Skip to content

Merge pull request #1 from jgeraigery/whitesource/configure

Mend for GitHub.com / Mend Security Check failed Nov 1, 2024 in 12m 25s

Security Report

The Security Check found 151 vulnerabilities.

Partial results (61 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.


CVE Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Suggested Fix Issue Reachability
CVE-2018-14721

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 10.0 Not Defined 1.0% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.7.9.5,2.8.11.3,2.9.7 #234

Reachable

CVE-2022-22965

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-beans/4.0.8.RELEASE/spring-beans-4.0.8.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-starter-1.1.9.RELEASE.jar

     -> spring-boot-1.1.9.RELEASE.jar

       -> spring-context-4.0.8.RELEASE.jar

         -> spring-aop-4.0.8.RELEASE.jar

           -> ❌ spring-beans-4.0.8.RELEASE.jar (Vulnerable Library)

Critical 9.8 High 97.5% spring-beans-4.0.8.RELEASE.jar Upgrade to version: org.springframework:spring-beans:5.2.20.RELEASE,5.3.18 #234

Reachable

CVE-2020-9548

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.4% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4 #234

Reachable

CVE-2020-9547

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.70000005% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.6,2.9.10.4 #234

Reachable

CVE-2020-9546

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.70000005% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.10.3 #234

Reachable

CVE-2020-8840

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 3.0% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.3 #234

Reachable

CVE-2019-20330

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.6% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.7,2.8.11.5,2.9.10.2 #234

Reachable

CVE-2019-17531

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 1.0% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10.1 #234

Reachable

CVE-2019-17267

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 1.4000001% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.8.11.5,2.9.10 #234

Reachable

CVE-2019-16943

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.5% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.7.9.7,2.8.11.5,2.9.10.1 #234

Reachable

CVE-2019-16942

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.5% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.7.9.7,2.8.11.5,2.9.10.1 #234

Reachable

CVE-2019-16335

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.5% jackson-databind-2.3.4.jar Upgrade to version: 2.9.10 #234

Reachable

CVE-2019-14893

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 2.5% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.10.0 #234

Reachable

CVE-2019-14892

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.4% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10 #234

Reachable

CVE-2019-14540

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.6% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.3,2.8.11.5,2.9.10 #234

Reachable

CVE-2019-14379

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 1.0% jackson-databind-2.3.4.jar Upgrade to version: 2.9.9.2 #234

Reachable

CVE-2019-10202

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 1.9% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.0.0 #234

Reachable

CVE-2018-7489

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 93.7% jackson-databind-2.3.4.jar Upgrade to version: 2.8.11.1,2.9.5 #234

Reachable

CVE-2018-19362

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.5% jackson-databind-2.3.4.jar Upgrade to version: 2.9.8 #234

Reachable

CVE-2018-19361

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.5% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.5,2.8.11.3,2.9.8 #234

Reachable

CVE-2018-19360

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.5% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.5,2.8.11.3,2.9.8,2.10.0.pr1 #234

Reachable

CVE-2018-14720

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.5,2.8.11.3,2.9.7 #234

Reachable

CVE-2018-14719

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 1.0% jackson-databind-2.3.4.jar Upgrade to version: 2.9.7 #234

Reachable

CVE-2018-14718

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 3.9% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.7.9.5,2.8.11.3,2.9.7 #234

Reachable

CVE-2018-11307

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 1.3000001% jackson-databind-2.3.4.jar Upgrade to version: jackson-databind-2.9.6 #234

Reachable

CVE-2017-7525

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 49.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.6.7.1,2.7.9.1,2.8.9 #234

Reachable

CVE-2017-17485

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 14.0% jackson-databind-2.3.4.jar Upgrade to version: 2.9.4 #234

Reachable

CVE-2017-15095

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

Critical 9.8 Not Defined 2.6000001% jackson-databind-2.3.4.jar Upgrade to version: 2.8.10,2.9.1 #234

Reachable

CVE-2015-5211

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.0.8.RELEASE/spring-web-4.0.8.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-security-1.1.9.RELEASE.jar (Root Library)

   -> ❌ spring-web-4.0.8.RELEASE.jar (Vulnerable Library)

