Update dependency org.eclipse.jetty:jetty-server to v9.4.51.v20230217 - autoclosed #6
Dev - Mend for GitHub.com / Mend Security Check
failed
Jan 9, 2025 in 5m 24s
Security Report
You have successfully remediated 25 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
---|---|---|---|---|---|---|
CVE-2017-9801Path to dependency file: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Path to vulnerable library: /nifi-nar-bundles/nifi-email-bundle/nifi-email-processors/pom.xml Dependency Hierarchy: -> ❌ commons-email-1.4.jar (Vulnerable Library) |
7.5 | commons-email-1.4.jar | Upgrade to version: 1.5 | #90 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2023-26048 | jetty-server-9.4.3.v20170317.jar |
CVE-2021-28165 | jetty-io-9.4.3.v20170317.jar |
CVE-2019-10241 | jetty-util-9.4.3.v20170317.jar |
CVE-2017-7657 | jetty-server-9.4.3.v20170317.jar |
CVE-2020-27218 | jetty-server-9.4.3.v20170317.jar |
CVE-2021-28169 | jetty-servlets-9.4.3.v20170317.jar |
CVE-2019-10241 | jetty-servlet-9.4.3.v20170317.jar |
CVE-2017-7657 | jetty-http-9.4.3.v20170317.jar |
CVE-2018-12536 | jetty-server-9.4.3.v20170317.jar |
CVE-2018-12536 | jetty-servlet-9.4.3.v20170317.jar |
CVE-2017-7656 | jetty-http-9.4.3.v20170317.jar |
CVE-2020-27216 | jetty-webapp-9.4.3.v20170317.jar |
CVE-2018-12538 | jetty-server-9.4.3.v20170317.jar |
CVE-2018-12536 | jetty-util-9.4.3.v20170317.jar |
CVE-2019-10247 | jetty-server-9.4.3.v20170317.jar |
CVE-2019-10241 | jetty-server-9.4.3.v20170317.jar |
CVE-2017-7658 | jetty-http-9.4.3.v20170317.jar |
CVE-2017-9735 | jetty-util-9.4.3.v20170317.jar |
CVE-2021-28169 | jetty-server-9.4.3.v20170317.jar |
CVE-2021-28169 | jetty-http-9.4.3.v20170317.jar |
CVE-2017-7658 | jetty-server-9.4.3.v20170317.jar |
CVE-2019-12421 | nifi-rel/nifi-1.3.0 |
CVE-2021-34428 | jetty-server-9.4.3.v20170317.jar |
CVE-2017-7656 | jetty-server-9.4.3.v20170317.jar |
CVE-2023-26049 | jetty-http-9.4.3.v20170317.jar |
Base branch total remaining vulnerabilities: 261
Base branch commit: d672f5c3ea38dd0e23359cf12d310c2c27abf963
Total libraries scanned: 411
Scan token: 8942ef87d48e4a36bb56ec4bfaf3a55a
Loading