath engine for Java. License:
BSD License 2.0: https://raw.githubusercontent.com/jaxen-xpath/jaxen/master/LICENSE.txt File Path: /home/frederic/.m2/repository/jaxen/jaxen/1.2.0/jaxen-1.2.0.jar
MD5: c32cf69356254b8f5050fce6e86358e9
SHA1: c10535a925bd35129a4329bc75065cc6b5293f2c
SHA256: 70feef9dd75ad064def05a3ce8975aeba515ee7d1be146d12199c8828a64174c
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname jaxen Medium Vendor jar package name xpath Highest Vendor pom organization name The Jaxen Project High Vendor pom url http://www.cafeconleche.org/jaxen Highest Vendor Manifest bundle-docurl http://www.cafeconleche.org/jaxen Low Vendor pom groupid jaxen Highest Vendor jar package name jaxen Highest Vendor pom organization url http://www.cafeconleche.org/jaxen Medium Vendor pom artifactid jaxen Low Vendor pom name jaxen High Vendor file name jaxen High Product jar package name xpath Highest Product Manifest Bundle-Name jaxen Medium Product Manifest bundle-docurl http://www.cafeconleche.org/jaxen Low Product jar package name jaxen Highest Product pom groupid jaxen Highest Product pom organization name The Jaxen Project Low Product file name jaxen High Product Manifest bundle-symbolicname jaxen Medium Product pom name jaxen High Product pom url http://www.cafeconleche.org/jaxen Medium Product pom organization url http://www.cafeconleche.org/jaxen Low Product pom artifactid jaxen Highest Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version pom version 1.2.0 Highest
jsr305-3.0.2.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.google.code.findbugs Highest Vendor Manifest bundle-symbolicname org.jsr-305 Medium Vendor file name jsr305 High Vendor pom name FindBugs-jsr305 High Vendor pom url http://findbugs.sourceforge.net/ Highest Vendor pom artifactid jsr305 Low Vendor pom groupid google.code.findbugs Highest Product Manifest Bundle-Name FindBugs-jsr305 Medium Product Manifest bundle-symbolicname org.jsr-305 Medium Product file name jsr305 High Product pom name FindBugs-jsr305 High Product pom url http://findbugs.sourceforge.net/ Medium Product pom artifactid jsr305 Highest Product pom groupid google.code.findbugs Highest Version Manifest Bundle-Version 3.0.2 High Version pom version 3.0.2 Highest Version file version 3.0.2 High
logback-core-1.2.3.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /home/frederic/.m2/repository/ch/qos/logback/logback-core/1.2.3/logback-core-1.2.3.jar
MD5: 841fc80c6edff60d947a3872a2db4d45
SHA1: 864344400c3d4d92dfeb0a305dc87d953677c03c
SHA256: 5946d837fe6f960c02a53eda7a6926ecc3c758bbdd69aa453ee429f858217f22
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name ch Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor pom parent-artifactid logback-parent Low Vendor jar package name qos Highest Vendor jar package name logback Highest Vendor pom groupid ch.qos.logback Highest Vendor file name logback-core High Vendor pom name Logback Core Module High Vendor pom artifactid logback-core Low Vendor jar package name core Highest Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom artifactid logback-core Highest Product jar package name ch Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom parent-artifactid logback-parent Medium Product jar package name logback Highest Product jar package name qos Highest Product pom groupid ch.qos.logback Highest Product file name logback-core High Product pom name Logback Core Module High Product Manifest Bundle-Name Logback Core Module Medium Product jar package name core Highest Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Version file version 1.2.3 High Version Manifest Bundle-Version 1.2.3 High Version pom version 1.2.3 Highest
