Update dependency com.google.guava:guava to v30 - autoclosed #99
Dev - Mend for GitHub.com / Mend Security Check
failed
May 4, 2024 in 4m 14s
Security Report
You have successfully remediated 3 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2021-45046Path to dependency file: /nifi-nar-bundles/nifi-elasticsearch-bundle/nifi-elasticsearch-5-processors/pom.xml Path to vulnerable library: /nifi-nar-bundles/nifi-elasticsearch-bundle/nifi-elasticsearch-5-processors/pom.xml Dependency Hierarchy: -> ❌ log4j-core-2.7.jar (Vulnerable Library) |
9.0 | log4j-core-2.7.jar | Upgrade to version: org.apache.logging.log4j:log4j-core:2.3.1,2.12.2,2.16.0;org.ops4j.pax.logging:pax-logging-log4j2:1.11.10,2.0.11 | #79 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2020-8908 | guava-19.0.jar |
CVE-2018-10237 | guava-19.0.jar |
CVE-2019-12421 | nifi-rel/nifi-1.3.0 |
Base branch total remaining vulnerabilities: 199
Base branch commit: 08fb68355bdaf12739263105c347040a39d349a3
Total libraries scanned: 415
Scan token: 90fd04f95a1846c2851aafae18144b3e
Loading