Skip to content

Change gradle copy to sync to clear old jars (#609)

Mend for GitHub.com / Mend Security Check failed Apr 24, 2024 in 12m 32s

Security Report

The Security Check found 2 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-46136

Path to dependency file: /FetchMigration/python/dev-requirements.txt

Path to vulnerable library: /FetchMigration/python/dev-requirements.txt

Dependency Hierarchy:

-> ❌ Werkzeug-2.2.3-py3-none-any.whl (Vulnerable Library)

High 7.5 Werkzeug-2.2.3-py3-none-any.whl Upgrade to version: werkzeug - 2.3.8,3.0.1 #402
CVE-2024-29025

Path to dependency file: /TrafficCapture/replayerPlugins/jsonMessageTransformers/jsonJoltMessageTransformerProvider/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.100.Final/992623e7d8f2d96e41faf1687bb963f5433e3517/netty-codec-http-4.1.100.Final.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.100.Final/992623e7d8f2d96e41faf1687bb963f5433e3517/netty-codec-http-4.1.100.Final.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.100.Final/992623e7d8f2d96e41faf1687bb963f5433e3517/netty-codec-http-4.1.100.Final.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.100.Final/992623e7d8f2d96e41faf1687bb963f5433e3517/netty-codec-http-4.1.100.Final.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/io.netty/netty-codec-http/4.1.100.Final/992623e7d8f2d96e41faf1687bb963f5433e3517/netty-codec-http-4.1.100.Final.jar

Dependency Hierarchy:

-> aws-msk-iam-auth-2.0.3.jar (Root Library)

   -> ssooidc-2.23.3.jar

     -> netty-nio-client-2.23.3.jar

       -> ❌ netty-codec-http-4.1.100.Final.jar (Vulnerable Library)

Medium 5.3 netty-codec-http-4.1.100.Final.jar Upgrade to version: io.netty:netty-codec-http:4.1.108.Final #604

Total libraries scanned: 696
Scan token: f2fcaae7539c48df884ccad57005c23d