Related Dependencies logback-classic-1.2.3.jarFile Path: /home/frederic/.m2/repository/ch/qos/logback/logback-classic/1.2.3/logback-classic-1.2.3.jar MD5: 64f7a68f931aed8e5ad8243470440f0b SHA1: 7c4f3c474fb2c041d8028740440937705ebb473a SHA256: fb53f8539e7fcb8f093a56e138112056ec1dc809ebb020b59d8a36a5ebac37e0 pkg:maven/ch.qos.logback/logback-classic@1.2.3 mariadb-java-client-1.7.4.jarDescription:
JDBC driver for MariaDB and MySQL License:
LGPL-2.1 File Path: /home/frederic/.m2/repository/org/mariadb/jdbc/mariadb-java-client/1.7.4/mariadb-java-client-1.7.4.jar
MD5: b9549eb5ba94a85eb1754f030657b853
SHA1: fc07a80cf17857573632d950d7387232474007ba
SHA256: bd14e9d13e79a15b6b2ad4668492d926cf7bfe7da8f5a0434f1b6b65d62a7b6a
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor jar package name driver Highest Vendor pom groupid mariadb.jdbc Highest Vendor jar package name jdbc Highest Vendor pom groupid org.mariadb.jdbc Highest Vendor file name mariadb-java-client High Vendor pom url https://mariadb.com/kb/en/mariadb/about-mariadb-connector-j/ Highest Vendor jar package name mariadb Highest Vendor pom organization url https://mariadb.org Medium Vendor pom organization name mariadb.org High Vendor Manifest bundle-symbolicname org.mariadb.jdbc Medium Vendor pom artifactid mariadb-java-client Low Vendor Manifest automatic-module-name org.mariadb.jdbc Medium Vendor pom name mariadb-java-client High Product jar package name driver Highest Product pom organization name mariadb.org Low Product Manifest Bundle-Name mariadb-java-client Medium Product pom groupid mariadb.jdbc Highest Product pom organization url https://mariadb.org Low Product jar package name jdbc Highest Product file name mariadb-java-client High Product jar package name mariadb Highest Product Manifest bundle-symbolicname org.mariadb.jdbc Medium Product Manifest automatic-module-name org.mariadb.jdbc Medium Product pom url https://mariadb.com/kb/en/mariadb/about-mariadb-connector-j/ Medium Product pom name mariadb-java-client High Product pom artifactid mariadb-java-client Highest Version pom version 1.7.4 Highest Version file version 1.7.4 High Version Manifest Bundle-Version 1.7.4 High
mysql-connector-java-5.1.49.jarDescription:
MySQL JDBC Type 4 driver License:
The GNU General Public License, Version 2: http://www.gnu.org/licenses/old-licenses/gpl-2.0.html File Path: /home/frederic/.m2/repository/mysql/mysql-connector-java/5.1.49/mysql-connector-java-5.1.49.jar
MD5: b46c5a50b6d707b37bd34e27e0f6cbaf
SHA1: cf76d2e4c9c3782a85c15c87bec5772b34ffd0e5
SHA256: 5bba9ff50e5e637a0996a730619dee19ccae274883a4d28c890d945252bb0e12
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor jar package name driver Highest Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom url http://dev.mysql.com/doc/connector-j/en/ Highest Vendor Manifest bundle-symbolicname com.mysql.jdbc Medium Vendor jar package name jdbc Highest Vendor hint analyzer (hint) vendor sun Highest Vendor Manifest Implementation-Vendor-Id com.mysql Medium Vendor file name mysql-connector-java High Vendor jar package name mysql Highest Vendor pom organization url http://www.oracle.com Medium Vendor pom artifactid mysql-connector-java Low Vendor pom name MySQL Connector/J High Vendor hint analyzer vendor oracle Highest Vendor pom groupid mysql Highest Vendor Manifest Implementation-Vendor Oracle High Vendor pom organization name Oracle Corporation High Product jar package name driver Highest Product Manifest bundle-symbolicname com.mysql.jdbc Medium Product pom artifactid mysql-connector-java Highest Product jar package name jdbc Highest Product hint analyzer product mysql_connectors Highest Product hint analyzer product mysql_connector_j Highest Product file name mysql-connector-java High Product pom organization name Oracle Corporation Low Product jar package name mysql Highest Product Manifest specification-title JDBC Medium Product Manifest Implementation-Title MySQL Connector Java High Product pom name MySQL Connector/J High Product Manifest Bundle-Name Oracle Corporation's JDBC Driver for MySQL Medium Product pom organization url http://www.oracle.com Low Product pom groupid mysql Highest Product hint analyzer product mysql_connector/j Highest Product pom url http://dev.mysql.com/doc/connector-j/en/ Medium Version file version 5.1.49 High Version pom version 5.1.49 Highest Version Manifest Implementation-Version 5.1.49 High Version Manifest Bundle-Version 5.1.49 High