Critical 9.6 Not Defined 0.3% spring-web-4.0.8.RELEASE.jar Upgrade to version: org.springframework:spring-web:4.2.2.RELEASE,4.1.8.RELEASE,3.2.15.RELEASE,org.springframework:spring-webmvc:4.2.2.RELEASE,4.1.8.RELEASE,3.2.15.RELEASE,org.springframework:spring-websocket:4.2.2.RELEASE,4.1.8.RELEASE,3.2.15.RELEASE #232

Reachable

WS-2021-0170

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-core/4.0.8.RELEASE/spring-core-4.0.8.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-starter-1.1.9.RELEASE.jar

     -> spring-boot-1.1.9.RELEASE.jar

       -> ❌ spring-core-4.0.8.RELEASE.jar (Vulnerable Library)

Critical 9.0 Not Defined spring-core-4.0.8.RELEASE.jar Upgrade to version: org.springframework:spring-core:v4.1.9.RELEASE,v4.2.3.RELEASE #234

Reachable

CVE-2020-11113

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4;2.10.0 #234

Reachable

CVE-2020-11112

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0 #234

Reachable

CVE-2020-11111

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4,2.10.0 #234

Reachable

CVE-2020-10969

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.8.11.6;com.fasterxml.jackson.core:jackson-databind:2.7.9.7 #234

Reachable

CVE-2020-10968

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: jackson-databind-2.9.10.4 #234

Reachable

CVE-2020-10673

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4 #234

Reachable

CVE-2020-10672

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.8 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: jackson-databind-2.9.10.4 #234

Reachable

CVE-2024-22262

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.0.8.RELEASE/spring-web-4.0.8.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-security-1.1.9.RELEASE.jar (Root Library)

   -> ❌ spring-web-4.0.8.RELEASE.jar (Vulnerable Library)

High 8.1 Not Defined 0.1% spring-web-4.0.8.RELEASE.jar Upgrade to version: org.springframework:spring-web:5.3.34;6.0.19,6.1.6 #232

Reachable

CVE-2024-22259

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.0.8.RELEASE/spring-web-4.0.8.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-security-1.1.9.RELEASE.jar (Root Library)

   -> ❌ spring-web-4.0.8.RELEASE.jar (Vulnerable Library)

High 8.1 Not Defined 0.1% spring-web-4.0.8.RELEASE.jar Upgrade to version: org.springframework:spring-web:5.3.33,6.0.18,6.1.5 #232

Reachable

CVE-2024-22243

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-web/4.0.8.RELEASE/spring-web-4.0.8.RELEASE.jar

Dependency Hierarchy:

-> spring-boot-starter-security-1.1.9.RELEASE.jar (Root Library)

   -> ❌ spring-web-4.0.8.RELEASE.jar (Vulnerable Library)

High 8.1 Not Defined 0.1% spring-web-4.0.8.RELEASE.jar Upgrade to version: org.springframework:spring-web:5.3.32,6.0.17,6.1.4 #232

Reachable

CVE-2021-20190

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.4% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind-2.9.10.7 #234

Reachable

CVE-2020-36189

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36188

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36187

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36186

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36185

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36184

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36183

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36182

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36181

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36180

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-36179

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.4% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.8 #234

Reachable

CVE-2020-24750

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.70000005% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.6 #234

Reachable

CVE-2020-24616

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 1.2% jackson-databind-2.3.4.jar Upgrade to version: 2.9.10.6 #234

Reachable

CVE-2020-14195

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 3.4% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.5 #234

Reachable

CVE-2020-14062

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 7.2% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.10.0 #234

Reachable

CVE-2020-14061

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 4.7% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.10.0 #234

Reachable

CVE-2020-14060

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 13.500001% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.10.0 #234

Reachable

CVE-2020-11620

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 4.3% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4 #234

Reachable

CVE-2020-11619

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 5.0% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4 #234

Reachable

CVE-2020-10650

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.4/jackson-databind-2.3.4.jar

Dependency Hierarchy:

-> spring-boot-starter-actuator-1.1.9.RELEASE.jar (Root Library)

   -> spring-boot-actuator-1.1.9.RELEASE.jar

     -> ❌ jackson-databind-2.3.4.jar (Vulnerable Library)

High 8.1 Not Defined 0.8% jackson-databind-2.3.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.9.10.4 #234

Reachable


Total libraries scanned: 39
Scan token: 38db85a7b54514040a8d0e2f33744bc2b1730462400064_411