[AUTO] Increment version to 2.12.1-SNAPSHOT #1440
Security Report
2 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
CVE-2024-23080Path to dependency file: /build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/joda-time/joda-time/2.12.2/78e18a7b4180e911dafba0a412adfa82c1e3d14b/joda-time-2.12.2.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/joda-time/joda-time/2.12.2/78e18a7b4180e911dafba0a412adfa82c1e3d14b/joda-time-2.12.2.jar Dependency Hierarchy: -> opensearch-2.12.1-SNAPSHOT.jar (Root Library) -> ❌ joda-time-2.12.2.jar (Vulnerable Library) |
Medium | 5.5 | joda-time-2.12.2.jar | None | |
CVE-2021-28170Path to dependency file: /core/build.gradle Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.glassfish/javax.el/3.0.0/dd532526e7c8de48e40419e6af1183658a973379/javax.el-3.0.0.jar Dependency Hierarchy: -> cron-utils-9.1.6.jar (Root Library) -> ❌ javax.el-3.0.0.jar (Vulnerable Library) |
Medium | 5.3 | javax.el-3.0.0.jar | Upgrade to version: org.glassfish:jakarta.el:3.0.4, com.sun.el:el-ri:3.0.4 | None |
Base branch total remaining vulnerabilities: 0
Base branch commit: 62003eed7bc18c52d2e87d0b4f661709e3cec267
Total libraries scanned: 164
Scan token: 83dc34c6110843e6a6127c1b3f2443ea