Published Vulnerabilities CVE-2017-15945 suppress
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: HIGH (7.2) Vector: /AV:L/AC:L/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2018-3258 (OSSINDEX) suppress
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:mysql:mysql-connector-java:5.1.49:*:*:*:*:*:*:* CVE-2019-2692 suppress
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H). NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:L/AC:H/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: MEDIUM (6.3) Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
netty-all-4.1.59.Final.jarFile Path: /home/frederic/.m2/repository/io/netty/netty-all/4.1.59.Final/netty-all-4.1.59.Final.jarMD5: 20d0265af69d43d65093d152d1ac5f51SHA1: 4d83eab2c554587e15fa9cc20de48c530b23c479SHA256: c483e8103dbce2a4b57e0b99ea2c128a29b57be677ee62e44d767fa425c3fe7aReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor jar package name io Highest Vendor pom artifactid netty-all Low Vendor pom parent-artifactid netty-parent Low Vendor Manifest automatic-module-name io.netty.all Medium Vendor Manifest Implementation-Vendor-Id io.netty Medium Vendor jar package name netty Highest Vendor pom name Netty/All-in-One High Vendor pom groupid io.netty Highest Vendor Manifest Implementation-Vendor The Netty Project High Vendor file name netty-all High Vendor Manifest implementation-url https://netty.io/netty-all/ Low Product jar package name io Highest Product Manifest Implementation-Title Netty/All-in-One High Product Manifest automatic-module-name io.netty.all Medium Product jar package name netty Highest Product pom name Netty/All-in-One High Product pom groupid io.netty Highest Product pom artifactid netty-all Highest Product file name netty-all High Product Manifest implementation-url https://netty.io/netty-all/ Low Product pom parent-artifactid netty-parent Medium Version pom version 4.1.59.Final Highest Version Manifest Implementation-Version 4.1.59.Final High
netty-http-java6-1.5.0.jarDescription:
Waarp shaded jar for Netty HTTP Router for Java 6 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/Waarp/netty-http-java6/1.5.0/netty-http-java6-1.5.0.jar
MD5: c626a48ebeb6d2c0dfea9953a1db333b
SHA1: 11a3759b842014ccadd544dd58c9320a44ff41a1
SHA256: 6676f2f137eace2c32a534567d92c2167aa9e27cc47de585c5d79e7e32bdf373
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid netty-http-java6 Low Vendor pom name Netty based path router Shaded for Java6 High Vendor file name netty-http-java6 High Vendor pom groupid Waarp Highest Vendor pom url cdapio/netty-http Highest Vendor jar package name http Highest Vendor pom parent-artifactid Waarp-Shaded-Parent Low Product Manifest build-jdk-spec 1.8 Low Product pom name Netty based path router Shaded for Java6 High Product pom parent-artifactid Waarp-Shaded-Parent Medium Product pom artifactid netty-http-java6 Highest Product file name netty-http-java6 High Product pom groupid Waarp Highest Product pom url cdapio/netty-http High Product jar package name http Highest Version file version 1.5.0 High Version pom parent-version 1.5.0 Low Version pom version 1.5.0 Highest
netty-tcnative-boringssl-static-2.0.36.Final.jarDescription:
A Mavenized fork of Tomcat Native which incorporates various patches. This artifact is statically linked
to BoringSSL and Apache APR.
File Path: /home/frederic/.m2/repository/io/netty/netty-tcnative-boringssl-static/2.0.36.Final/netty-tcnative-boringssl-static-2.0.36.Final.jarMD5: 61fca971d9f1175e934d5c01d3fcabebSHA1: f35f05118d846dfe30a4e7f757a47601ee9d0ceaSHA256: 2c0d55797dbfcb3d8639eab4957b37a8d7982f32196f029b25a2ff0e326f118fReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor jar package name io Highest Vendor pom parent-artifactid netty-tcnative-parent Low Vendor Manifest automatic-module-name io.netty.tcnative.boringssl Medium Vendor pom name Netty/TomcatNative [BoringSSL - Static] High Vendor file name netty-tcnative-boringssl-static High Vendor jar package name netty Highest Vendor jar package name tcnative Highest Vendor pom groupid io.netty Highest Vendor pom artifactid netty-tcnative-boringssl-static Low Product jar package name io Highest Product pom artifactid netty-tcnative-boringssl-static Highest Product Manifest automatic-module-name io.netty.tcnative.boringssl Medium Product pom name Netty/TomcatNative [BoringSSL - Static] High Product file name netty-tcnative-boringssl-static High Product jar package name netty Highest Product jar package name tcnative Highest Product pom groupid io.netty Highest Product pom parent-artifactid netty-tcnative-parent Medium Version pom version 2.0.36.Final Highest
plugin-1.6.jarDescription:
POM was created from install:install-file File Path: /home/frederic/.m2/repository/sun/plugin/plugin/1.6/plugin-1.6.jarMD5: 9f2c2d224a86c781c284ff697f96cb19SHA1: 3b512f6b1a9b86c83a6e3b95632691e11100a76eSHA256: 35885c3b8bc43df3ada12e05ca74d582d7e4288a03d5f769077095df33cf9b1eReferenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor pom groupid sun.plugin Highest Vendor jar (hint) package name oracle Highest Vendor jar (hint) package name oracle Low Vendor file name plugin High Vendor pom artifactid plugin Low Vendor jar package name sun Highest Vendor jar package name plugin Highest Vendor jar package name sun Low Vendor jar package name plugin2 Low Product pom groupid sun.plugin Highest Product file name plugin High Product pom artifactid plugin Highest Product jar package name sun Highest Product jar package name plugin Highest Product jar package name plugin2 Low Version pom version 1.6 Highest Version file version 1.6 High
postgresql-42.2.19.jre6.jarDescription:
PostgreSQL JDBC Driver Postgresql-jre6 License:
BSD-2-Clause: https://jdbc.postgresql.org/about/license.html File Path: /home/frederic/.m2/repository/org/postgresql/postgresql/42.2.19.jre6/postgresql-42.2.19.jre6.jar
MD5: 3b73434467f488892dffe8948be277b1
SHA1: 3af16b10c6854d42389dffdeb5ca3aa6846c2095
SHA256: 2467bbbb47b868e4ef801b6d20cfd76a0e6dfb8599df2e5d63a0521245cd4e0d
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor jar package name driver Highest Vendor pom groupid org.postgresql Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low Vendor pom name pgdjbc Postgresql-jre6 High Vendor pom url https://jdbc.postgresql.org Highest Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium Vendor jar package name postgresql Highest Vendor Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Vendor pom organization name PostgreSQL Global Development Group High Vendor Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.6))" Low Vendor jar package name jdbc Highest Vendor pom organization url https://jdbc.postgresql.org/ Medium Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High Vendor Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Vendor Manifest Implementation-Vendor-Id org.postgresql Medium Vendor pom artifactid postgresql Low Vendor file name postgresql High Vendor pom groupid postgresql Highest Product jar package name driver Highest Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low Product pom name pgdjbc Postgresql-jre6 High Product Manifest bundle-symbolicname org.postgresql.jdbc Medium Product pom url https://jdbc.postgresql.org Medium Product jar package name postgresql Highest Product Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Product pom organization url https://jdbc.postgresql.org/ Low Product pom artifactid postgresql Highest Product jar package name version Highest Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium Product Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.6))" Low Product Manifest Implementation-Title PostgreSQL JDBC Driver High Product jar package name jdbc Highest Product Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Product jar package name osgi Highest Product Manifest specification-title JDBC Medium Product file name postgresql High Product pom organization name PostgreSQL Global Development Group Low Product pom groupid postgresql Highest Version Manifest Bundle-Version 42.2.19.jre6 High Version Manifest Implementation-Version 42.2.19.jre6 High Version file version 42.2.19.jre6 High Version pom version 42.2.19.jre6 Highest
slf4j-api-1.7.30.jarDescription:
The slf4j API File Path: /home/frederic/.m2/repository/org/slf4j/slf4j-api/1.7.30/slf4j-api-1.7.30.jarMD5: f8be00da99bc4ab64c79ab1e2be7cb7cSHA1: b5a4b6d16ab13e34a88fae84c35cd5d68cac922cSHA256: cdba07964d1bb40a0761485c6b1e8c2f8fd9eb1d19c53928ac0d7f9510105c57Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor pom groupid slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest automatic-module-name org.slf4j Medium Vendor jar package name slf4j Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor file name slf4j-api High Vendor pom parent-groupid org.slf4j Medium Vendor pom artifactid slf4j-api Low Vendor pom url http://www.slf4j.org Highest Product pom groupid slf4j Highest Product pom name SLF4J API Module High Product Manifest Bundle-Name slf4j-api Medium Product pom url http://www.slf4j.org Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest automatic-module-name org.slf4j Medium Product jar package name slf4j Highest Product Manifest Implementation-Title slf4j-api High Product Manifest bundle-symbolicname slf4j.api Medium Product file name slf4j-api High Product pom parent-groupid org.slf4j Medium Product pom parent-artifactid slf4j-parent Medium Product pom artifactid slf4j-api Highest Version pom version 1.7.30 Highest Version Manifest Bundle-Version 1.7.30 High Version file version 1.7.30 High Version Manifest Implementation-Version 1.7.30 High
xercesImpl-2.12.1.jarDescription:
Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family.
This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building
parser components and configurations that is extremely modular and easy to program. The Apache Xerces2 parser is
the reference implementation of XNI but other parser components, configurations, and parsers can be written
using the Xerces Native Interface. For complete design and implementation documents, refer to the XNI Manual.
Xerces2 is a fully conforming XML Schema 1.0 processor. A partial experimental implementation of the XML Schema
1.1 Structures and Datatypes Working Drafts (December 2009) and an experimental implementation of the XML Schema
Definition Language (XSD): Component Designators (SCD) Candidate Recommendation (January 2010) are provided for
evaluation. For more information, refer to the XML Schema page. Xerces2 also provides a complete implementation
of the Document Object Model Level 3 Core and Load/Save W3C Recommendations and provides a complete
implementation of the XML Inclusions (XInclude) W3C Recommendation. It also provides support for OASIS XML
Catalogs v1.1. Xerces2 is able to parse documents written according to the XML 1.1 Recommendation, except that
it does not yet provide an option to enable normalization checking as described in section 2.13 of this
specification. It also handles namespaces according to the XML Namespaces 1.1 Recommendation, and will correctly
serialize XML 1.1 documents if the DOM level 3 load/save APIs are in use.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/frederic/.m2/repository/org/exist-db/thirdparty/xerces/xercesImpl/2.12.1/xercesImpl-2.12.1.jar
MD5: 9f82c362c893779109c1de812c5d4deb
SHA1: 3a206b25679f598a03374afd4e0410d8849b088b
SHA256: ae0c329a3187178c8e7b0369a5346845e426062ffbb8a08fc68ced6affe6c626
Referenced In Project/Scope: Waarp XMLEditor:compile
Evidence Type Source Name Value Confidence Vendor pom groupid exist-db.thirdparty.xerces Highest Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xerces/impl/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium Vendor pom url https://xerces.apache.org/xerces2-j/ Highest Vendor pom name Xerces2-j High Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name parsers Highest Vendor jar package name xml Highest Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium Vendor jar package name datatypes Highest Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name xinclude Highest Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/namespace/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name dom Highest Vendor jar package name version Highest Vendor jar package name xni Highest Vendor manifest: javax/xml/stream/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name serialize Highest Vendor jar package name w3c Highest Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name xerces Highest Vendor file name xercesImpl High Vendor pom artifactid xercesImpl Low Vendor jar package name apache Highest Vendor pom groupid org.exist-db.thirdparty.xerces Highest Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium Product pom groupid exist-db.thirdparty.xerces Highest Product pom name Xerces2-j High Product manifest: org/apache/xerces/impl/ Implementation-Title org.apache.xerces.impl.Version Medium Product jar package name impl Highest Product jar package name parsers Highest Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium Product jar package name xml Highest Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/namespace/ Implementation-Title javax.xml.namespace Medium Product manifest: javax/xml/stream/ Implementation-Title javax.xml.stream Medium Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium Product jar package name datatypes Highest Product manifest: javax/xml/stream/ Specification-Title Streaming API for XML Medium Product jar package name xinclude Highest Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium Product jar package name xpath Highest Product pom artifactid xercesImpl Highest Product jar package name datatype Highest Product jar package name dom Highest Product jar package name xni Highest Product jar package name version Highest Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product jar package name serialize Highest Product jar package name w3c Highest Product jar package name xerces Highest Product file name xercesImpl High Product jar package name validation Highest Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product jar package name apache Highest Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium Product pom url https://xerces.apache.org/xerces2-j/ Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product manifest: javax/xml/namespace/ Specification-Title Java API for XML Processing Medium Version file version 2.12.1 High Version pom version 2.12.1 Highest Version manifest: org/apache/xerces/impl/ Implementation-Version 2.12.1 Medium
Published Vulnerabilities CVE-2018-1000823 suppress
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (10.0) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )