Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 7.3.2Report Generated On : Mon, 21 Nov 2022 18:37:52 +0200Dependencies Scanned : 536 (467 unique)Vulnerable Dependencies : 65 Vulnerabilities Found : 411Vulnerabilities Suppressed : 0... NVD CVE Checked : 2022-11-21T17:46:58NVD CVE Modified : 2022-11-21T17:00:04VersionCheckOn : 2022-11-21T11:57:38Analysis Exceptions Unable to resolve system scoped dependency: com.sun:tools:jar:1.8.0:system exception : org.owasp.dependencycheck.exception.DependencyNotFoundException: Unable to resolve system scoped dependency: com.sun:tools:jar:1.8.0:system
org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.collectMavenDependencies(BaseDependencyCheckMojo.java:1359) org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.collectDependencies(BaseDependencyCheckMojo.java:1573) org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.scanArtifacts(BaseDependencyCheckMojo.java:1163) org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.scanArtifacts(BaseDependencyCheckMojo.java:1129) org.owasp.dependencycheck.maven.CheckMojo.scanDependencies(CheckMojo.java:104) org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.runCheck(BaseDependencyCheckMojo.java:1833) org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.execute(BaseDependencyCheckMojo.java:1016) org.apache.maven.plugin.DefaultBuildPluginManager.executeMojo(DefaultBuildPluginManager.java:137) org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:208) org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:154) org.apache.maven.lifecycle.internal.MojoExecutor.execute(MojoExecutor.java:146) org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject(LifecycleModuleBuilder.java:117) org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject(LifecycleModuleBuilder.java:81) org.apache.maven.lifecycle.internal.builder.singlethreaded.SingleThreadedBuilder.build(SingleThreadedBuilder.java:56) org.apache.maven.lifecycle.internal.LifecycleStarter.execute(LifecycleStarter.java:128) org.apache.maven.DefaultMaven.doExecute(DefaultMaven.java:305) org.apache.maven.DefaultMaven.doExecute(DefaultMaven.java:192) org.apache.maven.DefaultMaven.execute(DefaultMaven.java:105) org.apache.maven.cli.MavenCli.execute(MavenCli.java:954) org.apache.maven.cli.MavenCli.doMain(MavenCli.java:288) org.apache.maven.cli.MavenCli.main(MavenCli.java:192) sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) java.lang.reflect.Method.invoke(Method.java:498) org.codehaus.plexus.classworlds.launcher.Launcher.launchEnhanced(Launcher.java:289) org.codehaus.plexus.classworlds.launcher.Launcher.launch(Launcher.java:229) org.codehaus.plexus.classworlds.launcher.Launcher.mainWithExitCode(Launcher.java:415) org.codehaus.plexus.classworlds.launcher.Launcher.main(Launcher.java:356) org.codehaus.classworlds.Launcher.main(Launcher.java:47) Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies CommentComponent.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/src/CommentComponent.jsMD5: f604e3836e3e5b07bd1eb3a56aff87efSHA1: 76878fccff6799e9dad6d45c2c7d712126d3b191SHA256: 9a35214888ae993a828897e6a082f762afb73a91b01d255979a761b4f99b30daReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
CommentsList.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/src/CommentsList.jsMD5: 24577052f327a98f59343628104fda57SHA1: ea8973c83cb28ed7c2f622b6e0b8f7b72a5885a6SHA256: fd7fc72ecafa0af0f963b7e8c1cd6fd193a6ebdc16f6a3db1bb60e5d2df9a41bReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
CommentsListTable.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/src/CommentsListTable.jsMD5: 9deba8c86d98d7c790971cd15fb80400SHA1: ef2b4c463397b40b259cd549b346ece6a29a1588SHA256: 69f764a06392e3c4611c6d8f3574a7039aef6ead5415be4b2ce56ca091e4fba2Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
FastInfoset-1.2.15.jarDescription:
Open Source implementation of the Fast Infoset Standard for Binary XML (http://www.itu.int/ITU-T/asn1/). License:
http://www.opensource.org/licenses/apache2.0.php File Path: /home/andrii/.m2/repository/com/sun/xml/fastinfoset/FastInfoset/1.2.15/FastInfoset-1.2.15.jar
MD5: 57f3894ad7e069ae740b277d92d10fa0
SHA1: bb7b7ec0379982b97c62cd17465cb6d9155f68e8
SHA256: 785861db11ca1bd0d1956682b974ad73eb19cd3e01a4b3fa82d62eca97210aec
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name FastInfoset High Vendor jar package name fastinfoset Highest Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname com.sun.xml.fastinfoset.FastInfoset Medium Vendor Manifest extension-name com.sun.xml.fastinfoset Medium Vendor Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Vendor Manifest implementation-url http://fi.java.net Low Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor Manifest url http://fi.java.net Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom artifactid FastInfoset Highest Vendor pom artifactid FastInfoset Low Vendor pom groupid com.sun.xml.fastinfoset Highest Vendor pom name fastinfoset High Vendor pom parent-artifactid fastinfoset-project Low Vendor pom url http://fi.java.net Highest Product file name FastInfoset High Product jar package name fastinfoset Highest Product jar package name sun Highest Product jar package name xml Highest Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name fastinfoset Medium Product Manifest bundle-symbolicname com.sun.xml.fastinfoset.FastInfoset Medium Product Manifest extension-name com.sun.xml.fastinfoset Medium Product Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Product Manifest Implementation-Title Fast Infoset Implementation High Product Manifest implementation-url http://fi.java.net Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product Manifest specification-title ITU-T Rec. X.891 | ISO/IEC 24824-1 (Fast Infoset) Medium Product Manifest url http://fi.java.net Low Product pom artifactid FastInfoset Highest Product pom groupid com.sun.xml.fastinfoset Highest Product pom name fastinfoset High Product pom parent-artifactid fastinfoset-project Medium Product pom url http://fi.java.net Medium Version file version 1.2.15 High Version Manifest Bundle-Version 1.2.15 High Version Manifest Implementation-Version 1.2.15 High Version pom version 1.2.15 Highest
HdrHistogram-2.1.11.jarDescription:
HdrHistogram supports the recording and analyzing sampled data value
counts across a configurable integer value range with configurable value
precision within the range. Value precision is expressed as the number of
significant digits in the value recording, and provides control over value
quantization behavior across the value range and the subsequent value
resolution at any given level.
License:
Public Domain, per Creative Commons CC0: http://creativecommons.org/publicdomain/zero/1.0/
BSD-2-Clause: https://opensource.org/licenses/BSD-2-Clause File Path: /home/andrii/.m2/repository/org/hdrhistogram/HdrHistogram/2.1.11/HdrHistogram-2.1.11.jar
MD5: f3a8c558c7786948ff98819f8eac191f
SHA1: 1b035a1a4ce5d3441a4a1a331d04839ef487ec49
SHA256: 96671e0898b35d602869efd9339b1929cdac855d2bc64922efbbcdd2209816bc
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name HdrHistogram High Vendor jar package name hdrhistogram Highest Vendor Manifest bundle-symbolicname org.hdrhistogram.HdrHistogram Medium Vendor Manifest Implementation-Vendor-Id org.hdrhistogram Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid HdrHistogram Highest Vendor pom artifactid HdrHistogram Low Vendor pom developer id giltene Medium Vendor pom developer name Gil Tene Medium Vendor pom groupid org.hdrhistogram Highest Vendor pom name HdrHistogram High Vendor pom url http://hdrhistogram.github.io/HdrHistogram/ Highest Product file name HdrHistogram High Product jar package name hdrhistogram Highest Product jar package name version Highest Product Manifest Bundle-Name HdrHistogram Medium Product Manifest bundle-symbolicname org.hdrhistogram.HdrHistogram Medium Product Manifest Implementation-Title HdrHistogram High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title HdrHistogram Medium Product pom artifactid HdrHistogram Highest Product pom developer id giltene Low Product pom developer name Gil Tene Low Product pom groupid org.hdrhistogram Highest Product pom name HdrHistogram High Product pom url http://hdrhistogram.github.io/HdrHistogram/ Medium Version file version 2.1.11 High Version Manifest Bundle-Version 2.1.11 High Version Manifest Implementation-Version 2.1.11 High Version pom version 2.1.11 Highest
Header.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/src/components/Header.jsMD5: bfb3be919ff22b414815f7b95ce90f2fSHA1: 55f1378910bb06280791d4a929538761881d6135SHA256: d0dc6faf13d0e692aa6852fe152adf9ae66b7b7995b3e401e2b907f508177ec9Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
HikariCP-2.5.1.jarDescription:
Ultimate JDBC Connection Pool License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/zaxxer/HikariCP/2.5.1/HikariCP-2.5.1.jar
MD5: 4fd401dee8e525cbb8403476381e34cd
SHA1: b896b711e2d98fedf403de590559a123b5fbf1a6
SHA256: 3cf7bc5258414b77613e8d8ef0ce63b3ae1c53a441fd95b9ea335ec051c652b2
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name HikariCP High Vendor jar package name pool Highest Vendor jar package name zaxxer Highest Vendor Manifest bundle-docurl https://github.com/brettwooldridge Low Vendor Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid HikariCP Highest Vendor pom artifactid HikariCP Low Vendor pom developer email brett.wooldridge@gmail.com Low Vendor pom developer name Brett Wooldridge Medium Vendor pom groupid com.zaxxer Highest Vendor pom name HikariCP High Vendor pom organization name Zaxxer.com High Vendor pom organization url brettwooldridge Medium Vendor pom url brettwooldridge/HikariCP Highest Product file name HikariCP High Product jar package name pool Highest Product jar package name zaxxer Highest Product Manifest bundle-docurl https://github.com/brettwooldridge Low Product Manifest Bundle-Name HikariCP Medium Product Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid HikariCP Highest Product pom developer email brett.wooldridge@gmail.com Low Product pom developer name Brett Wooldridge Low Product pom groupid com.zaxxer Highest Product pom name HikariCP High Product pom organization name Zaxxer.com Low Product pom url brettwooldridge High Product pom url brettwooldridge/HikariCP High Version file version 2.5.1 High Version Manifest Bundle-Version 2.5.1 High Version pom version 2.5.1 Highest
LatencyUtils-2.0.3.jarDescription:
LatencyUtils is a package that provides latency recording and reporting utilities.
License:
Public Domain, per Creative Commons CC0: http://creativecommons.org/publicdomain/zero/1.0/ File Path: /home/andrii/.m2/repository/org/latencyutils/LatencyUtils/2.0.3/LatencyUtils-2.0.3.jar
MD5: 2ad12e1ef7614cecfb0483fa9ac6da73
SHA1: 769c0b82cb2421c8256300e907298a9410a2a3d3
SHA256: a32a9ffa06b2f4e01c5360f8f9df7bc5d9454a5d373cd8f361347fa5a57165ec
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name LatencyUtils High Vendor jar package name latencyutils Highest Vendor jar package name latencyutils Low Vendor pom artifactid LatencyUtils Highest Vendor pom artifactid LatencyUtils Low Vendor pom developer id giltene Medium Vendor pom developer name Gil Tene Medium Vendor pom groupid org.latencyutils Highest Vendor pom name LatencyUtils High Vendor pom url http://latencyutils.github.io/LatencyUtils/ Highest Product file name LatencyUtils High Product jar package name latencyutils Highest Product pom artifactid LatencyUtils Highest Product pom developer id giltene Low Product pom developer name Gil Tene Low Product pom groupid org.latencyutils Highest Product pom name LatencyUtils High Product pom url http://latencyutils.github.io/LatencyUtils/ Medium Version file version 2.0.3 High Version pom version 2.0.3 Highest
Profile.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/src/Profile.jsMD5: 7010338352cbac6fbb39cf9e45c9f861SHA1: 89b9c79b3f52d2d6ff87efc96f9025e564f1fc2aSHA256: 5fdf376e4f07d4905550fe069852311f20e13a13526a32b30ce8b315f4f11019Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
Select-7552e2b8.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/Select-7552e2b8.jsMD5: 633817c17f07db70dab12018d3d1125dSHA1: 9dba0ed054a9ec5cf449a7d275859e9d1b478324SHA256: f15ff74055fe99b81430b46cf847b8c896260d1c6e82ed8282401c3bad37c238Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
activation-1.0.2.jarDescription:
JavaBeans Activation Framework (JAF) is a standard extension to the Java platform that lets you take advantage of standard services to: determine the type of an arbitrary piece of data; encapsulate access to it; discover the operations available on it; and instantiate the appropriate bean to perform the operation(s).
File Path: /home/andrii/.m2/repository/javax/activation/activation/1.0.2/activation-1.0.2.jarMD5: 5ff36dc2285e21d8628e92fdcc63f6a4SHA1: a2a2e2e89d143d24ddba9a76e5c36603969db30fSHA256: 846f22648b244e521ec8478b1e3c9606f487f0577022d3c0c6f7b9d5d843ffe1Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name activation High Vendor jar package name activation Highest Vendor jar package name javax Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest extension-name javax.activation Medium Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest sccs-id @(#)jaf.mf 1.1 02/03/15 Low Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor pom artifactid activation Highest Vendor pom artifactid activation Low Vendor pom groupid javax.activation Highest Vendor pom name JavaBeans Activation Framework (JAF) High Vendor pom url http://java.sun.com/products/javabeans/jaf/index.jsp Highest Product file name activation High Product jar package name activation Highest Product jar package name javax Highest Product Manifest extension-name javax.activation Medium Product Manifest sccs-id @(#)jaf.mf 1.1 02/03/15 Low Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium Product pom artifactid activation Highest Product pom groupid javax.activation Highest Product pom name JavaBeans Activation Framework (JAF) High Product pom url http://java.sun.com/products/javabeans/jaf/index.jsp Medium Version file version 1.0.2 High Version Manifest Implementation-Version 1.0.2 High Version pom version 1.0.2 Highest
activeobjects-dbex-3.3.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/activeobjects/activeobjects-dbex/3.3.1/activeobjects-dbex-3.3.1.jarMD5: f3658eee5bc7326eb7cd90e822198094SHA1: 532fb0da1761b86ff32b7bb6ad52324ab4e89cc8SHA256: c7ef3546c23aba7408cb3023ed1a84bbccceaae6cb33633c81a7a53a68627a91Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name activeobjects-dbex High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name dbexporter Low Vendor jar package name exporter Highest Vendor jar package name importer Highest Vendor pom artifactid activeobjects-dbex Highest Vendor pom artifactid activeobjects-dbex Low Vendor pom groupid com.atlassian.activeobjects Highest Vendor pom name DB Exporter (and Importer) High Vendor pom parent-artifactid activeobjects-plugin-parent-pom Low Product file name activeobjects-dbex High Product jar package name atlassian Highest Product jar package name dbexporter Low Product jar package name exporter Highest Product jar package name importer Highest Product pom artifactid activeobjects-dbex Highest Product pom groupid com.atlassian.activeobjects Highest Product pom name DB Exporter (and Importer) High Product pom parent-artifactid activeobjects-plugin-parent-pom Medium Version file version 3.3.1 High Version pom version 3.3.1 Highest
activeobjects-spi-3.3.1.jarDescription:
This is the SPI that Atlassian product need to implement in order to support ActiveObjects. File Path: /home/andrii/.m2/repository/com/atlassian/activeobjects/activeobjects-spi/3.3.1/activeobjects-spi-3.3.1.jarMD5: 48802dda593a18f0160290b603aaf474SHA1: 6934b3dc0ba7dceea31c63ac7e39b44cf3f40ab2SHA256: 889f9ab723b26d551ef9bcbfb5a9ed65e727e915a80c61f439f8b7cffae59314Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name activeobjects-spi High Vendor jar package name activeobjects Highest Vendor jar package name activeobjects Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor pom artifactid activeobjects-spi Highest Vendor pom artifactid activeobjects-spi Low Vendor pom groupid com.atlassian.activeobjects Highest Vendor pom name ActiveObjects Plugin - SPI High Vendor pom parent-artifactid activeobjects-plugin-parent-pom Low Product file name activeobjects-spi High Product jar package name activeobjects Highest Product jar package name activeobjects Low Product jar package name atlassian Highest Product jar package name spi Highest Product jar package name spi Low Product pom artifactid activeobjects-spi Highest Product pom groupid com.atlassian.activeobjects Highest Product pom name ActiveObjects Plugin - SPI High Product pom parent-artifactid activeobjects-plugin-parent-pom Medium Version file version 3.3.1 High Version pom version 3.3.1 Highest
adal4j-1.6.6.jarDescription:
Azure active directory library for Java gives you the ability to add Windows Azure Active Directory
authentication to your web application with just a few lines of additional code. Using our ADAL SDKs you
can quickly and easily extend your existing application to all the employees that use Windows Azure
AD and Active Directory on-premises using Active Directory Federation Services, including Office365
customers.
License:
MIT License File Path: /home/andrii/.m2/repository/com/microsoft/azure/adal4j/1.6.6/adal4j-1.6.6.jar
MD5: 611ee5f9a29bdb17454ed39b53d5e75b
SHA1: 44a306f7974f1e10e077efb60fdc478bf312dfd0
SHA256: 87c5b1739f29587f2d7784e53a4ef4091e6a60373783773aed2ff6b6d8b7dd7e
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name adal4j High Vendor jar package name adal4j Highest Vendor jar package name microsoft Highest Vendor Manifest Implementation-Vendor-Id com.microsoft.azure Medium Vendor pom artifactid adal4j Highest Vendor pom artifactid adal4j Low Vendor pom developer id msopentech Medium Vendor pom developer name Microsoft Open Technologies, Inc. Medium Vendor pom groupid com.microsoft.azure Highest Vendor pom name adal4j High Vendor pom url AzureAD/azure-activedirectory-library-for-java Highest Product file name adal4j High Product jar package name adal4j Highest Product jar package name microsoft Highest Product Manifest Implementation-Title adal4j High Product Manifest specification-title adal4j Medium Product pom artifactid adal4j Highest Product pom developer id msopentech Low Product pom developer name Microsoft Open Technologies, Inc. Low Product pom groupid com.microsoft.azure Highest Product pom name adal4j High Product pom url AzureAD/azure-activedirectory-library-for-java High Version file version 1.6.6 High Version Manifest Implementation-Version 1.6.6 High Version pom version 1.6.6 Highest
CVE-2021-42306 suppress
Azure Active Directory Information Disclosure Vulnerability CWE-522 Insufficiently Protected Credentials
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
aether-api-1.0.0.v20140518.jarDescription:
The application programming interface for the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/andrii/.m2/repository/org/eclipse/aether/aether-api/1.0.0.v20140518/aether-api-1.0.0.v20140518.jar
MD5: b05ef5410dad83a4e9ba50e08e0dbbf4
SHA1: be68e917f454dcd841865ad7cf9b7615b26a51f7
SHA256: 84b98521684ab22f9528470fa6d8ab68a230e1b211623c989ba7016c306eb773
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aether-api High Vendor jar package name aether Highest Vendor jar package name eclipse Highest Vendor jar package name repository Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-api/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.eclipse.aether.api Medium Vendor pom artifactid aether-api Highest Vendor pom artifactid aether-api Low Vendor pom groupid org.eclipse.aether Highest Vendor pom name Aether API High Vendor pom parent-artifactid aether Low Product file name aether-api High Product jar package name aether Highest Product jar package name eclipse Highest Product jar package name repository Highest Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-api/ Low Product Manifest Bundle-Name Aether API Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.eclipse.aether.api Medium Product pom artifactid aether-api Highest Product pom groupid org.eclipse.aether Highest Product pom name Aether API High Product pom parent-artifactid aether Medium Version file version 1.0.0.v20140518 High Version Manifest Bundle-Version 1.0.0.v20140518 High Version pom version 1.0.0.v20140518 Highest
aether-api-1.7.jarDescription:
The application programming interface for the repository system.
File Path: /home/andrii/.m2/repository/org/sonatype/aether/aether-api/1.7/aether-api-1.7.jarMD5: fa35448855735ad6aa16952b0efc7a4eSHA1: 0c491a637ee6795143b6708ce5f112e6a9f548f4SHA256: 1c5c5ac5e8f29aefc8faa051ffa14eccd85b9e20f4bb35dc82fba7d5da50d326Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aether-api High Vendor jar package name aether Highest Vendor jar package name aether Low Vendor jar package name repository Highest Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor pom artifactid aether-api Highest Vendor pom artifactid aether-api Low Vendor pom groupid org.sonatype.aether Highest Vendor pom name Aether :: API High Vendor pom parent-artifactid aether-parent Low Product file name aether-api High Product jar package name aether Highest Product jar package name aether Low Product jar package name repository Highest Product jar package name sonatype Highest Product pom artifactid aether-api Highest Product pom groupid org.sonatype.aether Highest Product pom name Aether :: API High Product pom parent-artifactid aether-parent Medium Version file version 1.7 High Version pom version 1.7 Highest
aether-impl-1.7.jarDescription:
An implementation of the repository system.
File Path: /home/andrii/.m2/repository/org/sonatype/aether/aether-impl/1.7/aether-impl-1.7.jarMD5: 88f67bb92b68df022a22ca837b0ebeeeSHA1: 5cc1803eb7126f759d34007b74e6dc44e9a9fb08SHA256: 288149850d8d131763df4151f7e443fd2739e48510a6e4cfe49ca082c76130faReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aether-impl High Vendor jar package name aether Highest Vendor jar package name aether Low Vendor jar package name impl Highest Vendor jar package name impl Low Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor pom artifactid aether-impl Highest Vendor pom artifactid aether-impl Low Vendor pom groupid org.sonatype.aether Highest Vendor pom name Aether :: Implementation High Vendor pom parent-artifactid aether-parent Low Product file name aether-impl High Product jar package name aether Highest Product jar package name aether Low Product jar package name impl Highest Product jar package name impl Low Product jar package name internal Low Product jar package name sonatype Highest Product pom artifactid aether-impl Highest Product pom groupid org.sonatype.aether Highest Product pom name Aether :: Implementation High Product pom parent-artifactid aether-parent Medium Version file version 1.7 High Version pom version 1.7 Highest
aether-spi-1.7.jarDescription:
The service provider interface for repository system implementations and repository connectors.
File Path: /home/andrii/.m2/repository/org/sonatype/aether/aether-spi/1.7/aether-spi-1.7.jarMD5: ba2419eb80b2eca0c804e21b58fb3e1fSHA1: 1ea472b28d9d891d353c0311593f5e2a0e73d4beSHA256: f54a0a28ce3d62af0e1cfe41dde616f645c28e452e77f77b78bc36e74d5e1a69Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aether-spi High Vendor jar package name aether Highest Vendor jar package name aether Low Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor pom artifactid aether-spi Highest Vendor pom artifactid aether-spi Low Vendor pom groupid org.sonatype.aether Highest Vendor pom name Aether :: SPI High Vendor pom parent-artifactid aether-parent Low Product file name aether-spi High Product jar package name aether Highest Product jar package name aether Low Product jar package name connector Low Product jar package name sonatype Highest Product jar package name spi Highest Product jar package name spi Low Product pom artifactid aether-spi Highest Product pom groupid org.sonatype.aether Highest Product pom name Aether :: SPI High Product pom parent-artifactid aether-parent Medium Version file version 1.7 High Version pom version 1.7 Highest
aether-util-1.0.0.v20140518.jarDescription:
A collection of utility classes to ease usage of the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/andrii/.m2/repository/org/eclipse/aether/aether-util/1.0.0.v20140518/aether-util-1.0.0.v20140518.jar
MD5: 08495ee7ecf90f0b528e7d65471532af
SHA1: 7df5ba98ce8b78985d75fdd8c2981fe69234ef85
SHA256: aff0951639837c4e3a4699a421fa79f410032f603f5c6a5bba435e98531f3984
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aether-util High Vendor jar package name aether Highest Vendor jar package name eclipse Highest Vendor jar package name repository Highest Vendor jar package name util Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-util/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.eclipse.aether.util Medium Vendor pom artifactid aether-util Highest Vendor pom artifactid aether-util Low Vendor pom groupid org.eclipse.aether Highest Vendor pom name Aether Utilities High Vendor pom parent-artifactid aether Low Product file name aether-util High Product jar package name aether Highest Product jar package name eclipse Highest Product jar package name repository Highest Product jar package name util Highest Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-util/ Low Product Manifest Bundle-Name Aether Utilities Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.eclipse.aether.util Medium Product pom artifactid aether-util Highest Product pom groupid org.eclipse.aether Highest Product pom name Aether Utilities High Product pom parent-artifactid aether Medium Version file version 1.0.0.v20140518 High Version Manifest Bundle-Version 1.0.0.v20140518 High Version pom version 1.0.0.v20140518 Highest
aether-util-1.7.jarDescription:
A collection of utility classes to ease usage of the repository system.
File Path: /home/andrii/.m2/repository/org/sonatype/aether/aether-util/1.7/aether-util-1.7.jarMD5: df02504fdf485555fc8bec459325d4baSHA1: 38485c9c086c3c867c2dd5371909337bd056c492SHA256: ff690ffc550b7ada3a4b79ef4ca89bf002b24f43a13a35d10195c3bba63d7654Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aether-util High Vendor jar package name aether Highest Vendor jar package name aether Low Vendor jar package name repository Highest Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor jar package name util Highest Vendor jar package name util Low Vendor pom artifactid aether-util Highest Vendor pom artifactid aether-util Low Vendor pom groupid org.sonatype.aether Highest Vendor pom name Aether :: Utilities High Vendor pom parent-artifactid aether-parent Low Product file name aether-util High Product jar package name aether Highest Product jar package name aether Low Product jar package name repository Highest Product jar package name sonatype Highest Product jar package name util Highest Product jar package name util Low Product pom artifactid aether-util Highest Product pom groupid org.sonatype.aether Highest Product pom name Aether :: Utilities High Product pom parent-artifactid aether-parent Medium Version file version 1.7 High Version pom version 1.7 Highest
aho-corasick-double-array-trie-1.2.3.jarDescription:
An extremely fast implementation of Aho Corasick algorithm based on Double Array Trie.
License:
Apache License Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/com/hankcs/aho-corasick-double-array-trie/1.2.3/aho-corasick-double-array-trie-1.2.3.jar
MD5: e19c35a59076f62613b6aa49f03ae116
SHA1: 7692c7e46a056a87ce01fa0d0b733ad3586552e5
SHA256: 564f0fc690d50702a313510b9a72e9505ace6e81108e84f65de4feb0da244eb8
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name aho-corasick-double-array-trie High Vendor jar package name ahocorasickdoublearraytrie Highest Vendor jar package name algorithm Highest Vendor jar package name algorithm Low Vendor jar package name hankcs Highest Vendor jar package name hankcs Low Vendor pom artifactid aho-corasick-double-array-trie Highest Vendor pom artifactid aho-corasick-double-array-trie Low Vendor pom developer email me@hankcs.com Low Vendor pom developer name hankcs Medium Vendor pom groupid com.hankcs Highest Vendor pom name AhoCorasickDoubleArrayTrie High Vendor pom organization name 码农场 High Vendor pom organization url http://www.hankcs.com/ Medium Vendor pom url hankcs/AhoCorasickDoubleArrayTrie Highest Product file name aho-corasick-double-array-trie High Product jar package name ahocorasickdoublearraytrie Highest Product jar package name algorithm Highest Product jar package name algorithm Low Product jar package name hankcs Highest Product pom artifactid aho-corasick-double-array-trie Highest Product pom developer email me@hankcs.com Low Product pom developer name hankcs Low Product pom groupid com.hankcs Highest Product pom name AhoCorasickDoubleArrayTrie High Product pom organization name 码农场 Low Product pom organization url http://www.hankcs.com/ Low Product pom url hankcs/AhoCorasickDoubleArrayTrie High Version file version 1.2.3 High Version pom version 1.2.3 Highest
analytics-api-5.8.10.jarDescription:
API for analytics event publishers License:
http://www.atlassian.com/end-user-agreement/ File Path: /home/andrii/.m2/repository/com/atlassian/analytics/analytics-api/5.8.10/analytics-api-5.8.10.jar
MD5: 4f75cfcfbced356f9608aab56232a2d3
SHA1: 953955aa6328c915a84975904fe9506973ff58e2
SHA256: 71c6141c056504fd0a7779f745347bd4cfd7bfd3c7c6282a48342bb2673b1341
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name analytics-api High Vendor jar package name analytics Highest Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.analytics.api Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest spring-context * Low Vendor pom artifactid analytics-api Highest Vendor pom artifactid analytics-api Low Vendor pom groupid com.atlassian.analytics Highest Vendor pom name Analytics Client API Plugin High Vendor pom parent-artifactid analytics-project Low Product file name analytics-api High Product jar package name analytics Highest Product jar package name api Highest Product jar package name atlassian Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Analytics Client API Plugin Medium Product Manifest bundle-symbolicname com.atlassian.analytics.api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest spring-context * Low Product pom artifactid analytics-api Highest Product pom groupid com.atlassian.analytics Highest Product pom name Analytics Client API Plugin High Product pom parent-artifactid analytics-project Medium Version file version 5.8.10 High Version Manifest Bundle-Version 5.8.10 High Version pom version 5.8.10 Highest
android-json-0.0.20131108.vaadin1.jarDescription:
JSON (JavaScript Object Notation) is a lightweight data-interchange format.
This is the org.json compatible Android implementation extracted from the Android SDK
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/vaadin/external/google/android-json/0.0.20131108.vaadin1/android-json-0.0.20131108.vaadin1.jar
MD5: 10612241a9cc269501a7a2b8a984b949
SHA1: fa26d351fe62a6a17f5cda1287c1c6110dec413f
SHA256: dfb7bae2f404cfe0b72b4d23944698cb716b7665171812a0a4d0f5926c0fac79
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name android-json High Vendor jar package name json Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor Manifest bundle-symbolicname org.json Medium Vendor Manifest implementation-url http://developer.android.com/sdk Low Vendor Manifest Implementation-Vendor Google High Vendor pom artifactid android-json Highest Vendor pom artifactid android-json Low Vendor pom developer email androiddev Low Vendor pom developer id id Medium Vendor pom developer name Android Dev Medium Vendor pom developer org Google Medium Vendor pom developer org URL http://www.google.com Medium Vendor pom groupid com.vaadin.external.google Highest Vendor pom name JSON library from Android SDK High Vendor pom url http://developer.android.com/sdk Highest Product file name android-json High Product jar package name json Highest Product Manifest Bundle-Name json-android Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product Manifest bundle-symbolicname org.json Medium Product Manifest implementation-url http://developer.android.com/sdk Low Product pom artifactid android-json Highest Product pom developer email androiddev Low Product pom developer id id Low Product pom developer name Android Dev Low Product pom developer org Google Low Product pom developer org URL http://www.google.com Low Product pom groupid com.vaadin.external.google Highest Product pom name JSON library from Android SDK High Product pom url http://developer.android.com/sdk Medium Version Manifest Bundle-Version 0.0.20131108.vaadin1 High Version Manifest Implementation-Version 0.0.20131108.vaadin1 High Version pom version 0.0.20131108.vaadin1 Highest
animal-sniffer-annotations-1.14.jarFile Path: /home/andrii/.m2/repository/org/codehaus/mojo/animal-sniffer-annotations/1.14/animal-sniffer-annotations-1.14.jarMD5: 9d42e46845c874f1710a9f6a741f6c14SHA1: 775b7e22fb10026eed3f86e8dc556dfafe35f2d5SHA256: 2068320bd6bad744c3673ab048f67e30bef8f518996fa380033556600669905dReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name animal-sniffer-annotations High Vendor jar package name animal_sniffer Low Vendor jar package name codehaus Highest Vendor jar package name codehaus Low Vendor jar package name mojo Highest Vendor jar package name mojo Low Vendor pom artifactid animal-sniffer-annotations Highest Vendor pom artifactid animal-sniffer-annotations Low Vendor pom groupid org.codehaus.mojo Highest Vendor pom name Animal Sniffer Annotations High Vendor pom parent-artifactid animal-sniffer-parent Low Product file name animal-sniffer-annotations High Product jar package name animal_sniffer Low Product jar package name codehaus Highest Product jar package name ignorejrerequirement Low Product jar package name mojo Highest Product jar package name mojo Low Product pom artifactid animal-sniffer-annotations Highest Product pom groupid org.codehaus.mojo Highest Product pom name Animal Sniffer Annotations High Product pom parent-artifactid animal-sniffer-parent Medium Version file version 1.14 High Version pom version 1.14 Highest
ant-1.10.9.jarFile Path: /home/andrii/.m2/repository/org/apache/ant/ant/1.10.9/ant-1.10.9.jarMD5: 92251abf72cdcededfad473cc40dcbe2SHA1: a8a0c9bc4473acdac25832d0a9da2ca9fd9cd35fSHA256: 0715478af585ea80a18985613ebecdc7922122d45b2c3c970ff9b352cddb75fcReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name ant High Vendor jar package name ant Highest Vendor jar package name apache Highest Vendor manifest: org/apache/tools/ant/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid ant Highest Vendor pom artifactid ant Low Vendor pom groupid org.apache.ant Highest Vendor pom name Apache Ant Core High Vendor pom parent-artifactid ant-parent Low Vendor pom url https://ant.apache.org/ Highest Product file name ant High Product jar package name ant Highest Product jar package name apache Highest Product jar package name tools Highest Product manifest: org/apache/tools/ant/ Implementation-Title org.apache.tools.ant Medium Product manifest: org/apache/tools/ant/ Specification-Title Apache Ant Medium Product pom artifactid ant Highest Product pom groupid org.apache.ant Highest Product pom name Apache Ant Core High Product pom parent-artifactid ant-parent Medium Product pom url https://ant.apache.org/ Medium Version file version 1.10.9 High Version manifest: org/apache/tools/ant/ Implementation-Version 1.10.9 Medium Version pom version 1.10.9 Highest
Related Dependencies ant-launcher-1.10.9.jarFile Path: /home/andrii/.m2/repository/org/apache/ant/ant-launcher/1.10.9/ant-launcher-1.10.9.jar MD5: 82cc6cc0b6e438ce026310dca729e1a8 SHA1: bcc582424a533933d9960b7a4ccde12c6f257245 SHA256: fcce891f57f3be72149ff96ac2a80574165b3e0839866b95d24528f3027d50c1 pkg:maven/org.apache.ant/ant-launcher@1.10.9 CVE-2021-36373 suppress
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-36374 suppress
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
antisamy-1.5.3-atlassian-7.jarFile Path: /home/andrii/.m2/repository/org/owasp/antisamy/antisamy/1.5.3-atlassian-7/antisamy-1.5.3-atlassian-7.jarMD5: 98e9400909949399ed425dd5d1b13f21SHA1: 306157c709a3fba8b3e3ac14371bc00206170ddaSHA256: 1c977f43c176be8f639fd3cfafdbd72069e8ebb8104ffdea5cac73e55cbc0fd1Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name antisamy High Vendor jar package name antisamy Highest Vendor jar package name owasp Highest Vendor Manifest implementation-url http://www.owasp.org/index.php/Category:OWASP_AntiSamy_Project/antisamy Low Vendor Manifest Implementation-Vendor The Open Web Application Security Project (OWASP) High Vendor Manifest Implementation-Vendor-Id org.owasp.antisamy Medium Vendor pom artifactid antisamy Highest Vendor pom artifactid antisamy Low Vendor pom groupid org.owasp.antisamy Highest Vendor pom name OWASP AntiSamy High Vendor pom parent-artifactid antisamy-project Low Product file name antisamy High Product jar package name antisamy Highest Product jar package name owasp Highest Product Manifest Implementation-Title OWASP AntiSamy High Product Manifest implementation-url http://www.owasp.org/index.php/Category:OWASP_AntiSamy_Project/antisamy Low Product pom artifactid antisamy Highest Product pom groupid org.owasp.antisamy Highest Product pom name OWASP AntiSamy High Product pom parent-artifactid antisamy-project Medium Version Manifest Implementation-Version 1.5.3-atlassian-7 High Version pom version 1.5.3-atlassian-7 Highest
CVE-2022-28366 suppress
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP AntiSamy before 1.6.6), but 1.9.22 is the last version of CyberNeko HTML. NOTE: this may be related to CVE-2022-24839. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2016-10006 suppress
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-14735 suppress
OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2021-35043 suppress
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-28367 suppress
OWASP AntiSamy before 1.6.6 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2022-29577 suppress
OWASP AntiSamy before 1.6.7 allows XSS via HTML tag smuggling on STYLE content with crafted input. The output serializer does not properly encode the supposed Cascading Style Sheets (CSS) content. NOTE: this issue exists because of an incomplete fix for CVE-2022-28367. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
antlr-2.7.7.jarDescription:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html File Path: /home/andrii/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
SHA256: 88fbda4b912596b9f56e8e12e580cc954bacfb51776ecfddd3e18fc1cf56dc4c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name antlr High Vendor jar package name actions Highest Vendor jar package name antlr Highest Vendor jar package name antlr Low Vendor jar package name java Highest Vendor jar package name parser Highest Vendor jar package name python Highest Vendor pom artifactid antlr Highest Vendor pom artifactid antlr Low Vendor pom groupid antlr Highest Vendor pom name AntLR Parser Generator High Vendor pom url http://www.antlr.org/ Highest Product file name antlr High Product jar package name actions Highest Product jar package name antlr Highest Product jar package name java Highest Product jar package name parser Highest Product jar package name python Highest Product pom artifactid antlr Highest Product pom groupid antlr Highest Product pom name AntLR Parser Generator High Product pom url http://www.antlr.org/ Medium Version file version 2.7.7 High Version pom version 2.7.7 Highest
antlr-runtime-3.5.2.jarDescription:
A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. File Path: /home/andrii/.m2/repository/org/antlr/antlr-runtime/3.5.2/antlr-runtime-3.5.2.jarMD5: 1fbbae2cb72530207c20b797bdabd029SHA1: cd9cd41361c155f3af0f653009dcecb08d8b4afdSHA256: ce3fc8ecb10f39e9a3cddcbb2ce350d272d9cd3d0b1e18e6fe73c3b9389c8734Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name antlr-runtime High Vendor jar package name antlr Highest Vendor jar package name runtime Highest Vendor Manifest Implementation-Vendor ANTLR High Vendor Manifest Implementation-Vendor-Id org.antlr Medium Vendor pom artifactid antlr-runtime Highest Vendor pom artifactid antlr-runtime Low Vendor pom developer email jimi@temporal-wave.com Low Vendor pom developer email parrt@antlr.org Low Vendor pom developer name Jim Idle Medium Vendor pom developer name Terence Parr Medium Vendor pom developer org Temporal Wave LLC Medium Vendor pom developer org USFCA Medium Vendor pom developer org URL http://www.cs.usfca.edu Medium Vendor pom developer org URL http://www.temporal-wave.com Medium Vendor pom groupid org.antlr Highest Vendor pom name ANTLR 3 Runtime High Vendor pom parent-artifactid antlr-master Low Vendor pom url http://www.antlr.org Highest Product file name antlr-runtime High Product jar package name antlr Highest Product jar package name runtime Highest Product Manifest Implementation-Title ANTLR 3 Runtime High Product pom artifactid antlr-runtime Highest Product pom developer email jimi@temporal-wave.com Low Product pom developer email parrt@antlr.org Low Product pom developer name Jim Idle Low Product pom developer name Terence Parr Low Product pom developer org Temporal Wave LLC Low Product pom developer org USFCA Low Product pom developer org URL http://www.cs.usfca.edu Low Product pom developer org URL http://www.temporal-wave.com Low Product pom groupid org.antlr Highest Product pom name ANTLR 3 Runtime High Product pom parent-artifactid antlr-master Medium Product pom url http://www.antlr.org Medium Version file version 3.5.2 High Version Manifest Implementation-Version 3.5.2 High Version pom version 3.5.2 Highest
aopalliance-1.0.jarDescription:
AOP Alliance License:
Public Domain File Path: /home/andrii/.m2/repository/aopalliance/aopalliance/1.0/aopalliance-1.0.jar
MD5: 04177054e180d09e3998808efa0401c7
SHA1: 0235ba8b489512805ac13a8f9ea77a1ca5ebe3e8
SHA256: 0addec670fedcd3f113c5c8091d783280d23f75e3acb841b61a9cdb079376a08
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name aopalliance High Vendor jar package name aop Highest Vendor jar package name aopalliance Highest Vendor jar package name aopalliance Low Vendor jar package name intercept Low Vendor pom artifactid aopalliance Highest Vendor pom artifactid aopalliance Low Vendor pom groupid aopalliance Highest Vendor pom name AOP alliance High Vendor pom url http://aopalliance.sourceforge.net Highest Product file name aopalliance High Product jar package name aop Highest Product jar package name aopalliance Highest Product jar package name intercept Low Product pom artifactid aopalliance Highest Product pom groupid aopalliance Highest Product pom name AOP alliance High Product pom url http://aopalliance.sourceforge.net Medium Version file version 1.0 High Version pom version 1.0 Highest
applinks-api-7.2.7.jarDescription:
[PUBLIC] API JAR library for the AppLinks plugin File Path: /home/andrii/.m2/repository/com/atlassian/applinks/applinks-api/7.2.7/applinks-api-7.2.7.jarMD5: cd714033228987cb9ea28204f6e781d6SHA1: 8bf49db094c936b4120ef5c6b1a1f407c3f9a426SHA256: 5c09a558e65003e97fae7597585c80b6db7c13a73b11694634e58939daa974acReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name applinks-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name applinks Highest Vendor jar package name applinks Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor pom artifactid applinks-api Highest Vendor pom artifactid applinks-api Low Vendor pom groupid com.atlassian.applinks Highest Vendor pom name Applinks - API High Vendor pom parent-artifactid applinks-parent Low Product file name applinks-api High Product jar package name api Highest Product jar package name api Low Product jar package name applinks Highest Product jar package name applinks Low Product jar package name atlassian Highest Product pom artifactid applinks-api Highest Product pom groupid com.atlassian.applinks Highest Product pom name Applinks - API High Product pom parent-artifactid applinks-parent Medium Version file version 7.2.7 High Version pom version 7.2.7 Highest
applinks-host-7.2.7.jarDescription:
[PUBLIC] Host integration classes for the AppLinks plugin File Path: /home/andrii/.m2/repository/com/atlassian/applinks/applinks-host/7.2.7/applinks-host-7.2.7.jarMD5: 1116558f5cff78ead84d4bd9466fb536SHA1: 3f18165758ed049687dcfc8fcd6137fe9ca56ec9SHA256: 432b1d3086ebb04b57b5263d237b948bbdeb9f33f4b71b3f2e92ceb751d54856Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name applinks-host High Vendor jar package name applinks Highest Vendor jar package name applinks Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name host Highest Vendor jar package name host Low Vendor pom artifactid applinks-host Highest Vendor pom artifactid applinks-host Low Vendor pom groupid com.atlassian.applinks Highest Vendor pom name Applinks - Host Integration Services High Vendor pom parent-artifactid applinks-parent Low Product file name applinks-host High Product jar package name applinks Highest Product jar package name applinks Low Product jar package name atlassian Highest Product jar package name host Highest Product jar package name host Low Product pom artifactid applinks-host Highest Product pom groupid com.atlassian.applinks Highest Product pom name Applinks - Host Integration Services High Product pom parent-artifactid applinks-parent Medium Version file version 7.2.7 High Version pom version 7.2.7 Highest
applinks-spi-7.2.7.jarDescription:
[PUBLIC] Application Links SPI components. Allows developers to implement their own authentication providers and
application types. File Path: /home/andrii/.m2/repository/com/atlassian/applinks/applinks-spi/7.2.7/applinks-spi-7.2.7.jarMD5: f745ac96bab2e98ca85cf53a35370da3SHA1: a0770598de58613bfe8f5421f515611d82f10690SHA256: 577cd5f134ba5a843450cf93087dc1c59406c7d2c53a133caa242fd17c2a99d5Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name applinks-spi High Vendor jar package name application Highest Vendor jar package name applinks Highest Vendor jar package name applinks Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor pom artifactid applinks-spi Highest Vendor pom artifactid applinks-spi Low Vendor pom groupid com.atlassian.applinks Highest Vendor pom name Applinks - SPI High Vendor pom parent-artifactid applinks-parent Low Product file name applinks-spi High Product jar package name application Highest Product jar package name applinks Highest Product jar package name applinks Low Product jar package name atlassian Highest Product jar package name spi Highest Product jar package name spi Low Product pom artifactid applinks-spi Highest Product pom groupid com.atlassian.applinks Highest Product pom name Applinks - SPI High Product pom parent-artifactid applinks-parent Medium Version file version 7.2.7 High Version pom version 7.2.7 Highest
asm-7.1.jarDescription:
ASM, a very small and fast Java bytecode manipulation framework License:
BSD: http://asm.ow2.org/license.html File Path: /home/andrii/.m2/repository/org/ow2/asm/asm/7.1/asm-7.1.jar
MD5: 04fc92647ce25b41121683674a50dfdf
SHA1: fa29aa438674ff19d5e1386d2c3527a0267f291e
SHA256: 4ab2fa2b6d2cc9ccb1eaa05ea329c407b47b13ed2915f62f8c4b8cc96258d4de
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name asm High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm Medium Vendor pom artifactid asm Highest Vendor pom artifactid asm Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.org/ Highest Product file name asm High Product jar package name asm Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm Medium Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High Product pom artifactid asm Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.org/ Medium Version file version 7.1 High Version Manifest Implementation-Version 7.1 High Version pom parent-version 7.1 Low Version pom version 7.1 Highest
aspectjweaver-1.9.6.jarDescription:
The AspectJ weaver introduces advices to java classes License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html File Path: /home/andrii/.m2/repository/org/aspectj/aspectjweaver/1.9.6/aspectjweaver-1.9.6.jar
MD5: cc461d78c6b67a7c31712c694213b0e1
SHA1: ee3b73aa16df35179255f17354d9dfd8e7822835
SHA256: 3167577eaa4be02817295d320c5a6578de8b80d15615d719d5be0a0d65d16165
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name aspectjweaver High Vendor jar package name aspectj Highest Vendor jar package name org Highest Vendor jar package name weaver Highest Vendor Manifest automatic-module-name org.aspectj.weaver Medium Vendor Manifest can-redefine-classes true Low Vendor manifest: org/aspectj/weaver/ Implementation-Vendor https://www.eclipse.org/aspectj/ Medium Vendor pom artifactid aspectjweaver Highest Vendor pom artifactid aspectjweaver Low Vendor pom developer email aclement@vmware.com Low Vendor pom developer id aclement Medium Vendor pom developer name Andy Clement Medium Vendor pom groupid org.aspectj Highest Vendor pom name AspectJ weaver High Vendor pom url https://www.eclipse.org/aspectj/ Highest Product file name aspectjweaver High Product jar package name aspectj Highest Product jar package name org Highest Product jar package name weaver Highest Product Manifest automatic-module-name org.aspectj.weaver Medium Product Manifest can-redefine-classes true Low Product manifest: org/aspectj/weaver/ Implementation-Title org.aspectj.weaver Medium Product manifest: org/aspectj/weaver/ Specification-Title AspectJ Weaver Classes Medium Product pom artifactid aspectjweaver Highest Product pom developer email aclement@vmware.com Low Product pom developer id aclement Low Product pom developer name Andy Clement Low Product pom groupid org.aspectj Highest Product pom name AspectJ weaver High Product pom url https://www.eclipse.org/aspectj/ Medium Version file version 1.9.6 High Version manifest: org/aspectj/weaver/ Implementation-Version 1.9.6 Medium Version pom version 1.9.6 Highest
atlassian-annotations-2.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/annotations/atlassian-annotations/2.1.0/atlassian-annotations-2.1.0.jarMD5: c6692f67afc832299a48de114f8d55a3SHA1: beeec862f2f5c864ed6aab1c2ef3f9512a4b4d1eSHA256: 1d097beb78dd8e8af8b121f5bc305fa764b6f0e81d496b6a9231404d59fa3450Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor pom artifactid atlassian-annotations Highest Vendor pom artifactid atlassian-annotations Low Vendor pom groupid com.atlassian.annotations Highest Vendor pom name Atlassian Annotations - Annotations High Vendor pom parent-artifactid atlassian-annotations-parent Low Product file name atlassian-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name atlassian Highest Product pom artifactid atlassian-annotations Highest Product pom groupid com.atlassian.annotations Highest Product pom name Atlassian Annotations - Annotations High Product pom parent-artifactid atlassian-annotations-parent Medium Version file version 2.1.0 High Version pom version 2.1.0 Highest
atlassian-audit-api-1.12.4.jarDescription:
APIs for producing and consuming audit events File Path: /home/andrii/.m2/repository/com/atlassian/audit/atlassian-audit-api/1.12.4/atlassian-audit-api-1.12.4.jarMD5: 7abbbe2db24951815da1d9519ad401a1SHA1: 6d801b29e774384414e771145141b74f112e1887SHA256: b8f908c80ec02c049563fed6ca5278ff975d24a8e155d120a8f6731821b37b96Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-audit-api High Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name audit Highest Vendor jar package name audit Low Vendor jar package name entity Low Vendor jar package name events Highest Vendor pom artifactid atlassian-audit-api Highest Vendor pom artifactid atlassian-audit-api Low Vendor pom groupid com.atlassian.audit Highest Vendor pom name Atlassian Advanced Auditing API High Vendor pom parent-artifactid atlassian-audit Low Product file name atlassian-audit-api High Product jar package name api Highest Product jar package name atlassian Highest Product jar package name audit Highest Product jar package name audit Low Product jar package name entity Low Product jar package name events Highest Product pom artifactid atlassian-audit-api Highest Product pom groupid com.atlassian.audit Highest Product pom name Atlassian Advanced Auditing API High Product pom parent-artifactid atlassian-audit Medium Version file version 1.12.4 High Version pom version 1.12.4 Highest
atlassian-audit-core-1.12.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/audit/atlassian-audit-core/1.12.4/atlassian-audit-core-1.12.4.jarMD5: bd2e4abf7cf57fe3483602d9115f9690SHA1: b6c5b998c08c95108809a56dffa474d642f459a3SHA256: f74d039dd76de4eea88ba538f1122cc9180173a1e74d3cafc38ff247cb9fc0a2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-audit-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name audit Highest Vendor jar package name audit Low Vendor jar package name core Highest Vendor jar package name core Low Vendor pom artifactid atlassian-audit-core Highest Vendor pom artifactid atlassian-audit-core Low Vendor pom groupid com.atlassian.audit Highest Vendor pom parent-artifactid atlassian-audit Low Product file name atlassian-audit-core High Product jar package name atlassian Highest Product jar package name audit Highest Product jar package name audit Low Product jar package name core Highest Product jar package name core Low Product pom artifactid atlassian-audit-core Highest Product pom groupid com.atlassian.audit Highest Product pom parent-artifactid atlassian-audit Medium Version file version 1.12.4 High Version pom version 1.12.4 Highest
atlassian-audit-spi-1.12.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/audit/atlassian-audit-spi/1.12.4/atlassian-audit-spi-1.12.4.jarMD5: 12e0c86ca75cc3678f8c833e0dae6d9aSHA1: 7d96420cda0afc3f80fb60d69a50325fdb7b6035SHA256: ffc4ae46828f4bf1c44bf1f8f2de1cecbe0bbd604e22703a217b0ef7659bb96dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-audit-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name audit Highest Vendor jar package name audit Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor pom artifactid atlassian-audit-spi Highest Vendor pom artifactid atlassian-audit-spi Low Vendor pom groupid com.atlassian.audit Highest Vendor pom parent-artifactid atlassian-audit Low Product file name atlassian-audit-spi High Product jar package name atlassian Highest Product jar package name audit Highest Product jar package name audit Low Product jar package name spi Highest Product jar package name spi Low Product pom artifactid atlassian-audit-spi Highest Product pom groupid com.atlassian.audit Highest Product pom parent-artifactid atlassian-audit Medium Version file version 1.12.4 High Version pom version 1.12.4 Highest
atlassian-bandana-3.1.jarDescription:
A library to provide nested configuration contexts to applications, persisted to anywhere.
File Path: /home/andrii/.m2/repository/com/atlassian/bandana/atlassian-bandana/3.1/atlassian-bandana-3.1.jarMD5: 2bfb036bf96e3cfde3d6495122f9ece8SHA1: 2091d961f3ed157a8619035bfcd47b80601fdbf0SHA256: 3c1a8f182e3187d3479ca6d8ede3e6fc4b4d7c8d32371272499bde6e9c3ab60bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-bandana High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name bandana Highest Vendor jar package name bandana Low Vendor pom artifactid atlassian-bandana Highest Vendor pom artifactid atlassian-bandana Low Vendor pom groupid com.atlassian.bandana Highest Vendor pom name Atlassian Bandana High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-bandana High Product jar package name atlassian Highest Product jar package name bandana Highest Product jar package name bandana Low Product pom artifactid atlassian-bandana Highest Product pom groupid com.atlassian.bandana Highest Product pom name Atlassian Bandana High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 3.1 High Version pom parent-version 3.1 Low Version pom version 3.1 Highest
atlassian-bonnie-8.0.0.jarDescription:
Bonnie contains Lucene indexing and utility classes. File Path: /home/andrii/.m2/repository/com/atlassian/bonnie/atlassian-bonnie/8.0.0/atlassian-bonnie-8.0.0.jarMD5: 5c63540f705ccb92e0af967f716ba635SHA1: 4cd64fc5dfdccf0c6e59510e2bce001ca5bcc7a8SHA256: 381a16ed88b06d1dae56eb63b0ee5cd6dbb3f96bd30d1c5245b4427b035b2557Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-bonnie High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name bonnie Highest Vendor jar package name bonnie Low Vendor jar package name lucene Highest Vendor pom artifactid atlassian-bonnie Highest Vendor pom artifactid atlassian-bonnie Low Vendor pom groupid com.atlassian.bonnie Highest Vendor pom name Atlassian Bonnie High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-bonnie High Product jar package name atlassian Highest Product jar package name bonnie Highest Product jar package name bonnie Low Product jar package name lucene Highest Product pom artifactid atlassian-bonnie Highest Product pom groupid com.atlassian.bonnie Highest Product pom name Atlassian Bonnie High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 8.0.0 High Version pom parent-version 8.0.0 Low Version pom version 8.0.0 Highest
atlassian-brave-spancollector-core-1.0.0.jarFile Path: /home/andrii/.m2/repository/io/atlassian/zipkin/atlassian-brave-spancollector-core/1.0.0/atlassian-brave-spancollector-core-1.0.0.jarMD5: ac8a55118c404cd478a757e1effb23eeSHA1: 087c2cf9b94b791f4f6c372a176efa5d2f2d7898SHA256: f0d4e9ab82a6c5500572e227bd1e39fa0c65e66efc5793ddc78e076b97da0920Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-brave-spancollector-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name brave Highest Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name zipkin Highest Vendor jar package name zipkin Low Vendor pom artifactid atlassian-brave-spancollector-core Highest Vendor pom artifactid atlassian-brave-spancollector-core Low Vendor pom groupid io.atlassian.zipkin Highest Vendor pom name SpanCollector Core High Vendor pom parent-artifactid atlassian-brave-spancollector Low Product file name atlassian-brave-spancollector-core High Product jar package name atlassian Highest Product jar package name atlassian Low Product jar package name brave Highest Product jar package name brave Low Product jar package name io Highest Product jar package name zipkin Highest Product jar package name zipkin Low Product pom artifactid atlassian-brave-spancollector-core Highest Product pom groupid io.atlassian.zipkin Highest Product pom name SpanCollector Core High Product pom parent-artifactid atlassian-brave-spancollector Medium Version file version 1.0.0 High Version pom version 1.0.0 Highest
CVE-2022-2393 suppress
A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled. This flaw allows an authenticated attacker on the adjacent network to impersonate another user within the scope of the domain, but they would not be able to decrypt message content. CWE-287 Improper Authentication
CVSSv3:
Base Score: MEDIUM (5.7) Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
atlassian-cache-api-5.3.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/cache/atlassian-cache-api/5.3.4/atlassian-cache-api-5.3.4.jarMD5: e7a008d2177ff3e04e71df6d206afcb6SHA1: 5eb7cb3dfab32a089de9ac29e39b3ba7723217a4SHA256: 05c5fb35fee0ea5ae5e057d0ccede435dfbf4de8b6c01f4c03678ffa374720d0Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-cache-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name cache Highest Vendor jar package name cache Low Vendor pom artifactid atlassian-cache-api Highest Vendor pom artifactid atlassian-cache-api Low Vendor pom groupid com.atlassian.cache Highest Vendor pom name Atlassian Cache - API High Vendor pom parent-artifactid atlassian-cache Low Product file name atlassian-cache-api High Product jar package name atlassian Highest Product jar package name cache Highest Product jar package name cache Low Product pom artifactid atlassian-cache-api Highest Product pom groupid com.atlassian.cache Highest Product pom name Atlassian Cache - API High Product pom parent-artifactid atlassian-cache Medium Version file version 5.3.4 High Version pom version 5.3.4 Highest
atlassian-cache-common-impl-5.3.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/cache/atlassian-cache-common-impl/5.3.4/atlassian-cache-common-impl-5.3.4.jarMD5: bf3adeabdc5cb540f5f1cff0f97a23a6SHA1: 52cd936db1a89367e4fe170f762f8ceca41172ecSHA256: 8bfc76b940e119068686276ede03b72b8eeca64207ae771f94f5633aa70d08d6Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-cache-common-impl High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name cache Highest Vendor jar package name cache Low Vendor jar package name impl Highest Vendor jar package name impl Low Vendor pom artifactid atlassian-cache-common-impl Highest Vendor pom artifactid atlassian-cache-common-impl Low Vendor pom groupid com.atlassian.cache Highest Vendor pom name Atlassian Cache - Common Implementation High Vendor pom parent-artifactid atlassian-cache Low Product file name atlassian-cache-common-impl High Product jar package name atlassian Highest Product jar package name cache Highest Product jar package name cache Low Product jar package name impl Highest Product jar package name impl Low Product pom artifactid atlassian-cache-common-impl Highest Product pom groupid com.atlassian.cache Highest Product pom name Atlassian Cache - Common Implementation High Product pom parent-artifactid atlassian-cache Medium Version file version 5.3.4 High Version pom version 5.3.4 Highest
atlassian-cache-memory-5.3.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/cache/atlassian-cache-memory/5.3.4/atlassian-cache-memory-5.3.4.jarMD5: 60bbf7eeede1cc14d2a1faa253b5cd4fSHA1: 11dd17302f9057da4a8cfac2dbddcdae60718771SHA256: a85a0a40a00e5ec79c8cc01d546570113114a0152643e4b39db0d2ef191e614dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-cache-memory High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name cache Highest Vendor jar package name cache Low Vendor jar package name memory Highest Vendor jar package name memory Low Vendor pom artifactid atlassian-cache-memory Highest Vendor pom artifactid atlassian-cache-memory Low Vendor pom groupid com.atlassian.cache Highest Vendor pom name Atlassian Cache - Memory Implementation High Vendor pom parent-artifactid atlassian-cache Low Product file name atlassian-cache-memory High Product jar package name atlassian Highest Product jar package name cache Highest Product jar package name cache Low Product jar package name memory Highest Product jar package name memory Low Product pom artifactid atlassian-cache-memory Highest Product pom groupid com.atlassian.cache Highest Product pom name Atlassian Cache - Memory Implementation High Product pom parent-artifactid atlassian-cache Medium Version file version 5.3.4 High Version pom version 5.3.4 Highest
atlassian-collectors-util-1.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/collectors/atlassian-collectors-util/1.1/atlassian-collectors-util-1.1.jarMD5: 82924c05235aa61cfb8dd00da7b4cdc3SHA1: ca1b7d3996501b0cbf0128ec6ce75392d0249017SHA256: 4f7cd4ee38b40b8ccbe591a575ba2bcf119f7c44e26647309d32e50aa73dc414Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-collectors-util High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name collectors Highest Vendor jar package name collectors Low Vendor pom artifactid atlassian-collectors-util Highest Vendor pom artifactid atlassian-collectors-util Low Vendor pom groupid com.atlassian.collectors Highest Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-collectors-util High Product jar package name atlassian Highest Product jar package name collectors Highest Product jar package name collectors Low Product pom artifactid atlassian-collectors-util Highest Product pom groupid com.atlassian.collectors Highest Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.1 High Version pom parent-version 1.1 Low Version pom version 1.1 Highest
atlassian-config-1.1.1.jarDescription:
Basic application configuration classes. File Path: /home/andrii/.m2/repository/com/atlassian/config/atlassian-config/1.1.1/atlassian-config-1.1.1.jarMD5: 283f205dc861142ac5120a400c380b31SHA1: 7c84d953a4dd53dfda9c6bc7bce6891150e3bfadSHA256: 066c38c618ff5ec9b787ea80374116dc7cff1728ca6d4230e2ca676e35f9c62bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-config High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name config Highest Vendor jar package name config Low Vendor pom artifactid atlassian-config Highest Vendor pom artifactid atlassian-config Low Vendor pom groupid com.atlassian.config Highest Vendor pom name Atlassian Config High Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://www.atlassian.com Highest Product file name atlassian-config High Product jar package name atlassian Highest Product jar package name config Highest Product jar package name config Low Product pom artifactid atlassian-config Highest Product pom groupid com.atlassian.config Highest Product pom name Atlassian Config High Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://www.atlassian.com Medium Version file version 1.1.1 High Version pom parent-version 1.1.1 Low Version pom version 1.1.1 Highest
atlassian-core-7.0.2.jarDescription:
Atlassian Core Tools. File Path: /home/andrii/.m2/repository/com/atlassian/core/atlassian-core/7.0.2/atlassian-core-7.0.2.jarMD5: 69e31727cf962b980eb18f5f71ecb6a1SHA1: ede0dcb31d3690c4a1628049c39eb5523497a5c5SHA256: 8e990efe091506d4ff7100f252fe1c692c3674cbbd31ce3f97ef380577d5c44cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor pom artifactid atlassian-core Highest Vendor pom artifactid atlassian-core Low Vendor pom groupid com.atlassian.core Highest Vendor pom name Atlassian Core High Vendor pom parent-artifactid atlassian-core-parent Low Product file name atlassian-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product pom artifactid atlassian-core Highest Product pom groupid com.atlassian.core Highest Product pom name Atlassian Core High Product pom parent-artifactid atlassian-core-parent Medium Version file version 7.0.2 High Version pom version 7.0.2 Highest
atlassian-core-thumbnail-7.0.2.jarDescription:
Atlassian Core Tools for Thumbnailing of images File Path: /home/andrii/.m2/repository/com/atlassian/core/atlassian-core-thumbnail/7.0.2/atlassian-core-thumbnail-7.0.2.jarMD5: 6d5f960bc6905d62a6205f9fb37df7efSHA1: f7ec7020b70fa0419a2a4f9cda582649af016416SHA256: 3d99b43772dd2095cede206bb186e982581d553eb8460711884113befb7d6c88Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-core-thumbnail High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name thumbnail Highest Vendor jar package name util Low Vendor pom artifactid atlassian-core-thumbnail Highest Vendor pom artifactid atlassian-core-thumbnail Low Vendor pom groupid com.atlassian.core Highest Vendor pom name Atlassian Core Thumbnail High Vendor pom parent-artifactid atlassian-core-parent Low Product file name atlassian-core-thumbnail High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name thumbnail Highest Product jar package name thumbnail Low Product jar package name util Low Product pom artifactid atlassian-core-thumbnail Highest Product pom groupid com.atlassian.core Highest Product pom name Atlassian Core Thumbnail High Product pom parent-artifactid atlassian-core-parent Medium Version file version 7.0.2 High Version pom version 7.0.2 Highest
atlassian-core-user-7.0.2.jarDescription:
Atlassian Core Tools for User management File Path: /home/andrii/.m2/repository/com/atlassian/core/atlassian-core-user/7.0.2/atlassian-core-user-7.0.2.jarMD5: 3b697a6df0844956aa7708c201f15e45SHA1: df6a73ba85a4abfc7cfe70c24d1a3186a2fed74aSHA256: d341e5d1fbab543f6124d59e0c1689ade182eb45c6194c40b3653ca17e96cb4aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-core-user High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name user Highest Vendor jar package name user Low Vendor pom artifactid atlassian-core-user Highest Vendor pom artifactid atlassian-core-user Low Vendor pom groupid com.atlassian.core Highest Vendor pom name Atlassian Core User High Vendor pom parent-artifactid atlassian-core-parent Low Product file name atlassian-core-user High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name preferences Low Product jar package name user Highest Product jar package name user Low Product pom artifactid atlassian-core-user Highest Product pom groupid com.atlassian.core Highest Product pom name Atlassian Core User High Product pom parent-artifactid atlassian-core-parent Medium Version file version 7.0.2 High Version pom version 7.0.2 Highest
atlassian-diagnostics-api-1.1.10.jarDescription:
API for Atlassian Diagnostics File Path: /home/andrii/.m2/repository/com/atlassian/diagnostics/atlassian-diagnostics-api/1.1.10/atlassian-diagnostics-api-1.1.10.jarMD5: f02df8ce7f60e27374da7ff6c72f8f2eSHA1: 8532ad25a53dbb238fdb9757ee136b0420a22ba3SHA256: 6a68e2e608b38d69bbfd0fec810ab0536465ae609576ce5eb12bc12203aeff5fReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-diagnostics-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name diagnostics Highest Vendor jar package name diagnostics Low Vendor pom artifactid atlassian-diagnostics-api Highest Vendor pom artifactid atlassian-diagnostics-api Low Vendor pom groupid com.atlassian.diagnostics Highest Vendor pom name Atlassian Diagnostics - API High Vendor pom parent-artifactid atlassian-diagnostics-parent Low Product file name atlassian-diagnostics-api High Product jar package name atlassian Highest Product jar package name diagnostics Highest Product jar package name diagnostics Low Product pom artifactid atlassian-diagnostics-api Highest Product pom groupid com.atlassian.diagnostics Highest Product pom name Atlassian Diagnostics - API High Product pom parent-artifactid atlassian-diagnostics-parent Medium Version file version 1.1.10 High Version pom version 1.1.10 Highest
atlassian-diagnostics-core-1.1.10.jarDescription:
Components for embedding atlassian-diagnostics in host applications File Path: /home/andrii/.m2/repository/com/atlassian/diagnostics/atlassian-diagnostics-core/1.1.10/atlassian-diagnostics-core-1.1.10.jarMD5: 35f871abd9e9fb839bf2b2e75f3e4e8aSHA1: e83de3c29d51c8063dfceb133d5bd69a717b5a8bSHA256: 6df2d4e007bc86c1158d3e44adddb13fc156db7bf6c785466ec7da2488a32ac6Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-diagnostics-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name diagnostics Highest Vendor jar package name diagnostics Low Vendor jar package name internal Low Vendor pom artifactid atlassian-diagnostics-core Highest Vendor pom artifactid atlassian-diagnostics-core Low Vendor pom groupid com.atlassian.diagnostics Highest Vendor pom name Atlassian Diagnostics - Core High Vendor pom parent-artifactid atlassian-diagnostics-parent Low Product file name atlassian-diagnostics-core High Product jar package name atlassian Highest Product jar package name diagnostics Highest Product jar package name diagnostics Low Product jar package name internal Low Product pom artifactid atlassian-diagnostics-core Highest Product pom groupid com.atlassian.diagnostics Highest Product pom name Atlassian Diagnostics - Core High Product pom parent-artifactid atlassian-diagnostics-parent Medium Version file version 1.1.10 High Version pom version 1.1.10 Highest
atlassian-diagnostics-platform-1.1.10.jarDescription:
Monitors for the Atlassian Platform File Path: /home/andrii/.m2/repository/com/atlassian/diagnostics/atlassian-diagnostics-platform/1.1.10/atlassian-diagnostics-platform-1.1.10.jarMD5: 937ebb0fefbb5fbe507e9b8b814974f5SHA1: faf36e854eb4252bd05d27c05accb2dc7f52494cSHA256: 6a19615d236aa62c6cc27f3f9308ca616b9f451d0e9579153d215fc043eef25fReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-diagnostics-platform High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name diagnostics Highest Vendor jar package name diagnostics Low Vendor jar package name internal Low Vendor jar package name platform Highest Vendor pom artifactid atlassian-diagnostics-platform Highest Vendor pom artifactid atlassian-diagnostics-platform Low Vendor pom groupid com.atlassian.diagnostics Highest Vendor pom name Atlassian Diagnostics - Platform High Vendor pom parent-artifactid atlassian-diagnostics-parent Low Product file name atlassian-diagnostics-platform High Product jar package name atlassian Highest Product jar package name diagnostics Highest Product jar package name diagnostics Low Product jar package name internal Low Product jar package name platform Highest Product jar package name platform Low Product pom artifactid atlassian-diagnostics-platform Highest Product pom groupid com.atlassian.diagnostics Highest Product pom name Atlassian Diagnostics - Platform High Product pom parent-artifactid atlassian-diagnostics-parent Medium Version file version 1.1.10 High Version pom version 1.1.10 Highest
atlassian-embedded-crowd-atlassian-user-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/atlassian-embedded-crowd-atlassian-user/7.13.0/atlassian-embedded-crowd-atlassian-user-7.13.0.jarMD5: eda8f1a9e29b9a21f8578413120517b6SHA1: e4a68117641381344d40c97feeb0ee929add5c17SHA256: dbe527b47d8e7997d175cfa1658c04e8582cb33918bd37ee39714e9372fe32fcReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-embedded-crowd-atlassian-user High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name crowd Highest Vendor jar package name crowd Low Vendor jar package name embedded Highest Vendor jar package name embedded Low Vendor pom artifactid atlassian-embedded-crowd-atlassian-user Highest Vendor pom artifactid atlassian-embedded-crowd-atlassian-user Low Vendor pom groupid com.atlassian.confluence Highest Vendor pom parent-artifactid confluence-legacy-components Low Product file name atlassian-embedded-crowd-atlassian-user High Product jar package name atlassian Highest Product jar package name atlassianuser Low Product jar package name crowd Highest Product jar package name crowd Low Product jar package name embedded Highest Product jar package name embedded Low Product pom artifactid atlassian-embedded-crowd-atlassian-user Highest Product pom groupid com.atlassian.confluence Highest Product pom parent-artifactid confluence-legacy-components Medium Version file version 7.13.0 High Version pom version 7.13.0 Highest
atlassian-event-4.0.1.jarDescription:
Atlassian eventing system for use with Spring projects License:
BSD License: http://opensource.org/licenses/BSD-3-Clause File Path: /home/andrii/.m2/repository/com/atlassian/event/atlassian-event/4.0.1/atlassian-event-4.0.1.jar
MD5: 443687a7fd327157b1d4b5b927d211e5
SHA1: 12e8cd48b125049d66d564986567749ef87f91c7
SHA256: 7505ea897ad9c16e3faa834c49e93f235ce390f01cbd0586eefdb574a5a2cfc1
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-event High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name event Highest Vendor jar package name event Low Vendor jar package name internal Low Vendor jar package name spring Highest Vendor pom artifactid atlassian-event Highest Vendor pom artifactid atlassian-event Low Vendor pom groupid com.atlassian.event Highest Vendor pom name Atlassian Event High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-event High Product jar package name atlassian Highest Product jar package name event Highest Product jar package name event Low Product jar package name internal Low Product jar package name spring Highest Product pom artifactid atlassian-event Highest Product pom groupid com.atlassian.event Highest Product pom name Atlassian Event High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 4.0.1 High Version pom parent-version 4.0.1 Low Version pom version 4.0.1 Highest
atlassian-extras-api-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/extras/atlassian-extras-api/3.4.1/atlassian-extras-api-3.4.1.jarMD5: 42cb6b763ae13f403db1fd9a5c15bd19SHA1: 103796443cd2156ab785b4bd1cd3714a008b396bSHA256: d1ba89f1c9c0cef19860bece0124ee689aa4a89973b45a94e825a736467bdad8Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-extras-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name extras Highest Vendor jar package name extras Low Vendor pom artifactid atlassian-extras-api Highest Vendor pom artifactid atlassian-extras-api Low Vendor pom groupid com.atlassian.extras Highest Vendor pom name Atlassian Extras - API High Vendor pom parent-artifactid atlassian-extras-closedsource Low Product file name atlassian-extras-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name extras Highest Product jar package name extras Low Product pom artifactid atlassian-extras-api Highest Product pom groupid com.atlassian.extras Highest Product pom name Atlassian Extras - API High Product pom parent-artifactid atlassian-extras-closedsource Medium Version file version 3.4.1 High Version pom version 3.4.1 Highest
atlassian-extras-common-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/extras/atlassian-extras-common/3.4.1/atlassian-extras-common-3.4.1.jarMD5: ee0a3bf9626ed9b642f0a179dcb17fa6SHA1: 400767c17365a22ccadd5343bde8557fcbc3e8c0SHA256: a4be6806b3aaf5db9178b620f7a4ee1d725356f70cdd503d0491edc832a53fa2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-extras-common High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name common Highest Vendor jar package name common Low Vendor jar package name extras Highest Vendor jar package name extras Low Vendor pom artifactid atlassian-extras-common Highest Vendor pom artifactid atlassian-extras-common Low Vendor pom groupid com.atlassian.extras Highest Vendor pom name Atlassian Extras - Common High Vendor pom parent-artifactid atlassian-extras-closedsource Low Product file name atlassian-extras-common High Product jar package name atlassian Highest Product jar package name common Highest Product jar package name common Low Product jar package name extras Highest Product jar package name extras Low Product pom artifactid atlassian-extras-common Highest Product pom groupid com.atlassian.extras Highest Product pom name Atlassian Extras - Common High Product pom parent-artifactid atlassian-extras-closedsource Medium Version file version 3.4.1 High Version pom version 3.4.1 Highest
atlassian-extras-core-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/extras/atlassian-extras-core/3.4.1/atlassian-extras-core-3.4.1.jarMD5: 5eecd7e6dcafc092be21ffcd0d4caecfSHA1: 750bf5df3b3846e8ac6709438084020f33345c66SHA256: f3e0c46fe2d09f8390c1bfbff8137a7dd60fcea2b61fabf688d469a31acc470cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-extras-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name extras Highest Vendor jar package name extras Low Vendor pom artifactid atlassian-extras-core Highest Vendor pom artifactid atlassian-extras-core Low Vendor pom groupid com.atlassian.extras Highest Vendor pom name Atlassian Extras - Core High Vendor pom parent-artifactid atlassian-extras-closedsource Low Product file name atlassian-extras-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name extras Highest Product jar package name extras Low Product pom artifactid atlassian-extras-core Highest Product pom groupid com.atlassian.extras Highest Product pom name Atlassian Extras - Core High Product pom parent-artifactid atlassian-extras-closedsource Medium Version file version 3.4.1 High Version pom version 3.4.1 Highest
atlassian-extras-decoder-api-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/extras/atlassian-extras-decoder-api/3.4.1/atlassian-extras-decoder-api-3.4.1.jarMD5: 2ef536159c7b4b4a8b16915816d240f5SHA1: f3d4beac9ccb105f1a397fa737130ff1572d6094SHA256: f905dbf509b5164a9453d2ad5a9c6fe8b950cde1453518011f2b510d82f87063Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-extras-decoder-api High Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name decoder Highest Vendor jar package name decoder Low Vendor jar package name extras Highest Vendor jar package name extras Low Vendor pom artifactid atlassian-extras-decoder-api Highest Vendor pom artifactid atlassian-extras-decoder-api Low Vendor pom groupid com.atlassian.extras Highest Vendor pom name Atlassian Extras - Decoder API High Vendor pom parent-artifactid atlassian-extras-closedsource Low Product file name atlassian-extras-decoder-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name decoder Highest Product jar package name decoder Low Product jar package name extras Highest Product jar package name extras Low Product pom artifactid atlassian-extras-decoder-api Highest Product pom groupid com.atlassian.extras Highest Product pom name Atlassian Extras - Decoder API High Product pom parent-artifactid atlassian-extras-closedsource Medium Version file version 3.4.1 High Version pom version 3.4.1 Highest
atlassian-extras-decoder-v2-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/extras/atlassian-extras-decoder-v2/3.4.1/atlassian-extras-decoder-v2-3.4.1.jarMD5: 1fa8f760b08a7109cfc2d5c256550677SHA1: da5f3f0552c7a30afcdbf855581370e51283cef0SHA256: 9c44f684dbb9e26b30581ca850ad640f9f358cef4bc6c970c312359a38760285Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-extras-decoder-v2 High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name decoder Highest Vendor jar package name decoder Low Vendor jar package name extras Highest Vendor jar package name extras Low Vendor jar package name v2 Highest Vendor pom artifactid atlassian-extras-decoder-v2 Highest Vendor pom artifactid atlassian-extras-decoder-v2 Low Vendor pom groupid com.atlassian.extras Highest Vendor pom name Atlassian Extras - Decoder High Vendor pom parent-artifactid atlassian-extras-closedsource Low Product file name atlassian-extras-decoder-v2 High Product jar package name atlassian Highest Product jar package name decoder Highest Product jar package name decoder Low Product jar package name extras Highest Product jar package name extras Low Product jar package name v2 Highest Product jar package name v2 Low Product pom artifactid atlassian-extras-decoder-v2 Highest Product pom groupid com.atlassian.extras Highest Product pom name Atlassian Extras - Decoder High Product pom parent-artifactid atlassian-extras-closedsource Medium Version file version 3.4.1 High Version pom version 3.4.1 Highest
atlassian-extras-legacy-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/extras/atlassian-extras-legacy/3.4.1/atlassian-extras-legacy-3.4.1.jarMD5: 2108da575eadc162122970fb6f8e533eSHA1: 6844548e0c793663b55e8ae1c536c7069eac9ad6SHA256: d549dcd2d64e459f8ee8a99851d676937407eff0ebece045b501b62ce58a0439Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-extras-legacy High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name extras Highest Vendor jar package name legacy Highest Vendor jar package name license Low Vendor pom artifactid atlassian-extras-legacy Highest Vendor pom artifactid atlassian-extras-legacy Low Vendor pom groupid com.atlassian.extras Highest Vendor pom name Atlassian Extras - Legacy High Vendor pom parent-artifactid atlassian-extras-closedsource Low Product file name atlassian-extras-legacy High Product jar package name atlassian Highest Product jar package name extras Highest Product jar package name legacy Highest Product jar package name license Low Product pom artifactid atlassian-extras-legacy Highest Product pom groupid com.atlassian.extras Highest Product pom name Atlassian Extras - Legacy High Product pom parent-artifactid atlassian-extras-closedsource Medium Version file version 3.4.1 High Version pom version 3.4.1 Highest
atlassian-flushable-gzipoutputstream-1.1.jarLicense:
APL 2.0 License: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/atlassian/gzipfilter/atlassian-flushable-gzipoutputstream/1.1/atlassian-flushable-gzipoutputstream-1.1.jar
MD5: 8ef8fe767f9600a0fb1ee9f0bfb16ca7
SHA1: 3c4f49949c6021f396273e2afba4d6593450091c
SHA256: 509bd01ed08190755a174bcb71d9933b4da6d0cc7360bb6f0827427a58f2fa9a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-flushable-gzipoutputstream High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name flushable Highest Vendor jar package name flushable Low Vendor jar package name gzipfilter Highest Vendor jar package name gzipfilter Low Vendor pom artifactid atlassian-flushable-gzipoutputstream Highest Vendor pom artifactid atlassian-flushable-gzipoutputstream Low Vendor pom groupid com.atlassian.gzipfilter Highest Vendor pom name atlassian-flushable-gzipoutputstream High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-flushable-gzipoutputstream High Product jar package name atlassian Highest Product jar package name flushable Highest Product jar package name flushable Low Product jar package name flushablegzipoutputstream Low Product jar package name gzipfilter Highest Product jar package name gzipfilter Low Product pom artifactid atlassian-flushable-gzipoutputstream Highest Product pom groupid com.atlassian.gzipfilter Highest Product pom name atlassian-flushable-gzipoutputstream High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.1 High Version pom parent-version 1.1 Low Version pom version 1.1 Highest
atlassian-graphql-annotations-1.3.7.jarFile Path: /home/andrii/.m2/repository/com/atlassian/graphql/atlassian-graphql-annotations/1.3.7/atlassian-graphql-annotations-1.3.7.jarMD5: 996f41411820d46b5d48a4da6eb810e8SHA1: 3f5091b63def4ab8e366625c90ae9f54c11172c8SHA256: e02a9f58bbe6ed65cc91231c28d5766ca3bbe43638a7d4974a0c1b9c366b2a75Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-graphql-annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name graphql Highest Vendor jar package name graphql Low Vendor pom artifactid atlassian-graphql-annotations Highest Vendor pom artifactid atlassian-graphql-annotations Low Vendor pom groupid com.atlassian.graphql Highest Vendor pom name Atlassian GraphQL - Annotations High Vendor pom parent-artifactid atlassian-graphql-parent Low Product file name atlassian-graphql-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name atlassian Highest Product jar package name graphql Highest Product jar package name graphql Low Product pom artifactid atlassian-graphql-annotations Highest Product pom groupid com.atlassian.graphql Highest Product pom name Atlassian GraphQL - Annotations High Product pom parent-artifactid atlassian-graphql-parent Medium Version file version 1.3.7 High Version pom version 1.3.7 Highest
atlassian-gzipfilter-3.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/gzipfilter/atlassian-gzipfilter/3.0.0/atlassian-gzipfilter-3.0.0.jarMD5: 2b4780173856f6505483860679f1ec21SHA1: 7f423cfb3dcad5b07b094323980315e340154fcdSHA256: a66b00a9f59cbcc0854f3ac684a2e3b4aa3d5673c08811d7236fe3ba2e8a4e52Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-gzipfilter High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name gzipfilter Highest Vendor jar package name gzipfilter Low Vendor pom artifactid atlassian-gzipfilter Highest Vendor pom artifactid atlassian-gzipfilter Low Vendor pom groupid com.atlassian.gzipfilter Highest Vendor pom name Atlassian Gzip Filter High Vendor pom parent-artifactid atlassian-gzipfilter-parent Low Product file name atlassian-gzipfilter High Product jar package name atlassian Highest Product jar package name gzipfilter Highest Product jar package name gzipfilter Low Product pom artifactid atlassian-gzipfilter Highest Product pom groupid com.atlassian.gzipfilter Highest Product pom name Atlassian Gzip Filter High Product pom parent-artifactid atlassian-gzipfilter-parent Medium Version file version 3.0.0 High Version pom version 3.0.0 Highest
atlassian-h2-server-integration-2.2.0.jarDescription:
H2 server integration into Atlassian's application configuration framework License:
Atlassian 3.0 End User License Agreement: http://www.atlassian.com/end-user-agreement/ File Path: /home/andrii/.m2/repository/com/atlassian/h2/atlassian-h2-server-integration/2.2.0/atlassian-h2-server-integration-2.2.0.jar
MD5: 3ead3224505016e7e3225fa0edd3b398
SHA1: 15d692f501b6630af336cd0b59284b80cdb89c26
SHA256: df554d29c5e30472aafe117c821e9925be64e129a9fb987fb9ff968c3d008097
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-h2-server-integration High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name h2 Highest Vendor jar package name h2 Low Vendor pom artifactid atlassian-h2-server-integration Highest Vendor pom artifactid atlassian-h2-server-integration Low Vendor pom groupid com.atlassian.h2 Highest Vendor pom organization name Atlassian High Vendor pom organization url http://www.atlassian.com/ Medium Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-h2-server-integration High Product jar package name atlassian Highest Product jar package name h2 Highest Product jar package name h2 Low Product pom artifactid atlassian-h2-server-integration Highest Product pom groupid com.atlassian.h2 Highest Product pom organization name Atlassian Low Product pom organization url http://www.atlassian.com/ Low Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 2.2.0 High Version pom parent-version 2.2.0 Low Version pom version 2.2.0 Highest
atlassian-healthcheck-plugin-check-api-6.0.0.jarDescription:
Provides code for reuse by JIRA, Confluence and Refapp TestHealthChecks, TestPluginStartup etc. which call atlassian-healthcheck plugin healthchecks. File Path: /home/andrii/.m2/repository/com/atlassian/healthcheck/atlassian-healthcheck-plugin-check-api/6.0.0/atlassian-healthcheck-plugin-check-api-6.0.0.jarMD5: 056fa4585108ed633cd94d3e19fe0cb8SHA1: 1dee0a6f07449f61ce8cd035dec6ba2a99bd80f0SHA256: cc3af2a8c6914a42b37da7da53ba4642bdc2c94af763bdc6c9e1e5489c7be1faReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-healthcheck-plugin-check-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name checks Low Vendor jar package name healthcheck Highest Vendor jar package name healthcheck Low Vendor jar package name plugin Highest Vendor pom artifactid atlassian-healthcheck-plugin-check-api Highest Vendor pom artifactid atlassian-healthcheck-plugin-check-api Low Vendor pom groupid com.atlassian.healthcheck Highest Vendor pom name Atlassian HealthCheck library support in-product tests: plugin healthcheck related constants High Vendor pom parent-artifactid atlassian-healthcheck-parent Low Product file name atlassian-healthcheck-plugin-check-api High Product jar package name atlassian Highest Product jar package name checks Low Product jar package name healthcheck Highest Product jar package name healthcheck Low Product jar package name plugin Highest Product jar package name plugin Low Product pom artifactid atlassian-healthcheck-plugin-check-api Highest Product pom groupid com.atlassian.healthcheck Highest Product pom name Atlassian HealthCheck library support in-product tests: plugin healthcheck related constants High Product pom parent-artifactid atlassian-healthcheck-parent Medium Version file version 6.0.0 High Version pom version 6.0.0 Highest
atlassian-healthcheck-spi-6.0.0.jarDescription:
Provides components provided to atlassian-healthcheck by product core. File Path: /home/andrii/.m2/repository/com/atlassian/healthcheck/atlassian-healthcheck-spi/6.0.0/atlassian-healthcheck-spi-6.0.0.jarMD5: d6d22531b0447a16b87c6da29b13da3aSHA1: 145613db7efcf32e35cb5eb219c90c48b0a09851SHA256: 8f332058bb272eeb15679b590f643270f591e12be1510fe17d8b62a04f85a8d6Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-healthcheck-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name healthcheck Highest Vendor jar package name healthcheck Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor pom artifactid atlassian-healthcheck-spi Highest Vendor pom artifactid atlassian-healthcheck-spi Low Vendor pom groupid com.atlassian.healthcheck Highest Vendor pom name Atlassian HealthCheck SPI High Vendor pom parent-artifactid atlassian-healthcheck-parent Low Product file name atlassian-healthcheck-spi High Product jar package name atlassian Highest Product jar package name healthcheck Highest Product jar package name healthcheck Low Product jar package name impl Low Product jar package name spi Highest Product jar package name spi Low Product pom artifactid atlassian-healthcheck-spi Highest Product pom groupid com.atlassian.healthcheck Highest Product pom name Atlassian HealthCheck SPI High Product pom parent-artifactid atlassian-healthcheck-parent Medium Version file version 6.0.0 High Version pom version 6.0.0 Highest
atlassian-hibernate2-extras-6.2.5.jarFile Path: /home/andrii/.m2/repository/com/atlassian/hibernate/atlassian-hibernate2-extras/6.2.5/atlassian-hibernate2-extras-6.2.5.jarMD5: 0e563b7f914816a3d9c7b19ee63bf8c5SHA1: d9aaf868bbca5085dcfd3f2ae459e8236bb275c6SHA256: c4efaba04786acce8b173144123f8c918e5d699617ddcceea37af6ff7a1e65cdReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-hibernate2-extras High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name extras Highest Vendor jar package name extras Low Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor pom artifactid atlassian-hibernate2-extras Highest Vendor pom artifactid atlassian-hibernate2-extras Low Vendor pom groupid com.atlassian.hibernate Highest Vendor pom name Atlassian Hibernate 2 Extras High Vendor pom parent-artifactid atlassian-hibernate-extras-parent Low Product file name atlassian-hibernate2-extras High Product jar package name atlassian Highest Product jar package name extras Highest Product jar package name extras Low Product jar package name hibernate Highest Product jar package name hibernate Low Product pom artifactid atlassian-hibernate2-extras Highest Product pom groupid com.atlassian.hibernate Highest Product pom name Atlassian Hibernate 2 Extras High Product pom parent-artifactid atlassian-hibernate-extras-parent Medium Version file version 6.2.5 High Version pom version 6.2.5 Highest
atlassian-hsqdlb-server-integration-1.1.0.jarDescription:
HSQLDB server integration into Atlassian's application configuration framework License:
Atlassian 3.0 End User License Agreement: http://www.atlassian.com/end-user-agreement/ File Path: /home/andrii/.m2/repository/com/atlassian/hsqldb/atlassian-hsqdlb-server-integration/1.1.0/atlassian-hsqdlb-server-integration-1.1.0.jar
MD5: 8feca11266ffc9ed9384c6b055a201c1
SHA1: 7ca10950fc090499fdc5eb513391f036ac4f04c8
SHA256: cb950173c505be16abd8d65b00d2f5bd13a53e2fe34d2032560b8a7c053566b3
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-hsqdlb-server-integration High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name hsqldb Highest Vendor jar package name hsqldb Low Vendor pom artifactid atlassian-hsqdlb-server-integration Highest Vendor pom artifactid atlassian-hsqdlb-server-integration Low Vendor pom groupid com.atlassian.hsqldb Highest Vendor pom organization name Atlassian High Vendor pom organization url http://www.atlassian.com/ Medium Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-hsqdlb-server-integration High Product jar package name atlassian Highest Product jar package name hsqldb Highest Product jar package name hsqldb Low Product pom artifactid atlassian-hsqdlb-server-integration Highest Product pom groupid com.atlassian.hsqldb Highest Product pom organization name Atlassian Low Product pom organization url http://www.atlassian.com/ Low Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.1.0 High Version pom parent-version 1.1.0 Low Version pom version 1.1.0 Highest
atlassian-html-encoder-1.5.jarLicense:
BSD: http://opensource.org/licenses/BSD-3-Clause File Path: /home/andrii/.m2/repository/com/atlassian/html/atlassian-html-encoder/1.5/atlassian-html-encoder-1.5.jar
MD5: c1527fcbf1f40a5b58348c7bc8b888b5
SHA1: 40bd03045da35d1e3019a5bc76ca90c360217dd3
SHA256: d492fd77181b2bf68a53e0ca961789cc69b76e26a5cbefe9f333122bb1bcc959
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-html-encoder High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name encode Low Vendor jar package name html Highest Vendor jar package name html Low Vendor pom artifactid atlassian-html-encoder Highest Vendor pom artifactid atlassian-html-encoder Low Vendor pom groupid com.atlassian.html Highest Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-html-encoder High Product jar package name atlassian Highest Product jar package name encode Low Product jar package name html Highest Product jar package name html Low Product pom artifactid atlassian-html-encoder Highest Product pom groupid com.atlassian.html Highest Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.5 High Version pom parent-version 1.5 Low Version pom version 1.5 Highest
atlassian-http-2.0.8.jarDescription:
This project contains utility classes for manipulation of http concepts, such as
cookies, MIME types, and browser agent sniffing.
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/atlassian/http/atlassian-http/2.0.8/atlassian-http-2.0.8.jar
MD5: e7505091f16f66bdc4ce2ed19d840600
SHA1: d895b554f0f023dd466b90b8cbcebea03b836ece
SHA256: e99285c07259321746c868f9d2ee580cbcfce10d042e2c14375a78ddc46d1687
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-http High Vendor jar package name atlassian Highest Vendor jar package name http Highest Vendor jar package name mime Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.http.atlassian-http Medium Vendor pom artifactid atlassian-http Highest Vendor pom artifactid atlassian-http Low Vendor pom developer email jxie@atlassian.com Low Vendor pom developer name Joe Xie Medium Vendor pom groupid com.atlassian.http Highest Vendor pom name Atlassian Http High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://bitbucket.org/atlassian/atlassian-http Highest Product file name atlassian-http High Product jar package name atlassian Highest Product jar package name http Highest Product jar package name mime Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Atlassian Http Medium Product Manifest bundle-symbolicname com.atlassian.http.atlassian-http Medium Product pom artifactid atlassian-http Highest Product pom developer email jxie@atlassian.com Low Product pom developer name Joe Xie Low Product pom groupid com.atlassian.http Highest Product pom name Atlassian Http High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://bitbucket.org/atlassian/atlassian-http Medium Version file version 2.0.8 High Version Manifest Bundle-Version 2.0.8 High Version pom parent-version 2.0.8 Low Version pom version 2.0.8 Highest
atlassian-image-consumer-1.0.1.jarLicense:
LGPL 2.1 License: http://www.gnu.org/licenses/lgpl-2.1.txt File Path: /home/andrii/.m2/repository/com/atlassian/image/atlassian-image-consumer/1.0.1/atlassian-image-consumer-1.0.1.jar
MD5: 28bbc9e0d0d31fcf258fea467201dae1
SHA1: 3e85562e44c029d8fe7944ad0119b998e57a7110
SHA256: 6b9da341d7ef47fe3d053e83afdd24e4654da4cf5fdab992bb96a7d233555d4e
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-image-consumer High Vendor jar package name j3d Low Vendor jar package name util Low Vendor pom artifactid atlassian-image-consumer Highest Vendor pom artifactid atlassian-image-consumer Low Vendor pom groupid com.atlassian.image Highest Vendor pom name atlassian-image-consumer High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-image-consumer High Product jar package name imagegenerator Low Product jar package name util Low Product pom artifactid atlassian-image-consumer Highest Product pom groupid com.atlassian.image Highest Product pom name atlassian-image-consumer High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.0.1 High Version pom parent-version 1.0.1 Low Version pom version 1.0.1 Highest
atlassian-instrumentation-core-3.0.0.jarDescription:
Core library to give systems the ability to instrument their internal state through the
use of counters / gauges and general operation profiling
File Path: /home/andrii/.m2/repository/com/atlassian/instrumentation/atlassian-instrumentation-core/3.0.0/atlassian-instrumentation-core-3.0.0.jarMD5: c361878da34251de86d90388c55f8ea8SHA1: 7940f31e37dcb67d6aaf16aeed6ea27b43c4025aSHA256: af8845fd2eb47dc72a9f27b00ce5e4de962416d5e95c7426b525c39c50cfbba9Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-instrumentation-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name instrument Highest Vendor jar package name instrumentation Highest Vendor jar package name instrumentation Low Vendor pom artifactid atlassian-instrumentation-core Highest Vendor pom artifactid atlassian-instrumentation-core Low Vendor pom groupid com.atlassian.instrumentation Highest Vendor pom name Atlassian Instrumentation Aggregation - Core High Vendor pom parent-artifactid atlassian-instrumentation-parent Low Product file name atlassian-instrumentation-core High Product jar package name atlassian Highest Product jar package name instrument Highest Product jar package name instrumentation Highest Product jar package name instrumentation Low Product pom artifactid atlassian-instrumentation-core Highest Product pom groupid com.atlassian.instrumentation Highest Product pom name Atlassian Instrumentation Aggregation - Core High Product pom parent-artifactid atlassian-instrumentation-parent Medium Version file version 3.0.0 High Version pom version 3.0.0 Highest
atlassian-ip-3.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/ip/atlassian-ip/3.1/atlassian-ip-3.1.jarMD5: cf295c31c48dd7e42e5441a6a9c6a256SHA1: 3dd393bd3e9004f72ca48a4f098a90886d544d69SHA256: 284e8ff2bf1620eb2d0e9ffa55a402de65736717688ea99daa03b42d250aee90Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-ip High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name ip Highest Vendor jar package name ip Low Vendor pom artifactid atlassian-ip Highest Vendor pom artifactid atlassian-ip Low Vendor pom groupid com.atlassian.ip Highest Vendor pom name Atlassian IP High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-ip High Product jar package name atlassian Highest Product jar package name ip Highest Product jar package name ip Low Product pom artifactid atlassian-ip Highest Product pom groupid com.atlassian.ip Highest Product pom name Atlassian IP High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 3.1 High Version pom parent-version 3.1 Low Version pom version 3.1 Highest
atlassian-jdk-utilities-0.6.jarDescription:
A set of utilities that work with a JDK. File Path: /home/andrii/.m2/repository/com/atlassian/jdk/utilities/atlassian-jdk-utilities/0.6/atlassian-jdk-utilities-0.6.jarMD5: 0e8d78323799855328e08ad47dcc92f5SHA1: 542bd5b872240175427b0cd5bf6e556ddaa6ca48SHA256: 70edc5c7f0855f7fece10dd3710e5647b8c1c05eb56b2b4d3385d627bac089e7Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-jdk-utilities High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name jdk Highest Vendor jar package name jdk Low Vendor jar package name utilities Highest Vendor jar package name utilities Low Vendor pom artifactid atlassian-jdk-utilities Highest Vendor pom artifactid atlassian-jdk-utilities Low Vendor pom groupid com.atlassian.jdk.utilities Highest Vendor pom name Atlassian JDK Utilities High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-jdk-utilities High Product jar package name atlassian Highest Product jar package name jdk Highest Product jar package name jdk Low Product jar package name runtimeinformation Low Product jar package name utilities Highest Product jar package name utilities Low Product pom artifactid atlassian-jdk-utilities Highest Product pom groupid com.atlassian.jdk.utilities Highest Product pom name Atlassian JDK Utilities High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 0.6 High Version pom parent-version 0.6 Low Version pom version 0.6 Highest
atlassian-johnson-core-4.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/johnson/atlassian-johnson-core/4.0.0/atlassian-johnson-core-4.0.0.jarMD5: 47432b89ce7413a911def497536d1f4cSHA1: 52f24677e5199b9579fd54a9d1077157cae1dcbbSHA256: 8e91458afbb47f9d5832f066c394381e400db50906cb79afa23c9a44cfa14c41Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-johnson-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name johnson Highest Vendor jar package name johnson Low Vendor pom artifactid atlassian-johnson-core Highest Vendor pom artifactid atlassian-johnson-core Low Vendor pom groupid com.atlassian.johnson Highest Vendor pom name Atlassian Johnson :: Core High Vendor pom parent-artifactid atlassian-johnson-parent Low Product file name atlassian-johnson-core High Product jar package name atlassian Highest Product jar package name johnson Highest Product jar package name johnson Low Product pom artifactid atlassian-johnson-core Highest Product pom groupid com.atlassian.johnson Highest Product pom name Atlassian Johnson :: Core High Product pom parent-artifactid atlassian-johnson-parent Medium Version file version 4.0.0 High Version pom version 4.0.0 Highest
atlassian-johnson-plugins-4.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/johnson/atlassian-johnson-plugins/4.0.0/atlassian-johnson-plugins-4.0.0.jarMD5: 8e90b774a89faaff34b5e4fab869f5d1SHA1: 8946d63832e1b7f96e662f34b2f8030cbc62d37cSHA256: 62ed16ace366c1911d2335b9e4ea6a59bd214c4d19688ae7b767994d4e2c5973Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-johnson-plugins High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name johnson Highest Vendor jar package name johnson Low Vendor jar package name plugin Highest Vendor jar package name plugin Low Vendor pom artifactid atlassian-johnson-plugins Highest Vendor pom artifactid atlassian-johnson-plugins Low Vendor pom groupid com.atlassian.johnson Highest Vendor pom name Atlassian Johnson :: Plugin Framework Extensions High Vendor pom parent-artifactid atlassian-johnson-parent Low Product file name atlassian-johnson-plugins High Product jar package name atlassian Highest Product jar package name johnson Highest Product jar package name johnson Low Product jar package name plugin Highest Product jar package name plugin Low Product jar package name servlet Low Product pom artifactid atlassian-johnson-plugins Highest Product pom groupid com.atlassian.johnson Highest Product pom name Atlassian Johnson :: Plugin Framework Extensions High Product pom parent-artifactid atlassian-johnson-parent Medium Version file version 4.0.0 High Version pom version 4.0.0 Highest
atlassian-json-api-0.11.jarFile Path: /home/andrii/.m2/repository/com/atlassian/json/atlassian-json-api/0.11/atlassian-json-api-0.11.jarMD5: c55e7d4b0ef3edb9f8ffee7f662b2a0eSHA1: 84374bc858c65e8663b1a33bb4d8ff7ef9ca850eSHA256: f1b6cfc4addfcd10e4a378417656ffeaedc3e11d18406a6b14d443d5767ab0daReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-json-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name json Highest Vendor jar package name json Low Vendor jar package name marshal Low Vendor pom artifactid atlassian-json-api Highest Vendor pom artifactid atlassian-json-api Low Vendor pom groupid com.atlassian.json Highest Vendor pom name Streamy JSON interfaces High Vendor pom parent-artifactid atlassian-json Low Product file name atlassian-json-api High Product jar package name atlassian Highest Product jar package name json Highest Product jar package name json Low Product jar package name marshal Low Product jar package name wrapped Low Product pom artifactid atlassian-json-api Highest Product pom groupid com.atlassian.json Highest Product pom name Streamy JSON interfaces High Product pom parent-artifactid atlassian-json Medium Version file version 0.11 High Version pom version 0.11 Highest
atlassian-json-jsonorg-0.11.jarFile Path: /home/andrii/.m2/repository/com/atlassian/json/atlassian-json-jsonorg/0.11/atlassian-json-jsonorg-0.11.jarMD5: 7fad99f50cb3ac1e26207f46024b9feaSHA1: a83e00cc4e37fde293b6dd2715b67a767a4feb6fSHA256: 88056f81d07421daf9e6441298c8f4512d38fdb4ffb2729b50eaca49b08b0295Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-json-jsonorg High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name json Highest Vendor jar package name json Low Vendor jar package name jsonorg Highest Vendor jar package name jsonorg Low Vendor pom artifactid atlassian-json-jsonorg Highest Vendor pom artifactid atlassian-json-jsonorg Low Vendor pom groupid com.atlassian.json Highest Vendor pom name json.org inspired JSON code without the thorny checked exceptions High Vendor pom parent-artifactid atlassian-json Low Product file name atlassian-json-jsonorg High Product jar package name atlassian Highest Product jar package name json Highest Product jar package name json Low Product jar package name jsonorg Highest Product jar package name jsonorg Low Product pom artifactid atlassian-json-jsonorg Highest Product pom groupid com.atlassian.json Highest Product pom name json.org inspired JSON code without the thorny checked exceptions High Product pom parent-artifactid atlassian-json Medium Version file version 0.11 High Version pom version 0.11 Highest
atlassian-localhost-1.1.0.jarDescription:
Provides library method(s) for establishing the fully-qualified hostname (FQHN)
of the local machine. Created to shim the slightly changed behaviour of
java.net.InetAddress.getLocalHost().getHostName() in java8 compared to java7.
File Path: /home/andrii/.m2/repository/com/atlassian/atlassian-localhost/1.1.0/atlassian-localhost-1.1.0.jarMD5: c601fbd8b8778db8ab2211e8111e79faSHA1: 74c10ea79995a53e8a33d43abf7632d279be9518SHA256: ab56b636ec686350507b68a71d6abd37310347b9c5b1754082a99e9c37ef204cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-localhost High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name net Highest Vendor jar package name net Low Vendor pom artifactid atlassian-localhost Highest Vendor pom artifactid atlassian-localhost Low Vendor pom groupid com.atlassian Highest Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-localhost High Product jar package name atlassian Highest Product jar package name net Highest Product jar package name net Low Product jar package name networkutils Low Product pom artifactid atlassian-localhost Highest Product pom groupid com.atlassian Highest Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.1.0 High Version pom parent-version 1.1.0 Low Version pom version 1.1.0 Highest
atlassian-mail-5.0.6.jarDescription:
Atlassian Mail is a generic mail sending component used by Atlassian applications. License:
BSD: LICENSE.txt File Path: /home/andrii/.m2/repository/com/atlassian/mail/atlassian-mail/5.0.6/atlassian-mail-5.0.6.jar
MD5: 63f32c79f60b44e9fe998f411c91baeb
SHA1: f6da3ecc6695ada3b6cfca19b515c011e468c15e
SHA256: 9cbe9ccd95b9da0523f01d5e2dfcd1e7a55975e7ef56a377d12c453b53ab5125
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-mail High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name mail Highest Vendor jar package name mail Low Vendor pom artifactid atlassian-mail Highest Vendor pom artifactid atlassian-mail Low Vendor pom groupid com.atlassian.mail Highest Vendor pom name Atlassian Mail High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-mail High Product jar package name atlassian Highest Product jar package name mail Highest Product jar package name mail Low Product pom artifactid atlassian-mail Highest Product pom groupid com.atlassian.mail Highest Product pom name Atlassian Mail High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 5.0.6 High Version pom parent-version 5.0.6 Low Version pom version 5.0.6 Highest
atlassian-marshalling-api-1.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/marshalling/atlassian-marshalling-api/1.0.0/atlassian-marshalling-api-1.0.0.jarMD5: 873cd17f998ad28d0df6cf32068df034SHA1: d09fcc51162406304dcbed853ea918b642c13ac0SHA256: bcf1c4781f6094de71bc57a3585c1c9f4e2429c804cd177ca4f6f949bdb7d80dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-marshalling-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name marshalling Highest Vendor jar package name marshalling Low Vendor pom artifactid atlassian-marshalling-api Highest Vendor pom artifactid atlassian-marshalling-api Low Vendor pom groupid com.atlassian.marshalling Highest Vendor pom name Atlassian Marshalling API High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-marshalling-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name marshalling Highest Product jar package name marshalling Low Product pom artifactid atlassian-marshalling-api Highest Product pom groupid com.atlassian.marshalling Highest Product pom name Atlassian Marshalling API High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 1.0.0 High Version pom parent-version 1.0.0 Low Version pom version 1.0.0 Highest
atlassian-marshalling-gson-3.0.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/marshalling/atlassian-marshalling-gson/3.0.1/atlassian-marshalling-gson-3.0.1.jarMD5: 0c25ffd5fc88d7ee23f070fc37640ff2SHA1: cfc09455a17bd412145e2fd1bdc798f7717b3034SHA256: 259e52d8198b4b4a2eea746783eb7a6f29697b47dfc8d5d35968ac8dcf059768Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-marshalling-gson High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name gson Highest Vendor jar package name gson Low Vendor jar package name marshalling Highest Vendor jar package name marshalling Low Vendor pom artifactid atlassian-marshalling-gson Highest Vendor pom artifactid atlassian-marshalling-gson Low Vendor pom groupid com.atlassian.marshalling Highest Vendor pom name Atlassian Marshalling Gson High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-marshalling-gson High Product jar package name atlassian Highest Product jar package name gson Highest Product jar package name gson Low Product jar package name marshalling Highest Product jar package name marshalling Low Product pom artifactid atlassian-marshalling-gson Highest Product pom groupid com.atlassian.marshalling Highest Product pom name Atlassian Marshalling Gson High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 3.0.1 High Version pom parent-version 3.0.1 Low Version pom version 3.0.1 Highest
atlassian-marshalling-jdk-1.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/marshalling/atlassian-marshalling-jdk/1.1.0/atlassian-marshalling-jdk-1.1.0.jarMD5: e44737df383073ee5fdb55c0b205ae57SHA1: 24214acccc6eb2b01eba1afb85333bae6920ee92SHA256: 6723fdaf380ae921cffc62f2c14c2b8b91f9b1c55eeb8d6cfe9b4c5d19070d74Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-marshalling-jdk High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name jdk Highest Vendor jar package name jdk Low Vendor jar package name marshalling Highest Vendor jar package name marshalling Low Vendor pom artifactid atlassian-marshalling-jdk Highest Vendor pom artifactid atlassian-marshalling-jdk Low Vendor pom groupid com.atlassian.marshalling Highest Vendor pom name Atlassian Marshalling JDK High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-marshalling-jdk High Product jar package name atlassian Highest Product jar package name jdk Highest Product jar package name jdk Low Product jar package name marshalling Highest Product jar package name marshalling Low Product pom artifactid atlassian-marshalling-jdk Highest Product pom groupid com.atlassian.marshalling Highest Product pom name Atlassian Marshalling JDK High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 1.1.0 High Version pom parent-version 1.1.0 Low Version pom version 1.1.0 Highest
atlassian-marshalling-protobuf-1.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/marshalling/atlassian-marshalling-protobuf/1.0.0/atlassian-marshalling-protobuf-1.0.0.jarMD5: 7a8e1abd64408e23f6bd91c595221767SHA1: e6011e2f8beeca0c6176b26852e31b806b2ae7f1SHA256: dcd524faf2440025caa6b9124c374dcb2a0e9473ed13cec0947b87096101ecefReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-marshalling-protobuf High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name marshalling Highest Vendor jar package name marshalling Low Vendor jar package name protobuf Highest Vendor jar package name protobuf Low Vendor pom artifactid atlassian-marshalling-protobuf Highest Vendor pom artifactid atlassian-marshalling-protobuf Low Vendor pom groupid com.atlassian.marshalling Highest Vendor pom name Atlassian Marshalling Protobuf High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-marshalling-protobuf High Product jar package name atlassian Highest Product jar package name marshalling Highest Product jar package name marshalling Low Product jar package name protobuf Highest Product jar package name protobuf Low Product pom artifactid atlassian-marshalling-protobuf Highest Product pom groupid com.atlassian.marshalling Highest Product pom name Atlassian Marshalling Protobuf High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 1.0.0 High Version pom parent-version 1.0.0 Low Version pom version 1.0.0 Highest
atlassian-password-encoder-3.2.10.jarDescription:
Password encoder interface and default implementation for Atlassian applications. File Path: /home/andrii/.m2/repository/com/atlassian/security/atlassian-password-encoder/3.2.10/atlassian-password-encoder-3.2.10.jarMD5: e530758dc17d3d63a398851817175beeSHA1: 2be29a732b14c9426c2261107cf95a6d27f28126SHA256: c0ba9fcc078862d9ce53f270bcad36e4c4b2aa771f8c672227421b5b65ded018Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-password-encoder High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name password Highest Vendor jar package name password Low Vendor jar package name security Highest Vendor jar package name security Low Vendor pom artifactid atlassian-password-encoder Highest Vendor pom artifactid atlassian-password-encoder Low Vendor pom groupid com.atlassian.security Highest Vendor pom name Atlassian Password Encoder High Vendor pom parent-artifactid atlassian-security Low Product file name atlassian-password-encoder High Product jar package name atlassian Highest Product jar package name password Highest Product jar package name password Low Product jar package name security Highest Product jar package name security Low Product pom artifactid atlassian-password-encoder Highest Product pom groupid com.atlassian.security Highest Product pom name Atlassian Password Encoder High Product pom parent-artifactid atlassian-security Medium Version file version 3.2.10 High Version pom version 3.2.10 Highest
atlassian-plugin-point-safety-1.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/ozymandias/atlassian-plugin-point-safety/1.0.0/atlassian-plugin-point-safety-1.0.0.jarMD5: c6a4ea2561efb5682c1cd1b6d2d5c77aSHA1: 7ae0837bac6f52b9a836a19acfba5039147e47fbSHA256: 54cb294f734f3249fdc74abc993197dc403b2f879d186ecd04e9708fb64fa8d9Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugin-point-safety High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name ozymandias Highest Vendor jar package name ozymandias Low Vendor pom artifactid atlassian-plugin-point-safety Highest Vendor pom artifactid atlassian-plugin-point-safety Low Vendor pom groupid com.atlassian.ozymandias Highest Vendor pom name Atlassian Ozymandias Library High Vendor pom parent-artifactid atlassian-ozymandias-parent Low Product file name atlassian-plugin-point-safety High Product jar package name atlassian Highest Product jar package name ozymandias Highest Product jar package name ozymandias Low Product pom artifactid atlassian-plugin-point-safety Highest Product pom groupid com.atlassian.ozymandias Highest Product pom name Atlassian Ozymandias Library High Product pom parent-artifactid atlassian-ozymandias-parent Medium Version file version 1.0.0 High Version pom version 1.0.0 Highest
atlassian-plugins-api-5.3.11.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-api/5.3.11/atlassian-plugins-api-5.3.11.jarMD5: 5e0239fde5b44af18730ed8e32444a2dSHA1: e589a3c552bcf3e26284217e30dc24b07598bcb0SHA256: 5263efb14d3550a8de0ac861dce13c1b6de985606437ab64896c787d88361878Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor pom artifactid atlassian-plugins-api Highest Vendor pom artifactid atlassian-plugins-api Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-api High Product jar package name atlassian Highest Product jar package name plugin Low Product pom artifactid atlassian-plugins-api Highest Product pom groupid com.atlassian.plugins Highest Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-core-5.3.11.jarDescription:
A library to give systems the ability to have plugins, make them more pluggable and hence add pluggability
(it's late - that makes sense in my head).
File Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-core/5.3.11/atlassian-plugins-core-5.3.11.jarMD5: 0cc95a860d3e66861a89c0e57e5a3d85SHA1: 6674276088c5a4ebde61dfee7d716f3e3fda8558SHA256: 6df87b7de6793872d354d519c48dac3ce9edf381e2135e0507bb14acff488280Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor pom artifactid atlassian-plugins-core Highest Vendor pom artifactid atlassian-plugins-core Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Core High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-core High Product jar package name atlassian Highest Product jar package name plugin Low Product pom artifactid atlassian-plugins-core Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Core High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-osgi-5.3.11.jarDescription:
An extension to Atlassian Plugins that provides a loader that loads plugins into OSGi
File Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-osgi/5.3.11/atlassian-plugins-osgi-5.3.11.jarMD5: bfdf07909c25dd937b22d785344fc7e0SHA1: 6e5395048a45c0c91548362403679c8511fcd60fSHA256: 055f82e1f8fa0dda350ec89a7595f8969c5d0f3acc5c3aedd6b760efda5cc713Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-osgi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name osgi Highest Vendor jar package name osgi Low Vendor jar package name plugin Low Vendor pom artifactid atlassian-plugins-osgi Highest Vendor pom artifactid atlassian-plugins-osgi Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - OSGi Loader High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-osgi High Product jar package name atlassian Highest Product jar package name factory Low Product jar package name osgi Highest Product jar package name osgi Low Product jar package name plugin Low Product pom artifactid atlassian-plugins-osgi Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - OSGi Loader High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-osgi-events-5.3.11.jarDescription:
Events used to better bridge OSGi actions into the Atlassian Plugins framework
File Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-osgi-events/5.3.11/atlassian-plugins-osgi-events-5.3.11.jarMD5: c6de8d722ddae54cfd4249983b69b645SHA1: f77883c96e66d113c24e1bc49868b1865cb948f0SHA256: a79e893f50ea2911d34cde8f8f0c4f02fc1f98cfb48e2c84b436a4d5110028b8Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-osgi-events High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name osgi Highest Vendor jar package name osgi Low Vendor jar package name plugin Low Vendor pom artifactid atlassian-plugins-osgi-events Highest Vendor pom artifactid atlassian-plugins-osgi-events Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - OSGi events High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-osgi-events High Product jar package name atlassian Highest Product jar package name event Low Product jar package name osgi Highest Product jar package name osgi Low Product jar package name plugin Low Product pom artifactid atlassian-plugins-osgi-events Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - OSGi events High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-schema-5.3.11.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-schema/5.3.11/atlassian-plugins-schema-5.3.11.jarMD5: 0e8f251222d98cb21e3a801aeb9e4c1aSHA1: 2b746621b5a2314239c8b0ec078d486f38334492SHA256: 2ab684e1865315fa1207fecb19adb80b7424f55811ed9cfc5ae9b6975d1733caReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-schema High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name schema Highest Vendor jar package name schema Low Vendor pom artifactid atlassian-plugins-schema Highest Vendor pom artifactid atlassian-plugins-schema Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins Schema High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-schema High Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name schema Highest Product jar package name schema Low Product jar package name spi Low Product pom artifactid atlassian-plugins-schema Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins Schema High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-servlet-5.3.11.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-servlet/5.3.11/atlassian-plugins-servlet-5.3.11.jarMD5: 6dfbd5832c1f219f723fdab17e7278daSHA1: 4954478828f7ccb48891924ddcf033f58c1357c8SHA256: e12bebd4484b2072aa6ff5ecb333e1c71beac9e5ef5f2722d6566073765aaa20Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-servlet High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name servlet Highest Vendor jar package name servlet Low Vendor pom artifactid atlassian-plugins-servlet Highest Vendor pom artifactid atlassian-plugins-servlet Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Web Servlet High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-servlet High Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name servlet Highest Product jar package name servlet Low Product pom artifactid atlassian-plugins-servlet Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Web Servlet High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-spring-5.3.11.jarDescription:
Integration classes that tie Atlassian Plugins and Spring together
File Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-spring/5.3.11/atlassian-plugins-spring-5.3.11.jarMD5: 8d4e7e7d9dc03f61db90b352bd635ffeSHA1: fb1ffec2a9f23fd0708ed485ca0b42d644c2a9aeSHA256: 7c1e06fd31766ded90237f6651adc7a721ce6c69603250f467c99d537d8eb327Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-spring High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name spring Highest Vendor jar package name spring Low Vendor pom artifactid atlassian-plugins-spring Highest Vendor pom artifactid atlassian-plugins-spring Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Spring Integration High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-spring High Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name spring Highest Product jar package name spring Low Product pom artifactid atlassian-plugins-spring Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Spring Integration High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-webfragment-5.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-webfragment/5.0.0/atlassian-plugins-webfragment-5.0.0.jarMD5: 9132f7492167ca473269f55682a7a929SHA1: 9a37f5eb59111bc605fe58e0219732790de00f02SHA256: be529f88975589896adb3d4b1d5fbf8315d8d251db8e6b47d6163fcc7cd18316Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-webfragment High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name web Highest Vendor jar package name web Low Vendor pom artifactid atlassian-plugins-webfragment Highest Vendor pom artifactid atlassian-plugins-webfragment Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Web Fragments for Atlassian Plugins High Vendor pom parent-artifactid atlassian-plugins-webfragment-parent Low Product file name atlassian-plugins-webfragment High Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name web Highest Product jar package name web Low Product pom artifactid atlassian-plugins-webfragment Highest Product pom groupid com.atlassian.plugins Highest Product pom name Web Fragments for Atlassian Plugins High Product pom parent-artifactid atlassian-plugins-webfragment-parent Medium Version file version 5.0.0 High Version pom version 5.0.0 Highest
atlassian-plugins-webfragment-api-5.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-webfragment-api/5.0.0/atlassian-plugins-webfragment-api-5.0.0.jarMD5: a4fd934f3f492303ac6664ef4e0995efSHA1: 93f39798e09e4d0683d58a5cdce6a7abdabf434dSHA256: ccff309c947de4e20f2062fe57d022c91cfc8b4c7e617d63d748b067585da4d5Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-webfragment-api High Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name web Highest Vendor jar package name web Low Vendor pom artifactid atlassian-plugins-webfragment-api Highest Vendor pom artifactid atlassian-plugins-webfragment-api Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Web Fragments API for Atlassian Plugins High Vendor pom parent-artifactid atlassian-plugins-webfragment-parent Low Product file name atlassian-plugins-webfragment-api High Product jar package name api Highest Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name web Highest Product jar package name web Low Product pom artifactid atlassian-plugins-webfragment-api Highest Product pom groupid com.atlassian.plugins Highest Product pom name Web Fragments API for Atlassian Plugins High Product pom parent-artifactid atlassian-plugins-webfragment-parent Medium Version file version 5.0.0 High Version pom version 5.0.0 Highest
atlassian-plugins-webresource-4.1.6.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-webresource/4.1.6/atlassian-plugins-webresource-4.1.6.jarMD5: 14d63a85b735722450124b6d2bd571baSHA1: fec87edbe09f3b0a5c49d0555683251866fe2888SHA256: 68dcc508e913aea8bab84ccc6a0c75fe9a9e392f481e8a0f1726cd852fae99d5Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-webresource High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name webresource Highest Vendor jar package name webresource Low Vendor pom artifactid atlassian-plugins-webresource Highest Vendor pom artifactid atlassian-plugins-webresource Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Web Resources High Vendor pom parent-artifactid atlassian-plugins-webresource-parent Low Product file name atlassian-plugins-webresource High Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name webresource Highest Product jar package name webresource Low Product pom artifactid atlassian-plugins-webresource Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Web Resources High Product pom parent-artifactid atlassian-plugins-webresource-parent Medium Version file version 4.1.6 High Version pom version 4.1.6 Highest
atlassian-plugins-webresource-api-4.1.6.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-webresource-api/4.1.6/atlassian-plugins-webresource-api-4.1.6.jarMD5: 86a847b65d927fd73a426be1fdc09ffdSHA1: 43629deb9d557b9b738c9b86ee436cd337906ae3SHA256: 4865e53c6ab522149dfafb8c2f132dbc30a3051bfe0f4cd16d03ae0d85f30097Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-webresource-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name webresource Highest Vendor jar package name webresource Low Vendor pom artifactid atlassian-plugins-webresource-api Highest Vendor pom artifactid atlassian-plugins-webresource-api Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Web Resources API High Vendor pom parent-artifactid atlassian-plugins-webresource-parent Low Product file name atlassian-plugins-webresource-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name webresource Highest Product jar package name webresource Low Product pom artifactid atlassian-plugins-webresource-api Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Web Resources API High Product pom parent-artifactid atlassian-plugins-webresource-parent Medium Version file version 4.1.6 High Version pom version 4.1.6 Highest
atlassian-plugins-webresource-common-5.3.11.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-webresource-common/5.3.11/atlassian-plugins-webresource-common-5.3.11.jarMD5: 172c2e0af1179c586c4a09503192abf7SHA1: 84f83ddb01e90086c80019decbf4494998462a0bSHA256: 31ec5afdc540de740c668ecc1a535b07399f41491c42fd714b0f506a5e70d0d7Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-webresource-common High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name plugin Low Vendor jar package name servlet Low Vendor pom artifactid atlassian-plugins-webresource-common Highest Vendor pom artifactid atlassian-plugins-webresource-common Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Web Resource Common High Vendor pom parent-artifactid atlassian-plugins-parent Low Product file name atlassian-plugins-webresource-common High Product jar package name atlassian Highest Product jar package name plugin Low Product jar package name servlet Low Product pom artifactid atlassian-plugins-webresource-common Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Web Resource Common High Product pom parent-artifactid atlassian-plugins-parent Medium Version file version 5.3.11 High Version pom version 5.3.11 Highest
atlassian-plugins-webresource-spi-4.1.6.jarFile Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-plugins-webresource-spi/4.1.6/atlassian-plugins-webresource-spi-4.1.6.jarMD5: 0dc7c6be43a0b3a8878e183659909c41SHA1: 1fea50d31afff8f6304cd846f64cfe67e1c7bd6dSHA256: c2cf9b7dbe77cf023f62a44892d585495aea64ee545aa0225910273aca642617Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-plugins-webresource-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor jar package name webresource Highest Vendor jar package name webresource Low Vendor pom artifactid atlassian-plugins-webresource-spi Highest Vendor pom artifactid atlassian-plugins-webresource-spi Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Web Resources SPI High Vendor pom parent-artifactid atlassian-plugins-webresource-parent Low Product file name atlassian-plugins-webresource-spi High Product jar package name atlassian Highest Product jar package name spi Highest Product jar package name spi Low Product jar package name webresource Highest Product jar package name webresource Low Product pom artifactid atlassian-plugins-webresource-spi Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Web Resources SPI High Product pom parent-artifactid atlassian-plugins-webresource-parent Medium Version file version 4.1.6 High Version pom version 4.1.6 Highest
atlassian-profiling-3.4.3.jarDescription:
A simple framework for run-time profiling an application, focused on JEE web applications.
File Path: /home/andrii/.m2/repository/com/atlassian/profiling/atlassian-profiling/3.4.3/atlassian-profiling-3.4.3.jarMD5: c692bf3e1e76390ff56f962d0e050495SHA1: 753346e768bd2c3c3a9272e258964c39f11679a7SHA256: 4f890ed7e10c6fbf69c89ced62c5295a530aa2a832f2dd8d6dd6db80ac8a5c49Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-profiling High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name profiling Highest Vendor jar package name profiling Low Vendor jar package name util Low Vendor pom artifactid atlassian-profiling Highest Vendor pom artifactid atlassian-profiling Low Vendor pom groupid com.atlassian.profiling Highest Vendor pom name Atlassian Profiling High Vendor pom parent-artifactid atlassian-profiling-parent Low Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-profiling High Product jar package name atlassian Highest Product jar package name profiling Highest Product jar package name profiling Low Product jar package name util Low Product pom artifactid atlassian-profiling Highest Product pom groupid com.atlassian.profiling Highest Product pom name Atlassian Profiling High Product pom parent-artifactid atlassian-profiling-parent Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 3.4.3 High Version pom version 3.4.3 Highest
atlassian-profiling-dropwizard-metrics-3.4.3.jarDescription:
Dropwizard Metrics based implementation of MetricStrategy File Path: /home/andrii/.m2/repository/com/atlassian/profiling/atlassian-profiling-dropwizard-metrics/3.4.3/atlassian-profiling-dropwizard-metrics-3.4.3.jarMD5: c723a204a91d2f958b7ac87eac0587a2SHA1: 33b1c49a08e8ce26ed984ea57453532ef6b574b0SHA256: 01a7acd48ada67cf54f36cfe5b2a9ae81c1494116e8eac084730405d1fa88febReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-profiling-dropwizard-metrics High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name dropwizard Highest Vendor jar package name profiling Highest Vendor jar package name profiling Low Vendor jar package name util Low Vendor pom artifactid atlassian-profiling-dropwizard-metrics Highest Vendor pom artifactid atlassian-profiling-dropwizard-metrics Low Vendor pom groupid com.atlassian.profiling Highest Vendor pom name Atlassian Profiling - Dropwizard metrics High Vendor pom parent-artifactid atlassian-profiling-parent Low Product file name atlassian-profiling-dropwizard-metrics High Product jar package name atlassian Highest Product jar package name dropwizard Highest Product jar package name dropwizard Low Product jar package name profiling Highest Product jar package name profiling Low Product jar package name util Low Product pom artifactid atlassian-profiling-dropwizard-metrics Highest Product pom groupid com.atlassian.profiling Highest Product pom name Atlassian Profiling - Dropwizard metrics High Product pom parent-artifactid atlassian-profiling-parent Medium Version file version 3.4.3 High Version pom version 3.4.3 Highest
atlassian-profiling-micrometer-3.4.3.jarDescription:
Micrometer-based implementation of MetricStrategy File Path: /home/andrii/.m2/repository/com/atlassian/profiling/atlassian-profiling-micrometer/3.4.3/atlassian-profiling-micrometer-3.4.3.jarMD5: f6efdfcabcf2149de0d0c935abe2376cSHA1: 42be933b3f53ff72364ec715d9f3337b7289a174SHA256: 5bd5efb89134a5cac07532df3f80f376eee2de8f0b01191272701eec87976ebaReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-profiling-micrometer High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name micrometer Highest Vendor jar package name profiling Highest Vendor jar package name profiling Low Vendor jar package name util Low Vendor pom artifactid atlassian-profiling-micrometer Highest Vendor pom artifactid atlassian-profiling-micrometer Low Vendor pom groupid com.atlassian.profiling Highest Vendor pom name Atlassian Profiling - Micrometer High Vendor pom parent-artifactid atlassian-profiling-parent Low Product file name atlassian-profiling-micrometer High Product jar package name atlassian Highest Product jar package name micrometer Highest Product jar package name micrometer Low Product jar package name profiling Highest Product jar package name profiling Low Product jar package name util Low Product pom artifactid atlassian-profiling-micrometer Highest Product pom groupid com.atlassian.profiling Highest Product pom name Atlassian Profiling - Micrometer High Product pom parent-artifactid atlassian-profiling-parent Medium Version file version 3.4.3 High Version pom version 3.4.3 Highest
atlassian-renderer-legacy-6.2.25.jarDescription:
The library that renders wiki markup for Confluence and JIRA. File Path: /home/andrii/.m2/repository/com/atlassian/renderer/atlassian-renderer-legacy/6.2.25/atlassian-renderer-legacy-6.2.25.jarMD5: 4ec3d0b5e9dc9d1c8fa752d5c5775a7fSHA1: e090c00197a1378ebf9699bc127e48964ca30cabSHA256: 6edf838c29b1e663aa2035076dd88c9670be86b0e2e6def9ed4290fc3770a44bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-renderer-legacy High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name renderer Highest Vendor jar package name renderer Low Vendor pom artifactid atlassian-renderer-legacy Highest Vendor pom artifactid atlassian-renderer-legacy Low Vendor pom groupid com.atlassian.renderer Highest Vendor pom name Atlassian Renderer Legacy High Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-renderer-legacy High Product jar package name atlassian Highest Product jar package name renderer Highest Product jar package name renderer Low Product pom artifactid atlassian-renderer-legacy Highest Product pom groupid com.atlassian.renderer Highest Product pom name Atlassian Renderer Legacy High Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url http://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 6.2.25 High Version pom parent-version 6.2.25 Low Version pom version 6.2.25 Highest
atlassian-scheduler-api-3.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/scheduler/atlassian-scheduler-api/3.0.0/atlassian-scheduler-api-3.0.0.jarMD5: 863d14e2534880ac184c25f33856e977SHA1: c609daefcad0208b6b8553b1b54af245d029555dSHA256: 31960ebda1751157fd5956a24c8f0e5a2f13f6bb83491a5bd402a1050b8cf0c1Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-scheduler-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name scheduler Highest Vendor jar package name scheduler Low Vendor pom artifactid atlassian-scheduler-api Highest Vendor pom artifactid atlassian-scheduler-api Low Vendor pom groupid com.atlassian.scheduler Highest Vendor pom name Atlassian Scheduler - API High Vendor pom parent-artifactid atlassian-scheduler Low Product file name atlassian-scheduler-api High Product jar package name atlassian Highest Product jar package name scheduler Highest Product jar package name scheduler Low Product pom artifactid atlassian-scheduler-api Highest Product pom groupid com.atlassian.scheduler Highest Product pom name Atlassian Scheduler - API High Product pom parent-artifactid atlassian-scheduler Medium Version file version 3.0.0 High Version pom version 3.0.0 Highest
atlassian-scheduler-caesium-3.0.0.jarDescription:
Caesium is like Quartz, in that it can be used to keep track of scheduled things.
However, it is much simpler and hopefully does not have has many bugs.
The name derives from the fact that since 1967 the definition of 1 second has
been "The duration of 9,192,631,770 periods of the radiation corresponding to
the transition between the two hyperfine levels of the ground state of the
caesium-133 atom."
Note: I would have preferred to spell this "cesium," but IUPAC says otherwise.
File Path: /home/andrii/.m2/repository/com/atlassian/scheduler/caesium/atlassian-scheduler-caesium/3.0.0/atlassian-scheduler-caesium-3.0.0.jarMD5: d6511b9aa19f704500f88dd397095d51SHA1: 98611dc21e49f62e76a684132eb3c12a918ee4eeSHA256: 4ef1146b8af1b030f885b8bda898cd23c711c2f0036750c71ea97c00f5c81b79Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-scheduler-caesium High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name caesium Highest Vendor jar package name caesium Low Vendor jar package name scheduler Highest Vendor jar package name scheduler Low Vendor pom artifactid atlassian-scheduler-caesium Highest Vendor pom artifactid atlassian-scheduler-caesium Low Vendor pom groupid com.atlassian.scheduler.caesium Highest Vendor pom name Atlassian Scheduler - Caesium Implementation High Vendor pom parent-artifactid caesium-parent Low Product file name atlassian-scheduler-caesium High Product jar package name atlassian Highest Product jar package name caesium Highest Product jar package name caesium Low Product jar package name cron Low Product jar package name scheduler Highest Product jar package name scheduler Low Product pom artifactid atlassian-scheduler-caesium Highest Product pom groupid com.atlassian.scheduler.caesium Highest Product pom name Atlassian Scheduler - Caesium Implementation High Product pom parent-artifactid caesium-parent Medium Version file version 3.0.0 High Version pom version 3.0.0 Highest
atlassian-scheduler-core-3.0.0.jarDescription:
Provides reusable core classes that most implementations are likely to need File Path: /home/andrii/.m2/repository/com/atlassian/scheduler/atlassian-scheduler-core/3.0.0/atlassian-scheduler-core-3.0.0.jarMD5: 98afce24578a777458892a5484bf59aeSHA1: e33f847c660e641d9afd6732d42f6dbb527ec507SHA256: a089718bb41ec12d96f9440e80c5db6ecb53346ee9c90f348be250d58d133d96Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-scheduler-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name scheduler Highest Vendor jar package name scheduler Low Vendor pom artifactid atlassian-scheduler-core Highest Vendor pom artifactid atlassian-scheduler-core Low Vendor pom groupid com.atlassian.scheduler Highest Vendor pom name Atlassian Scheduler - Core High Vendor pom parent-artifactid atlassian-scheduler Low Product file name atlassian-scheduler-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name scheduler Highest Product jar package name scheduler Low Product pom artifactid atlassian-scheduler-core Highest Product pom groupid com.atlassian.scheduler Highest Product pom name Atlassian Scheduler - Core High Product pom parent-artifactid atlassian-scheduler Medium Version file version 3.0.0 High Version pom version 3.0.0 Highest
atlassian-secure-random-3.2.10.jarDescription:
Random generator service for producing cryptographically secure random data. File Path: /home/andrii/.m2/repository/com/atlassian/security/atlassian-secure-random/3.2.10/atlassian-secure-random-3.2.10.jarMD5: 0d573e8c730327ef9d67078a4c294e9eSHA1: 15364f167f32887ad9f8131c19c4cd4468625be4SHA256: e185cae3199daa31f5d7161611b58422a5852985c52b6fb0720f98f6d363491cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-secure-random High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name random Highest Vendor jar package name random Low Vendor jar package name security Highest Vendor jar package name security Low Vendor pom artifactid atlassian-secure-random Highest Vendor pom artifactid atlassian-secure-random Low Vendor pom groupid com.atlassian.security Highest Vendor pom name Atlassian Secure Random High Vendor pom parent-artifactid atlassian-security Low Product file name atlassian-secure-random High Product jar package name atlassian Highest Product jar package name random Highest Product jar package name random Low Product jar package name security Highest Product jar package name security Low Product pom artifactid atlassian-secure-random Highest Product pom groupid com.atlassian.security Highest Product pom name Atlassian Secure Random High Product pom parent-artifactid atlassian-security Medium Version file version 3.2.10 High Version pom version 3.2.10 Highest
atlassian-secure-utils-3.2.11.jarDescription:
A bunch of secure utilities. File Path: /home/andrii/.m2/repository/com/atlassian/security/atlassian-secure-utils/3.2.11/atlassian-secure-utils-3.2.11.jarMD5: 3869ab335eca8ae36e2f4269cc271c36SHA1: 9a7a1a16ecf020a435a54ba67e6a530b134042c4SHA256: d89f267c8ca87dcdc696556b87ede94df7a0b696f7a808218f1647eeee049818Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-secure-utils High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name security Highest Vendor jar package name security Low Vendor jar package name utils Highest Vendor jar package name utils Low Vendor pom artifactid atlassian-secure-utils Highest Vendor pom artifactid atlassian-secure-utils Low Vendor pom groupid com.atlassian.security Highest Vendor pom name Atlassian Secure Utils High Vendor pom parent-artifactid atlassian-security Low Product file name atlassian-secure-utils High Product jar package name atlassian Highest Product jar package name constanttimecomparison Low Product jar package name security Highest Product jar package name security Low Product jar package name utils Highest Product jar package name utils Low Product pom artifactid atlassian-secure-utils Highest Product pom groupid com.atlassian.security Highest Product pom name Atlassian Secure Utils High Product pom parent-artifactid atlassian-security Medium Version file version 3.2.11 High Version pom version 3.2.11 Highest
atlassian-secure-xml-3.2.14.jarDescription:
Utility methods to construct parsers suitable for XML from untrusted sources. File Path: /home/andrii/.m2/repository/com/atlassian/security/atlassian-secure-xml/3.2.14/atlassian-secure-xml-3.2.14.jarMD5: af9be6e00c2e3a43a38502811df42bffSHA1: dd19972f2606f6bbc8b22d1d74e572b943deec24SHA256: e6a238e8717cb97041c59cf8784091cf3e223a8c8b46273c84f513c30de04205Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-secure-xml High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name security Highest Vendor jar package name security Low Vendor jar package name xml Highest Vendor jar package name xml Low Vendor pom artifactid atlassian-secure-xml Highest Vendor pom artifactid atlassian-secure-xml Low Vendor pom groupid com.atlassian.security Highest Vendor pom name Atlassian Secure XML High Vendor pom parent-artifactid atlassian-security Low Product file name atlassian-secure-xml High Product jar package name atlassian Highest Product jar package name security Highest Product jar package name security Low Product jar package name xml Highest Product jar package name xml Low Product pom artifactid atlassian-secure-xml Highest Product pom groupid com.atlassian.security Highest Product pom name Atlassian Secure XML High Product pom parent-artifactid atlassian-security Medium Version file version 3.2.14 High Version pom version 3.2.14 Highest
atlassian-seraph-4.1.0.jarDescription:
Seraph is a Servlet security framework for use in Java EE web applications. File Path: /home/andrii/.m2/repository/com/atlassian/seraph/atlassian-seraph/4.1.0/atlassian-seraph-4.1.0.jarMD5: d0eefd13d46c3765a74094920a5def72SHA1: 392695177de5edf662fe83e4039e4dac98415fa1SHA256: c389abfc237893c1abb8509b1e1b367a8cc3df9cb40eacfce6b79deb80a311c0Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-seraph High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name seraph Highest Vendor jar package name seraph Low Vendor pom artifactid atlassian-seraph Highest Vendor pom artifactid atlassian-seraph Low Vendor pom groupid com.atlassian.seraph Highest Vendor pom name Atlassian Seraph High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-seraph High Product jar package name atlassian Highest Product jar package name seraph Highest Product jar package name seraph Low Product pom artifactid atlassian-seraph Highest Product pom groupid com.atlassian.seraph Highest Product pom name Atlassian Seraph High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 4.1.0 High Version pom parent-version 4.1.0 Low Version pom version 4.1.0 Highest
atlassian-spring-2.0.8.jarDescription:
Common Atlassian Spring Components File Path: /home/andrii/.m2/repository/com/atlassian/spring/atlassian-spring/2.0.8/atlassian-spring-2.0.8.jarMD5: 6b5d48e55158b8d14d2722e237c27df2SHA1: ea07f2757114efe2440c7797f3883ef95e0073baSHA256: 218be0f9f81be41d209733b9637f98b27208aa18583ddf8a6752b320f53630ecReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-spring High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name spring Highest Vendor jar package name spring Low Vendor pom artifactid atlassian-spring Highest Vendor pom artifactid atlassian-spring Low Vendor pom groupid com.atlassian.spring Highest Vendor pom name Atlassian Spring High Vendor pom parent-artifactid atlassian-spring-parent Low Product file name atlassian-spring High Product jar package name atlassian Highest Product jar package name spring Highest Product jar package name spring Low Product pom artifactid atlassian-spring Highest Product pom groupid com.atlassian.spring Highest Product pom name Atlassian Spring High Product pom parent-artifactid atlassian-spring-parent Medium Version file version 2.0.8 High Version pom version 2.0.8 Highest
atlassian-spring-hibernate2-2.0.8.jarDescription:
Common Atlassian Spring+Hibernate 2 Components File Path: /home/andrii/.m2/repository/com/atlassian/spring/atlassian-spring-hibernate2/2.0.8/atlassian-spring-hibernate2-2.0.8.jarMD5: 013bdbbf5ed9d7343b518d8298a4d8f3SHA1: aba40d266af1c4aa3ae185a88ba971d1f6d6cfafSHA256: bd46f0ec2c7a6e1473ffabfd7a255a66c5409bee288c467530bf36f5645d974aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-spring-hibernate2 High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name filter Low Vendor jar package name spring Highest Vendor jar package name spring Low Vendor pom artifactid atlassian-spring-hibernate2 Highest Vendor pom artifactid atlassian-spring-hibernate2 Low Vendor pom groupid com.atlassian.spring Highest Vendor pom name Atlassian Spring Hibernate 2 High Vendor pom parent-artifactid atlassian-spring-parent Low Product file name atlassian-spring-hibernate2 High Product jar package name atlassian Highest Product jar package name filter Low Product jar package name flushingspringsessioninviewfilter Low Product jar package name spring Highest Product jar package name spring Low Product pom artifactid atlassian-spring-hibernate2 Highest Product pom groupid com.atlassian.spring Highest Product pom name Atlassian Spring Hibernate 2 High Product pom parent-artifactid atlassian-spring-parent Medium Version file version 2.0.8 High Version pom version 2.0.8 Highest
atlassian-spring-interceptor-adapter-spi-1.1.jarDescription:
Host application-side library of the Spring Interceptor Adapter plugin. File Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-spring-interceptor-adapter-spi/1.1/atlassian-spring-interceptor-adapter-spi-1.1.jarMD5: 3867eba2f428678dc6133c80cf1f7a3aSHA1: 40835db7e396d4be3bf9c5a1ef48354bdf43bd94SHA256: c9999ed6be9a6d6e4db1f110d0717e198b81dfefab8dfca6f71f55bf6a4f4e3bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-spring-interceptor-adapter-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name interceptor Highest Vendor jar package name plugins Highest Vendor jar package name plugins Low Vendor jar package name spring Highest Vendor jar package name spring Low Vendor pom artifactid atlassian-spring-interceptor-adapter-spi Highest Vendor pom artifactid atlassian-spring-interceptor-adapter-spi Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Spring Interceptor Adapter SPI High Vendor pom parent-artifactid atlassian-spring-interceptor-adapter Low Vendor pom url http://maven.apache.org Highest Product file name atlassian-spring-interceptor-adapter-spi High Product jar package name atlassian Highest Product jar package name interceptor Highest Product jar package name interceptor Low Product jar package name plugins Highest Product jar package name plugins Low Product jar package name spring Highest Product jar package name spring Low Product pom artifactid atlassian-spring-interceptor-adapter-spi Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Spring Interceptor Adapter SPI High Product pom parent-artifactid atlassian-spring-interceptor-adapter Medium Product pom url http://maven.apache.org Medium Version file version 1.1 High Version pom version 1.1 Highest
atlassian-spring-scanner-annotation-2.1.7.jarDescription:
A set of tools and libraries to ease in creating no-transform Atlassian plugins using java annotations License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/atlassian/plugin/atlassian-spring-scanner-annotation/2.1.7/atlassian-spring-scanner-annotation-2.1.7.jar
MD5: 68364763f9db56b95df35601ff8434d2
SHA1: fa11c70a59763069a95e885038c8aee56d495ba8
SHA256: 2d3d91607229e03565a2a58fdd4a5a2c9b500e8cd5ccf2cf967ee7f100ab5d26
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-spring-scanner-annotation High Vendor jar package name atlassian Highest Vendor jar package name plugin Highest Vendor jar package name scanner Highest Vendor jar package name spring Highest Vendor Manifest atlassian-build-date 2018-04-18T06:07:44+0000 Low Vendor Manifest atlassian-plugin-key com.atlassian.plugin.atlassian-spring-scanner-annotation Low Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.plugin.atlassian-spring-scanner-annotation Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid atlassian-spring-scanner-annotation Highest Vendor pom artifactid atlassian-spring-scanner-annotation Low Vendor pom groupid com.atlassian.plugin Highest Vendor pom name Atlassian Spring Scanner Annotations High Vendor pom parent-artifactid atlassian-spring-scanner-parent Low Product file name atlassian-spring-scanner-annotation High Product jar package name atlassian Highest Product jar package name plugin Highest Product jar package name scanner Highest Product jar package name spring Highest Product Manifest atlassian-build-date 2018-04-18T06:07:44+0000 Low Product Manifest atlassian-plugin-key com.atlassian.plugin.atlassian-spring-scanner-annotation Low Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Atlassian Spring Scanner Annotations Medium Product Manifest bundle-symbolicname com.atlassian.plugin.atlassian-spring-scanner-annotation Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid atlassian-spring-scanner-annotation Highest Product pom groupid com.atlassian.plugin Highest Product pom name Atlassian Spring Scanner Annotations High Product pom parent-artifactid atlassian-spring-scanner-parent Medium Version file version 2.1.7 High Version Manifest Bundle-Version 2.1.7 High Version pom version 2.1.7 Highest
atlassian-template-renderer-api-3.0.0.jarDescription:
API and plugins for easily rendering content from different template engines. License:
http://opensource.org/licenses/BSD-3-Clause File Path: /home/andrii/.m2/repository/com/atlassian/templaterenderer/atlassian-template-renderer-api/3.0.0/atlassian-template-renderer-api-3.0.0.jar
MD5: 644b3b2d6ee96fa002cd43ed17c15e79
SHA1: a4853f74bbb296912de29c0b9c3269e154a98abb
SHA256: c499ab8b445a6eaa17482ad206612a4f79c43007bce4915c5b3efb0a77ad5d58
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-template-renderer-api High Vendor jar package name atlassian Highest Vendor jar package name templaterenderer Highest Vendor Manifest atlassian-build-date 2015-11-13T04:57:09+0000 Low Vendor Manifest bundle-docurl http://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.templaterenderer.atlassian-template-renderer-api Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest spring-context * Low Vendor pom artifactid atlassian-template-renderer-api Highest Vendor pom artifactid atlassian-template-renderer-api Low Vendor pom groupid com.atlassian.templaterenderer Highest Vendor pom name Atlassian Template Renderer API High Vendor pom parent-artifactid atlassian-template-renderer Low Product file name atlassian-template-renderer-api High Product jar package name atlassian Highest Product jar package name plugins Highest Product jar package name templaterenderer Highest Product Manifest atlassian-build-date 2015-11-13T04:57:09+0000 Low Product Manifest bundle-docurl http://www.atlassian.com/ Low Product Manifest Bundle-Name Atlassian Template Renderer API Medium Product Manifest bundle-symbolicname com.atlassian.templaterenderer.atlassian-template-renderer-api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest spring-context * Low Product pom artifactid atlassian-template-renderer-api Highest Product pom groupid com.atlassian.templaterenderer Highest Product pom name Atlassian Template Renderer API High Product pom parent-artifactid atlassian-template-renderer Medium Version file version 3.0.0 High Version Manifest Bundle-Version 3.0.0 High Version pom version 3.0.0 Highest
atlassian-tenancy-api-3.0.1.jarDescription:
API for interacting with the tenancy lifecycle of an application File Path: /home/andrii/.m2/repository/com/atlassian/tenancy/atlassian-tenancy-api/3.0.1/atlassian-tenancy-api-3.0.1.jarMD5: 7899d266c6bb6f2a7def14540e3e38a1SHA1: 72b6f494e1343b79bd0332c6390e3e332e2d2a34SHA256: e3d0ed9ab54b41c77cc6b40c51c1fcd76d0379655ee4e41f8ee39c0a2157e693Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-tenancy-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name tenancy Highest Vendor jar package name tenancy Low Vendor pom artifactid atlassian-tenancy-api Highest Vendor pom artifactid atlassian-tenancy-api Low Vendor pom groupid com.atlassian.tenancy Highest Vendor pom name Atlassian Tenancy API High Vendor pom parent-artifactid atlassian-tenancy Low Product file name atlassian-tenancy-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name tenancy Highest Product jar package name tenancy Low Product pom artifactid atlassian-tenancy-api Highest Product pom groupid com.atlassian.tenancy Highest Product pom name Atlassian Tenancy API High Product pom parent-artifactid atlassian-tenancy Medium Version file version 3.0.1 High Version pom version 3.0.1 Highest
atlassian-threadlocal-1.4.jarDescription:
A library of code dealing with that most wonderful of programminng idioms - ThreadLocal File Path: /home/andrii/.m2/repository/com/atlassian/threadlocal/atlassian-threadlocal/1.4/atlassian-threadlocal-1.4.jarMD5: bb65e84df52456707f7da83ff0532d29SHA1: ebf872b864a2fc74bf77c5920b8f7b19a54794b0SHA256: 4b8b9a9802316f644173e993d5deb15fb3d8b5778371b387cd10ff60d2e3bc0dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-threadlocal High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name threadlocal Highest Vendor jar package name threadlocal Low Vendor pom artifactid atlassian-threadlocal Highest Vendor pom artifactid atlassian-threadlocal Low Vendor pom groupid com.atlassian.threadlocal Highest Vendor pom name atlassian-threadlocal High Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-threadlocal High Product jar package name atlassian Highest Product jar package name threadlocal Highest Product jar package name threadlocal Low Product pom artifactid atlassian-threadlocal Highest Product pom groupid com.atlassian.threadlocal Highest Product pom name atlassian-threadlocal High Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest
atlassian-trackback-0.10.jarDescription:
A very simple component to send and receive trackback pings. File Path: /home/andrii/.m2/repository/com/atlassian/trackback/atlassian-trackback/0.10/atlassian-trackback-0.10.jarMD5: 40f6f47cd223be5e392621ef2a05f4beSHA1: 905e31e7719b7e5df1216404f059c3c87b20c6c1SHA256: d839cf1fd3c2c160e10c945dc93ff4caef5791dca3b468ae106c1b7f374db3baReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-trackback High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name trackback Highest Vendor jar package name trackback Low Vendor pom artifactid atlassian-trackback Highest Vendor pom artifactid atlassian-trackback Low Vendor pom groupid com.atlassian.trackback Highest Vendor pom name Atlassian Trackback High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name atlassian-trackback High Product jar package name atlassian Highest Product jar package name trackback Highest Product jar package name trackback Low Product pom artifactid atlassian-trackback Highest Product pom groupid com.atlassian.trackback Highest Product pom name Atlassian Trackback High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 0.10 High Version pom parent-version 0.10 Low Version pom version 0.10 Highest
atlassian-trusted-apps-core-5.0.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/security/auth/trustedapps/atlassian-trusted-apps-core/5.0.1/atlassian-trusted-apps-core-5.0.1.jarMD5: 5f1fdd2be7a4c6ec651890b8593fb90aSHA1: 40880cdce9c42e80f1994231a06a5055fa3c03aeSHA256: 097e82f525af7576a5b6225a40c3ce5294410bee03f57c5f6776895bcbc8598aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-trusted-apps-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name auth Highest Vendor jar package name auth Low Vendor jar package name security Highest Vendor jar package name security Low Vendor jar package name trustedapps Highest Vendor pom artifactid atlassian-trusted-apps-core Highest Vendor pom artifactid atlassian-trusted-apps-core Low Vendor pom groupid com.atlassian.security.auth.trustedapps Highest Vendor pom name Atlassian Trusted Apps Core High Vendor pom parent-artifactid atlassian-trusted-apps Low Product file name atlassian-trusted-apps-core High Product jar package name atlassian Highest Product jar package name auth Highest Product jar package name auth Low Product jar package name security Highest Product jar package name security Low Product jar package name trustedapps Highest Product jar package name trustedapps Low Product pom artifactid atlassian-trusted-apps-core Highest Product pom groupid com.atlassian.security.auth.trustedapps Highest Product pom name Atlassian Trusted Apps Core High Product pom parent-artifactid atlassian-trusted-apps Medium Version file version 5.0.1 High Version pom version 5.0.1 Highest
atlassian-trusted-apps-seraph-integration-5.0.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/security/auth/trustedapps/atlassian-trusted-apps-seraph-integration/5.0.1/atlassian-trusted-apps-seraph-integration-5.0.1.jarMD5: b8afbcee21da74bd7550e0505a20dacfSHA1: 7939591daec0ecac362c42285165b8cf4e751b7bSHA256: 164beb557d03de30dad44a3ba43790991c25fa5686e0ba15c60062805f7cec07Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-trusted-apps-seraph-integration High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name auth Highest Vendor jar package name auth Low Vendor jar package name security Highest Vendor jar package name security Low Vendor jar package name seraph Highest Vendor jar package name trustedapps Highest Vendor pom artifactid atlassian-trusted-apps-seraph-integration Highest Vendor pom artifactid atlassian-trusted-apps-seraph-integration Low Vendor pom groupid com.atlassian.security.auth.trustedapps Highest Vendor pom name Atlassian Trusted Apps - Seraph Integration High Vendor pom parent-artifactid atlassian-trusted-apps Low Product file name atlassian-trusted-apps-seraph-integration High Product jar package name atlassian Highest Product jar package name auth Highest Product jar package name auth Low Product jar package name security Highest Product jar package name security Low Product jar package name seraph Highest Product jar package name trustedapps Highest Product jar package name trustedapps Low Product pom artifactid atlassian-trusted-apps-seraph-integration Highest Product pom groupid com.atlassian.security.auth.trustedapps Highest Product pom name Atlassian Trusted Apps - Seraph Integration High Product pom parent-artifactid atlassian-trusted-apps Medium Version file version 5.0.1 High Version pom version 5.0.1 Highest
atlassian-user-3.0.jarDescription:
Atlassian-user is an internal project, modelling users and groups for all Atlassian applications. File Path: /home/andrii/.m2/repository/com/atlassian/user/atlassian-user/3.0/atlassian-user-3.0.jarMD5: 42dcca5ff9b7171daa87bf1f2116ea09SHA1: 38697a7d52d17953097c41304e770b5ac15580deSHA256: 43dfeba0757f12cb6da929ac96b1e4c976b67476eef721a1353e5b16d45fa41bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-user High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name impl Low Vendor jar package name user Highest Vendor jar package name user Low Vendor pom artifactid atlassian-user Highest Vendor pom artifactid atlassian-user Low Vendor pom groupid com.atlassian.user Highest Vendor pom name Atlassian User High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-user High Product jar package name atlassian Highest Product jar package name impl Low Product jar package name user Highest Product jar package name user Low Product pom artifactid atlassian-user Highest Product pom groupid com.atlassian.user Highest Product pom name Atlassian User High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 3.0 High Version pom parent-version 3.0 Low Version pom version 3.0 Highest
atlassian-util-concurrent-3.0.0.jarDescription:
This project contains utility classes that are used by
various products and projects inside Atlassian and may have some
utility to the world at large. License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/atlassian/util/concurrent/atlassian-util-concurrent/3.0.0/atlassian-util-concurrent-3.0.0.jar
MD5: 5ce073b4e866f9afe741b466b32c62f6
SHA1: 26480e5153e6574157a114844275c37fc9fd38e1
SHA256: 45566c43c61c80bb75b5a203018f6f348efaef4c2b4c6fb3e4ba31bd099cb3f7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-util-concurrent High Vendor jar package name atlassian Highest Vendor jar package name concurrent Highest Vendor jar package name util Highest Vendor Manifest bundle-docurl http://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.util.concurrent.atlassian-util-concurrent Medium Vendor pom artifactid atlassian-util-concurrent Highest Vendor pom artifactid atlassian-util-concurrent Low Vendor pom developer email jed@atlassian.com Low Vendor pom developer name Jed Wesley-Smith Medium Vendor pom groupid com.atlassian.util.concurrent Highest Vendor pom name Atlassian Concurrency Utilities High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://labs.atlassian.com/wiki/display/CONCURRENT/Home Highest Product file name atlassian-util-concurrent High Product jar package name atlassian Highest Product jar package name concurrent Highest Product jar package name util Highest Product Manifest bundle-docurl http://www.atlassian.com/ Low Product Manifest Bundle-Name Atlassian Concurrency Utilities Medium Product Manifest bundle-symbolicname com.atlassian.util.concurrent.atlassian-util-concurrent Medium Product pom artifactid atlassian-util-concurrent Highest Product pom developer email jed@atlassian.com Low Product pom developer name Jed Wesley-Smith Low Product pom groupid com.atlassian.util.concurrent Highest Product pom name Atlassian Concurrency Utilities High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://labs.atlassian.com/wiki/display/CONCURRENT/Home Medium Version file version 3.0.0 High Version Manifest Bundle-Version 3.0.0 High Version pom parent-version 3.0.0 Low Version pom version 3.0.0 Highest
atlassian-util-concurrent-4.0.1.jarDescription:
This project contains utility classes that are used by
various products and projects inside Atlassian and may have some
utility to the world at large. License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/io/atlassian/util/concurrent/atlassian-util-concurrent/4.0.1/atlassian-util-concurrent-4.0.1.jar
MD5: 64d75ee6a8eb440831c1d4d96351bfd1
SHA1: 34fdb324a609ff5e008e707de7c0741aeaa4b981
SHA256: 8b89b72fd29b646ac2bb86e40c2353a05741d56bad6d3a28d27df44e7d351e74
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-util-concurrent High Vendor jar package name atlassian Highest Vendor jar package name concurrent Highest Vendor jar package name io Highest Vendor jar package name util Highest Vendor Manifest bundle-docurl http://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname io.atlassian.util.concurrent.atlassian-util-concurrent Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid atlassian-util-concurrent Highest Vendor pom artifactid atlassian-util-concurrent Low Vendor pom developer email jed@atlassian.com Low Vendor pom developer name Jed Wesley-Smith Medium Vendor pom groupid io.atlassian.util.concurrent Highest Vendor pom name Atlassian Concurrency Utilities High Vendor pom parent-artifactid central-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://labs.atlassian.com/wiki/display/CONCURRENT/Home Highest Product file name atlassian-util-concurrent High Product jar package name atlassian Highest Product jar package name concurrent Highest Product jar package name io Highest Product jar package name util Highest Product Manifest bundle-docurl http://www.atlassian.com/ Low Product Manifest Bundle-Name Atlassian Concurrency Utilities Medium Product Manifest bundle-symbolicname io.atlassian.util.concurrent.atlassian-util-concurrent Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid atlassian-util-concurrent Highest Product pom developer email jed@atlassian.com Low Product pom developer name Jed Wesley-Smith Low Product pom groupid io.atlassian.util.concurrent Highest Product pom name Atlassian Concurrency Utilities High Product pom parent-artifactid central-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://labs.atlassian.com/wiki/display/CONCURRENT/Home Medium Version file version 4.0.1 High Version Manifest Bundle-Version 4.0.1 High Version pom parent-version 4.0.1 Low Version pom version 4.0.1 Highest
atlassian-vcache-api-1.12.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/vcache/atlassian-vcache-api/1.12.2/atlassian-vcache-api-1.12.2.jarMD5: 7fc89df8d04e2b73bd7f5df3aa0051a6SHA1: f04c72359ada400ef27141e6d5225485e4913bb9SHA256: c8ff10ec84e64813fd6ee4a55b66e47a2a065cca921117c313e97f3584b19662Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-vcache-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name vcache Highest Vendor jar package name vcache Low Vendor pom artifactid atlassian-vcache-api Highest Vendor pom artifactid atlassian-vcache-api Low Vendor pom groupid com.atlassian.vcache Highest Vendor pom name Atlassian VCache - API High Vendor pom parent-artifactid atlassian-vcache Low Product file name atlassian-vcache-api High Product jar package name atlassian Highest Product jar package name vcache Highest Product jar package name vcache Low Product pom artifactid atlassian-vcache-api Highest Product pom groupid com.atlassian.vcache Highest Product pom name Atlassian VCache - API High Product pom parent-artifactid atlassian-vcache Medium Version file version 1.12.2 High Version pom version 1.12.2 Highest
atlassian-vcache-internal-api-1.12.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/vcache/atlassian-vcache-internal-api/1.12.2/atlassian-vcache-internal-api-1.12.2.jarMD5: 0716c95b9301f3d4d41d07e04d3ec416SHA1: e28f69a9a1cddf330be147af81f33a3a9f003775SHA256: b7797ec715429f83e9c1f453826ed3cf69c6394090b72d49f18d20e26c203486Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-vcache-internal-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name internal Highest Vendor jar package name internal Low Vendor jar package name vcache Highest Vendor jar package name vcache Low Vendor pom artifactid atlassian-vcache-internal-api Highest Vendor pom artifactid atlassian-vcache-internal-api Low Vendor pom groupid com.atlassian.vcache Highest Vendor pom name Atlassian VCache - Internal API High Vendor pom parent-artifactid atlassian-vcache Low Product file name atlassian-vcache-internal-api High Product jar package name atlassian Highest Product jar package name internal Highest Product jar package name internal Low Product jar package name vcache Highest Product jar package name vcache Low Product pom artifactid atlassian-vcache-internal-api Highest Product pom groupid com.atlassian.vcache Highest Product pom name Atlassian VCache - Internal API High Product pom parent-artifactid atlassian-vcache Medium Version file version 1.12.2 High Version pom version 1.12.2 Highest
atlassian-vcache-internal-core-1.12.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/vcache/atlassian-vcache-internal-core/1.12.2/atlassian-vcache-internal-core-1.12.2.jarMD5: 9512d9bd79ed6969feffd0ede654343aSHA1: a2e5a36988a6e0a2f0ddc481e2dcb605b80e7ad0SHA256: d264872ec08934ba2c467d830fb0e3c510c5e26cb6ba78045cc1e127a179ff29Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-vcache-internal-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name internal Highest Vendor jar package name internal Low Vendor jar package name vcache Highest Vendor jar package name vcache Low Vendor pom artifactid atlassian-vcache-internal-core Highest Vendor pom artifactid atlassian-vcache-internal-core Low Vendor pom groupid com.atlassian.vcache Highest Vendor pom name Atlassian VCache - Core Impl High Vendor pom parent-artifactid atlassian-vcache Low Product file name atlassian-vcache-internal-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name internal Highest Product jar package name internal Low Product jar package name vcache Highest Product jar package name vcache Low Product pom artifactid atlassian-vcache-internal-core Highest Product pom groupid com.atlassian.vcache Highest Product pom name Atlassian VCache - Core Impl High Product pom parent-artifactid atlassian-vcache Medium Version file version 1.12.2 High Version pom version 1.12.2 Highest
atlassian-vcache-internal-legacy-1.12.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/vcache/atlassian-vcache-internal-legacy/1.12.2/atlassian-vcache-internal-legacy-1.12.2.jarMD5: ac5511d053356b5592145e017a78940dSHA1: 3df39eeeba320dc81d98d240b07f9cd7e1977f3aSHA256: 683fb4f65c1ef7da5a33d6e1a4eb3586eaccedb5c34ed2c90ef2be2af29bca31Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-vcache-internal-legacy High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name internal Highest Vendor jar package name internal Low Vendor jar package name legacy Highest Vendor jar package name vcache Highest Vendor jar package name vcache Low Vendor pom artifactid atlassian-vcache-internal-legacy Highest Vendor pom artifactid atlassian-vcache-internal-legacy Low Vendor pom groupid com.atlassian.vcache Highest Vendor pom name Atlassian VCache - Atlassian Cache Impl High Vendor pom parent-artifactid atlassian-vcache Low Product file name atlassian-vcache-internal-legacy High Product jar package name atlassian Highest Product jar package name internal Highest Product jar package name internal Low Product jar package name legacy Highest Product jar package name legacy Low Product jar package name vcache Highest Product jar package name vcache Low Product pom artifactid atlassian-vcache-internal-legacy Highest Product pom groupid com.atlassian.vcache Highest Product pom name Atlassian VCache - Atlassian Cache Impl High Product pom parent-artifactid atlassian-vcache Medium Version file version 1.12.2 High Version pom version 1.12.2 Highest
atlassian-velocity-1.3.jarDescription:
Atlassian Velocity File Path: /home/andrii/.m2/repository/com/atlassian/velocity/atlassian-velocity/1.3/atlassian-velocity-1.3.jarMD5: 481f196dd01b472f0e38e1e4d08779b0SHA1: b51cf1ab3cadc4e2e1bc46957b2eef1c501e3ab7SHA256: 45c43615f9facef594160db07920e54f7b331fe973b3f7de3d4e841b9f621668Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-velocity High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name velocity Highest Vendor jar package name velocity Low Vendor pom artifactid atlassian-velocity Highest Vendor pom artifactid atlassian-velocity Low Vendor pom groupid com.atlassian.velocity Highest Vendor pom name Atlassian Velocity High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Vendor pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Highest Product file name atlassian-velocity High Product jar package name atlassian Highest Product jar package name velocity Highest Product jar package name velocity Low Product pom artifactid atlassian-velocity Highest Product pom groupid com.atlassian.velocity Highest Product pom name Atlassian Velocity High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Product pom url https://docs.atlassian.com/${project.artifactId}/${project.version} Medium Version file version 1.3 High Version pom parent-version 1.3 Low Version pom version 1.3 Highest
atlassian-webhooks-api-6.2.0.jarDescription:
API for Atlassian Webhooks File Path: /home/andrii/.m2/repository/com/atlassian/webhooks/atlassian-webhooks-api/6.2.0/atlassian-webhooks-api-6.2.0.jarMD5: a277f2e18b8386cb9285b22e11db67d1SHA1: 2880369200c2f04c15872f1f81b059e4b0617369SHA256: 2330bf87c615bc7c786a502cccf1e29f6a65a23ab806dc364764f9c5f58d669dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-webhooks-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name webhooks Highest Vendor jar package name webhooks Low Vendor pom artifactid atlassian-webhooks-api Highest Vendor pom artifactid atlassian-webhooks-api Low Vendor pom groupid com.atlassian.webhooks Highest Vendor pom name Atlassian Webhooks API High Vendor pom parent-artifactid atlassian-webhooks-parent Low Product file name atlassian-webhooks-api High Product jar package name atlassian Highest Product jar package name webhooks Highest Product jar package name webhooks Low Product pom artifactid atlassian-webhooks-api Highest Product pom groupid com.atlassian.webhooks Highest Product pom name Atlassian Webhooks API High Product pom parent-artifactid atlassian-webhooks-parent Medium Version file version 6.2.0 High Version pom version 6.2.0 Highest
atlassian-webhooks-spi-6.2.0.jarDescription:
The SPI for Atlassian Webhooks that host applications are expected to implement File Path: /home/andrii/.m2/repository/com/atlassian/webhooks/atlassian-webhooks-spi/6.2.0/atlassian-webhooks-spi-6.2.0.jarMD5: 6d597e610681cbdd9be7871ec83ed1c9SHA1: dc8035458bb166533a11f680df354e85d17cf0c2SHA256: 7d2b997dea99afe4b692b8c4338a14db9d51a3a87545bb9bff5a6e73e8575727Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-webhooks-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name webhooks Highest Vendor jar package name webhooks Low Vendor pom artifactid atlassian-webhooks-spi Highest Vendor pom artifactid atlassian-webhooks-spi Low Vendor pom groupid com.atlassian.webhooks Highest Vendor pom name Atlassian Webhooks SPI High Vendor pom parent-artifactid atlassian-webhooks-parent Low Product file name atlassian-webhooks-spi High Product jar package name atlassian Highest Product jar package name webhooks Highest Product jar package name webhooks Low Product pom artifactid atlassian-webhooks-spi Highest Product pom groupid com.atlassian.webhooks Highest Product pom name Atlassian Webhooks SPI High Product pom parent-artifactid atlassian-webhooks-parent Medium Version file version 6.2.0 High Version pom version 6.2.0 Highest
atlassian-whitelist-api-plugin-5.0.5.jarDescription:
API for Whitelist publishers. License:
https://www.atlassian.com/legal/customer-agreement File Path: /home/andrii/.m2/repository/com/atlassian/plugins/atlassian-whitelist-api-plugin/5.0.5/atlassian-whitelist-api-plugin-5.0.5.jar
MD5: 219b1d18ce390d6465c9d95ae608ae9f
SHA1: 777bd41b4636d875091ef5f206f80a674e73fb0b
SHA256: e422562be9298fba3a8282d26f39ee11f6d75ef534576fee0016c8cfc5eb64e7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-whitelist-api-plugin High Vendor jar package name atlassian Highest Vendor jar package name plugins Highest Vendor jar package name whitelist Highest Vendor Manifest atlassian-build-date 2021-02-19T00:52:52+0000 Low Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.plugins.atlassian-whitelist-api-plugin Medium Vendor Manifest spring-context * Low Vendor pom artifactid atlassian-whitelist-api-plugin Highest Vendor pom artifactid atlassian-whitelist-api-plugin Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Whitelist API Plugin High Vendor pom parent-artifactid atlassian-whitelist-parent Low Product file name atlassian-whitelist-api-plugin High Product jar package name atlassian Highest Product jar package name plugins Highest Product jar package name whitelist Highest Product Manifest atlassian-build-date 2021-02-19T00:52:52+0000 Low Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Atlassian Whitelist API Plugin Medium Product Manifest bundle-symbolicname com.atlassian.plugins.atlassian-whitelist-api-plugin Medium Product Manifest spring-context * Low Product pom artifactid atlassian-whitelist-api-plugin Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Whitelist API Plugin High Product pom parent-artifactid atlassian-whitelist-parent Medium Version file version 5.0.5 High Version Manifest Bundle-Version 5.0.5 High Version pom version 5.0.5 Highest
atlassian-xwork-10-2.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/xwork/atlassian-xwork-10/2.1.0/atlassian-xwork-10-2.1.0.jarMD5: a97b4bc30807131cbd962448f75779e7SHA1: 4c968fa8fd4fbc6d97f8b0d6e5c8bbfd5f5f09d2SHA256: a90d725178adc4b05eb68a892d6dccc7c5532b3704c557d283a1cd4c9081e2fcReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-xwork-10 High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name interceptors Low Vendor jar package name xwork10 Low Vendor pom artifactid atlassian-xwork-10 Highest Vendor pom artifactid atlassian-xwork-10 Low Vendor pom groupid com.atlassian.xwork Highest Vendor pom name Atlassian XWork 1.0.x Implementation High Vendor pom parent-artifactid atlassian-xwork Low Product file name atlassian-xwork-10 High Product jar package name atlassian Highest Product jar package name interceptors Low Product jar package name xwork10 Low Product pom artifactid atlassian-xwork-10 Highest Product pom groupid com.atlassian.xwork Highest Product pom name Atlassian XWork 1.0.x Implementation High Product pom parent-artifactid atlassian-xwork Medium Version file version 2.1.0 High Version pom version 2.1.0 Highest
atlassian-xwork-core-2.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/xwork/atlassian-xwork-core/2.1.0/atlassian-xwork-core-2.1.0.jarMD5: 6d62b718d3db32b800e41c3724886620SHA1: 09a53ffc09a042eeaf33645fb5ba96fdf5f07aabSHA256: ccb8853745e33d375704781ba7e31b04cb8652d2c6e493df47f4b749d259079eReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name atlassian-xwork-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name xwork Highest Vendor jar package name xwork Low Vendor pom artifactid atlassian-xwork-core Highest Vendor pom artifactid atlassian-xwork-core Low Vendor pom groupid com.atlassian.xwork Highest Vendor pom name Atlassian XWork Core High Vendor pom parent-artifactid atlassian-xwork Low Product file name atlassian-xwork-core High Product jar package name atlassian Highest Product jar package name xwork Highest Product jar package name xwork Low Product pom artifactid atlassian-xwork-core Highest Product pom groupid com.atlassian.xwork Highest Product pom name Atlassian XWork Core High Product pom parent-artifactid atlassian-xwork Medium Version file version 2.1.0 High Version pom version 2.1.0 Highest
avatar-plugin-api-1.3.5.jarDescription:
Defines the cross-product Avatar API. File Path: /home/andrii/.m2/repository/com/atlassian/plugins/avatar-plugin-api/1.3.5/avatar-plugin-api-1.3.5.jarMD5: 219776861137378c01903e06596b240dSHA1: 7e7a90ad8324f051a79b01472517ddf4f889d296SHA256: 026d210d98100d62e314ec1c7ac90b5757de4f315148a1602d00d2626d34966aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name avatar-plugin-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name avatar Highest Vendor jar package name avatar Low Vendor jar package name plugins Highest Vendor jar package name plugins Low Vendor pom artifactid avatar-plugin-api Highest Vendor pom artifactid avatar-plugin-api Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Plugins - Avatar Plugin API High Vendor pom parent-artifactid avatar-plugin-parent Low Product file name avatar-plugin-api High Product jar package name atlassian Highest Product jar package name avatar Highest Product jar package name avatar Low Product jar package name plugins Highest Product jar package name plugins Low Product pom artifactid avatar-plugin-api Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Plugins - Avatar Plugin API High Product pom parent-artifactid avatar-plugin-parent Medium Version file version 1.3.5 High Version pom version 1.3.5 Highest
avatar.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/avatar.jsMD5: 9093401e0c2f1f8413e9b211d30eed89SHA1: edbbe5b11ee2e9ef21071a4745f79d3e568f6130SHA256: 08e3bdb446439fd034178b9a337db491e0cdb00443f5a7279b2ad0c25e157698Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
base-a385f246.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/base-a385f246.jsMD5: df913f17c56e213f4c451b5e8457ad45SHA1: 6ef493f1ffa29270160c04169b1762f139f17706SHA256: d0d82e9d06bdb12f469ae0328309418a3456f5e5aca5e59b9470f50d4d6191d9Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
batik-css-1.14.jarDescription:
Batik CSS engine File Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-css/1.14/batik-css-1.14.jarMD5: 7ddd4cfd4b3ab7576c3e1ae116fd8ff8SHA1: 3118d46f4879ec08c6c6471c7c0825652ed659eeSHA256: 968ba271cab6dfdd0458eb9ff42cc51e258d471499225b9063edbda61becbe17Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name batik-css High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name batik Highest Vendor jar package name batik Low Vendor jar package name css Highest Vendor jar package name css Low Vendor jar package name engine Highest Vendor pom artifactid batik-css Highest Vendor pom artifactid batik-css Low Vendor pom groupid org.apache.xmlgraphics Highest Vendor pom parent-artifactid batik Low Product file name batik-css High Product jar package name apache Highest Product jar package name batik Highest Product jar package name batik Low Product jar package name css Highest Product jar package name css Low Product jar package name engine Highest Product jar package name engine Low Product pom artifactid batik-css Highest Product pom groupid org.apache.xmlgraphics Highest Product pom parent-artifactid batik Medium Version file version 1.14 High Version pom version 1.14 Highest
Related Dependencies batik-anim-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-anim/1.14/batik-anim-1.14.jar MD5: b6b05576b5c5d7ff990b0763360af9db SHA1: 135d69b4deb4569237e9ee9c508a13ba407a77bb SHA256: a1953099e04c202ee32d8e13912326d15cc488538051c691e897b0b7d2523b40 pkg:maven/org.apache.xmlgraphics/batik-anim@1.14 batik-awt-util-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-awt-util/1.14/batik-awt-util-1.14.jar MD5: 1b0d578658f9880e61e002764b6ca564 SHA1: 8f30e4cfc76626e7786ce0991df351cd91cddec6 SHA256: 9cbaeae98dacad502aa2b08f206a5c04f14703afe9d99d905f0f7f8b733db5e7 pkg:maven/org.apache.xmlgraphics/batik-awt-util@1.14 batik-bridge-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-bridge/1.14/batik-bridge-1.14.jar MD5: f10e8f93ce99da341da79c7c3a048f1c SHA1: 5833c8b8dc292081e0db6bbaee935e7e1391daaf SHA256: fc137699f14f9289732d4ff8214f0a14a7ea4f5ea7a6b24b745d9d6d943c259e pkg:maven/org.apache.xmlgraphics/batik-bridge@1.14 batik-codec-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-codec/1.14/batik-codec-1.14.jar MD5: c3807c087d1b5e7b10217ec55069ceb3 SHA1: f63ed1f18412cead069fa97b677fdbda43b6a1af SHA256: c6c0ea0f4ca00ca13d76f7ff0bf37042e5788af9f16cbe5892f40c91711359c4 pkg:maven/org.apache.xmlgraphics/batik-codec@1.14 batik-constants-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-constants/1.14/batik-constants-1.14.jar MD5: 7110a6bd56690a1730a1227ac5afec90 SHA1: 371acf696982f1c8e2689f5899b4e8453ccd74ff SHA256: 7882eb789257905413bcb0adcb1562dd50b8103cadef9534c33612bf51527990 pkg:maven/org.apache.xmlgraphics/batik-constants@1.14 batik-dom-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-dom/1.14/batik-dom-1.14.jar MD5: cea3009585fe1d8277d5db7aa2d88f29 SHA1: 066943d7b34766d0d270cce9c61fba4d769362af SHA256: 6b71b91514f2cbe9b9e46f9699803c1fe7434addf61388b07755d586e20c57de pkg:maven/org.apache.xmlgraphics/batik-dom@1.14 batik-ext-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-ext/1.14/batik-ext-1.14.jar MD5: 33cbf00dbc546bce6af0c6aec42e323d SHA1: 79fe8cc37676e7af4c85f2f7fd51e17f46bc75ed SHA256: 1f74fc638058c5d05b6da7b207e895d1a04c19d64250ae9f52c059689e681a7a pkg:maven/org.apache.xmlgraphics/batik-ext@1.14 batik-gvt-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-gvt/1.14/batik-gvt-1.14.jar MD5: d255a28c398c884b6109a994def1c896 SHA1: 93aacfbe75655c2900c9fb069ffa059370366c78 SHA256: 5230e4339035867bbb9c82683a065fb2abe135779f57c43a70b7766395aeab38 pkg:maven/org.apache.xmlgraphics/batik-gvt@1.14 batik-parser-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-parser/1.14/batik-parser-1.14.jar MD5: a989caccb2ba9a0a76068d918702755f SHA1: 4ac928fd781673c0b6a181fabaa89f0ee3b32f28 SHA256: aca5e08b52e54af0a1acaf9c134082a0ed0b357b8eef74de369bdba054d1e1e2 pkg:maven/org.apache.xmlgraphics/batik-parser@1.14 batik-script-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-script/1.14/batik-script-1.14.jar MD5: c308755946eed44b925b2a1216086cfe SHA1: f39a410e0cb936d0538c4a7411e1ae45c0d0a10a SHA256: d3584655227b4f1b56beea081a5b0b1fa228aeb165f19895f10dfbae999bc4e4 pkg:maven/org.apache.xmlgraphics/batik-script@1.14 batik-shared-resources-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-shared-resources/1.14/batik-shared-resources-1.14.jar MD5: 2d89a3feed01c06eea83a5ad83c3f7f6 SHA1: 42e9d6345952575e8b2f4ee26108b2811c334305 SHA256: 987ceb566e2101418465bb3227ec60812b71e7c4b2c3e842d977efa732fa90f5 pkg:maven/org.apache.xmlgraphics/batik-shared-resources@1.14 batik-svg-dom-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-svg-dom/1.14/batik-svg-dom-1.14.jar MD5: 519daf3309fd47e064b1d2f5d04bc996 SHA1: 916c216454503413ed4fc76dbfac55b30bbcae2b SHA256: c6023eca4fe1c6c2616173d2308217713c76895b780167f19382db0e57eac412 pkg:maven/org.apache.xmlgraphics/batik-svg-dom@1.14 batik-svggen-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-svggen/1.14/batik-svggen-1.14.jar MD5: fc6896041901f36ec32149b01b93980b SHA1: cc2f028925cc156a2df665802a403b8fa16d90a8 SHA256: c2a7fba84eddc3815992a1f14f554feeccaabf9c1730867b28569dcbbbc272e2 pkg:maven/org.apache.xmlgraphics/batik-svggen@1.14 batik-transcoder-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-transcoder/1.14/batik-transcoder-1.14.jar MD5: f6be2631fb6ea5d04aa967e0e60ab780 SHA1: ad3a750a02e53cf9b66d67371f0ddf889f06c070 SHA256: c5f863137fbfe440911b376a0a3e605c9e1b196d1b4a83854007e303a95b9889 pkg:maven/org.apache.xmlgraphics/batik-transcoder@1.14 batik-util-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-util/1.14/batik-util-1.14.jar MD5: 42b3f763e59956a088b2d7764471158b SHA1: 7ca55c864e5ddd690ba07f44e3ba8e68e9048a02 SHA256: ad76103ecb3fcad91aac1cd0a34f6d46cd1e4224d0406a5d58b269a64f6c3788 pkg:maven/org.apache.xmlgraphics/batik-util@1.14 batik-xml-1.14.jarFile Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-xml/1.14/batik-xml-1.14.jar MD5: a22490025e3f9ccf43f2498879179e1e SHA1: b78b3e2f87579f02dcc342a147017cce8fc0ffc6 SHA256: 673a82f56185a023e5196a59eb16f8503071477af4a82bb58e7267bb3d4ff828 pkg:maven/org.apache.xmlgraphics/batik-xml@1.14 CVE-2022-40146 suppress
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2022-41704 suppress
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2022-42890 suppress
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users are recommended to upgrade to version 1.16. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2022-38398 suppress
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Batik 1.14. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2022-38648 suppress
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
batik-i18n-1.14.jarDescription:
Batik i18n library File Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/batik-i18n/1.14/batik-i18n-1.14.jarMD5: aa98b2f42450d4767d5345b4cf7c37a0SHA1: a4e7b0cda9132904f21b25ab29a0b73e1867e7fdSHA256: fb1ad02ccaa36f5a60c4115316e15ac071386f96445e5d89bdad0c7e45da9560Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name batik-i18n High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name batik Highest Vendor jar package name batik Low Vendor jar package name i18n Highest Vendor jar package name i18n Low Vendor pom artifactid batik-i18n Highest Vendor pom artifactid batik-i18n Low Vendor pom groupid org.apache.xmlgraphics Highest Vendor pom parent-artifactid batik Low Product file name batik-i18n High Product jar package name apache Highest Product jar package name batik Highest Product jar package name batik Low Product jar package name i18n Highest Product jar package name i18n Low Product pom artifactid batik-i18n Highest Product pom groupid org.apache.xmlgraphics Highest Product pom parent-artifactid batik Medium Version file version 1.14 High Version pom version 1.14 Highest
bcmail-jdk15on-1.68.jarDescription:
The Bouncy Castle Java S/MIME APIs for handling S/MIME protocols. This jar contains S/MIME APIs for JDK 1.5 and up. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. The JavaMail API and the Java activation framework will also be needed. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /home/andrii/.m2/repository/org/bouncycastle/bcmail-jdk15on/1.68/bcmail-jdk15on-1.68.jar
MD5: 612e03e1c69a53e7165b4765cf47815e
SHA1: e7bf3026b44293f2213f369d8c9051d2e6b828cf
SHA256: a5bc386101e85aa5dbe6a47963415f472674d5ee0b2229642b23c195e3da6820
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name bcmail-jdk15on High Vendor jar package name bouncycastle Highest Vendor jar package name mail Highest Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest application-name Bouncy Castle S/MIME API Medium Vendor Manifest automatic-module-name org.bouncycastle.mail Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname bcmail Medium Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor Manifest extension-name org.bouncycastle.bcmail Medium Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by 25.275-b01 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest trusted-library true Low Vendor pom artifactid bcmail-jdk15on Highest Vendor pom artifactid bcmail-jdk15on Low Vendor pom developer email feedback-crypto@bouncycastle.org Low Vendor pom developer id feedback-crypto Medium Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium Vendor pom groupid org.bouncycastle Highest Vendor pom name Bouncy Castle S/MIME API High Vendor pom url http://www.bouncycastle.org/java.html Highest Product file name bcmail-jdk15on High Product jar package name bouncycastle Highest Product jar package name mail Highest Product Manifest application-library-allowable-codebase * Low Product Manifest application-name Bouncy Castle S/MIME API Medium Product Manifest automatic-module-name org.bouncycastle.mail Medium Product Manifest Bundle-Name bcmail Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname bcmail Medium Product Manifest caller-allowable-codebase * Low Product Manifest codebase * Low Product Manifest extension-name org.bouncycastle.bcmail Medium Product Manifest multi-release true Low Product Manifest originally-created-by 25.275-b01 (Private Build) Low Product Manifest permissions all-permissions Low Product Manifest trusted-library true Low Product pom artifactid bcmail-jdk15on Highest Product pom developer email feedback-crypto@bouncycastle.org Low Product pom developer id feedback-crypto Low Product pom developer name The Legion of the Bouncy Castle Inc. Low Product pom groupid org.bouncycastle Highest Product pom name Bouncy Castle S/MIME API High Product pom url http://www.bouncycastle.org/java.html Medium Version file version 1.68 High Version Manifest Bundle-Version 1.68 High Version pom version 1.68 Highest
bcpg-jdk18on-1.71.jarDescription:
The Bouncy Castle Java API for handling the OpenPGP protocol. This jar contains the OpenPGP API for JDK 1.8 and up. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
Apache Software License, Version 1.1: https://www.apache.org/licenses/LICENSE-1.1 File Path: /home/andrii/.m2/repository/org/bouncycastle/bcpg-jdk18on/1.71/bcpg-jdk18on-1.71.jar
MD5: dbc4cb1dcb79a19a809e29f4be3f6eb7
SHA1: d42ad9fe1b89246bb4ca2a45c0646bf6f6066013
SHA256: 57f9ab76a8358abbea90ba1ef8e553b8ae3d07b2337078a4ca20b1cbd48b4ec5
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name bcpg-jdk18on High Vendor jar package name bcpg Highest Vendor jar package name bouncycastle Highest Vendor jar package name openpgp Highest Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest application-name Bouncy Castle OpenPGP API Medium Vendor Manifest automatic-module-name org.bouncycastle.pg Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname bcpg Medium Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor Manifest extension-name org.bouncycastle.bcpg Medium Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by 25.312-b07 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest trusted-library true Low Vendor pom artifactid bcpg-jdk18on Highest Vendor pom artifactid bcpg-jdk18on Low Vendor pom developer email feedback-crypto@bouncycastle.org Low Vendor pom developer id feedback-crypto Medium Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium Vendor pom groupid org.bouncycastle Highest Vendor pom name Bouncy Castle OpenPGP API High Vendor pom url https://www.bouncycastle.org/java.html Highest Product file name bcpg-jdk18on High Product jar package name bcpg Highest Product jar package name bouncycastle Highest Product jar package name openpgp Highest Product Manifest application-library-allowable-codebase * Low Product Manifest application-name Bouncy Castle OpenPGP API Medium Product Manifest automatic-module-name org.bouncycastle.pg Medium Product Manifest Bundle-Name bcpg Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname bcpg Medium Product Manifest caller-allowable-codebase * Low Product Manifest codebase * Low Product Manifest extension-name org.bouncycastle.bcpg Medium Product Manifest multi-release true Low Product Manifest originally-created-by 25.312-b07 (Private Build) Low Product Manifest permissions all-permissions Low Product Manifest trusted-library true Low Product pom artifactid bcpg-jdk18on Highest Product pom developer email feedback-crypto@bouncycastle.org Low Product pom developer id feedback-crypto Low Product pom developer name The Legion of the Bouncy Castle Inc. Low Product pom groupid org.bouncycastle Highest Product pom name Bouncy Castle OpenPGP API High Product pom url https://www.bouncycastle.org/java.html Medium Version file version 1.71 High Version Manifest Bundle-Version 1.71 High Version pom version 1.71 Highest
pkg:maven/org.bouncycastle/bcpg-jdk18on@1.71 (Confidence :High)cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:openpgp:openpgp:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress bcpkix-jdk15on-1.68.jarDescription:
The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 and up. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /home/andrii/.m2/repository/org/bouncycastle/bcpkix-jdk15on/1.68/bcpkix-jdk15on-1.68.jar
MD5: 37e058210e056a04d4521d8185fb0051
SHA1: 81da950604ff0b2652348cbd2b48fde46ced9867
SHA256: fb8d0f8f673ad6e16c604732093d7aa31b26ff4e0bd9cae1d7f99984c06b8a0f
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name bcpkix-jdk15on High Vendor jar package name bouncycastle Highest Vendor jar package name cmp Highest Vendor jar package name cms Highest Vendor jar package name crmf Highest Vendor jar package name eac Highest Vendor jar package name ocsp Highest Vendor jar package name pkcs Highest Vendor jar package name pkix Highest Vendor jar package name tsp Highest Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest application-name Bouncy Castle PKIX API Medium Vendor Manifest automatic-module-name org.bouncycastle.pkix Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname bcpkix Medium Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor Manifest extension-name org.bouncycastle.bcpkix Medium Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by 25.275-b01 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest trusted-library true Low Vendor pom artifactid bcpkix-jdk15on Highest Vendor pom artifactid bcpkix-jdk15on Low Vendor pom developer email feedback-crypto@bouncycastle.org Low Vendor pom developer id feedback-crypto Medium Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium Vendor pom groupid org.bouncycastle Highest Vendor pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High Vendor pom url http://www.bouncycastle.org/java.html Highest Product file name bcpkix-jdk15on High Product jar package name bouncycastle Highest Product jar package name cmp Highest Product jar package name cms Highest Product jar package name crmf Highest Product jar package name eac Highest Product jar package name ocsp Highest Product jar package name pkcs Highest Product jar package name pkix Highest Product jar package name tsp Highest Product Manifest application-library-allowable-codebase * Low Product Manifest application-name Bouncy Castle PKIX API Medium Product Manifest automatic-module-name org.bouncycastle.pkix Medium Product Manifest Bundle-Name bcpkix Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname bcpkix Medium Product Manifest caller-allowable-codebase * Low Product Manifest codebase * Low Product Manifest extension-name org.bouncycastle.bcpkix Medium Product Manifest multi-release true Low Product Manifest originally-created-by 25.275-b01 (Private Build) Low Product Manifest permissions all-permissions Low Product Manifest trusted-library true Low Product pom artifactid bcpkix-jdk15on Highest Product pom developer email feedback-crypto@bouncycastle.org Low Product pom developer id feedback-crypto Low Product pom developer name The Legion of the Bouncy Castle Inc. Low Product pom groupid org.bouncycastle Highest Product pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High Product pom url http://www.bouncycastle.org/java.html Medium Version file version 1.68 High Version Manifest Bundle-Version 1.68 High Version pom version 1.68 Highest
bcprov-jdk15on-1.68.jarDescription:
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 and up. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /home/andrii/.m2/repository/org/bouncycastle/bcprov-jdk15on/1.68/bcprov-jdk15on-1.68.jar
MD5: f34043ac8be2793843364b4406a15543
SHA1: 46a080368d38b428d237a59458f9bc915222894d
SHA256: f732a46c8de7e2232f2007c682a21d1f4cc8a8a0149b6b7bd6aa1afdc65a0f8d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name bcprov-jdk15on High Vendor jar package name bouncycastle Highest Vendor jar package name crypto Highest Vendor jar package name jce Highest Vendor jar package name org Highest Vendor jar package name provider Highest Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest application-name Bouncy Castle Provider Medium Vendor Manifest automatic-module-name org.bouncycastle.provider Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname bcprov Medium Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor Manifest extension-name org.bouncycastle.bcprovider Medium Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by 25.275-b01 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest trusted-library true Low Vendor pom artifactid bcprov-jdk15on Highest Vendor pom artifactid bcprov-jdk15on Low Vendor pom developer email feedback-crypto@bouncycastle.org Low Vendor pom developer id feedback-crypto Medium Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium Vendor pom groupid org.bouncycastle Highest Vendor pom name Bouncy Castle Provider High Vendor pom url http://www.bouncycastle.org/java.html Highest Product file name bcprov-jdk15on High Product hint analyzer product legion-of-the-bouncy-castle-java-crytography-api High Product hint analyzer product the_bouncy_castle_crypto_package_for_java High Product jar package name bouncycastle Highest Product jar package name crypto Highest Product jar package name jce Highest Product jar package name org Highest Product jar package name provider Highest Product Manifest application-library-allowable-codebase * Low Product Manifest application-name Bouncy Castle Provider Medium Product Manifest automatic-module-name org.bouncycastle.provider Medium Product Manifest Bundle-Name bcprov Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname bcprov Medium Product Manifest caller-allowable-codebase * Low Product Manifest codebase * Low Product Manifest extension-name org.bouncycastle.bcprovider Medium Product Manifest multi-release true Low Product Manifest originally-created-by 25.275-b01 (Private Build) Low Product Manifest permissions all-permissions Low Product Manifest trusted-library true Low Product pom artifactid bcprov-jdk15on Highest Product pom developer email feedback-crypto@bouncycastle.org Low Product pom developer id feedback-crypto Low Product pom developer name The Legion of the Bouncy Castle Inc. Low Product pom groupid org.bouncycastle Highest Product pom name Bouncy Castle Provider High Product pom url http://www.bouncycastle.org/java.html Medium Version file version 1.68 High Version Manifest Bundle-Version 1.68 High Version pom version 1.68 Highest
pkg:maven/org.bouncycastle/bcprov-jdk15on@1.68 (Confidence :High)cpe:2.3:a:bouncycastle:bouncy-castle-crypto-package:1.68:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:1.68:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.68:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.68:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:the_bouncy_castle_crypto_package_for_java:1.68:*:*:*:*:*:*:* (Confidence :Low) suppress bcprov-jdk18on-1.71.jarDescription:
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.8 and up. License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html File Path: /home/andrii/.m2/repository/org/bouncycastle/bcprov-jdk18on/1.71/bcprov-jdk18on-1.71.jar
MD5: bf1578f78f5db468a5f21ee8f8e42b0d
SHA1: 943e8d0c2bd592ad78759c39d6f749fafaf29cf4
SHA256: f3433a97d780fe9fa3dc3d562a41decd59b2e617ce884de9060349ac14750045
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name bcprov-jdk18on High Vendor jar package name bouncycastle Highest Vendor jar package name crypto Highest Vendor jar package name jce Highest Vendor jar package name org Highest Vendor jar package name provider Highest Vendor Manifest application-library-allowable-codebase * Low Vendor Manifest application-name Bouncy Castle Provider Medium Vendor Manifest automatic-module-name org.bouncycastle.provider Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname bcprov Medium Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor Manifest extension-name org.bouncycastle.bcprovider Medium Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by 25.312-b07 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest specification-vendor BouncyCastle.org Low Vendor Manifest trusted-library true Low Vendor pom artifactid bcprov-jdk18on Highest Vendor pom artifactid bcprov-jdk18on Low Vendor pom developer email feedback-crypto@bouncycastle.org Low Vendor pom developer id feedback-crypto Medium Vendor pom developer name The Legion of the Bouncy Castle Inc. Medium Vendor pom groupid org.bouncycastle Highest Vendor pom name Bouncy Castle Provider High Vendor pom url https://www.bouncycastle.org/java.html Highest Product file name bcprov-jdk18on High Product hint analyzer product legion-of-the-bouncy-castle-java-crytography-api High Product hint analyzer product the_bouncy_castle_crypto_package_for_java High Product jar package name bouncycastle Highest Product jar package name crypto Highest Product jar package name jce Highest Product jar package name org Highest Product jar package name provider Highest Product Manifest application-library-allowable-codebase * Low Product Manifest application-name Bouncy Castle Provider Medium Product Manifest automatic-module-name org.bouncycastle.provider Medium Product Manifest Bundle-Name bcprov Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname bcprov Medium Product Manifest caller-allowable-codebase * Low Product Manifest codebase * Low Product Manifest extension-name org.bouncycastle.bcprovider Medium Product Manifest multi-release true Low Product Manifest originally-created-by 25.312-b07 (Private Build) Low Product Manifest permissions all-permissions Low Product Manifest trusted-library true Low Product pom artifactid bcprov-jdk18on Highest Product pom developer email feedback-crypto@bouncycastle.org Low Product pom developer id feedback-crypto Low Product pom developer name The Legion of the Bouncy Castle Inc. Low Product pom groupid org.bouncycastle Highest Product pom name Bouncy Castle Provider High Product pom url https://www.bouncycastle.org/java.html Medium Version file version 1.71 High Version Manifest Bundle-Version 1.71 High Version pom version 1.71 Highest
pkg:maven/org.bouncycastle/bcprov-jdk18on@1.71 (Confidence :High)cpe:2.3:a:bouncycastle:bouncy-castle-crypto-package:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:the_bouncy_castle_crypto_package_for_java:1.71:*:*:*:*:*:*:* (Confidence :Low) suppress beehive-api-2.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/beehive/beehive-api/2.0.0/beehive-api-2.0.0.jarMD5: efae979b42ca470486ab1e3bc337c460SHA1: db5355bfe7202c4139c1912b1396349d89828420SHA256: 2334230d7f2c85fd4e01f13b0b2706572656e462b436d7362608ae035574f5afReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name beehive-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name beehive Highest Vendor jar package name beehive Low Vendor pom artifactid beehive-api Highest Vendor pom artifactid beehive-api Low Vendor pom groupid com.atlassian.beehive Highest Vendor pom name Beehive - API High Vendor pom parent-artifactid beehive Low Product file name beehive-api High Product jar package name atlassian Highest Product jar package name beehive Highest Product jar package name beehive Low Product pom artifactid beehive-api Highest Product pom groupid com.atlassian.beehive Highest Product pom name Beehive - API High Product pom parent-artifactid beehive Medium Version file version 2.0.0 High Version pom version 2.0.0 Highest
biz.aQute.bndlib-3.5.0.jarDescription:
A Swiss Army Knife for OSGi License:
Apache-2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/biz/aQute/bnd/biz.aQute.bndlib/3.5.0/biz.aQute.bndlib-3.5.0.jar
MD5: 17c66eb51d1e11ab9545ae317aa864de
SHA1: 31d8a6d8c951d954d02a37323c10c26aaa6e8c8b
SHA256: 884322bca122810402776527496ac6faa7eca5463b4f806587fe708cb6ca862c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name biz.aQute.bndlib High Vendor jar package name aqute Highest Vendor jar package name bnd Highest Vendor jar package name osgi Highest Vendor Manifest bundle-contributors per.kristian.soreide@comactivity.net, ferry.huberts@pelagic.nl, bj@bjhargrave.com Low Vendor Manifest bundle-copyright Copyright (c) aQute SARL (2000, 2017) and others. All Rights Reserved. Low Vendor Manifest bundle-developers peter.kriens@aQute.biz, njbartlett@gmail.com Low Vendor Manifest bundle-docurl http://bnd.bndtools.org/ Low Vendor Manifest bundle-icon img/bnd-64.png;size=64 Low Vendor Manifest bundle-symbolicname biz.aQute.bndlib Medium Vendor Manifest git-descriptor 3.5.0.REL Low Vendor Manifest git-sha bb70d103dd9c02096f516a0581be0fe9c252d581 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid biz.aQute.bndlib Highest Vendor pom artifactid biz.aQute.bndlib Low Vendor pom developer email njbartlett@gmail.com Low Vendor pom developer email peter.kriens@aQute.biz Low Vendor pom developer id njbartlett@gmail.com Medium Vendor pom developer id peter.kriens@aQute.biz Medium Vendor pom groupid biz.aQute.bnd Highest Vendor pom name bndlib High Vendor pom organization name Bndtools High Vendor pom organization url http://bndtools.org/ Medium Vendor pom url http://bnd.bndtools.org/ Highest Product file name biz.aQute.bndlib High Product jar package name aqute Highest Product jar package name bnd Highest Product jar package name filter Highest Product jar package name http Highest Product jar package name osgi Highest Product jar package name version Highest Product Manifest bundle-contributors per.kristian.soreide@comactivity.net, ferry.huberts@pelagic.nl, bj@bjhargrave.com Low Product Manifest bundle-copyright Copyright (c) aQute SARL (2000, 2017) and others. All Rights Reserved. Low Product Manifest bundle-developers peter.kriens@aQute.biz, njbartlett@gmail.com Low Product Manifest bundle-docurl http://bnd.bndtools.org/ Low Product Manifest bundle-icon img/bnd-64.png;size=64 Low Product Manifest Bundle-Name bndlib Medium Product Manifest bundle-symbolicname biz.aQute.bndlib Medium Product Manifest git-descriptor 3.5.0.REL Low Product Manifest git-sha bb70d103dd9c02096f516a0581be0fe9c252d581 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid biz.aQute.bndlib Highest Product pom developer email njbartlett@gmail.com Low Product pom developer email peter.kriens@aQute.biz Low Product pom developer id njbartlett@gmail.com Low Product pom developer id peter.kriens@aQute.biz Low Product pom groupid biz.aQute.bnd Highest Product pom name bndlib High Product pom organization name Bndtools Low Product pom organization url http://bndtools.org/ Low Product pom url http://bnd.bndtools.org/ Medium Version file version 3.5.0 High Version pom version 3.5.0 Highest
botocss-core-6.3.jarDescription:
Pronounced "botox". Injects CSS into your HTML markup for sending via email. File Path: /home/andrii/.m2/repository/com/atlassian/botocss/botocss-core/6.3/botocss-core-6.3.jarMD5: 7f480efc1adcc99879bfde941f660306SHA1: 1634cef977baab0321f3cdc4cd4201af9aa6c41fSHA256: 00ec56cf6fc53d2eca564a28ec6351a5467a73fa08a5a87f4d3acd92672ba0a9Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name botocss-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name botocss Highest Vendor jar package name botocss Low Vendor pom artifactid botocss-core Highest Vendor pom artifactid botocss-core Low Vendor pom groupid com.atlassian.botocss Highest Vendor pom name Botocss core High Vendor pom parent-artifactid botocss-parent Low Vendor pom url https://bitbucket.org/atlassian/botocss Highest Product file name botocss-core High Product jar package name atlassian Highest Product jar package name botocss Highest Product jar package name botocss Low Product pom artifactid botocss-core Highest Product pom groupid com.atlassian.botocss Highest Product pom name Botocss core High Product pom parent-artifactid botocss-parent Medium Product pom url https://bitbucket.org/atlassian/botocss Medium Version file version 6.3 High Version pom version 6.3 Highest
CVE-2022-26136 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-26137 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-346 Origin Validation Error
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-36233 suppress
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory. CWE-276 Incorrect Default Permissions
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-14171 suppress
Atlassian Bitbucket Server from version 4.9.0 before version 7.2.4 allows remote attackers to intercept unencrypted repository import requests via a Man-in-the-Middle (MITM) attack. CWE-319 Cleartext Transmission of Sensitive Information
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2019-15005 suppress
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14170 suppress
Webhooks in Atlassian Bitbucket Server from version 5.4.0 before version 7.3.1 allow remote attackers to access the content of internal network resources via a Server-Side Request Forgery (SSRF) vulnerability. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
brave-apache-http-interceptors-3.0.0.jarDescription:
Apache http client request and response interceptor implementations.
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/github/kristofa/brave-apache-http-interceptors/3.0.0/brave-apache-http-interceptors-3.0.0.jar
MD5: be26a2572bcc062af1e8515d6e3e5389
SHA1: df53928eefc797f48ba726efa8bd344a475fb6e6
SHA256: 8e9de9cfc0b88fd0eafc10953b923baddcc560ee52e4a86c318c72898eb18e9a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name brave-apache-http-interceptors High Vendor jar package name brave Highest Vendor jar package name brave Low Vendor jar package name github Highest Vendor jar package name github Low Vendor jar package name kristofa Highest Vendor jar package name kristofa Low Vendor pom artifactid brave-apache-http-interceptors Highest Vendor pom artifactid brave-apache-http-interceptors Low Vendor pom groupid com.github.kristofa Highest Vendor pom name brave-apache-http-interceptors High Vendor pom parent-artifactid brave Low Vendor pom url kristofa/brave Highest Product file name brave-apache-http-interceptors High Product jar package name brave Highest Product jar package name brave Low Product jar package name github Highest Product jar package name httpclient Low Product jar package name kristofa Highest Product jar package name kristofa Low Product pom artifactid brave-apache-http-interceptors Highest Product pom groupid com.github.kristofa Highest Product pom name brave-apache-http-interceptors High Product pom parent-artifactid brave Medium Product pom url kristofa/brave High Version file version 3.0.0 High Version pom version 3.0.0 Highest
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
brave-core-3.0.0.jarDescription:
Brave core.
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/github/kristofa/brave-core/3.0.0/brave-core-3.0.0.jar
MD5: b643ee0d38f3d98ef95565028aa5857b
SHA1: 4203bd1367b0fceb261faa1f3606c232da28f9e5
SHA256: 9dbc877cb7317d1ad0f86f160d7dab43cd07584eee406569517b9bb26802430a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name brave-core High Vendor jar package name brave Highest Vendor jar package name brave Low Vendor jar package name github Highest Vendor jar package name github Low Vendor jar package name kristofa Highest Vendor jar package name kristofa Low Vendor pom artifactid brave-core Highest Vendor pom artifactid brave-core Low Vendor pom groupid com.github.kristofa Highest Vendor pom name brave-core High Vendor pom parent-artifactid brave Low Vendor pom url kristofa/brave Highest Product file name brave-core High Product jar package name brave Highest Product jar package name brave Low Product jar package name github Highest Product jar package name kristofa Highest Product jar package name kristofa Low Product pom artifactid brave-core Highest Product pom groupid com.github.kristofa Highest Product pom name brave-core High Product pom parent-artifactid brave Medium Product pom url kristofa/brave High Version file version 3.0.0 High Version pom version 3.0.0 Highest
brave-http-3.0.0.jarDescription:
Abstraction that makes it easier to implement brave in http clients and servers.
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/github/kristofa/brave-http/3.0.0/brave-http-3.0.0.jar
MD5: 2eb3cb5b8bd35cc6e1385c0778c8f23d
SHA1: b2f2655e1144a3258cdf9712c5b6ee98d44e855e
SHA256: 4396da6ce72cc0d9559eb27f3cf9dfae91c2e27541ab50f476cb2abcc1e284c6
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name brave-http High Vendor jar package name brave Highest Vendor jar package name brave Low Vendor jar package name github Highest Vendor jar package name github Low Vendor jar package name http Highest Vendor jar package name kristofa Highest Vendor jar package name kristofa Low Vendor pom artifactid brave-http Highest Vendor pom artifactid brave-http Low Vendor pom groupid com.github.kristofa Highest Vendor pom name brave-http High Vendor pom parent-artifactid brave Low Vendor pom url kristofa/brave Highest Product file name brave-http High Product jar package name brave Highest Product jar package name brave Low Product jar package name github Highest Product jar package name http Highest Product jar package name http Low Product jar package name kristofa Highest Product jar package name kristofa Low Product pom artifactid brave-http Highest Product pom groupid com.github.kristofa Highest Product pom name brave-http High Product pom parent-artifactid brave Medium Product pom url kristofa/brave High Version file version 3.0.0 High Version pom version 3.0.0 Highest
brave-web-servlet-filter-3.0.0.jarDescription:
Servlet Filter implementation.
File Path: /home/andrii/.m2/repository/com/github/kristofa/brave-web-servlet-filter/3.0.0/brave-web-servlet-filter-3.0.0.jarMD5: f6d3afcaaf587c101acb05559dc28257SHA1: 40eee12656bd80766d0c4763f2e6eadc6669a251SHA256: 3e360af55da9c54117350d4d77a212bda206d3b9d9ddd35cb6c6bcfcf6def516Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name brave-web-servlet-filter High Vendor jar package name brave Highest Vendor jar package name brave Low Vendor jar package name github Highest Vendor jar package name github Low Vendor jar package name kristofa Highest Vendor jar package name kristofa Low Vendor jar package name servlet Highest Vendor pom artifactid brave-web-servlet-filter Highest Vendor pom artifactid brave-web-servlet-filter Low Vendor pom groupid com.github.kristofa Highest Vendor pom parent-artifactid brave Low Product file name brave-web-servlet-filter High Product jar package name brave Highest Product jar package name brave Low Product jar package name github Highest Product jar package name kristofa Highest Product jar package name kristofa Low Product jar package name servlet Highest Product jar package name servlet Low Product pom artifactid brave-web-servlet-filter Highest Product pom groupid com.github.kristofa Highest Product pom parent-artifactid brave Medium Version file version 3.0.0 High Version pom version 3.0.0 Highest
button-b301ec95.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/button-b301ec95.jsMD5: 3dd082cb5a76022a3a0cb63e8b362628SHA1: 2146283af55631cb5250dcf7b004e0a1ab778e1bSHA256: 45eb3aef9ea0bfe6369265beb2b233a71546b238ed01054fe214ce08902e7f18Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
button.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/button.jsMD5: 4781908ccadd86441377b11f141f7bfeSHA1: 702d5430338ba25c68bc33ef2d2137b023c334a8SHA256: 0a94f7721c42b795bc06c33871df1cacc44c9ed1836e749b38b92f92e7660e2bReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
c3p0-0.9.5.5.jarDescription:
a JDBC Connection pooling / Statement caching library License:
GNU Lesser General Public License, Version 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Eclipse Public License, Version 1.0: http://www.eclipse.org/org/documents/epl-v10.php File Path: /home/andrii/.m2/repository/com/mchange/c3p0/0.9.5.5/c3p0-0.9.5.5.jar
MD5: 9fc982b4b179e44cec986ea86fe1bff7
SHA1: 37dfc3021e5589d65ff2ae0becf811510b87ab01
SHA256: 96cec5ddfe2f08b8407125d8228eb0392121e1bf2239ca621bb19228b67f741a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name c3p0 High Vendor jar package name c3p0 Highest Vendor jar package name mchange Highest Vendor jar package name v2 Highest Vendor Manifest extension-name com.mchange.v2.c3p0 Medium Vendor Manifest Implementation-Vendor Machinery For Change, Inc. High Vendor Manifest Implementation-Vendor-Id com.mchange Medium Vendor Manifest specification-vendor Machinery For Change, Inc. Low Vendor pom artifactid c3p0 Highest Vendor pom artifactid c3p0 Low Vendor pom developer email swaldman@mchange.com Low Vendor pom developer id swaldman Medium Vendor pom developer name Steve Waldman Medium Vendor pom groupid com.mchange Highest Vendor pom name c3p0 High Vendor pom url swaldman/c3p0 Highest Product file name c3p0 High Product jar package name c3p0 Highest Product jar package name mchange Highest Product jar package name v2 Highest Product Manifest extension-name com.mchange.v2.c3p0 Medium Product pom artifactid c3p0 Highest Product pom developer email swaldman@mchange.com Low Product pom developer id swaldman Low Product pom developer name Steve Waldman Low Product pom groupid com.mchange Highest Product pom name c3p0 High Product pom url swaldman/c3p0 High Version file version 0.9.5.5 High Version Manifest Implementation-Version 0.9.5.5 High Version pom version 0.9.5.5 Highest
cglib-3.2.12.jarFile Path: /home/andrii/.m2/repository/cglib/cglib/3.2.12/cglib-3.2.12.jarMD5: dd6eef2e7cc00d0314f2bce471121d4cSHA1: 16c0d1d8b5d50ea9ad38c1f6f9f1e35a42727bf0SHA256: 82f941d7d60989433d61893cb0d0ec742e31925a471ed9d5a4ed786f5c9614a1Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name cglib High Vendor jar package name cglib Highest Vendor jar package name cglib Low Vendor jar package name net Low Vendor jar package name sf Low Vendor pom artifactid cglib Highest Vendor pom artifactid cglib Low Vendor pom groupid cglib Highest Vendor pom parent-artifactid cglib-parent Low Product file name cglib High Product jar package name cglib Highest Product jar package name cglib Low Product jar package name sf Low Product pom artifactid cglib Highest Product pom groupid cglib Highest Product pom parent-artifactid cglib-parent Medium Version file version 3.2.12 High Version pom version 3.2.12 Highest
checker-qual-2.8.2.jarDescription:
Checker Qual is the set of annotations (qualifiers) and supporting classes
used by the Checker Framework to type check Java source code. Please
see artifact:
org.checkerframework:checker
License:
The MIT License: http://opensource.org/licenses/MIT File Path: /home/andrii/.m2/repository/org/checkerframework/checker-qual/2.8.2/checker-qual-2.8.2.jar
MD5: a1a80f11f9345cadb5fad1df898f43f5
SHA1: c1e0de498581b923865ff5c9c6f22db7be223b2e
SHA256: 65b684eb34c8236ac89af713ba1d35a8dd8d8d496fc349b7d20410cc7988311a
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name checker-qual High Vendor jar package name checker Highest Vendor jar package name checkerframework Highest Vendor jar package name framework Highest Vendor jar package name qual Highest Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium Vendor Manifest bundle-symbolicname checker-qual Medium Vendor Manifest implementation-url https://checkerframework.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid checker-qual Highest Vendor pom artifactid checker-qual Low Vendor pom developer email mernst@cs.washington.edu Low Vendor pom developer email smillst@cs.washington.edu Low Vendor pom developer email wdietl@uwaterloo.ca Low Vendor pom developer id mernst Medium Vendor pom developer id smillst Medium Vendor pom developer id wmdietl Medium Vendor pom developer name Michael Ernst Medium Vendor pom developer name Suzanne Millstein Medium Vendor pom developer name Werner M. Dietl Medium Vendor pom developer org University of Washington Medium Vendor pom developer org University of Washington PLSE Group Medium Vendor pom developer org University of Waterloo Medium Vendor pom developer org URL http://uwaterloo.ca/ Medium Vendor pom developer org URL https://www.cs.washington.edu/ Medium Vendor pom developer org URL https://www.cs.washington.edu/research/plse/ Medium Vendor pom groupid org.checkerframework Highest Vendor pom name Checker Qual High Vendor pom url https://checkerframework.org Highest Product file name checker-qual High Product jar package name checker Highest Product jar package name checkerframework Highest Product jar package name framework Highest Product jar package name qual Highest Product Manifest automatic-module-name org.checkerframework.checker.qual Medium Product Manifest Bundle-Name checker-qual Medium Product Manifest bundle-symbolicname checker-qual Medium Product Manifest implementation-url https://checkerframework.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid checker-qual Highest Product pom developer email mernst@cs.washington.edu Low Product pom developer email smillst@cs.washington.edu Low Product pom developer email wdietl@uwaterloo.ca Low Product pom developer id mernst Low Product pom developer id smillst Low Product pom developer id wmdietl Low Product pom developer name Michael Ernst Low Product pom developer name Suzanne Millstein Low Product pom developer name Werner M. Dietl Low Product pom developer org University of Washington Low Product pom developer org University of Washington PLSE Group Low Product pom developer org University of Waterloo Low Product pom developer org URL http://uwaterloo.ca/ Low Product pom developer org URL https://www.cs.washington.edu/ Low Product pom developer org URL https://www.cs.washington.edu/research/plse/ Low Product pom groupid org.checkerframework Highest Product pom name Checker Qual High Product pom url https://checkerframework.org Medium Version file version 2.8.2 High Version Manifest Bundle-Version 2.8.2 High Version Manifest Implementation-Version 2.8.2 High Version pom version 2.8.2 Highest
classmate-1.3.0.jarDescription:
Library for introspecting types with full generic information
including resolving of field and method types.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/classmate/1.3.0/classmate-1.3.0.jar
MD5: 80a7f4753882087669739bc119136da5
SHA1: 183407ff982e9375f1a1c4a51ed0a9307c598fc7
SHA256: 11f836b0f3eba1544967317c052917c2987d78f0d1fb1e5a2bf93265174b9d77
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name classmate High Vendor jar package name classmate Highest Vendor jar package name fasterxml Highest Vendor jar package name types Highest Vendor Manifest bundle-docurl http://github.com/cowtowncoder/java-classmate Low Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor Manifest implementation-build-date 2015-09-16 22:08:50+0000 Low Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor fasterxml.com Low Vendor pom artifactid classmate Highest Vendor pom artifactid classmate Low Vendor pom developer email blangel@ocheyedan.net Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id blangel Medium Vendor pom developer id tatu Medium Vendor pom developer name Brian Langel Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid com.fasterxml Highest Vendor pom name ClassMate High Vendor pom organization name fasterxml.com High Vendor pom organization url http://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom url http://github.com/cowtowncoder/java-classmate Highest Product file name classmate High Product jar package name classmate Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product jar package name types Highest Product Manifest bundle-docurl http://github.com/cowtowncoder/java-classmate Low Product Manifest Bundle-Name ClassMate Medium Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product Manifest implementation-build-date 2015-09-16 22:08:50+0000 Low Product Manifest Implementation-Title ClassMate High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title ClassMate Medium Product pom artifactid classmate Highest Product pom developer email blangel@ocheyedan.net Low Product pom developer email tatu@fasterxml.com Low Product pom developer id blangel Low Product pom developer id tatu Low Product pom developer name Brian Langel Low Product pom developer name Tatu Saloranta Low Product pom groupid com.fasterxml Highest Product pom name ClassMate High Product pom organization name fasterxml.com Low Product pom organization url http://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom url http://github.com/cowtowncoder/java-classmate Medium Version file version 1.3.0 High Version Manifest Bundle-Version 1.3.0 High Version Manifest Implementation-Version 1.3.0 High Version pom parent-version 1.3.0 Low Version pom version 1.3.0 Highest
cluster-monitoring-spi-3.0.2.jarDescription:
SPI the Cluster Monitoring plugin -- Allows developers to implement their own monitoring data suppliers. File Path: /home/andrii/.m2/repository/com/atlassian/cluster/monitoring/cluster-monitoring-spi/3.0.2/cluster-monitoring-spi-3.0.2.jarMD5: 34365ace291ee6bb31305d4cc568ac83SHA1: 6163c14b81e2771ef2752c3b641ff636fa28cf5bSHA256: 2403418b9c8ceeb7e62562802b1f55d3b9119f79f9a64751265e1cbdf4ad0a47Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name cluster-monitoring-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name cluster Highest Vendor jar package name cluster Low Vendor jar package name monitoring Highest Vendor jar package name monitoring Low Vendor jar package name spi Highest Vendor pom artifactid cluster-monitoring-spi Highest Vendor pom artifactid cluster-monitoring-spi Low Vendor pom groupid com.atlassian.cluster.monitoring Highest Vendor pom name Atlassian Cluster Monitoring SPI High Vendor pom parent-artifactid cluster-monitoring-parent Low Product file name cluster-monitoring-spi High Product jar package name atlassian Highest Product jar package name cluster Highest Product jar package name cluster Low Product jar package name monitoring Highest Product jar package name monitoring Low Product jar package name spi Highest Product jar package name spi Low Product pom artifactid cluster-monitoring-spi Highest Product pom groupid com.atlassian.cluster.monitoring Highest Product pom name Atlassian Cluster Monitoring SPI High Product pom parent-artifactid cluster-monitoring-parent Medium Version file version 3.0.2 High Version pom version 3.0.2 Highest
colors-25aad6bf.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/colors-25aad6bf.jsMD5: a727666f430ee17dc01658b4256cfea0SHA1: 06f20a2f54e9694b0a5b5c6893894aed7380b8eaSHA256: 985c65edeb31d25ec0e225309ad9577fcce69ed291d74ab03859fe9b939c37dcReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
comment.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/comment.jsMD5: bbdb6b26b614567a472a6335dea4247aSHA1: e1e1e450f6896e7a759d0c7c43ad70dc4e355bacSHA256: 77dd214284c17e2dffa0e28e8050c3c95d1d51f3b0196d3a62ce9e1d02509b02Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
common-io-3.4.1.jarDescription:
The TwelveMonkeys Common IO support
File Path: /home/andrii/.m2/repository/com/twelvemonkeys/common/common-io/3.4.1/common-io-3.4.1.jarMD5: 331071330075f62d047cb9f119fe4f1eSHA1: 21f183828ef9431e007a67957cab3ad4ea1561ceSHA256: cb734241b1c11f7aede68e49d1ae8e71ce7e307abebfc4fe99535a2b3ddecde5Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name common-io High Vendor jar package name io Highest Vendor jar package name twelvemonkeys Highest Vendor Manifest implementation-url https://github.com/haraldk/TwelveMonkeys/common/common-io Low Vendor Manifest Implementation-Vendor TwelveMonkeys High Vendor pom artifactid common-io Highest Vendor pom artifactid common-io Low Vendor pom groupid com.twelvemonkeys.common Highest Vendor pom name TwelveMonkeys :: Common :: IO High Vendor pom parent-artifactid common Low Product file name common-io High Product jar package name io Highest Product jar package name twelvemonkeys Highest Product Manifest Implementation-Title twelvemonkeys-common-io High Product Manifest implementation-url https://github.com/haraldk/TwelveMonkeys/common/common-io Low Product pom artifactid common-io Highest Product pom groupid com.twelvemonkeys.common Highest Product pom name TwelveMonkeys :: Common :: IO High Product pom parent-artifactid common Medium Version file version 3.4.1 High Version Manifest Implementation-Version 3.4.1 High Version pom version 3.4.1 Highest
Related Dependencies common-image-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/common/common-image/3.4.1/common-image-3.4.1.jar MD5: a9b7a43a507277db0544ee8c8a1ae521 SHA1: 48a6483960ecedec05cccefb17b95facef98c1da SHA256: e3717da5e934d08cd11990217e25af32948100e2346167ae7ae831dbd897eacf pkg:maven/com.twelvemonkeys.common/common-image@3.4.1 common-lang-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/common/common-lang/3.4.1/common-lang-3.4.1.jar MD5: a1898977d7a567efdedce5ab2d157a74 SHA1: 294a093960aa1169a849544f83ee4a4686bfd408 SHA256: 8aef005944e1f3f0fcae297b3868f7effe5ac4583369b51fc9f599b7cbb8d453 pkg:maven/com.twelvemonkeys.common/common-lang@3.4.1 CVE-2021-23792 suppress
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
commons-beanutils-1.9.4.jarDescription:
Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar
MD5: 07dc532ee316fe1f2f0323e9bd2f8df4
SHA1: d52b9abcd97f38c81342bb7e7ae1eee9b73cba51
SHA256: 7d938c81789028045c08c065e94be75fc280527620d5bd62b519d5838532368a
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-beanutils High Vendor jar package name apache Highest Vendor jar package name beanutils Highest Vendor jar package name commons Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2019-07-28 22:14:44+0000 Low Vendor Manifest implementation-url https://commons.apache.org/proper/commons-beanutils/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-beanutils Highest Vendor pom artifactid commons-beanutils Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email craigmcc@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email epugh@apache.org Low Vendor pom developer email geirm@apache.org Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email jconlon@apache.org Low Vendor pom developer email jstrachan@apache.org Low Vendor pom developer email morgand@apache.org Low Vendor pom developer email mvdb@apache.org Low Vendor pom developer email niallp@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer email scolebourne@apache.org Low Vendor pom developer email skitching@apache.org Low Vendor pom developer email stain@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer email yoavs@apache.org Low Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dion Medium Vendor pom developer id epugh Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id jconlon Medium Vendor pom developer id jstrachan Medium Vendor pom developer id morgand Medium Vendor pom developer id mvdb Medium Vendor pom developer id niallp Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer id skitching Medium Vendor pom developer id stain Medium Vendor pom developer id tobrien Medium Vendor pom developer id yoavs Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name David Eric Pugh Medium Vendor pom developer name Dion Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Jr. Medium Vendor pom developer name James Carman Medium Vendor pom developer name James Strachan Medium Vendor pom developer name John E. Conlon Medium Vendor pom developer name Martin van den Bemt Medium Vendor pom developer name Morgan James Delagrange Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Simon Kitching Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Stian Soiland-Reyes Medium Vendor pom developer name Tim O'Brien Medium Vendor pom developer name Yoav Shapira Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom groupid commons-beanutils Highest Vendor pom name Apache Commons BeanUtils High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-beanutils/ Highest Product file name commons-beanutils High Product jar package name apache Highest Product jar package name beanutils Highest Product jar package name commons Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-beanutils/ Low Product Manifest Bundle-Name Apache Commons BeanUtils Medium Product Manifest bundle-symbolicname org.apache.commons.commons-beanutils Medium Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2019-07-28 22:14:44+0000 Low Product Manifest Implementation-Title Apache Commons BeanUtils High Product Manifest implementation-url https://commons.apache.org/proper/commons-beanutils/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache Commons BeanUtils Medium Product pom artifactid commons-beanutils Highest Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email craigmcc@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email epugh@apache.org Low Product pom developer email geirm@apache.org Low Product pom developer email ggregory@apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email jconlon@apache.org Low Product pom developer email jstrachan@apache.org Low Product pom developer email morgand@apache.org Low Product pom developer email mvdb@apache.org Low Product pom developer email niallp@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer email scolebourne@apache.org Low Product pom developer email skitching@apache.org Low Product pom developer email stain@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer email yoavs@apache.org Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id craigmcc Low Product pom developer id dion Low Product pom developer id epugh Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id jconlon Low Product pom developer id jstrachan Low Product pom developer id morgand Low Product pom developer id mvdb Low Product pom developer id niallp Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer id skitching Low Product pom developer id stain Low Product pom developer id tobrien Low Product pom developer id yoavs Low Product pom developer name Benedikt Ritter Low Product pom developer name Craig McClanahan Low Product pom developer name David Eric Pugh Low Product pom developer name Dion Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Jr. Low Product pom developer name James Carman Low Product pom developer name James Strachan Low Product pom developer name John E. Conlon Low Product pom developer name Martin van den Bemt Low Product pom developer name Morgan James Delagrange Low Product pom developer name Niall Pemberton Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Simon Kitching Low Product pom developer name Stephen Colebourne Low Product pom developer name Stian Soiland-Reyes Low Product pom developer name Tim O'Brien Low Product pom developer name Yoav Shapira Low Product pom developer org The Apache Software Foundation Low Product pom groupid commons-beanutils Highest Product pom name Apache Commons BeanUtils High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-beanutils/ Medium Version file version 1.9.4 High Version Manifest Bundle-Version 1.9.4 High Version Manifest Implementation-Version 1.9.4 High Version pom parent-version 1.9.4 Low Version pom version 1.9.4 Highest
commons-codec-1.14.jarDescription:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-codec/commons-codec/1.14/commons-codec-1.14.jar
MD5: e9158e0983096d3df09236f7b53125aa
SHA1: 3cb1181b2141a7e752f5bdc998b7ef1849f726cf
SHA256: a128e4f93fabe5381ded64cf2873019e06030b718eb43ceeae0b0e5d17ad33e9
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-codec High Vendor jar package name apache Highest Vendor jar package name codec Highest Vendor jar package name commons Highest Vendor jar package name encoder Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product file name commons-codec High Product jar package name apache Highest Product jar package name codec Highest Product jar package name commons Highest Product jar package name encoder Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Apache Commons Codec Medium Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version file version 1.14 High Version Manifest Implementation-Version 1.14 High Version pom parent-version 1.14 Low Version pom version 1.14 Highest
commons-collections-3.2.2.jarDescription:
Types that extend and augment the Java Collections Framework. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
SHA256: eeeae917917144a68a741d4c0dff66aa5c5c5fd85593ff217bced3fc8ca783b8
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-collections High Vendor jar package name apache Highest Vendor jar package name collections Highest Vendor jar package name commons Highest Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low Vendor Manifest implementation-url http://commons.apache.org/collections/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-collections Highest Vendor pom artifactid commons-collections Low Vendor pom developer id amamment Medium Vendor pom developer id bayard Medium Vendor pom developer id craigmcc Medium Vendor pom developer id geirm Medium Vendor pom developer id jcarman Medium Vendor pom developer id matth Medium Vendor pom developer id morgand Medium Vendor pom developer id psteitz Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Arun M. Thomas Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Phil Steitz Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom groupid commons-collections Highest Vendor pom name Apache Commons Collections High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/collections/ Highest Product file name commons-collections High Product jar package name apache Highest Product jar package name collections Highest Product jar package name commons Highest Product Manifest bundle-docurl http://commons.apache.org/collections/ Low Product Manifest Bundle-Name Apache Commons Collections Medium Product Manifest bundle-symbolicname org.apache.commons.collections Medium Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low Product Manifest Implementation-Title Apache Commons Collections High Product Manifest implementation-url http://commons.apache.org/collections/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low Product Manifest specification-title Apache Commons Collections Medium Product pom artifactid commons-collections Highest Product pom developer id amamment Low Product pom developer id bayard Low Product pom developer id craigmcc Low Product pom developer id geirm Low Product pom developer id jcarman Low Product pom developer id matth Low Product pom developer id morgand Low Product pom developer id psteitz Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id scolebourne Low Product pom developer name Arun M. Thomas Low Product pom developer name Craig McClanahan Low Product pom developer name Geir Magnusson Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Matthew Hawthorne Low Product pom developer name Morgan Delagrange Low Product pom developer name Phil Steitz Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Stephen Colebourne Low Product pom groupid commons-collections Highest Product pom name Apache Commons Collections High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/collections/ Medium Version file version 3.2.2 High Version Manifest Bundle-Version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom parent-version 3.2.2 Low Version pom version 3.2.2 Highest
commons-collections4-4.3.jarDescription:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-collections4/4.3/commons-collections4-4.3.jar
MD5: 20d1ebd548752d0d75aaae9faee66d6a
SHA1: 1c262f70f9b3c2351f1d13a9a9bd10d2ec7cfbc4
SHA256: 62f8db7da73e551f82d70fd533834177af6bd953de4b5e85c44dc2100de4beb8
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-collections4 High Vendor jar package name apache Highest Vendor jar package name collections4 Highest Vendor jar package name commons Highest Vendor Manifest automatic-module-name org.apache.commons.collections4 Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Vendor Manifest implementation-url http://commons.apache.org/proper/commons-collections/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-collections4 Highest Vendor pom artifactid commons-collections4 Low Vendor pom developer id adriannistor Medium Vendor pom developer id amamment Medium Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dlaha Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id luc Medium Vendor pom developer id matth Medium Vendor pom developer id mbenson Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id scolebourne Medium Vendor pom developer id tn Medium Vendor pom developer name Adrian Nistor Medium Vendor pom developer name Arun M. Thomas Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Dipanjan Laha Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Luc Maisonobe Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Collections High Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-collections/ Highest Product file name commons-collections4 High Product jar package name apache Highest Product jar package name collections4 Highest Product jar package name commons Highest Product Manifest automatic-module-name org.apache.commons.collections4 Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-collections/ Low Product Manifest Bundle-Name Apache Commons Collections Medium Product Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Product Manifest Implementation-Title Apache Commons Collections High Product Manifest implementation-url http://commons.apache.org/proper/commons-collections/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Collections Medium Product pom artifactid commons-collections4 Highest Product pom developer id adriannistor Low Product pom developer id amamment Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id craigmcc Low Product pom developer id dlaha Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id luc Low Product pom developer id matth Low Product pom developer id mbenson Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id scolebourne Low Product pom developer id tn Low Product pom developer name Adrian Nistor Low Product pom developer name Arun M. Thomas Low Product pom developer name Craig McClanahan Low Product pom developer name Dipanjan Laha Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Luc Maisonobe Low Product pom developer name Matt Benson Low Product pom developer name Matthew Hawthorne Low Product pom developer name Morgan Delagrange Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Stephen Colebourne Low Product pom developer name Thomas Neidhart Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Collections High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-collections/ Medium Version file version 4.3 High Version Manifest Implementation-Version 4.3 High Version pom parent-version 4.3 Low Version pom version 4.3 Highest
commons-compress-1.19.jarDescription:
Apache Commons Compress software defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
lzma, xz, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-compress/1.19/commons-compress-1.19.jar
MD5: fe897bced43468450b785b66c1cff455
SHA1: 7e65777fb451ddab6a9c054beb879e521b7eab78
SHA256: ff2d59fad74e867630fbc7daab14c432654712ac624dbee468d220677b124dd5
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-compress High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name compress Highest Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest implementation-build UNKNOWN@r516f76ac1fe48be9a5162e53e4d0a99f23774565; 2019-08-24 16:14:33+0000 Low Vendor Manifest implementation-url https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-compress Highest Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product file name commons-compress High Product jar package name apache Highest Product jar package name commons Highest Product jar package name compress Highest Product Manifest automatic-module-name org.apache.commons.compress Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest implementation-build UNKNOWN@r516f76ac1fe48be9a5162e53e4d0a99f23774565; 2019-08-24 16:14:33+0000 Low Product Manifest Implementation-Title Apache Commons Compress High Product Manifest implementation-url https://commons.apache.org/proper/commons-compress/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Apache Commons Compress Medium Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version file version 1.19 High Version Manifest Implementation-Version 1.19 High Version pom parent-version 1.19 Low Version pom version 1.19 Highest
CVE-2021-35515 suppress
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20211022-0001/ MISC - https://commons.apache.org/proper/commons-compress/security-reports.html MISC - https://lists.apache.org/thread.html/r19ebfd71770ec0617a9ea180e321ef927b3fefb4c81ec5d1902d20ab%40%3Cuser.commons.apache.org%3E MISC - https://www.oracle.com/security-alerts/cpuapr2022.html MISC - https://www.oracle.com/security-alerts/cpujan2022.html MISC - https://www.oracle.com/security-alerts/cpuoct2021.html MLIST - [announce] 20210713 CVE-2021-35515: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability MLIST - [druid-commits] 20210726 [GitHub] [druid] suneet-s merged pull request #11496: Address CVE-2021-35515 CVE-2021-36090 MLIST - [druid-commits] 20210726 [GitHub] [druid] suneet-s opened a new pull request #11496: Address CVE-2021-35515 CVE-2021-36090 MLIST - [druid-commits] 20210726 [druid] branch master updated: Address CVE-2021-35515 CVE-2021-36090 (#11496) MLIST - [oss-security] 20210713 CVE-2021-35515: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability MLIST - [poi-dev] 20210923 Re: [VOTE] Apache POI 5.1.0 release (RC1) MLIST - [pulsar-commits] 20210716 [GitHub] [pulsar] lhotari opened a new pull request #11345: [Security] Upgrade commons-compress to 1.21 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] commented on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] wu-sheng opened a new pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [skywalking] 01/01: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] hanahmily merged pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [skywalking] branch master updated: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 (#7400) N/A - N/A OSSINDEX - [CVE-2021-35515] CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-35515 OSSIndex - https://commons.apache.org/proper/commons-compress/security-reports.html OSSIndex - https://lists.apache.org/thread.html/rbaea15ddc5a7c0c6b66660f1d6403b28595e2561bb283eade7d7cd69@%3Cannounce.apache.org%3E Vulnerable Software & Versions: (show all )
CVE-2021-35516 suppress
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20211022-0001/ MISC - https://commons.apache.org/proper/commons-compress/security-reports.html MISC - https://lists.apache.org/thread.html/rf68442d67eb166f4b6cf0bbbe6c7f99098c12954f37332073c9822ca%40%3Cuser.commons.apache.org%3E MISC - https://www.oracle.com/security-alerts/cpuapr2022.html MISC - https://www.oracle.com/security-alerts/cpujan2022.html MISC - https://www.oracle.com/security-alerts/cpuoct2021.html MLIST - [announce] 20210713 CVE-2021-35516: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability MLIST - [oss-security] 20210713 CVE-2021-35516: Apache Commons Compress 1.6 to 1.20 denial of service vulnerability MLIST - [poi-dev] 20210923 Re: [VOTE] Apache POI 5.1.0 release (RC1) MLIST - [pulsar-commits] 20210716 [GitHub] [pulsar] lhotari opened a new pull request #11345: [Security] Upgrade commons-compress to 1.21 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] commented on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] wu-sheng opened a new pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [skywalking] 01/01: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] hanahmily merged pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [skywalking] branch master updated: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 (#7400) N/A - N/A OSSINDEX - [CVE-2021-35516] CWE-770: Allocation of Resources Without Limits or Throttling OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-35516 OSSIndex - https://commons.apache.org/proper/commons-compress/security-reports.html OSSIndex - https://issues.apache.org/jira/browse/COMPRESS-542 Vulnerable Software & Versions: (show all )
CVE-2021-35517 suppress
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20211022-0001/ MISC - https://commons.apache.org/proper/commons-compress/security-reports.html MISC - https://lists.apache.org/thread.html/r605d906b710b95f1bbe0036a53ac6968f667f2c249b6fbabada9a940%40%3Cuser.commons.apache.org%3E MISC - https://www.oracle.com/security-alerts/cpuapr2022.html MISC - https://www.oracle.com/security-alerts/cpujan2022.html MISC - https://www.oracle.com/security-alerts/cpuoct2021.html MLIST - [announce] 20210713 CVE-2021-35517: Apache Commons Compress 1.1 to 1.20 denial of service vulnerability MLIST - [announce] 20210713 CVE-2021-36373: Apache Ant TAR archive denial of service vulnerability MLIST - [ant-user] 20210713 CVE-2021-36373: Apache Ant TAR archive denial of service vulnerability MLIST - [flink-issues] 20210908 [GitHub] [flink] MartijnVisser opened a new pull request #17194: [FLINK-24034] Upgrade commons-compress to 1.21 and other apache.commons updates MLIST - [oss-security] 20210713 CVE-2021-35517: Apache Commons Compress 1.1 to 1.20 denial of service vulnerability MLIST - [oss-security] 20210713 CVE-2021-36373: Apache Ant TAR archive denial of service vulnerability MLIST - [poi-dev] 20210923 Re: [VOTE] Apache POI 5.1.0 release (RC1) MLIST - [pulsar-commits] 20210716 [GitHub] [pulsar] lhotari opened a new pull request #11345: [Security] Upgrade commons-compress to 1.21 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] commented on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] wu-sheng opened a new pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [skywalking] 01/01: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] hanahmily merged pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [skywalking] branch master updated: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 (#7400) N/A - N/A OSSINDEX - [CVE-2021-35517] CWE-770: Allocation of Resources Without Limits or Throttling OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-35517 OSSIndex - https://github.com/OpenLiberty/open-liberty/issues/18808 OSSIndex - https://github.com/OpenLiberty/open-liberty/pull/17872 OSSIndex - https://lists.apache.org/thread.html/ra393ffdc7c90a4a37ea023946f390285693795013a642d80fba20203@%3Cannounce.apache.org%3E OSSIndex - https://openliberty.io/docs/latest/security-vulnerabilities.html Vulnerable Software & Versions: (show all )
CVE-2021-36090 suppress
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://security.netapp.com/advisory/ntap-20211022-0001/ MISC - https://commons.apache.org/proper/commons-compress/security-reports.html MISC - https://lists.apache.org/thread.html/rc4134026d7d7b053d4f9f2205531122732405012c8804fd850a9b26f%40%3Cuser.commons.apache.org%3E MISC - https://www.oracle.com/security-alerts/cpuapr2022.html MISC - https://www.oracle.com/security-alerts/cpujan2022.html MISC - https://www.oracle.com/security-alerts/cpuoct2021.html MLIST - [announce] 20210713 CVE-2021-36090: Apache Commons Compress 1.0 to 1.20 denial of service vulnerability MLIST - [announce] 20210713 CVE-2021-36374: Apache Ant ZIP, and ZIP based, archive denial of service vulerability MLIST - [ant-user] 20210713 CVE-2021-36374: Apache Ant ZIP, and ZIP based, archive denial of service vulerability MLIST - [drill-commits] 20210804 [drill] branch master updated: Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-dev] 20210803 [jira] [Created] (DRILL-7981) Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-dev] 20210804 [GitHub] [drill] luocooong merged pull request #2285: DRILL-7981: Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-dev] 20210804 [GitHub] [drill] luocooong opened a new pull request #2285: Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-dev] 20210805 [GitHub] [drill] luocooong merged pull request #2285: DRILL-7981: Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-issues] 20210803 [jira] [Created] (DRILL-7981) Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-issues] 20210804 [jira] [Commented] (DRILL-7981) Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [drill-issues] 20210805 [jira] [Commented] (DRILL-7981) Bump commons-compress from 1.20 to 1.21 for CVE-2021-36090 MLIST - [druid-commits] 20210726 [GitHub] [druid] suneet-s merged pull request #11496: Address CVE-2021-35515 CVE-2021-36090 MLIST - [druid-commits] 20210726 [GitHub] [druid] suneet-s opened a new pull request #11496: Address CVE-2021-35515 CVE-2021-36090 MLIST - [druid-commits] 20210726 [druid] branch master updated: Address CVE-2021-35515 CVE-2021-36090 (#11496) MLIST - [james-notifications] 20210714 [GitHub] [james-project] chibenwa opened a new pull request #537: [UPGRADE] Security upgrade: common-compress to 1.21 MLIST - [oss-security] 20210713 CVE-2021-36090: Apache Commons Compress 1.0 to 1.20 denial of service vulnerability MLIST - [oss-security] 20210713 CVE-2021-36374: Apache Ant ZIP, and ZIP based, archive denial of service vulerability MLIST - [poi-dev] 20210923 Re: [VOTE] Apache POI 5.1.0 release (RC1) MLIST - [pulsar-commits] 20210716 [GitHub] [pulsar] lhotari opened a new pull request #11345: [Security] Upgrade commons-compress to 1.21 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] commented on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [GitHub] [skywalking] wu-sheng opened a new pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210802 [skywalking] 01/01: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] codecov[bot] edited a comment on pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [GitHub] [skywalking] hanahmily merged pull request #7400: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 MLIST - [skywalking-notifications] 20210803 [skywalking] branch master updated: Fix CVE-2021-35515, CVE-2021-35516, CVE-2021-35517, CVE-2021-36090 (#7400) MLIST - [tomcat-dev] 20210811 [GitHub] [tomcat-jakartaee-migration] ebourg commented on issue #23: Vulnerability with Apache Commons Compress v1.20 N/A - N/A OSSINDEX - [CVE-2021-36090] CWE-130: Improper Handling of Length Parameter Inconsistency OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-36090 OSSIndex - https://commons.apache.org/proper/commons-compress/security-reports.html OSSIndex - https://github.com/OpenLiberty/open-liberty/issues/18808 OSSIndex - https://github.com/OpenLiberty/open-liberty/pull/17872 OSSIndex - https://lists.apache.org/thread.html/r0e87177f8e78b4ee453cd4d3d8f4ddec6f10d2c27707dd71e12cafc9@%3Cannounce.apache.org%3E OSSIndex - https://openliberty.io/docs/latest/security-vulnerabilities.html Vulnerable Software & Versions: (show all )
commons-dbcp2-2.9.0.jarDescription:
Apache Commons DBCP software implements Database Connection Pooling License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-dbcp2/2.9.0/commons-dbcp2-2.9.0.jar
MD5: c2a72212a55d105b0eaeaab26557e6e7
SHA1: 16d808749cf3dac900c073dd834b5e288562a59c
SHA256: 887720912c5cbbcdff6e0e21d5034937555f8ffc597381eff8fa77f33ce6d64e
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-dbcp2 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name dbcp2 Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/dbcp/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-dbcp2 Medium Vendor Manifest implementation-build release@r2abdb498d0aa7b65d668fc5661795bc83844d8fa; 2021-07-31 15:06:39+0000 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-dbcp2 Highest Vendor pom artifactid commons-dbcp2 Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email markt@apache.org Low Vendor pom developer email mpoeschl@marmot.at Low Vendor pom developer email yoavs@apache.org Low Vendor pom developer id craigmcc Medium Vendor pom developer id dirkv Medium Vendor pom developer id dweinr1 Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id jmcnally Medium Vendor pom developer id joehni Medium Vendor pom developer id markt Medium Vendor pom developer id morgand Medium Vendor pom developer id mpoeschl Medium Vendor pom developer id nacho Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sullis Medium Vendor pom developer id yoavs Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name David Weinrich Medium Vendor pom developer name Dirk Verbeeck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Ignacio J. Ortega Medium Vendor pom developer name Jörg Schaible Medium Vendor pom developer name John McNally Medium Vendor pom developer name Mark Thomas Medium Vendor pom developer name Martin Poeschl Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Sean C. Sullivan Medium Vendor pom developer name Yoav Shapira Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org tucana.at Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons DBCP High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/dbcp/ Highest Product file name commons-dbcp2 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name dbcp2 Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/dbcp/ Low Product Manifest Bundle-Name Apache Commons DBCP Medium Product Manifest bundle-symbolicname org.apache.commons.commons-dbcp2 Medium Product Manifest implementation-build release@r2abdb498d0aa7b65d668fc5661795bc83844d8fa; 2021-07-31 15:06:39+0000 Low Product Manifest Implementation-Title Apache Commons DBCP High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons DBCP Medium Product pom artifactid commons-dbcp2 Highest Product pom developer email ggregory at apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email markt@apache.org Low Product pom developer email mpoeschl@marmot.at Low Product pom developer email yoavs@apache.org Low Product pom developer id craigmcc Low Product pom developer id dirkv Low Product pom developer id dweinr1 Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id jmcnally Low Product pom developer id joehni Low Product pom developer id markt Low Product pom developer id morgand Low Product pom developer id mpoeschl Low Product pom developer id nacho Low Product pom developer id rwaldhoff Low Product pom developer id sullis Low Product pom developer id yoavs Low Product pom developer name Craig McClanahan Low Product pom developer name David Weinrich Low Product pom developer name Dirk Verbeeck Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Low Product pom developer name Ignacio J. Ortega Low Product pom developer name Jörg Schaible Low Product pom developer name John McNally Low Product pom developer name Mark Thomas Low Product pom developer name Martin Poeschl Low Product pom developer name Morgan Delagrange Low Product pom developer name Rodney Waldhoff Low Product pom developer name Sean C. Sullivan Low Product pom developer name Yoav Shapira Low Product pom developer org The Apache Software Foundation Low Product pom developer org tucana.at Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons DBCP High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/dbcp/ Medium Version file version 2.9.0 High Version Manifest Bundle-Version 2.9.0 High Version Manifest Implementation-Version 2.9.0 High Version pom parent-version 2.9.0 Low Version pom version 2.9.0 Highest
commons-digester-1.5.jarDescription:
The Digester package lets you configure an XML->Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. File Path: /home/andrii/.m2/repository/commons-digester/commons-digester/1.5/commons-digester-1.5.jarMD5: 4bab2d22aa4dc855b13780237831d1f4SHA1: c1dd42b0c244ad2a354219192881be8f4140cdddSHA256: 5b43bd226c9de50fc507a30f964a8d1725b0a3d0e90ea3a0fcaeb33e641b1fc3Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-digester High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name digester Highest Vendor jar package name rules Highest Vendor Manifest extension-name org.apache.commons.digester Medium Vendor Manifest Implementation-Vendor "Apache Software Foundation" High Vendor Manifest specification-vendor "Apache Software Foundation" Low Vendor pom artifactid commons-digester Highest Vendor pom artifactid commons-digester Low Vendor pom developer email Craig.McClanahan@eng.sun.com Low Vendor pom developer email jstrachan@apache.org Low Vendor pom developer email jvanzyl@apache.org Low Vendor pom developer email robertburrelldonkin@blueyonder.co.uk Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id craigmcc Medium Vendor pom developer id jstrachan Medium Vendor pom developer id jvanzyl Medium Vendor pom developer id rdonkin Medium Vendor pom developer id sanders Medium Vendor pom developer id tobrien Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name James Strachan Medium Vendor pom developer name Jason van Zyl Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org Sun Microsystems Medium Vendor pom groupid commons-digester Highest Vendor pom name Digester High Product file name commons-digester High Product jar package name apache Highest Product jar package name commons Highest Product jar package name digester Highest Product jar package name rules Highest Product Manifest extension-name org.apache.commons.digester Medium Product Manifest Implementation-Title "org.apache.commons.digester" High Product Manifest specification-title "Jakarta Commons Digester" Medium Product pom artifactid commons-digester Highest Product pom developer email Craig.McClanahan@eng.sun.com Low Product pom developer email jstrachan@apache.org Low Product pom developer email jvanzyl@apache.org Low Product pom developer email robertburrelldonkin@blueyonder.co.uk Low Product pom developer email sanders@totalsync.com Low Product pom developer email tobrien@apache.org Low Product pom developer id craigmcc Low Product pom developer id jstrachan Low Product pom developer id jvanzyl Low Product pom developer id rdonkin Low Product pom developer id sanders Low Product pom developer id tobrien Low Product pom developer name Craig McClanahan Low Product pom developer name James Strachan Low Product pom developer name Jason van Zyl Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Scott Sanders Low Product pom developer name Tim OBrien Low Product pom developer org Sun Microsystems Low Product pom groupid commons-digester Highest Product pom name Digester High Version file version 1.5 High Version pom version 1.5 Highest
commons-discovery-0.5.jarDescription:
The Apache Commons Discovery component is about discovering, or finding,
implementations for pluggable interfaces. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-discovery/commons-discovery/0.5/commons-discovery-0.5.jar
MD5: b35120680c3a22cec7a037fce196cd97
SHA1: 3a8ac816bbe02d2f88523ef22cbf2c4abd71d6a8
SHA256: e5b7d58ae62e5b309d5c0ffa5a5b1d9d1e0f0c4c3cc18d1fe3103fd29f90149d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-discovery High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name discovery Highest Vendor Manifest bundle-docurl http://commons.apache.org/discovery/ Low Vendor Manifest bundle-symbolicname org.apache.commons.discovery Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-discovery Highest Vendor pom artifactid commons-discovery Low Vendor pom developer email dims@apache.org Low Vendor pom developer email jstrachan@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email rwinston@eircom.net Low Vendor pom developer email simonetripodi@apache.org Low Vendor pom developer id costin Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dims Medium Vendor pom developer id jstrachan Medium Vendor pom developer id matth Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rsitze Medium Vendor pom developer id rwinston Medium Vendor pom developer id simonetripodi Medium Vendor pom developer name Costin Manolache Medium Vendor pom developer name Craig R. McClanahan Medium Vendor pom developer name Davanum Srinivas Medium Vendor pom developer name James Strachan Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Richard Sitze Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rory Winston Medium Vendor pom developer name Simone Tripodi Medium Vendor pom developer org SpiritSoft, Inc. Medium Vendor pom groupid commons-discovery Highest Vendor pom name Commons Discovery High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/discovery/ Highest Product file name commons-discovery High Product jar package name apache Highest Product jar package name commons Highest Product jar package name discovery Highest Product Manifest bundle-docurl http://commons.apache.org/discovery/ Low Product Manifest Bundle-Name Commons Discovery Medium Product Manifest bundle-symbolicname org.apache.commons.discovery Medium Product Manifest Implementation-Title Commons Discovery High Product Manifest specification-title Commons Discovery Medium Product pom artifactid commons-discovery Highest Product pom developer email dims@apache.org Low Product pom developer email jstrachan@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email rwinston@eircom.net Low Product pom developer email simonetripodi@apache.org Low Product pom developer id costin Low Product pom developer id craigmcc Low Product pom developer id dims Low Product pom developer id jstrachan Low Product pom developer id matth Low Product pom developer id rdonkin Low Product pom developer id rsitze Low Product pom developer id rwinston Low Product pom developer id simonetripodi Low Product pom developer name Costin Manolache Low Product pom developer name Craig R. McClanahan Low Product pom developer name Davanum Srinivas Low Product pom developer name James Strachan Low Product pom developer name Matthew Hawthorne Low Product pom developer name Richard Sitze Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rory Winston Low Product pom developer name Simone Tripodi Low Product pom developer org SpiritSoft, Inc. Low Product pom groupid commons-discovery Highest Product pom name Commons Discovery High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/discovery/ Medium Version file version 0.5 High Version Manifest Bundle-Version 0.5 High Version Manifest Implementation-Version 0.5 High Version pom parent-version 0.5 Low Version pom version 0.5 Highest
CVE-2022-0869 suppress
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
commons-fileupload-1.4.jarDescription:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-fileupload/commons-fileupload/1.4/commons-fileupload-1.4.jar
MD5: 0c3b924dcaaa90c3fb93fe04ae96a35e
SHA1: f95188e3d372e20e7328706c37ef366e5d7859b0
SHA256: a4ec02336f49253ea50405698b79232b8c5cbf02cb60df3a674d77a749a1def7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-fileupload High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name fileupload Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-fileupload Medium Vendor Manifest implementation-build UNKNOWN@r047f31576411beee69cf75584ae76531cc9ac753; 2018-12-24 07:06:18+0000 Low Vendor Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-fileupload Highest Vendor pom artifactid commons-fileupload Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jason@zenplex.com Low Vendor pom developer email jmcnally@collab.net Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email sean |at| seansullivan |dot| com Low Vendor pom developer email simonetripodi@apache.org Low Vendor pom developer id chtompki Medium Vendor pom developer id dion Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jmcnally Medium Vendor pom developer id jochen Medium Vendor pom developer id jvanzyl Medium Vendor pom developer id martinc Medium Vendor pom developer id rdonkin Medium Vendor pom developer id simonetripodi Medium Vendor pom developer id sullis Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Jason van Zyl Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name John McNally Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Sean C. Sullivan Medium Vendor pom developer name Simone Tripodi Medium Vendor pom developer org Adobe Medium Vendor pom developer org CollabNet Medium Vendor pom developer org Multitask Consulting Medium Vendor pom developer org Yahoo! Medium Vendor pom developer org Zenplex Medium Vendor pom groupid commons-fileupload Highest Vendor pom name Apache Commons FileUpload High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest Product file name commons-fileupload High Product jar package name apache Highest Product jar package name commons Highest Product jar package name fileupload Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low Product Manifest Bundle-Name Apache Commons FileUpload Medium Product Manifest bundle-symbolicname org.apache.commons.commons-fileupload Medium Product Manifest implementation-build UNKNOWN@r047f31576411beee69cf75584ae76531cc9ac753; 2018-12-24 07:06:18+0000 Low Product Manifest Implementation-Title Apache Commons FileUpload High Product Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache Commons FileUpload Medium Product pom artifactid commons-fileupload Highest Product pom developer email chtompki@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jason@zenplex.com Low Product pom developer email jmcnally@collab.net Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email martinc@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email sean |at| seansullivan |dot| com Low Product pom developer email simonetripodi@apache.org Low Product pom developer id chtompki Low Product pom developer id dion Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jmcnally Low Product pom developer id jochen Low Product pom developer id jvanzyl Low Product pom developer id martinc Low Product pom developer id rdonkin Low Product pom developer id simonetripodi Low Product pom developer id sullis Low Product pom developer name Daniel Rall Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Jason van Zyl Low Product pom developer name Jochen Wiedmann Low Product pom developer name John McNally Low Product pom developer name Martin Cooper Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Sean C. Sullivan Low Product pom developer name Simone Tripodi Low Product pom developer org Adobe Low Product pom developer org CollabNet Low Product pom developer org Multitask Consulting Low Product pom developer org Yahoo! Low Product pom developer org Zenplex Low Product pom groupid commons-fileupload Highest Product pom name Apache Commons FileUpload High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium Version file version 1.4 High Version Manifest Implementation-Version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest
commons-httpclient-3.1-atlassian-2.jarDescription:
The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. License:
Apache License: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/commons-httpclient/commons-httpclient/3.1-atlassian-2/commons-httpclient-3.1-atlassian-2.jar
MD5: 283a27560da413ac4e7305e87a269dfa
SHA1: 1e4ff544b54f14355360aa5908e518f22567215e
SHA256: 522a4695d87fb0809ce335a92ee4c0a01105273ad6b45203eb1495362e6406c3
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-httpclient High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name commons Highest Vendor jar package name commons Low Vendor jar package name httpclient Highest Vendor jar package name httpclient Low Vendor jar package name methods Highest Vendor pom artifactid commons-httpclient Highest Vendor pom artifactid commons-httpclient Low Vendor pom developer email adrian.sutton -at- ephox.com Low Vendor pom developer email dion -at- apache.org Low Vendor pom developer email jericho -at- apache.org Low Vendor pom developer email jsdever -at- apache.org Low Vendor pom developer email mbecke -at- apache.org Low Vendor pom developer email oglueck -at- apache.org Low Vendor pom developer email olegk -at- apache.org Low Vendor pom developer email rwaldhoff -at- apache Low Vendor pom developer email sullis -at- apache.org Low Vendor pom developer id adrian Medium Vendor pom developer id dion Medium Vendor pom developer id jericho Medium Vendor pom developer id jsdever Medium Vendor pom developer id mbecke Medium Vendor pom developer id oglueck Medium Vendor pom developer id olegk Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sullis Medium Vendor pom developer name Adrian Sutton Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Jeff Dever Medium Vendor pom developer name Michael Becke Medium Vendor pom developer name Oleg Kalnichevski Medium Vendor pom developer name Ortwin Glueck Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Sean C. Sullivan Medium Vendor pom developer name Sung-Gu Medium Vendor pom developer org Britannica Medium Vendor pom developer org Independent consultant Medium Vendor pom developer org Intencha Medium Vendor pom developer org Multitask Consulting Medium Vendor pom groupid commons-httpclient Highest Vendor pom name HttpClient High Vendor pom organization name Apache Software Foundation High Vendor pom organization url http://jakarta.apache.org/ Medium Vendor pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Highest Product file name commons-httpclient High Product jar package name apache Highest Product jar package name commons Highest Product jar package name commons Low Product jar package name httpclient Highest Product jar package name httpclient Low Product jar package name methods Highest Product pom artifactid commons-httpclient Highest Product pom developer email adrian.sutton -at- ephox.com Low Product pom developer email dion -at- apache.org Low Product pom developer email jericho -at- apache.org Low Product pom developer email jsdever -at- apache.org Low Product pom developer email mbecke -at- apache.org Low Product pom developer email oglueck -at- apache.org Low Product pom developer email olegk -at- apache.org Low Product pom developer email rwaldhoff -at- apache Low Product pom developer email sullis -at- apache.org Low Product pom developer id adrian Low Product pom developer id dion Low Product pom developer id jericho Low Product pom developer id jsdever Low Product pom developer id mbecke Low Product pom developer id oglueck Low Product pom developer id olegk Low Product pom developer id rwaldhoff Low Product pom developer id sullis Low Product pom developer name Adrian Sutton Low Product pom developer name dIon Gillard Low Product pom developer name Jeff Dever Low Product pom developer name Michael Becke Low Product pom developer name Oleg Kalnichevski Low Product pom developer name Ortwin Glueck Low Product pom developer name Rodney Waldhoff Low Product pom developer name Sean C. Sullivan Low Product pom developer name Sung-Gu Low Product pom developer org Britannica Low Product pom developer org Independent consultant Low Product pom developer org Intencha Low Product pom developer org Multitask Consulting Low Product pom groupid commons-httpclient Highest Product pom name HttpClient High Product pom organization name Apache Software Foundation Low Product pom organization url http://jakarta.apache.org/ Low Product pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Medium Version pom version 3.1-atlassian-2 Highest
CVE-2012-5783 (OSSINDEX) suppress
Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. CWE-295 Improper Certificate Validation
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:commons-httpclient:commons-httpclient:3.1-atlassian-2:*:*:*:*:*:*:* CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
commons-io-2.8.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-io/commons-io/2.8.0/commons-io-2.8.0.jar
MD5: 21ba575792e2694c39af13918a80550b
SHA1: 92999e26e6534606b5678014e66948286298a35c
SHA256: 02f291e5d1243dc143496e3cbbb40a1ced47aa58f2d633d3e38780cd068d5074
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Highest Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory@apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.8.0 High Version Manifest Bundle-Version 2.8.0 High Version Manifest Implementation-Version 2.8.0 High Version pom parent-version 2.8.0 Low Version pom version 2.8.0 Highest
commons-jcs-core-2.2.1.jarDescription:
Apache Commons JCS is a distributed, versatile caching system. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-jcs-core/2.2.1/commons-jcs-core-2.2.1.jar
MD5: fd41b509c3853faf088e5c340402d609
SHA1: 3ffac1956b0d88fff8adefdf1e68d69cfe296191
SHA256: 7f98edf1e69b32137a2181722dadd1220f61d184414df17061a0e10e40535a2d
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-jcs-core High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name jcs Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-jcs/commons-jcs-core/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-jcs-core Medium Vendor Manifest implementation-build tags/commons-jcs-2.2.1-RC4/commons-jcs-core@r1838701; 2018-08-23 08:44:59+0000 Low Vendor Manifest implementation-url http://commons.apache.org/proper/commons-jcs/commons-jcs-core/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-jcs-core Highest Vendor pom artifactid commons-jcs-core Low Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons JCS :: Core High Vendor pom parent-artifactid commons-jcs Low Product file name commons-jcs-core High Product jar package name apache Highest Product jar package name commons Highest Product jar package name jcs Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-jcs/commons-jcs-core/ Low Product Manifest Bundle-Name Apache Commons JCS :: Core Medium Product Manifest bundle-symbolicname org.apache.commons.commons-jcs-core Medium Product Manifest implementation-build tags/commons-jcs-2.2.1-RC4/commons-jcs-core@r1838701; 2018-08-23 08:44:59+0000 Low Product Manifest Implementation-Title Apache Commons JCS :: Core High Product Manifest implementation-url http://commons.apache.org/proper/commons-jcs/commons-jcs-core/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache Commons JCS :: Core Medium Product pom artifactid commons-jcs-core Highest Product pom groupid org.apache.commons Highest Product pom name Apache Commons JCS :: Core High Product pom parent-artifactid commons-jcs Medium Version file version 2.2.1 High Version Manifest Bundle-Version 2.2.1 High Version Manifest Implementation-Version 2.2.1 High Version pom version 2.2.1 Highest
commons-jrcs-diff-0.1.7.jarFile Path: /home/andrii/.m2/repository/commons-jrcs/commons-jrcs/diff-0.1.7/commons-jrcs-diff-0.1.7.jarMD5: 713d64be8b4501f9a16300015cb1f06eSHA1: 36e7256f61983431dc218f9353a53e88c136c058SHA256: 7eea7d16fb486f25a27c312b9e99c69043be8ca30efa3c2569767b07bb4451d2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-jrcs-diff High Vendor jar package name apache Low Vendor jar package name commons Highest Vendor jar package name commons Low Vendor jar package name jrcs Highest Vendor jar package name jrcs Low Vendor pom artifactid commons-jrcs Highest Vendor pom artifactid commons-jrcs Low Vendor pom groupid commons-jrcs Highest Product file name commons-jrcs-diff High Product jar package name commons Highest Product jar package name commons Low Product jar package name diff Low Product jar package name jrcs Highest Product jar package name jrcs Low Product pom artifactid commons-jrcs Highest Product pom groupid commons-jrcs Highest Version pom version diff-0.1.7 Highest
commons-lang-2.6.jarDescription:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
SHA256: 50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-lang High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang Highest Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang Highest Vendor pom artifactid commons-lang Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@seagullsw.com Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email phil@steitz.com Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id psteitz Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary D. Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Phil Steitz Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org Seagull Software Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom groupid commons-lang Highest Vendor pom name Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/lang/ Highest Product file name commons-lang High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang Highest Product Manifest bundle-docurl http://commons.apache.org/lang/ Low Product Manifest Bundle-Name Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang Medium Product Manifest Implementation-Title Commons Lang High Product Manifest specification-title Commons Lang Medium Product pom artifactid commons-lang Highest Product pom developer email bayard@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@seagullsw.com Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email phil@steitz.com Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id psteitz Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Daniel Rall Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary D. Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Phil Steitz Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org Seagull Software Low Product pom developer org SITA ATS Ltd Low Product pom groupid commons-lang Highest Product pom name Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/lang/ Medium Version file version 2.6 High Version Manifest Bundle-Version 2.6 High Version Manifest Implementation-Version 2.6 High Version pom parent-version 2.6 Low Version pom version 2.6 Highest
commons-lang3-3.9.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-lang3/3.9/commons-lang3-3.9.jar
MD5: fa752c3cb5474b05e14bf2ed7e242020
SHA1: 0122c7cee69b53ed4a7681c03d4ee4c0e2765da5
SHA256: de2e1dcdcf3ef917a8ce858661a06726a9a944f28e33ad7f9e08bea44dc3c230
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Highest Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary D. Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary D. Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-lang/ Medium Version file version 3.9 High Version Manifest Implementation-Version 3.9 High Version pom parent-version 3.9 Low Version pom version 3.9 Highest
commons-logging-1.0.4.jarDescription:
Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
The Apache Software License, Version 2.0: /LICENSE.txt File Path: /home/andrii/.m2/repository/commons-logging/commons-logging/1.0.4/commons-logging-1.0.4.jar
MD5: 8a507817b28077e0478add944c64586a
SHA1: f029a2aefe2b3e1517573c580f948caac31b1056
SHA256: e94af49749384c11f5aa50e8d0f5fe679be771295b52030338d32843c980351e
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-logging High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor Manifest extension-name org.apache.commons.logging Medium Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor Manifest specification-vendor Apache Software Foundation Low Vendor pom artifactid commons-logging Highest Vendor pom artifactid commons-logging Low Vendor pom developer email baliuka@apache.org Low Vendor pom developer email costin at apache dot org Low Vendor pom developer email craigmcc at apache org Low Vendor pom developer email donaldp at apache dot org Low Vendor pom developer email morgand at apache dot org Low Vendor pom developer email rdonkin at apache dot org Low Vendor pom developer email rsitze at apache dot org Low Vendor pom developer email rwaldhoff at apache org Low Vendor pom developer email sanders at apache dot org Low Vendor pom developer id baliuka Medium Vendor pom developer id costin Medium Vendor pom developer id craigmcc Medium Vendor pom developer id donaldp Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rsitze Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer name Costin Manolache Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Juozas Baliuka Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Peter Donald Medium Vendor pom developer name Richard Sitze Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer org Apache Medium Vendor pom developer org Apache Software Foundation Medium Vendor pom groupid commons-logging Highest Vendor pom name Logging High Vendor pom organization name The Apache Software Foundation High Vendor pom organization url http://jakarta.apache.org Medium Vendor pom url http://jakarta.apache.org/commons/logging/ Highest Product file name commons-logging High Product jar package name apache Highest Product jar package name commons Highest Product jar package name logging Highest Product Manifest extension-name org.apache.commons.logging Medium Product pom artifactid commons-logging Highest Product pom developer email baliuka@apache.org Low Product pom developer email costin at apache dot org Low Product pom developer email craigmcc at apache org Low Product pom developer email donaldp at apache dot org Low Product pom developer email morgand at apache dot org Low Product pom developer email rdonkin at apache dot org Low Product pom developer email rsitze at apache dot org Low Product pom developer email rwaldhoff at apache org Low Product pom developer email sanders at apache dot org Low Product pom developer id baliuka Low Product pom developer id costin Low Product pom developer id craigmcc Low Product pom developer id donaldp Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rsitze Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer name Costin Manolache Low Product pom developer name Craig McClanahan Low Product pom developer name Juozas Baliuka Low Product pom developer name Morgan Delagrange Low Product pom developer name Peter Donald Low Product pom developer name Richard Sitze Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer org Apache Low Product pom developer org Apache Software Foundation Low Product pom groupid commons-logging Highest Product pom name Logging High Product pom organization name The Apache Software Foundation Low Product pom organization url http://jakarta.apache.org Low Product pom url http://jakarta.apache.org/commons/logging/ Medium Version file version 1.0.4 High Version Manifest Implementation-Version 1.0.4 High Version pom version 1.0.4 Highest
commons-math3-3.6.1.jarDescription:
The Apache Commons Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-math3/3.6.1/commons-math3-3.6.1.jar
MD5: 5b730d97e4e6368069de1983937c508e
SHA1: e4ba98f1d4b3c80ec46392f25e094a6a2e58fcbf
SHA256: 1e56d7b058d28b65abd256b8458e3885b674c1d588fa43cd7d1cbb9c7ef2b308
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-math3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name math3 Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-math/ Low Vendor Manifest bundle-symbolicname org.apache.commons.math3 Medium Vendor Manifest implementation-build 16abfe5de688cc52fb0396e0609cb33044b15653; 2016-03-17 13:30:43-0400 Low Vendor Manifest implementation-url http://commons.apache.org/proper/commons-math/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-math3 Highest Vendor pom artifactid commons-math3 Low Vendor pom developer email achou at apache dot org Low Vendor pom developer email billbarker at apache dot org Low Vendor pom developer email brentworden at apache dot org Low Vendor pom developer email celestin at apache dot org Low Vendor pom developer email dimpbx at apache dot org Low Vendor pom developer email erans at apache dot org Low Vendor pom developer email evanward at apache dot org Low Vendor pom developer email gregs at apache dot org Low Vendor pom developer email j3322ptm at yahoo dot de Low Vendor pom developer email luc at apache dot org Low Vendor pom developer email mdiggory at apache dot org Low Vendor pom developer email mikl at apache dot org Low Vendor pom developer email oertl at apache dot org Low Vendor pom developer email rdonkin at apache dot org Low Vendor pom developer email tn at apache dot org Low Vendor pom developer email tobrien at apache dot org Low Vendor pom developer id achou Medium Vendor pom developer id billbarker Medium Vendor pom developer id brentworden Medium Vendor pom developer id celestin Medium Vendor pom developer id dimpbx Medium Vendor pom developer id erans Medium Vendor pom developer id evanward Medium Vendor pom developer id gregs Medium Vendor pom developer id luc Medium Vendor pom developer id mdiggory Medium Vendor pom developer id mikl Medium Vendor pom developer id oertl Medium Vendor pom developer id pietsch Medium Vendor pom developer id rdonkin Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Albert Davidson Chou Medium Vendor pom developer name Bill Barker Medium Vendor pom developer name Brent Worden Medium Vendor pom developer name Dimitri Pourbaix Medium Vendor pom developer name Evan Ward Medium Vendor pom developer name Gilles Sadowski Medium Vendor pom developer name Greg Sterijevski Medium Vendor pom developer name J. Pietschmann Medium Vendor pom developer name Luc Maisonobe Medium Vendor pom developer name Mark Diggory Medium Vendor pom developer name Mikkel Meyer Andersen Medium Vendor pom developer name Otmar Ertl Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Sébastien Brisard Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim O'Brien Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Math High Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-math/ Highest Product file name commons-math3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name filter Highest Product jar package name math3 Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-math/ Low Product Manifest Bundle-Name Apache Commons Math Medium Product Manifest bundle-symbolicname org.apache.commons.math3 Medium Product Manifest implementation-build 16abfe5de688cc52fb0396e0609cb33044b15653; 2016-03-17 13:30:43-0400 Low Product Manifest Implementation-Title Apache Commons Math High Product Manifest implementation-url http://commons.apache.org/proper/commons-math/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low Product Manifest specification-title Apache Commons Math Medium Product pom artifactid commons-math3 Highest Product pom developer email achou at apache dot org Low Product pom developer email billbarker at apache dot org Low Product pom developer email brentworden at apache dot org Low Product pom developer email celestin at apache dot org Low Product pom developer email dimpbx at apache dot org Low Product pom developer email erans at apache dot org Low Product pom developer email evanward at apache dot org Low Product pom developer email gregs at apache dot org Low Product pom developer email j3322ptm at yahoo dot de Low Product pom developer email luc at apache dot org Low Product pom developer email mdiggory at apache dot org Low Product pom developer email mikl at apache dot org Low Product pom developer email oertl at apache dot org Low Product pom developer email rdonkin at apache dot org Low Product pom developer email tn at apache dot org Low Product pom developer email tobrien at apache dot org Low Product pom developer id achou Low Product pom developer id billbarker Low Product pom developer id brentworden Low Product pom developer id celestin Low Product pom developer id dimpbx Low Product pom developer id erans Low Product pom developer id evanward Low Product pom developer id gregs Low Product pom developer id luc Low Product pom developer id mdiggory Low Product pom developer id mikl Low Product pom developer id oertl Low Product pom developer id pietsch Low Product pom developer id rdonkin Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Albert Davidson Chou Low Product pom developer name Bill Barker Low Product pom developer name Brent Worden Low Product pom developer name Dimitri Pourbaix Low Product pom developer name Evan Ward Low Product pom developer name Gilles Sadowski Low Product pom developer name Greg Sterijevski Low Product pom developer name J. Pietschmann Low Product pom developer name Luc Maisonobe Low Product pom developer name Mark Diggory Low Product pom developer name Mikkel Meyer Andersen Low Product pom developer name Otmar Ertl Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Sébastien Brisard Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim O'Brien Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Math High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-math/ Medium Version file version 3.6.1 High Version Manifest Bundle-Version 3.6.1 High Version Manifest Implementation-Version 3.6.1 High Version pom parent-version 3.6.1 Low Version pom version 3.6.1 Highest
commons-pool-1.6.jarDescription:
Commons Object Pooling Library License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
SHA256: 46c42b4a38dc6b2db53a9ee5c92c63db103665d56694e2cfce2c95d51a6860cc
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name commons-pool High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name pool Highest Vendor Manifest bundle-docurl http://commons.apache.org/pool/ Low Vendor Manifest bundle-symbolicname org.apache.commons.pool Medium Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-pool Highest Vendor pom artifactid commons-pool Low Vendor pom developer id craigmcc Medium Vendor pom developer id dirkv Medium Vendor pom developer id dweinr1 Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sandymac Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name David Weinrich Medium Vendor pom developer name Dirk Verbeeck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Sandy McArthur Medium Vendor pom developer org Apache Software Foundation Medium Vendor pom groupid commons-pool Highest Vendor pom name Commons Pool High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/pool/ Highest Product file name commons-pool High Product jar package name apache Highest Product jar package name commons Highest Product jar package name pool Highest Product Manifest bundle-docurl http://commons.apache.org/pool/ Low Product Manifest Bundle-Name Commons Pool Medium Product Manifest bundle-symbolicname org.apache.commons.pool Medium Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low Product Manifest Implementation-Title Commons Pool High Product Manifest specification-title Commons Pool Medium Product pom artifactid commons-pool Highest Product pom developer id craigmcc Low Product pom developer id dirkv Low Product pom developer id dweinr1 Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id sandymac Low Product pom developer name Craig McClanahan Low Product pom developer name David Weinrich Low Product pom developer name Dirk Verbeeck Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Low Product pom developer name Morgan Delagrange Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Sandy McArthur Low Product pom developer org Apache Software Foundation Low Product pom groupid commons-pool Highest Product pom name Commons Pool High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/pool/ Medium Version file version 1.6 High Version Manifest Implementation-Version 1.6 High Version pom parent-version 1.6 Low Version pom version 1.6 Highest
commons-pool2-2.6.2.jarDescription:
The Apache Commons Object Pooling Library. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-pool2/2.6.2/commons-pool2-2.6.2.jar
MD5: 696197d79439773526f300b1a5eb38c9
SHA1: 775a8072995b29eafe8fb0a828a190589f71cede
SHA256: 689091759a3a4d8da3be38480e3df3fbcb3c3c9d81811d40cb64c56ae62e68f7
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-pool2 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name pool2 Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-pool/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-pool2 Medium Vendor Manifest implementation-build release@r06de412e2ce72007a6e43112164c371de4a66d3b; 2019-04-06 01:16:08+0000 Low Vendor Manifest implementation-url http://commons.apache.org/proper/commons-pool/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-pool2 Highest Vendor pom artifactid commons-pool2 Low Vendor pom developer id craigmcc Medium Vendor pom developer id dirkv Medium Vendor pom developer id dweinr1 Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id mattsicker Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sandymac Medium Vendor pom developer id simonetripodi Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name David Weinrich Medium Vendor pom developer name Dirk Verbeeck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Matt Sicker Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Sandy McArthur Medium Vendor pom developer name Simone Tripodi Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Pool High Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-pool/ Highest Product file name commons-pool2 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name pool2 Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-pool/ Low Product Manifest Bundle-Name Apache Commons Pool Medium Product Manifest bundle-symbolicname org.apache.commons.commons-pool2 Medium Product Manifest implementation-build release@r06de412e2ce72007a6e43112164c371de4a66d3b; 2019-04-06 01:16:08+0000 Low Product Manifest Implementation-Title Apache Commons Pool High Product Manifest implementation-url http://commons.apache.org/proper/commons-pool/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Apache Commons Pool Medium Product pom artifactid commons-pool2 Highest Product pom developer id craigmcc Low Product pom developer id dirkv Low Product pom developer id dweinr1 Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id mattsicker Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id sandymac Low Product pom developer id simonetripodi Low Product pom developer name Craig McClanahan Low Product pom developer name David Weinrich Low Product pom developer name Dirk Verbeeck Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Low Product pom developer name Matt Sicker Low Product pom developer name Morgan Delagrange Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Sandy McArthur Low Product pom developer name Simone Tripodi Low Product pom developer org The Apache Software Foundation Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Pool High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-pool/ Medium Version file version 2.6.2 High Version Manifest Bundle-Version 2.6.2 High Version Manifest Implementation-Version 2.6.2 High Version pom parent-version 2.6.2 Low Version pom version 2.6.2 Highest
commons-text-1.6.jarDescription:
Apache Commons Text is a library focused on algorithms working on strings. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/commons/commons-text/1.6/commons-text-1.6.jar
MD5: a1fb840c3963ed43c78291b5e61d55ac
SHA1: ba72cf0c40cf701e972fe7720ae844629f4ecca2
SHA256: df45e56549b63e0fe716953c9d43cc158f8bf008baf60498e7c17f3faa00a70b
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-text High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name text Highest Vendor Manifest automatic-module-name org.apache.commons.text Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-text Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-text Medium Vendor Manifest implementation-url http://commons.apache.org/proper/commons-text Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-text Highest Vendor pom artifactid commons-text Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email kinow@apache.org Low Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id ggregory Medium Vendor pom developer id kinow Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Bruno P. Kinoshita Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Rob Tompkins Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Text High Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-text Highest Product file name commons-text High Product jar package name apache Highest Product jar package name commons Highest Product jar package name text Highest Product Manifest automatic-module-name org.apache.commons.text Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-text Low Product Manifest Bundle-Name Apache Commons Text Medium Product Manifest bundle-symbolicname org.apache.commons.commons-text Medium Product Manifest Implementation-Title Apache Commons Text High Product Manifest implementation-url http://commons.apache.org/proper/commons-text Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Text Medium Product pom artifactid commons-text Highest Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email ggregory@apache.org Low Product pom developer email kinow@apache.org Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id ggregory Low Product pom developer id kinow Low Product pom developer name Benedikt Ritter Low Product pom developer name Bruno P. Kinoshita Low Product pom developer name Duncan Jones Low Product pom developer name Gary Gregory Low Product pom developer name Rob Tompkins Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Text High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-text Medium Version file version 1.6 High Version Manifest Implementation-Version 1.6 High Version pom parent-version 1.6 Low Version pom version 1.6 Highest
CVE-2022-42889 suppress
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
commons-validator-1.5.1.jarDescription:
Apache Commons Validator provides the building blocks for both client side validation and server side data validation.
It may be used standalone or with a framework like Struts.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/commons-validator/commons-validator/1.5.1/commons-validator-1.5.1.jar
MD5: 67fad26aa0c1e884a6aa4249a6126a88
SHA1: 86d05a46e8f064b300657f751b5a98c62807e2a0
SHA256: 142f83e56fed6d46d0472779cdbd52cd856894bc5189ac73f3e02b79f84b3dd6
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name commons-validator High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name validator Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-validator/ Low Vendor Manifest bundle-symbolicname org.apache.commons.validator Medium Vendor Manifest implementation-build tags/VALIDATOR_1_5_1_RC2@r1740857; 2016-04-25 17:32:34+0000 Low Vendor Manifest implementation-url http://commons.apache.org/proper/commons-validator/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-validator Highest Vendor pom artifactid commons-validator Low Vendor pom developer email craigmcc@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dwinterfeldt@apache.org Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email husted@apache.org Low Vendor pom developer email jmitchell NOSPAM apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email mrdon@apache.org Low Vendor pom developer email rleland at apache.org Low Vendor pom developer email turner@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id bspeakmon Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dgraham Medium Vendor pom developer id dwinterfeldt Medium Vendor pom developer id ggregory Medium Vendor pom developer id husted Medium Vendor pom developer id jmitchell Medium Vendor pom developer id martinc Medium Vendor pom developer id mrdon Medium Vendor pom developer id niallp Medium Vendor pom developer id nick Medium Vendor pom developer id rleland Medium Vendor pom developer id simonetripodi Medium Vendor pom developer id turner Medium Vendor pom developer name Ben Speakmon Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name David Graham Medium Vendor pom developer name David Winterfeldt Medium Vendor pom developer name Don Brown Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Mitchell Medium Vendor pom developer name James Turner Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nick Burch Medium Vendor pom developer name Rob Leland Medium Vendor pom developer name SimoneTripodi Medium Vendor pom developer name Ted Husted Medium Vendor pom developer org EdgeTech, Inc Medium Vendor pom groupid commons-validator Highest Vendor pom name Apache Commons Validator High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-validator/ Highest Product file name commons-validator High Product jar package name apache Highest Product jar package name commons Highest Product jar package name validator Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-validator/ Low Product Manifest Bundle-Name Apache Commons Validator Medium Product Manifest bundle-symbolicname org.apache.commons.validator Medium Product Manifest implementation-build tags/VALIDATOR_1_5_1_RC2@r1740857; 2016-04-25 17:32:34+0000 Low Product Manifest Implementation-Title Apache Commons Validator High Product Manifest implementation-url http://commons.apache.org/proper/commons-validator/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache Commons Validator Medium Product pom artifactid commons-validator Highest Product pom developer email craigmcc@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dwinterfeldt@apache.org Low Product pom developer email ggregory@apache.org Low Product pom developer email husted@apache.org Low Product pom developer email jmitchell NOSPAM apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email mrdon@apache.org Low Product pom developer email rleland at apache.org Low Product pom developer email turner@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id bspeakmon Low Product pom developer id craigmcc Low Product pom developer id dgraham Low Product pom developer id dwinterfeldt Low Product pom developer id ggregory Low Product pom developer id husted Low Product pom developer id jmitchell Low Product pom developer id martinc Low Product pom developer id mrdon Low Product pom developer id niallp Low Product pom developer id nick Low Product pom developer id rleland Low Product pom developer id simonetripodi Low Product pom developer id turner Low Product pom developer name Ben Speakmon Low Product pom developer name Benedikt Ritter Low Product pom developer name Craig McClanahan Low Product pom developer name David Graham Low Product pom developer name David Winterfeldt Low Product pom developer name Don Brown Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Mitchell Low Product pom developer name James Turner Low Product pom developer name Martin Cooper Low Product pom developer name Niall Pemberton Low Product pom developer name Nick Burch Low Product pom developer name Rob Leland Low Product pom developer name SimoneTripodi Low Product pom developer name Ted Husted Low Product pom developer org EdgeTech, Inc Low Product pom groupid commons-validator Highest Product pom name Apache Commons Validator High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-validator/ Medium Version file version 1.5.1 High Version Manifest Bundle-Version 1.5.1 High Version Manifest Implementation-Version 1.5.1 High Version pom parent-version 1.5.1 Low Version pom version 1.5.1 Highest
compiler-0.9.6.jarDescription:
Implementation of mustache.js for Java License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/github/spullara/mustache/java/compiler/0.9.6/compiler-0.9.6.jar
MD5: 9245fdbf50ad59ea81781ebdaa8cdb02
SHA1: 1b8707299c34406ed0ba40bbf8513352ac4765c9
SHA256: c4d697fd3619cb616cc5e22e9530c8a4fd4a8e9a76953c0655ee627cb2d22318
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name compiler High Vendor jar package name github Highest Vendor jar package name mustache Highest Vendor jar package name mustachejava Highest Vendor Manifest automatic-module-name com.github.mustachejava Medium Vendor pom artifactid compiler Highest Vendor pom artifactid compiler Low Vendor pom developer email sam@sampullara.com Low Vendor pom developer name Sam Pullara Medium Vendor pom groupid com.github.spullara.mustache.java Highest Vendor pom name compiler High Vendor pom parent-artifactid mustache.java Low Vendor pom url http://github.com/spullara/mustache.java Highest Product file name compiler High Product jar package name github Highest Product jar package name mustache Highest Product jar package name mustachejava Highest Product Manifest automatic-module-name com.github.mustachejava Medium Product pom artifactid compiler Highest Product pom developer email sam@sampullara.com Low Product pom developer name Sam Pullara Low Product pom groupid com.github.spullara.mustache.java Highest Product pom name compiler High Product pom parent-artifactid mustache.java Medium Product pom url http://github.com/spullara/mustache.java Medium Version file version 0.9.6 High Version pom version 0.9.6 Highest
confluence-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/confluence/7.13.0/confluence-7.13.0.jarMD5: 1ccb8b898e0e3d2343b292d04deceef6SHA1: 59d799a3b0a47783f4a1a4f3f4ebf9c63b91e06fSHA256: 05e67dd3a7f62abf26909a4b2f472299329c8e903f2dfbb191391eada297ddb6Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name confluence High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name confluence Highest Vendor jar package name confluence Low Vendor jar package name core Highest Vendor pom artifactid confluence Highest Vendor pom artifactid confluence Low Vendor pom groupid com.atlassian.confluence Highest Vendor pom name Confluence Core High Vendor pom parent-artifactid confluence-core Low Product file name confluence High Product jar package name atlassian Highest Product jar package name confluence Highest Product jar package name confluence Low Product jar package name core Highest Product pom artifactid confluence Highest Product pom groupid com.atlassian.confluence Highest Product pom name Confluence Core High Product pom parent-artifactid confluence-core Medium Version file version 7.13.0 High Version pom version 7.13.0 Highest
Related Dependencies confluence-bucket-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/confluence-bucket/7.13.0/confluence-bucket-7.13.0.jar MD5: 49ff0ac871ad7da7aac3ab855c76fc58 SHA1: 12e1c018266538b986588b859eadc7ab0a9ac750 SHA256: 05c1c42118f57c99f405333e786918d5223bbc4d63bc01cabe41a5ec079d4897 pkg:maven/com.atlassian.confluence/confluence-bucket@7.13.0 confluence-cache-spi-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/cache/confluence-cache-spi/7.13.0/confluence-cache-spi-7.13.0.jar MD5: 223535e18634a3f79c0e1f7ac696e2c6 SHA1: fdca18fec5f8bb616b70f87bd2e0c5a0e42b46c7 SHA256: a20fc5f440a405167e828cc4bc85ae99fb44694f96e1ce7b83d53f085c1e9ff1 pkg:maven/com.atlassian.confluence.cache/confluence-cache-spi@7.13.0 confluence-java-api-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/confluence-java-api/7.13.0/confluence-java-api-7.13.0.jar MD5: b664f39d65debe6edf781c76c2d0f4a1 SHA1: 2b17abcf3754d1e6e6846c53937b5dde3a0f8630 SHA256: 10926d02215a23d242b1f442cfb920b0748934705ca12814b3246eadd4257f33 pkg:maven/com.atlassian.confluence/confluence-java-api@7.13.0 confluence-rest-api-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/confluence-rest-api/7.13.0/confluence-rest-api-7.13.0.jar MD5: 5348ceffd0dc07200eadc4154abb3840 SHA1: 1d550660768162217841f076ec9239908b76e470 SHA256: c4080ea5b09f155595ddcadbea2dfb544a0a8d9fb65e35a7d2fb12efcd98011c pkg:maven/com.atlassian.confluence/confluence-rest-api@7.13.0 confluence-rest-serialization-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/confluence-rest-serialization/7.13.0/confluence-rest-serialization-7.13.0.jar MD5: fa1361f73a1cbc6a558721d193b9f0b1 SHA1: f0aa7711f27778ff0b0050e38950af741c7d9a9f SHA256: 6541203bbb7caee141bc5e04caed388e1fc5374235ffbe3d8c98e92ce6007354 pkg:maven/com.atlassian.confluence/confluence-rest-serialization@7.13.0 confluence-upgrade-7.13.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/confluence-upgrade/7.13.0/confluence-upgrade-7.13.0.jar MD5: bb8773b7c40f1bd9b816bf38b68aa247 SHA1: f00755c05cc11e27b511389d5d6dbb8c087f084b SHA256: a91712d14011262e128e0a6a354b499bc328cc7ea6b63919aa2d0cbf230dba0b pkg:maven/com.atlassian.confluence/confluence-upgrade@7.13.0 confluence-compat-lib-1.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/confluence/compat/confluence-compat-lib/1.0.0/confluence-compat-lib-1.0.0.jarMD5: 816090fdf2e323f32a7afabba27f5eb2SHA1: 48fb39610a4eec4dbb96339ce24bb0bc19e6fac3SHA256: 1800005119ec2da5cd18d66a6d482dc942c37e03b7a53d19196528306d56c40aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name confluence-compat-lib High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name compat Highest Vendor jar package name compat Low Vendor jar package name confluence Highest Vendor jar package name confluence Low Vendor pom artifactid confluence-compat-lib Highest Vendor pom artifactid confluence-compat-lib Low Vendor pom groupid com.atlassian.confluence.compat Highest Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name confluence-compat-lib High Product jar package name api Low Product jar package name atlassian Highest Product jar package name compat Highest Product jar package name compat Low Product jar package name confluence Highest Product jar package name confluence Low Product pom artifactid confluence-compat-lib Highest Product pom groupid com.atlassian.confluence.compat Highest Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.0.0 High Version pom parent-version 1.0.0 Low Version pom version 1.0.0 Highest
CVE-2019-3395 suppress
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-3396 suppress
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2012-2926 suppress
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20406 suppress
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability. CWE-427 Uncontrolled Search Path Element
CVSSv2:
Base Score: MEDIUM (4.4) Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2015-8398 suppress
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2016-6283 suppress
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-16856 suppress
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18085 suppress
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18086 suppress
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2016-4317 suppress
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18083 suppress
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18084 suppress
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2018-13389 suppress
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.7) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2020-4027 suppress
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1. CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: MEDIUM (4.7) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2015-8399 suppress
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2019-15005 suppress
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
confluence-extractor-api-plugin-2.0.9.jarLicense:
BSD License: https://maven.atlassian.com/public/licenses/license.txt File Path: /home/andrii/.m2/repository/com/atlassian/confluence/plugins/confluence-extractor-api-plugin/2.0.9/confluence-extractor-api-plugin-2.0.9.jar
MD5: 1b97fcee37b798559829e425dcb41b3a
SHA1: fdcbc19677fb9d05e43883c11e4a04fbf726a866
SHA256: 86e471689512c5e016c7a545baa13d28d47d82d1e0b1cd9a7bf27bf23be0d069
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name confluence-extractor-api-plugin High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name confluence Highest Vendor jar package name confluence Low Vendor jar package name plugins Highest Vendor jar package name plugins Low Vendor pom artifactid confluence-extractor-api-plugin Highest Vendor pom artifactid confluence-extractor-api-plugin Low Vendor pom groupid com.atlassian.confluence.plugins Highest Vendor pom name Confluence Extractor API High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name confluence-extractor-api-plugin High Product jar package name atlassian Highest Product jar package name confluence Highest Product jar package name confluence Low Product jar package name index Low Product jar package name plugins Highest Product jar package name plugins Low Product pom artifactid confluence-extractor-api-plugin Highest Product pom groupid com.atlassian.confluence.plugins Highest Product pom name Confluence Extractor API High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 2.0.9 High Version pom parent-version 2.0.9 Low Version pom version 2.0.9 Highest
CVE-2019-3395 suppress
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version 6.9.0 before 6.9.3 (the fixed version for 6.9.x) allows remote attackers to send arbitrary HTTP and WebDAV requests from a Confluence Server or Data Center instance via Server-Side Request Forgery. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-3396 suppress
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2012-2926 suppress
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-3398 suppress
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space can exploit this path traversal vulnerability to write files to arbitrary locations which can lead to remote code execution on systems that run a vulnerable version of Confluence Server or Data Center. All versions of Confluence Server from 2.0.0 before 6.6.13 (the fixed version for 6.6.x), from 6.7.0 before 6.12.4 (the fixed version for 6.12.x), from 6.13.0 before 6.13.4 (the fixed version for 6.13.x), from 6.14.0 before 6.14.3 (the fixed version for 6.14.x), and from 6.15.0 before 6.15.2 are affected by this vulnerability. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20406 suppress
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability. CWE-427 Uncontrolled Search Path Element
CVSSv2:
Base Score: MEDIUM (4.4) Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2015-8398 suppress
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to rest/prototype/1/session/check. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2016-6283 suppress
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or HTML via the newFileName parameter to pages/doeditattachment.action. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-16856 suppress
The RSS Feed macro in Atlassian Confluence before version 6.5.2 allows remote attackers to inject arbitrary HTML or JavaScript via cross site scripting (XSS) vulnerabilities in various rss properties which were used as links without restriction on their scheme. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18085 suppress
The viewdefaultdecorator resource in Atlassian Confluence Server before version 6.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the key parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18086 suppress
Various resources in Atlassian Confluence Server before version 6.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuesURL parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2016-4317 suppress
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18083 suppress
The editinword resource in Atlassian Confluence Server before version 6.4.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the contents of an uploaded file. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18084 suppress
The usermacros resource in Atlassian Confluence Server before version 6.3.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the description of a macro. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2018-13389 suppress
The attachment resource in Atlassian Confluence before version 6.6.1 allows remote attackers to spoof web content in the Mozilla Firefox Browser through attachments that have a content-type of application/rdf+xml. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.7) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2020-4027 suppress
Affected versions of Atlassian Confluence Server and Data Center allowed remote attackers with system administration permissions to bypass velocity template injection mitigations via an injection vulnerability in custom user macros. The affected versions are before version 7.4.5, and from version 7.5.0 before 7.5.1. CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: MEDIUM (4.7) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2015-8399 suppress
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName parameter to (1) spaces/viewdefaultdecorator.action or (2) admin/viewdefaultdecorator.action. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2019-15005 suppress
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
content-type-2.0.jarDescription:
Java library for Content (Media) Type representation License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/nimbusds/content-type/2.0/content-type-2.0.jar
MD5: 34127db525a09b004e298bcfa8806834
SHA1: 12ebb1f6b7794684e4c56918fe59df3d7aab72b0
SHA256: d54f0f6bc9faebf66490702da8ed57d3fb5f5578c4f26f76b13c06ea0f9b88f6
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name content-type High Vendor jar package name nimbusds Highest Vendor Manifest build-date ${timestamp} Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest build-number ${buildNumber} Low Vendor Manifest build-tag 2.0 Low Vendor Manifest bundle-docurl https://connect2id.com Low Vendor Manifest bundle-symbolicname com.nimbusds.content-type Medium Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor pom artifactid content-type Highest Vendor pom artifactid content-type Low Vendor pom developer email vladimir@dzhuvinov.com Low Vendor pom developer id vdzhuvinov Medium Vendor pom developer name Vladimir Dzhuvinov Medium Vendor pom groupid com.nimbusds Highest Vendor pom name Nimbus Content Type High Vendor pom organization name Connect2id Ltd. High Vendor pom organization url https://connect2id.com Medium Vendor pom url https://bitbucket.org/connect2id/nimbus-content-type Highest Product file name content-type High Product jar package name nimbusds Highest Product Manifest build-date ${timestamp} Low Product Manifest build-jdk-spec 1.8 Low Product Manifest build-number ${buildNumber} Low Product Manifest build-tag 2.0 Low Product Manifest bundle-docurl https://connect2id.com Low Product Manifest Bundle-Name Nimbus Content Type Medium Product Manifest bundle-symbolicname com.nimbusds.content-type Medium Product Manifest Implementation-Title Nimbus Content Type High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Nimbus Content Type Medium Product pom artifactid content-type Highest Product pom developer email vladimir@dzhuvinov.com Low Product pom developer id vdzhuvinov Low Product pom developer name Vladimir Dzhuvinov Low Product pom groupid com.nimbusds Highest Product pom name Nimbus Content Type High Product pom organization name Connect2id Ltd. Low Product pom organization url https://connect2id.com Low Product pom url https://bitbucket.org/connect2id/nimbus-content-type Medium Version file version 2.0 High Version Manifest build-tag 2.0 Low Version Manifest Implementation-Version 2.0 High Version pom version 2.0 Highest
core.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@js-joda/core.jsMD5: a6f56150560d1a52126574761435539fSHA1: ba2310952cc1abc2af3699d5d3720543ef601f9bSHA256: 1f3c81abd08c919048a66924fb30cd19df847c6d3a4c0be694de9efbf10038deReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
cpe-parser-2.0.2.jarDescription:
A utility for validating and parsing Common Platform Enumeration (CPE) v2.2 and v2.3 as originally defined by MITRE and maintained by NIST. License:
Apache-2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/us/springett/cpe-parser/2.0.2/cpe-parser-2.0.2.jar
MD5: f07de5ae8549a93b912a223a83c30655
SHA1: 677cff319cdc8bd9578a3d04c1fd9c366cc9ff6e
SHA256: 8fddc10cf23ad8d3329dd8343ea1e291e1eb39344dd6e61b676a0cde88cf6375
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name cpe-parser High Vendor jar package name cpe Highest Vendor jar package name parsers Low Vendor jar package name springett Highest Vendor jar package name springett Low Vendor jar package name us Highest Vendor jar package name us Low Vendor pom artifactid cpe-parser Highest Vendor pom artifactid cpe-parser Low Vendor pom developer email jeremy.long@owasp.org Low Vendor pom developer email Steve.Springett@owasp.org Low Vendor pom developer name Jeremy Long Medium Vendor pom developer name Steve Springett Medium Vendor pom developer org OWASP Medium Vendor pom developer org URL http://www.owasp.org/ Medium Vendor pom groupid us.springett Highest Vendor pom name CPE Parser High Vendor pom url stevespringett/CPE-Parser Highest Product file name cpe-parser High Product jar package name cpe Highest Product jar package name cpe Low Product jar package name parsers Low Product jar package name springett Highest Product jar package name springett Low Product jar package name us Highest Product pom artifactid cpe-parser Highest Product pom developer email jeremy.long@owasp.org Low Product pom developer email Steve.Springett@owasp.org Low Product pom developer name Jeremy Long Low Product pom developer name Steve Springett Low Product pom developer org OWASP Low Product pom developer org URL http://www.owasp.org/ Low Product pom groupid us.springett Highest Product pom name CPE Parser High Product pom url stevespringett/CPE-Parser High Version file version 2.0.2 High Version pom version 2.0.2 Highest
createAndFireEvent-5db755ab.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/createAndFireEvent-5db755ab.jsMD5: c1c9c6e007917c4dfc41427f80457cedSHA1: 3957331d91688fdac29145a9cfe16276cb599a03SHA256: 5fca054e95aecb8252ffa2c601743da59c39d48d7980f1740dab934c058da440Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
crowd-server-api-4.2.2.jarDescription:
API which only applies to Crowd as a standalone application. Consumed by plugins. File Path: /home/andrii/.m2/repository/com/atlassian/crowd/crowd-server-api/4.2.2/crowd-server-api-4.2.2.jarMD5: 3c8da6653f0b1c7f1f041ef0ccd9e683SHA1: c08c741a63d8ea100144dea1f92bea890ad3961eSHA256: 08baef896aa6854e1d749be69be1bb92d4c7637199c6386a7ebc5c1b7753d2c7Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name crowd-server-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name crowd Highest Vendor jar package name crowd Low Vendor jar package name manager Low Vendor pom artifactid crowd-server-api Highest Vendor pom artifactid crowd-server-api Low Vendor pom groupid com.atlassian.crowd Highest Vendor pom name Atlassian Crowd Server API High Vendor pom parent-artifactid atlassian-crowd-components Low Product file name crowd-server-api High Product jar package name atlassian Highest Product jar package name crowd Highest Product jar package name crowd Low Product jar package name manager Low Product pom artifactid crowd-server-api Highest Product pom groupid com.atlassian.crowd Highest Product pom name Atlassian Crowd Server API High Product pom parent-artifactid atlassian-crowd-components Medium Version file version 4.2.2 High Version pom version 4.2.2 Highest
Related Dependencies CVE-2022-26136 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-43782 suppress
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3 CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-26137 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-346 Origin Validation Error
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
daisydiff-1.1.20-atlassian-hosted.jarDescription:
Daisy Diff is a Java library that diffs (compares) HTML files. It highlights added and removed words
and annotates changes to the styling.
License:
Apache License: http://www.apache.org/licenses/ File Path: /home/andrii/.m2/repository/org/outerj/daisy/daisydiff/1.1.20-atlassian-hosted/daisydiff-1.1.20-atlassian-hosted.jar
MD5: 866832693eedf3e41840644f06f83e3e
SHA1: 7339ff559bead10bd3c3a767a89b6e854822cd46
SHA256: c641a811eb79ecf30a01edc14e0afabc0386861ab1710c361eab4be39b85e028
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name daisydiff High Vendor jar package name daisy Highest Vendor jar package name daisy Low Vendor jar package name daisydiff Highest Vendor jar package name diff Highest Vendor jar package name diff Low Vendor jar package name html Highest Vendor jar package name outerj Highest Vendor jar package name outerj Low Vendor pom artifactid daisydiff Highest Vendor pom artifactid daisydiff Low Vendor pom groupid org.outerj.daisy Highest Vendor pom name DaisyDiff Project High Vendor pom url http://code.google.com/p/daisydiff/ Highest Product file name daisydiff High Product jar package name daisy Highest Product jar package name daisy Low Product jar package name daisydiff Highest Product jar package name diff Highest Product jar package name diff Low Product jar package name html Highest Product jar package name outerj Highest Product pom artifactid daisydiff Highest Product pom groupid org.outerj.daisy Highest Product pom name DaisyDiff Project High Product pom url http://code.google.com/p/daisydiff/ Medium Version pom version 1.1.20-atlassian-hosted Highest
datetime-picker.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/datetime-picker.jsMD5: 75f1497e0477ba2f2229a755d2e45068SHA1: ad9cc1519995694e34b6153b2cf0615944ea9120SHA256: 67613dc6c9781cff0ae726ef08e654c420ae5a8d91f6fcb85fb66ebb9b3c301dReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
defineProperty-dce7b5ef.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/defineProperty-dce7b5ef.jsMD5: 5aa07531287954dad811bf0fc1ae4087SHA1: 8ecd400719a1d5f6af1cd04e9be77dd683932288SHA256: 7f494dbc69178de71a43a61e1cda6747398dfd902bdec6ef36cc283e0eba09dbReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
dependency-check-core-7.3.2.jarDescription:
dependency-check-core is the engine and reporting tool used to identify and report if there are any known, publicly disclosed vulnerabilities in the scanned project's dependencies. The engine extracts meta-data from the dependencies and uses this to do fuzzy key-word matching against the Common Platfrom Enumeration (CPE), if any CPE identifiers are found the associated Common Vulnerability and Exposure (CVE) entries are added to the generated report. File Path: /home/andrii/.m2/repository/org/owasp/dependency-check-core/7.3.2/dependency-check-core-7.3.2.jarMD5: 882692d7648fc45c3af42c94f65c48f7SHA1: d5525a67e8e61190c683dbf2cae6d5d83e237459SHA256: 5ee0d402b913e272ee49ab36257e424d0b484c99e59f4c973f414919717d24ebReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name dependency-check-core High Vendor jar package name data Highest Vendor jar package name dependency Highest Vendor jar package name engine Highest Vendor jar package name owasp Highest Vendor jar package name reporting Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor OWASP High Vendor pom artifactid dependency-check-core Highest Vendor pom artifactid dependency-check-core Low Vendor pom groupid org.owasp Highest Vendor pom name Dependency-Check Core High Vendor pom parent-artifactid dependency-check-parent Low Product file name dependency-check-core High Product jar package name data Highest Product jar package name dependency Highest Product jar package name engine Highest Product jar package name owasp Highest Product jar package name reporting Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Dependency-Check Core High Product pom artifactid dependency-check-core Highest Product pom groupid org.owasp Highest Product pom name Dependency-Check Core High Product pom parent-artifactid dependency-check-parent Medium Version file version 7.3.2 High Version Manifest Implementation-Version 7.3.2 High Version pom version 7.3.2 Highest
Related Dependencies dependency-check-maven-7.3.2.jarFile Path: /home/andrii/.m2/repository/org/owasp/dependency-check-maven/7.3.2/dependency-check-maven-7.3.2.jar MD5: d93838fa7af57b6bc428f9cabbdb9471 SHA1: 081ea70cb06c5be6524363353a9760d268653c06 SHA256: 0277a0f9534e016cf117f6732d9f3d15bfb1e2c94a9ad434aff21271c2b4447f pkg:maven/org.owasp/dependency-check-maven@7.3.2 dependency-check-utils-7.3.2.jarFile Path: /home/andrii/.m2/repository/org/owasp/dependency-check-utils/7.3.2/dependency-check-utils-7.3.2.jar MD5: dfb50f40a8ed4ad1a5a2babaf478ab73 SHA1: bc1d844f4b12fa9a33b37031fa4404ee9e94040c SHA256: cdbca2b852464966afcd864a1f8f2a0e70a6052aa6222054f3db345d213275cd pkg:maven/org.owasp/dependency-check-utils@7.3.2 dependency-check-core-7.3.2.jar: GrokAssembly.zip: GrokAssembly.dllFile Path: /home/andrii/.m2/repository/org/owasp/dependency-check-core/7.3.2/dependency-check-core-7.3.2.jar/GrokAssembly.zip/GrokAssembly.dllMD5: bb47dc65b1b26b32dc5cf58ac2c1af7fSHA1: bad180af19c0573834f7cecde9698215e80fe04fSHA256: af0a0ffd2cfa7170db914ab7dd7a2290dcd13f9df4a0928edaae904c2a1e803aReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name GrokAssembly High Product file name GrokAssembly High
dependency-check-core-7.3.2.jar: jquery-3.5.1.min.jsFile Path: /home/andrii/.m2/repository/org/owasp/dependency-check-core/7.3.2/dependency-check-core-7.3.2.jar/templates/scripts/jquery-3.5.1.min.jsMD5: 12b69d0ae6c6f0c42942ae6da2896e84SHA1: d2cc8d43ce1c854b1172e42b1209502ad563db83SHA256: 6150a35c0f486c46cadf0e230e2aa159c7c23ecfbb5611b64ee3f25fcbff341fReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence
dom4j-1.6.1-atlassian-2.jarDescription:
dom4j: the flexible XML framework for Java License:
MetaStuff, Ltd License: https://github.com/dom4j/dom4j/blob/master/LICENSE File Path: /home/andrii/.m2/repository/dom4j/dom4j/1.6.1-atlassian-2/dom4j-1.6.1-atlassian-2.jar
MD5: ddc67ad23e6f0d51326a89d7ef36db08
SHA1: b1d430a321c4830a98e244ced6e06c2e216851a5
SHA256: 0ee71e778117ff750c16d96cecb2f3e0d2eb3b4e8a14ab2cbc85b5b2e2140085
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dom4j High Vendor jar package name dom4j Highest Vendor jar package name dom4j Low Vendor pom artifactid dom4j Highest Vendor pom artifactid dom4j Low Vendor pom groupid dom4j Highest Vendor pom name dom4j High Vendor pom organization name MetaStuff Ltd. High Vendor pom organization url http://sourceforge.net/projects/dom4j Medium Vendor pom url http://dom4j.org Highest Product file name dom4j High Product jar package name dom4j Highest Product pom artifactid dom4j Highest Product pom groupid dom4j Highest Product pom name dom4j High Product pom organization name MetaStuff Ltd. Low Product pom organization url http://sourceforge.net/projects/dom4j Low Product pom url http://dom4j.org Medium Version pom version 1.6.1-atlassian-2 Highest
CVE-2020-10683 suppress
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
doxia-logging-api-1.11.1.jarDescription:
Doxia Logging API. File Path: /home/andrii/.m2/repository/org/apache/maven/doxia/doxia-logging-api/1.11.1/doxia-logging-api-1.11.1.jarMD5: 6452e33a36b87939630e0b18f8ffcff0SHA1: ee28757cce6ee0215bac550dead25074c97c532dSHA256: 243c66f842cd2b3ded7c6d2c36b177a65c3f5d94800cef988ba3e29ec8cf60c9Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name doxia-logging-api High Vendor jar package name apache Highest Vendor jar package name doxia Highest Vendor jar package name logging Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid doxia-logging-api Highest Vendor pom artifactid doxia-logging-api Low Vendor pom groupid org.apache.maven.doxia Highest Vendor pom name Doxia :: Logging API High Vendor pom parent-artifactid doxia Low Product file name doxia-logging-api High Product jar package name apache Highest Product jar package name doxia Highest Product jar package name logging Highest Product jar package name maven Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Doxia :: Logging API High Product Manifest specification-title Doxia :: Logging API Medium Product pom artifactid doxia-logging-api Highest Product pom groupid org.apache.maven.doxia Highest Product pom name Doxia :: Logging API High Product pom parent-artifactid doxia Medium Version file version 1.11.1 High Version Manifest Implementation-Version 1.11.1 High Version pom version 1.11.1 Highest
doxia-sink-api-1.11.1.jarDescription:
Doxia Sink API. File Path: /home/andrii/.m2/repository/org/apache/maven/doxia/doxia-sink-api/1.11.1/doxia-sink-api-1.11.1.jarMD5: b1bd5c9efde9f14969fa881b87fe709bSHA1: 59c2255f58c78fbbcb7e638e82bd2914e78aec8bSHA256: 39ac38bb7d752ea003be17a0065522e4e1b076a4f7e374bea55259f3e133f28fReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name doxia-sink-api High Vendor jar package name apache Highest Vendor jar package name doxia Highest Vendor jar package name maven Highest Vendor jar package name sink Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid doxia-sink-api Highest Vendor pom artifactid doxia-sink-api Low Vendor pom groupid org.apache.maven.doxia Highest Vendor pom name Doxia :: Sink API High Vendor pom parent-artifactid doxia Low Product file name doxia-sink-api High Product jar package name apache Highest Product jar package name doxia Highest Product jar package name maven Highest Product jar package name sink Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Doxia :: Sink API High Product Manifest specification-title Doxia :: Sink API Medium Product pom artifactid doxia-sink-api Highest Product pom groupid org.apache.maven.doxia Highest Product pom name Doxia :: Sink API High Product pom parent-artifactid doxia Medium Version file version 1.11.1 High Version Manifest Implementation-Version 1.11.1 High Version pom version 1.11.1 Highest
dragonfly-api-1.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/dragonfly/dragonfly-api/1.1/dragonfly-api-1.1.jarMD5: e616977a9e1904da4ac99cdd8836fdf2SHA1: e172aa98e42b86a48e5711f0e64c58b768d5200fSHA256: a272e48412c15b8df095176581a054d3ae2f37607e7c846a9d7474c5fd6f5fceReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dragonfly-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name dragonfly Highest Vendor jar package name dragonfly Low Vendor pom artifactid dragonfly-api Highest Vendor pom artifactid dragonfly-api Low Vendor pom groupid com.atlassian.dragonfly Highest Vendor pom name Dragonfly API High Vendor pom parent-artifactid dragonfly-parent Low Product file name dragonfly-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name dragonfly Highest Product jar package name dragonfly Low Product pom artifactid dragonfly-api Highest Product pom groupid com.atlassian.dragonfly Highest Product pom name Dragonfly API High Product pom parent-artifactid dragonfly-parent Medium Version file version 1.1 High Version pom version 1.1 Highest
dragonfly-core-1.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/dragonfly/dragonfly-core/1.1/dragonfly-core-1.1.jarMD5: 6bdcbde93194669ae9004a9f19c17092SHA1: c5925ccaa572c58a0a5aee397c6e1cc5fea4c1cdSHA256: 033e59c5ff64826969148017c0cb3e34dd7197c7c859ebd719ed3d85a12627e2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dragonfly-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name dragonfly Highest Vendor jar package name dragonfly Low Vendor pom artifactid dragonfly-core Highest Vendor pom artifactid dragonfly-core Low Vendor pom groupid com.atlassian.dragonfly Highest Vendor pom name Dragonfly Core High Vendor pom parent-artifactid dragonfly-parent Low Product file name dragonfly-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name dragonfly Highest Product jar package name dragonfly Low Product pom artifactid dragonfly-core Highest Product pom groupid com.atlassian.dragonfly Highest Product pom name Dragonfly Core High Product pom parent-artifactid dragonfly-parent Medium Version file version 1.1 High Version pom version 1.1 Highest
dragonfly-spi-1.1.jarFile Path: /home/andrii/.m2/repository/com/atlassian/dragonfly/dragonfly-spi/1.1/dragonfly-spi-1.1.jarMD5: 72ea20692440d5731ed977786dfc5f98SHA1: ff0363519b9a3665f8caa0587505459421a475b4SHA256: 88f6ac7ef998fe9f963ca1f06f8ac6d597abd30fc369735fa5cce4b46af0c6b3Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dragonfly-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name dragonfly Highest Vendor jar package name dragonfly Low Vendor jar package name spi Highest Vendor jar package name spi Low Vendor pom artifactid dragonfly-spi Highest Vendor pom artifactid dragonfly-spi Low Vendor pom groupid com.atlassian.dragonfly Highest Vendor pom name Dragonfly SPI High Vendor pom parent-artifactid dragonfly-parent Low Product file name dragonfly-spi High Product jar package name atlassian Highest Product jar package name dragonfly Highest Product jar package name dragonfly Low Product jar package name jiraintegrationsetuphelper Low Product jar package name spi Highest Product jar package name spi Low Product pom artifactid dragonfly-spi Highest Product pom groupid com.atlassian.dragonfly Highest Product pom name Dragonfly SPI High Product pom parent-artifactid dragonfly-parent Medium Version file version 1.1 High Version pom version 1.1 Highest
dt-filestore-client-api-1.3.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/filestore/dt-filestore-client-api/1.3.0/dt-filestore-client-api-1.3.0.jarMD5: 6e0acdc25a37465341e6eba0f3581487SHA1: 841fd905fe123ebea7e2224d73a7cff15d98d8fbSHA256: 0542a04706f610a0927b34787acdfa0f1842a8fce78d1fd50637c4cf26242906Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dt-filestore-client-api High Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name filestore Highest Vendor jar package name filestore Low Vendor pom artifactid dt-filestore-client-api Highest Vendor pom artifactid dt-filestore-client-api Low Vendor pom groupid com.atlassian.filestore Highest Vendor pom name FileStore client for Java API High Vendor pom parent-artifactid dt-filestore-java-client Low Product file name dt-filestore-client-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name client Highest Product jar package name client Low Product jar package name filestore Highest Product jar package name filestore Low Product pom artifactid dt-filestore-client-api Highest Product pom groupid com.atlassian.filestore Highest Product pom name FileStore client for Java API High Product pom parent-artifactid dt-filestore-java-client Medium Version file version 1.3.0 High Version pom version 1.3.0 Highest
dt-filestore-client-core-1.3.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/filestore/dt-filestore-client-core/1.3.0/dt-filestore-client-core-1.3.0.jarMD5: c0f887127860ed86ee9b40df2aa4f33dSHA1: 64edde6b7e71bd97663b4a3659119f9489d4ec4cSHA256: 8cfcb9071b64ba237ec9dea9c9ae5eb9e620356f83de25f8ac102e8252153e23Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dt-filestore-client-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name filestore Highest Vendor jar package name filestore Low Vendor pom artifactid dt-filestore-client-core Highest Vendor pom artifactid dt-filestore-client-core Low Vendor pom groupid com.atlassian.filestore Highest Vendor pom name FileStore client for Java core module High Vendor pom parent-artifactid dt-filestore-java-client Low Product file name dt-filestore-client-core High Product jar package name atlassian Highest Product jar package name client Highest Product jar package name client Low Product jar package name filestore Highest Product jar package name filestore Low Product jar package name util Low Product pom artifactid dt-filestore-client-core Highest Product pom groupid com.atlassian.filestore Highest Product pom name FileStore client for Java core module High Product pom parent-artifactid dt-filestore-java-client Medium Version file version 1.3.0 High Version pom version 1.3.0 Highest
dt-filestore-httpclient-1.3.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/filestore/dt-filestore-httpclient/1.3.0/dt-filestore-httpclient-1.3.0.jarMD5: 6f6c12afaf5f1a5925819fedd31bbb92SHA1: e51ca8b35de7747e50a1a80dc28a262473b7b697SHA256: bcdbc79b729c112477b23f75feabdd227a6140661e796f677e68662d48dd3ed2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dt-filestore-httpclient High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name filestore Highest Vendor jar package name filestore Low Vendor pom artifactid dt-filestore-httpclient Highest Vendor pom artifactid dt-filestore-httpclient Low Vendor pom groupid com.atlassian.filestore Highest Vendor pom name FileStore client for Java based on httpclient High Vendor pom parent-artifactid dt-filestore-java-client Low Product file name dt-filestore-httpclient High Product jar package name atlassian Highest Product jar package name client Highest Product jar package name client Low Product jar package name filestore Highest Product jar package name filestore Low Product jar package name impl Low Product pom artifactid dt-filestore-httpclient Highest Product pom groupid com.atlassian.filestore Highest Product pom name FileStore client for Java based on httpclient High Product pom parent-artifactid dt-filestore-java-client Medium Version file version 1.3.0 High Version pom version 1.3.0 Highest
dt-media-api-client-api-2.0.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/media/dt-media-api-client-api/2.0.4/dt-media-api-client-api-2.0.4.jarMD5: f3f2c977001bde8b12009517b0274bbdSHA1: 50403ac53430e6b4d639ad841517675dd164c57fSHA256: 613b9497274ac757f73881e8678c85a065c57a2607466b03b5f2fa85718c310bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dt-media-api-client-api High Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name media Highest Vendor jar package name media Low Vendor pom artifactid dt-media-api-client-api Highest Vendor pom artifactid dt-media-api-client-api Low Vendor pom groupid com.atlassian.media Highest Vendor pom name Media API client for Java API High Vendor pom parent-artifactid dt-media-api-java-client Low Product file name dt-media-api-client-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name client Highest Product jar package name client Low Product jar package name media Highest Product jar package name media Low Product pom artifactid dt-media-api-client-api Highest Product pom groupid com.atlassian.media Highest Product pom name Media API client for Java API High Product pom parent-artifactid dt-media-api-java-client Medium Version file version 2.0.4 High Version pom version 2.0.4 Highest
dt-media-api-client-core-2.0.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/media/dt-media-api-client-core/2.0.4/dt-media-api-client-core-2.0.4.jarMD5: 879293f36dee8a1ae64c105dee87f4bdSHA1: e4327c4e463c238a6b27226819534e5ee3e1e191SHA256: bac3a5fb96c57674546a93a091662b6c0aa970b9985d5bc5fdd8bd7cdded0394Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dt-media-api-client-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name media Highest Vendor jar package name media Low Vendor pom artifactid dt-media-api-client-core Highest Vendor pom artifactid dt-media-api-client-core Low Vendor pom groupid com.atlassian.media Highest Vendor pom name Media API client for Java core module High Vendor pom parent-artifactid dt-media-api-java-client Low Product file name dt-media-api-client-core High Product jar package name atlassian Highest Product jar package name client Highest Product jar package name client Low Product jar package name media Highest Product jar package name media Low Product jar package name util Low Product pom artifactid dt-media-api-client-core Highest Product pom groupid com.atlassian.media Highest Product pom name Media API client for Java core module High Product pom parent-artifactid dt-media-api-java-client Medium Version file version 2.0.4 High Version pom version 2.0.4 Highest
dt-media-api-httpclient-2.0.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/media/dt-media-api-httpclient/2.0.4/dt-media-api-httpclient-2.0.4.jarMD5: 46193d683ac809608323cf790b9a9105SHA1: ea53f3fac69038ed302c6c48cd7de9527f46eae7SHA256: 706f618bf4e6c495b5b6842d7d9070505ba6775ee789c6a3fe1688e466358d31Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name dt-media-api-httpclient High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name media Highest Vendor jar package name media Low Vendor pom artifactid dt-media-api-httpclient Highest Vendor pom artifactid dt-media-api-httpclient Low Vendor pom groupid com.atlassian.media Highest Vendor pom name Media API client for Java based on httpclient High Vendor pom parent-artifactid dt-media-api-java-client Low Product file name dt-media-api-httpclient High Product jar package name atlassian Highest Product jar package name client Highest Product jar package name client Low Product jar package name impl Low Product jar package name media Highest Product jar package name media Low Product pom artifactid dt-media-api-httpclient Highest Product pom groupid com.atlassian.media Highest Product pom name Media API client for Java based on httpclient High Product pom parent-artifactid dt-media-api-java-client Medium Version file version 2.0.4 High Version pom version 2.0.4 Highest
dynamic-table.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/dynamic-table.jsMD5: f186a0e7f7394ef1d38bca851ac66e3fSHA1: 4ba0178b853d1e5980c06bd91fde953bdba69c49SHA256: b16346c3d8e19413647f2d24f6510174b6012e844d5de571fb5f6bfb26b33d61Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
embedded-crowd-core-4.2.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/crowd/embedded-crowd-core/4.2.2/embedded-crowd-core-4.2.2.jarMD5: b323781d6fe04cf279d1baba1d8ccf7dSHA1: 65a1bc95f629b3c01cf7d8bd723af6ec2742c438SHA256: fdc0f55e5cb2d16a71f4700468772b418f242bb144bb4aaaa85c2dbade222ff2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name embedded-crowd-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name crowd Highest Vendor jar package name crowd Low Vendor jar package name embedded Highest Vendor jar package name embedded Low Vendor pom artifactid embedded-crowd-core Highest Vendor pom artifactid embedded-crowd-core Low Vendor pom groupid com.atlassian.crowd Highest Vendor pom name Atlassian Embedded Crowd - Core High Vendor pom parent-artifactid embedded-crowd Low Product file name embedded-crowd-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name crowd Highest Product jar package name crowd Low Product jar package name embedded Highest Product jar package name embedded Low Product jar package name validator Low Product pom artifactid embedded-crowd-core Highest Product pom groupid com.atlassian.crowd Highest Product pom name Atlassian Embedded Crowd - Core High Product pom parent-artifactid embedded-crowd Medium Version file version 4.2.2 High Version pom version 4.2.2 Highest
Related Dependencies embedded-crowd-api-4.2.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/crowd/embedded-crowd-api/4.2.2/embedded-crowd-api-4.2.2.jar MD5: fe8dee4045d8a4ce73980709173aff20 SHA1: 8429f1dec4574f6c629e180fd7a32f23a55ba7c8 SHA256: 0b32449398b04b1824c5d6e611ea88f33101d7864a3e2f224c1fd5921549f25e pkg:maven/com.atlassian.crowd/embedded-crowd-api@4.2.2 embedded-crowd-spi-4.2.2.jarFile Path: /home/andrii/.m2/repository/com/atlassian/crowd/embedded-crowd-spi/4.2.2/embedded-crowd-spi-4.2.2.jar MD5: 26a5255ab2ee1c7ebc0a8ecaf4870cb4 SHA1: 74cb01ea69396e2267e08cd2f043cfd9974a22b9 SHA256: 5af80a7f5a6e24798a0d713078f2c81d48617f69e2ae552312578dc0078c8152 pkg:maven/com.atlassian.crowd/embedded-crowd-spi@4.2.2 CVE-2022-26136 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-43782 suppress
Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by IPs specified under the crowd application allowlist in the Remote Addresses configuration, which is {{none}} by default. The affected versions are all versions 3.x.x, versions 4.x.x before version 4.4.4, and versions 5.x.x before 5.0.3 CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-26137 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-346 Origin Validation Error
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
error_prone_annotations-2.4.0.jarLicense:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/google/errorprone/error_prone_annotations/2.4.0/error_prone_annotations-2.4.0.jar
MD5: bac854c25d354c9fd973f73956c06916
SHA1: 32ecccc595e4e4d813a80ee9e3ab5813d65874eb
SHA256: 5f2a0648230a662e8be049df308d583d7369f13af683e44ddf5829b6d741a228
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name error_prone_annotations High Vendor jar package name annotations Highest Vendor jar package name errorprone Highest Vendor jar package name google Highest Vendor Manifest automatic-module-name com.google.errorprone.annotations Medium Vendor pom artifactid error_prone_annotations Highest Vendor pom artifactid error_prone_annotations Low Vendor pom groupid com.google.errorprone Highest Vendor pom name error-prone annotations High Vendor pom parent-artifactid error_prone_parent Low Product file name error_prone_annotations High Product jar package name annotations Highest Product jar package name errorprone Highest Product jar package name google Highest Product Manifest automatic-module-name com.google.errorprone.annotations Medium Product pom artifactid error_prone_annotations Highest Product pom groupid com.google.errorprone Highest Product pom name error-prone annotations High Product pom parent-artifactid error_prone_parent Medium Version file version 2.4.0 High Version pom version 2.4.0 Highest
fast-classpath-scanner-2.18.1.jarDescription:
Uber-fast, ultra-lightweight Java classpath scanner. Scans the classpath by parsing the classfile binary format directly rather than by using reflection.
See https://github.com/lukehutch/fast-classpath-scanner
License:
The MIT License (MIT): http://opensource.org/licenses/MIT File Path: /home/andrii/.m2/repository/io/github/lukehutch/fast-classpath-scanner/2.18.1/fast-classpath-scanner-2.18.1.jar
MD5: 91244322e274de00e948e1b92a58ba82
SHA1: 89d34f84d7119c97df018e20b31f80ea3e0ea321
SHA256: e1cf8c3ab10a9a838adc898d47a9f9e7cc61f7313e7bc6c778ff20c22cd2f75c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fast-classpath-scanner High Vendor jar package name fastclasspathscanner Highest Vendor jar package name github Highest Vendor jar package name io Highest Vendor jar package name lukehutch Highest Vendor Manifest bundle-category Utilities Low Vendor Manifest bundle-symbolicname io.github.lukehutch.fast-classpath-scanner Medium Vendor Manifest implementation-url https://github.com/lukehutch/fast-classpath-scanner Low Vendor Manifest Implementation-Vendor-Id io.github.lukehutch Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid fast-classpath-scanner Highest Vendor pom artifactid fast-classpath-scanner Low Vendor pom developer email luke.hutch@gmail.com Low Vendor pom developer name Luke Hutchison Medium Vendor pom developer org -- Medium Vendor pom developer org URL https://github.com/lukehutch Medium Vendor pom groupid io.github.lukehutch Highest Vendor pom name FastClasspathScanner High Vendor pom url lukehutch/fast-classpath-scanner Highest Product file name fast-classpath-scanner High Product jar package name fastclasspathscanner Highest Product jar package name github Highest Product jar package name io Highest Product jar package name lukehutch Highest Product Manifest bundle-category Utilities Low Product Manifest Bundle-Name FastClasspathScanner Medium Product Manifest bundle-symbolicname io.github.lukehutch.fast-classpath-scanner Medium Product Manifest Implementation-Title FastClasspathScanner High Product Manifest implementation-url https://github.com/lukehutch/fast-classpath-scanner Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title FastClasspathScanner Medium Product pom artifactid fast-classpath-scanner Highest Product pom developer email luke.hutch@gmail.com Low Product pom developer name Luke Hutchison Low Product pom developer org -- Low Product pom developer org URL https://github.com/lukehutch Low Product pom groupid io.github.lukehutch Highest Product pom name FastClasspathScanner High Product pom url lukehutch/fast-classpath-scanner High Version file version 2.18.1 High Version Manifest Bundle-Version 2.18.1 High Version Manifest Implementation-Version 2.18.1 High Version pom version 2.18.1 Highest
file-management-3.1.0.jarDescription:
API to collect files from a given directory using several include/exclude rules. File Path: /home/andrii/.m2/repository/org/apache/maven/shared/file-management/3.1.0/file-management-3.1.0.jarMD5: 94be12af3d234da86b130cb297234befSHA1: f87a3a54c856714e4157b9ce7a5ff6ffc310d447SHA256: 2e8cb2d546a01c2259cb17f1e06732db3d14b079d19622bf8400c82cb1ee6b96Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name file-management High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid file-management Highest Vendor pom artifactid file-management Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven File Management API High Vendor pom parent-artifactid maven-shared-components Low Product file name file-management High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven File Management API High Product Manifest specification-title Apache Maven File Management API Medium Product pom artifactid file-management Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven File Management API High Product pom parent-artifactid maven-shared-components Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
filestore-api-0.4.0.jarDescription:
The Data Center FileStore API File Path: /home/andrii/.m2/repository/com/atlassian/datacenter/filestore/filestore-api/0.4.0/filestore-api-0.4.0.jarMD5: 66301bf791dbb93386a57752d8bcf804SHA1: be8ea74d48ee6822855d0aad4fc952e30d4424c9SHA256: 486ba23c910cd9ec655937be4e138210a0d0966d857ab30a18db4659fb8034f9Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name filestore-api High Vendor jar package name api Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name dc Low Vendor jar package name filestore Highest Vendor jar package name filestore Low Vendor pom artifactid filestore-api Highest Vendor pom artifactid filestore-api Low Vendor pom groupid com.atlassian.datacenter.filestore Highest Vendor pom parent-artifactid filestore-project Low Product file name filestore-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name dc Low Product jar package name filestore Highest Product jar package name filestore Low Product pom artifactid filestore-api Highest Product pom groupid com.atlassian.datacenter.filestore Highest Product pom parent-artifactid filestore-project Medium Version file version 0.4.0 High Version pom version 0.4.0 Highest
Related Dependencies filestore-filesystem-0.4.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/datacenter/filestore/filestore-filesystem/0.4.0/filestore-filesystem-0.4.0.jar MD5: b524a00cc8412ca5d870fb1da92cada9 SHA1: 77b58a2b57483439576ecaa294c9e99480ea0309 SHA256: 668be74b55189f939fca72715008593ee8c5dea056cfe11d13a1bf7c719fd4f3 pkg:maven/com.atlassian.datacenter.filestore/filestore-filesystem@0.4.0 CVE-2017-18113 suppress
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as part of workflows. The fix for this issue blocks usage of unsafe conditions, validators, functions and registers that are build-in into OSWorkflow library and other Jira dependencies. Atlassian-made functions or functions provided by 3rd party plugins are not affected by this fix. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39113 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0. CWE-613 Insufficient Session Expiration
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39123 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-41312 suppress
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26070 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43947 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-36288 suppress
The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26078 suppress
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26079 suppress
The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39111 suppress
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-41304 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26082 suppress
The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26083 suppress
Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20101 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14181 suppress
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36237 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36238 suppress
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36286 suppress
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36287 suppress
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36289 suppress
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26069 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26081 suppress
REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/api/latest/user/avatar/temporary` endpoint. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39118 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39119 suppress
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39122 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39125 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36234 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39112 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (4.9) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39117 suppress
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43945 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-29451 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26075 suppress
The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when presented with an invalid filename. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39121 suppress
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39124 suppress
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43953 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2021-26076 suppress
The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set with a secure attribute if Jira was configured to use https. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.7) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26071 suppress
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: LOW (3.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
filters-2.0.235.jarDescription:
A collection of image processing filters. License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/jhlabs/filters/2.0.235/filters-2.0.235.jar
MD5: d91073d6b28e2505e96620709626495f
SHA1: af6a2dfefef70f1ab2d7a8d1f8173f67e276b3f4
SHA256: be6a1d54ebb043495e31e25e72b440f69156a5624cdd7e1c55c47e30d4fae308
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name filters High Vendor jar package name image Highest Vendor jar package name jhlabs Highest Vendor Manifest Implementation-Vendor-Id com.jhlabs Medium Vendor pom artifactid filters Highest Vendor pom artifactid filters Low Vendor pom groupid com.jhlabs Highest Vendor pom name JHLabs Image Processing Filters High Vendor pom url http://www.jhlabs.com/ip/index.html Highest Product file name filters High Product jar package name image Highest Product jar package name jhlabs Highest Product Manifest Implementation-Title JHLabs Image Processing Filters High Product Manifest specification-title JHLabs Image Processing Filters Medium Product pom artifactid filters Highest Product pom groupid com.jhlabs Highest Product pom name JHLabs Image Processing Filters High Product pom url http://www.jhlabs.com/ip/index.html Medium Version file version 2.0.235 High Version Manifest Implementation-Version 2.0.235 High Version pom version 2.0.235 Highest
pkg:maven/com.jhlabs/filters@2.0.235 (Confidence :High)cpe:2.3:a:image-processing_project:image-processing:2.0.235:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:image_processing_software:image_processing_software:2.0.235:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2005-0406 suppress
A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image. NVD-CWE-Other
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions:
findbugs-annotations-3.0.1.jarDescription:
Annotation defined by the FindBugs tool License:
GNU Lesser Public License: http://www.gnu.org/licenses/lgpl.html File Path: /home/andrii/.m2/repository/com/google/code/findbugs/findbugs-annotations/3.0.1/findbugs-annotations-3.0.1.jar
MD5: 5bcf1f717f297f87c55e8e3131758b09
SHA1: 0bf2342edabc0fc37fc0b1de0b03f071bef935c3
SHA256: 8de57cec5c240788a4d5301f67d51921d584fb25bff3899695a53e7e46205a71
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name findbugs-annotations High Vendor jar package name cs Highest Vendor jar package name edu Highest Vendor jar package name findbugs Highest Vendor jar package name umd Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname edu.umd.cs.findbugs.annotations Medium Vendor pom artifactid findbugs-annotations Highest Vendor pom artifactid findbugs-annotations Low Vendor pom developer email Loskutov@gmx.de Low Vendor pom developer email pugh at cs.umd.edu Low Vendor pom developer id al Medium Vendor pom developer id bp Medium Vendor pom developer name Andrey Loskutov Medium Vendor pom developer name Bill Pugh Medium Vendor pom developer name Keith Lea Medium Vendor pom groupid com.google.code.findbugs Highest Vendor pom name FindBugs-Native-Annotations High Vendor pom url http://findbugs.sourceforge.net/ Highest Product file name findbugs-annotations High Product jar package name cs Highest Product jar package name edu Highest Product jar package name findbugs Highest Product jar package name umd Highest Product Manifest Bundle-Name FindBugs-Native-Annotations Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname edu.umd.cs.findbugs.annotations Medium Product pom artifactid findbugs-annotations Highest Product pom developer email Loskutov@gmx.de Low Product pom developer email pugh at cs.umd.edu Low Product pom developer id al Low Product pom developer id bp Low Product pom developer name Andrey Loskutov Low Product pom developer name Bill Pugh Low Product pom developer name Keith Lea Low Product pom groupid com.google.code.findbugs Highest Product pom name FindBugs-Native-Annotations High Product pom url http://findbugs.sourceforge.net/ Medium Version file version 3.0.1 High Version Manifest Bundle-Version 3.0.1 High Version pom version 3.0.1 Highest
fontbox-2.0.24.jarDescription:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/pdfbox/fontbox/2.0.24/fontbox-2.0.24.jar
MD5: 6c2066df0d706d85e950fe8c73d52ed8
SHA1: df8ecb3006dfcd52355a5902096e5ec34f06112e
SHA256: 2e8c0a569a90b04734fbc0c805d77f4ec03f98c11f5705055ccd7718c1953d68
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fontbox High Vendor jar package name apache Highest Vendor jar package name fontbox Highest Vendor Manifest automatic-module-name org.apache.fontbox Medium Vendor Manifest bundle-docurl http://pdfbox.apache.org Low Vendor Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium Vendor Manifest implementation-url http://pdfbox.apache.org/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid fontbox Highest Vendor pom artifactid fontbox Low Vendor pom groupid org.apache.pdfbox Highest Vendor pom name Apache FontBox High Vendor pom parent-artifactid pdfbox-parent Low Vendor pom url http://pdfbox.apache.org/ Highest Product file name fontbox High Product jar package name apache Highest Product jar package name fontbox Highest Product Manifest automatic-module-name org.apache.fontbox Medium Product Manifest bundle-docurl http://pdfbox.apache.org Low Product Manifest Bundle-Name Apache FontBox Medium Product Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium Product Manifest Implementation-Title Apache FontBox High Product Manifest implementation-url http://pdfbox.apache.org/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache FontBox Medium Product pom artifactid fontbox Highest Product pom groupid org.apache.pdfbox Highest Product pom name Apache FontBox High Product pom parent-artifactid pdfbox-parent Medium Product pom url http://pdfbox.apache.org/ Medium Version file version 2.0.24 High Version Manifest Bundle-Version 2.0.24 High Version Manifest Implementation-Version 2.0.24 High Version pom version 2.0.24 Highest
fugue-2.7.0.jarDescription:
This is a version of atlassian-public-pom:3.x.y that allows releasing to artifactory License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/atlassian/fugue/fugue/2.7.0/fugue-2.7.0.jar
MD5: b9eaa7c0d9da891ebab26b7d3f66270d
SHA1: 7e5e1933563375e0d55ddfdca361eaf960e58c89
SHA256: 021e8b7b139ccca1b6e5878bd5b0a14fc7c4d78daf25c31d590e76d541b4d779
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fugue High Vendor jar package name atlassian Highest Vendor jar package name fugue Highest Vendor Manifest bundle-docurl http://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.fugue Medium Vendor pom artifactid fugue Highest Vendor pom artifactid fugue Low Vendor pom groupid com.atlassian.fugue Highest Vendor pom name Functional Guava Extensions High Vendor pom parent-artifactid fugue-parent Low Product file name fugue High Product jar package name atlassian Highest Product jar package name fugue Highest Product Manifest bundle-docurl http://www.atlassian.com/ Low Product Manifest Bundle-Name Functional Guava Extensions Medium Product Manifest bundle-symbolicname com.atlassian.fugue Medium Product pom artifactid fugue Highest Product pom groupid com.atlassian.fugue Highest Product pom name Functional Guava Extensions High Product pom parent-artifactid fugue-parent Medium Version file version 2.7.0 High Version Manifest Bundle-Version 2.7.0 High Version pom version 2.7.0 Highest
fugue-4.7.2.jarDescription:
Base POM for Atlassian projects License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/io/atlassian/fugue/fugue/4.7.2/fugue-4.7.2.jar
MD5: 9350f264bbd7056e0264c6d158f8477c
SHA1: 77a4cb8ddeb9f00193289dfa5dca624268cb049d
SHA256: bd421e60013a10e1b9eb6328123fa28fbe8736711d282070ac43f5366274d18d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fugue High Vendor jar package name atlassian Highest Vendor jar package name fugue Highest Vendor jar package name io Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname io.atlassian.fugue Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid fugue Highest Vendor pom artifactid fugue Low Vendor pom groupid io.atlassian.fugue Highest Vendor pom name Functional Extensions High Vendor pom parent-artifactid fugue-parent Low Product file name fugue High Product jar package name atlassian Highest Product jar package name fugue Highest Product jar package name io Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Functional Extensions Medium Product Manifest bundle-symbolicname io.atlassian.fugue Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid fugue Highest Product pom groupid io.atlassian.fugue Highest Product pom name Functional Extensions High Product pom parent-artifactid fugue-parent Medium Version file version 4.7.2 High Version Manifest Bundle-Version 4.7.2 High Version pom version 4.7.2 Highest
fugue-deprecated-4.7.2.jarDescription:
Base POM for Atlassian projects License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/io/atlassian/fugue/fugue-deprecated/4.7.2/fugue-deprecated-4.7.2.jar
MD5: f6ca36c2fc6786c94aeb50f7d888b49f
SHA1: eeebda060ab587bf90fec5268b41cebbfe8acae1
SHA256: 1c7f1def0de1b6e3c2206c4d4ac4f88eb4c40d94e4861cf084445e24894f7e27
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fugue-deprecated High Vendor jar package name atlassian Highest Vendor jar package name deprecated Highest Vendor jar package name fugue Highest Vendor jar package name io Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname io.atlassian.fugue.deprecated Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid fugue-deprecated Highest Vendor pom artifactid fugue-deprecated Low Vendor pom groupid io.atlassian.fugue Highest Vendor pom name Functional Extensions Deprecated Inter-Ops High Vendor pom parent-artifactid fugue-parent Low Product file name fugue-deprecated High Product jar package name atlassian Highest Product jar package name deprecated Highest Product jar package name fugue Highest Product jar package name io Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Functional Extensions Deprecated Inter-Ops Medium Product Manifest bundle-symbolicname io.atlassian.fugue.deprecated Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid fugue-deprecated Highest Product pom groupid io.atlassian.fugue Highest Product pom name Functional Extensions Deprecated Inter-Ops High Product pom parent-artifactid fugue-parent Medium Version file version 4.7.2 High Version Manifest Bundle-Version 4.7.2 High Version pom version 4.7.2 Highest
fugue-guava-4.7.2.jarDescription:
Base POM for Atlassian projects License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/io/atlassian/fugue/fugue-guava/4.7.2/fugue-guava-4.7.2.jar
MD5: a4850bfee8e1c4f5cda7096541dbca69
SHA1: 2c8c73dd6e1d1ddd73fba6c8c22457487171e5ff
SHA256: d525c74cb90bf75a54215b3969e9eae1963bf141d52dc5aa80b8c3c179b38849
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fugue-guava High Vendor jar package name atlassian Highest Vendor jar package name fugue Highest Vendor jar package name io Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname io.atlassian.fugue.guava Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid fugue-guava Highest Vendor pom artifactid fugue-guava Low Vendor pom groupid io.atlassian.fugue Highest Vendor pom name Functional Extensions Guava Inter-Ops High Vendor pom parent-artifactid fugue-parent Low Product file name fugue-guava High Product jar package name atlassian Highest Product jar package name fugue Highest Product jar package name io Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Functional Extensions Guava Inter-Ops Medium Product Manifest bundle-symbolicname io.atlassian.fugue.guava Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid fugue-guava Highest Product pom groupid io.atlassian.fugue Highest Product pom name Functional Extensions Guava Inter-Ops High Product pom parent-artifactid fugue-parent Medium Version file version 4.7.2 High Version Manifest Bundle-Version 4.7.2 High Version pom version 4.7.2 Highest
fugue-optics-4.7.2.jarDescription:
Base POM for Atlassian projects License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/io/atlassian/fugue/fugue-optics/4.7.2/fugue-optics-4.7.2.jar
MD5: ddfb1b197dab4656de8acdd3cc4b3a79
SHA1: 806e6f6aee86475986df5440ac47de65d029ed64
SHA256: 767af26f8205a9d0e8966a6101a3a7e6617465990026dfefb4e84330474dd28d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fugue-optics High Vendor jar package name atlassian Highest Vendor jar package name fugue Highest Vendor jar package name io Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname io.atlassian.fugue.optics Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid fugue-optics Highest Vendor pom artifactid fugue-optics Low Vendor pom groupid io.atlassian.fugue Highest Vendor pom name Functional Optics Library High Vendor pom parent-artifactid fugue-parent Low Product file name fugue-optics High Product jar package name atlassian Highest Product jar package name fugue Highest Product jar package name io Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Functional Optics Library Medium Product Manifest bundle-symbolicname io.atlassian.fugue.optics Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid fugue-optics Highest Product pom groupid io.atlassian.fugue Highest Product pom name Functional Optics Library High Product pom parent-artifactid fugue-parent Medium Version file version 4.7.2 High Version Manifest Bundle-Version 4.7.2 High Version pom version 4.7.2 Highest
fugue-retry-4.7.2.jarDescription:
Base POM for Atlassian projects License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/io/atlassian/fugue/fugue-retry/4.7.2/fugue-retry-4.7.2.jar
MD5: cc6ab0639eb81a61ca482ceeb869c68d
SHA1: 0ec6f81964b27f774b681fa0354121f41b32ec0e
SHA256: db85785b781ab0f247bbd756bb84415854511c12c9461544ec1d5bfa5acb7e9c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name fugue-retry High Vendor jar package name atlassian Highest Vendor jar package name fugue Highest Vendor jar package name io Highest Vendor jar package name retry Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname io.atlassian.fugue.retry Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid fugue-retry Highest Vendor pom artifactid fugue-retry Low Vendor pom groupid io.atlassian.fugue Highest Vendor pom name Functional Extensions Retry Inter-Ops High Vendor pom parent-artifactid fugue-parent Low Product file name fugue-retry High Product jar package name atlassian Highest Product jar package name fugue Highest Product jar package name io Highest Product jar package name retry Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Functional Extensions Retry Inter-Ops Medium Product Manifest bundle-symbolicname io.atlassian.fugue.retry Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid fugue-retry Highest Product pom groupid io.atlassian.fugue Highest Product pom name Functional Extensions Retry Inter-Ops High Product pom parent-artifactid fugue-parent Medium Version file version 4.7.2 High Version Manifest Bundle-Version 4.7.2 High Version pom version 4.7.2 Highest
future-converter-common-1.2.0.jarFile Path: /home/andrii/.m2/repository/net/javacrumbs/future-converter/future-converter-common/1.2.0/future-converter-common-1.2.0.jarMD5: 56ab39a9226af02748c144a7b0dfd46dSHA1: 5fc7ea7c58ee0ce950e6104d5dda899f81959d7bSHA256: 567aeb2907088298fe5e67fd0fb1843571c24b46ef5b369f495c3d52c654b67bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name future-converter-common High Vendor jar package name common Highest Vendor jar package name futureconverter Highest Vendor jar package name javacrumbs Highest Vendor jar package name net Highest Vendor Manifest automatic-module-name net.javacrumbs.futureconverter.common.internal Medium Vendor pom artifactid future-converter-common Highest Vendor pom artifactid future-converter-common Low Vendor pom groupid net.javacrumbs.future-converter Highest Vendor pom parent-artifactid future-converter Low Product file name future-converter-common High Product jar package name common Highest Product jar package name futureconverter Highest Product jar package name javacrumbs Highest Product jar package name net Highest Product Manifest automatic-module-name net.javacrumbs.futureconverter.common.internal Medium Product pom artifactid future-converter-common Highest Product pom groupid net.javacrumbs.future-converter Highest Product pom parent-artifactid future-converter Medium Version file version 1.2.0 High Version pom version 1.2.0 Highest
future-converter-guava-common-1.2.0.jarFile Path: /home/andrii/.m2/repository/net/javacrumbs/future-converter/future-converter-guava-common/1.2.0/future-converter-guava-common-1.2.0.jarMD5: 1bdb022fda4325f68c179f875bfe734bSHA1: b329c26e298bd77994cc2e304e4ac20da6f1569fSHA256: 82bfab706005ea51c3e76958a62564367cf9cae207c0b1d55b9734876b9780c1Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name future-converter-guava-common High Vendor jar package name futureconverter Highest Vendor jar package name guavacommon Highest Vendor jar package name javacrumbs Highest Vendor jar package name net Highest Vendor Manifest automatic-module-name net.javacrumbs.futureconverter.guavacommon Medium Vendor pom artifactid future-converter-guava-common Highest Vendor pom artifactid future-converter-guava-common Low Vendor pom groupid net.javacrumbs.future-converter Highest Vendor pom parent-artifactid future-converter Low Product file name future-converter-guava-common High Product jar package name futureconverter Highest Product jar package name guavacommon Highest Product jar package name javacrumbs Highest Product jar package name net Highest Product Manifest automatic-module-name net.javacrumbs.futureconverter.guavacommon Medium Product pom artifactid future-converter-guava-common Highest Product pom groupid net.javacrumbs.future-converter Highest Product pom parent-artifactid future-converter Medium Version file version 1.2.0 High Version pom version 1.2.0 Highest
future-converter-java8-common-1.2.0.jarFile Path: /home/andrii/.m2/repository/net/javacrumbs/future-converter/future-converter-java8-common/1.2.0/future-converter-java8-common-1.2.0.jarMD5: e4b2ae44b8a4ffa5f2a5ed1fc76da7fdSHA1: 575932e773d58ddd459af417b2df31e2d07c4afcSHA256: bed25293fabbf59e048f67f88e55140ebc1cfa4fa899e397545d0193e866a65cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name future-converter-java8-common High Vendor jar package name futureconverter Highest Vendor jar package name java8common Highest Vendor jar package name javacrumbs Highest Vendor jar package name net Highest Vendor Manifest automatic-module-name net.javacrumbs.futureconverter.java8common Medium Vendor pom artifactid future-converter-java8-common Highest Vendor pom artifactid future-converter-java8-common Low Vendor pom groupid net.javacrumbs.future-converter Highest Vendor pom parent-artifactid future-converter Low Product file name future-converter-java8-common High Product jar package name futureconverter Highest Product jar package name java8common Highest Product jar package name javacrumbs Highest Product jar package name net Highest Product Manifest automatic-module-name net.javacrumbs.futureconverter.java8common Medium Product pom artifactid future-converter-java8-common Highest Product pom groupid net.javacrumbs.future-converter Highest Product pom parent-artifactid future-converter Medium Version file version 1.2.0 High Version pom version 1.2.0 Highest
future-converter-java8-guava-1.2.0.jarFile Path: /home/andrii/.m2/repository/net/javacrumbs/future-converter/future-converter-java8-guava/1.2.0/future-converter-java8-guava-1.2.0.jarMD5: c43d5a3c364e851b169195a69eab8d77SHA1: 9d6d59ee4e8f337ccf69ddd66e291a1ef77fbf4eSHA256: 3b47ae8e2b2bfad810586c37537f002273c05237bd3adecafe9f9f57a2b18fdeReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name future-converter-java8-guava High Vendor jar package name futureconverter Highest Vendor jar package name java8guava Highest Vendor jar package name javacrumbs Highest Vendor jar package name net Highest Vendor Manifest automatic-module-name net.javacrumbs.futureconverter.java8guava Medium Vendor pom artifactid future-converter-java8-guava Highest Vendor pom artifactid future-converter-java8-guava Low Vendor pom groupid net.javacrumbs.future-converter Highest Vendor pom parent-artifactid future-converter Low Product file name future-converter-java8-guava High Product jar package name futureconverter Highest Product jar package name java8guava Highest Product jar package name javacrumbs Highest Product jar package name net Highest Product Manifest automatic-module-name net.javacrumbs.futureconverter.java8guava Medium Product pom artifactid future-converter-java8-guava Highest Product pom groupid net.javacrumbs.future-converter Highest Product pom parent-artifactid future-converter Medium Version file version 1.2.0 High Version pom version 1.2.0 Highest
get-is-only-single-icon-3e32a817.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/get-is-only-single-icon-3e32a817.jsMD5: 4d6c67c1ea54d414ae63900785410dc3SHA1: d2f5e961f48002dceb7e49912329401c1704e1e9SHA256: 41d1b553d3c32b0b403cb00f6342a7dea763fe00f48307359d1dc174458ebe51Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
gmbal-api-only-3.1.0-b001.jarDescription:
gmbal API License:
CDDL+GPL: https://glassfish.dev.java.net/public/CDDL+GPL.html File Path: /home/andrii/.m2/repository/org/glassfish/gmbal/gmbal-api-only/3.1.0-b001/gmbal-api-only-3.1.0-b001.jar
MD5: 5c18e371a6ef8dd3608d74396ece0d29
SHA1: 3502c55c7ad2085ece6b38202b5169dd9177e0a2
SHA256: 4b7c8dd878264bd4ab913b0cfe3e28bdf82fa81757e8cb8b373202e265cdbdbc
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name gmbal-api-only High Vendor jar package name glassfish Highest Vendor jar package name gmbal Highest Vendor Manifest bundle-symbolicname gmbal-api-only Medium Vendor pom artifactid gmbal-api-only Highest Vendor pom artifactid gmbal-api-only Low Vendor pom developer email ken.cavanaugh@sun.com Low Vendor pom developer id kcavanaugh Medium Vendor pom developer name Ken Cavanaugh Medium Vendor pom groupid org.glassfish.gmbal Highest Vendor pom name gmbal-api-only High Vendor pom organization name Sun Microsystems High Vendor pom organization url http://www.sun.com Medium Vendor pom url http://kenai.com/hg/gmbal~master Highest Product file name gmbal-api-only High Product jar package name glassfish Highest Product jar package name gmbal Highest Product Manifest Bundle-Name gmbal-api-only Medium Product Manifest bundle-symbolicname gmbal-api-only Medium Product pom artifactid gmbal-api-only Highest Product pom developer email ken.cavanaugh@sun.com Low Product pom developer id kcavanaugh Low Product pom developer name Ken Cavanaugh Low Product pom groupid org.glassfish.gmbal Highest Product pom name gmbal-api-only High Product pom organization name Sun Microsystems Low Product pom organization url http://www.sun.com Low Product pom url http://kenai.com/hg/gmbal~master Medium Version pom version 3.1.0-b001 Highest
gson-2.2.2-atlassian-1.jarDescription:
Google Gson library License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/google/code/gson/gson/2.2.2-atlassian-1/gson-2.2.2-atlassian-1.jar
MD5: 7c0993c455ed52bf9c6d6696f1df3534
SHA1: 0cfb0ac68acdb3a5ce496fd98a21791015d5ec25
SHA256: c898fee525753377d3d0f9f3bde910602e423a4a5b2c80e51d05d71da6811237
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name gson High Vendor jar package name google Highest Vendor jar package name gson Highest Vendor Manifest bundle-contactaddress http://code.google.com/p/google-gson/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname com.google.gson Medium Vendor pom artifactid gson Highest Vendor pom artifactid gson Low Vendor pom developer name Inderjeet Singh Medium Vendor pom developer name Jesse Wilson Medium Vendor pom developer name Joel Leitch Medium Vendor pom developer org Google Inc. Medium Vendor pom developer org Square Inc. Medium Vendor pom developer org Trymph Inc. Medium Vendor pom groupid com.google.code.gson Highest Vendor pom name Gson High Vendor pom organization name Google, Inc. High Vendor pom organization url http://www.google.com Medium Vendor pom url http://code.google.com/p/google-gson/ Highest Product file name gson High Product jar package name google Highest Product jar package name gson Highest Product Manifest bundle-contactaddress http://code.google.com/p/google-gson/ Low Product Manifest Bundle-Name Gson Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname com.google.gson Medium Product pom artifactid gson Highest Product pom developer name Inderjeet Singh Low Product pom developer name Jesse Wilson Low Product pom developer name Joel Leitch Low Product pom developer org Google Inc. Low Product pom developer org Square Inc. Low Product pom developer org Trymph Inc. Low Product pom groupid com.google.code.gson Highest Product pom name Gson High Product pom organization name Google, Inc. Low Product pom organization url http://www.google.com Low Product pom url http://code.google.com/p/google-gson/ Medium Version Manifest Bundle-Version 2.2.2-atlassian-1 High Version pom version 2.2.2-atlassian-1 Highest
CVE-2022-25647 suppress
The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
guava-26.0-jre.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/google/guava/guava/26.0-jre/guava-26.0-jre.jar
MD5: db2d6eae3ec08b0fd752ef0c5672aab7
SHA1: 6a806eff209f36f635f943e16d97491f00f6bfab
SHA256: a0e9cabad665bc20bcd2b01f108e5fc03f756e13aea80abaadb9f407033bea2c
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name guava High Vendor jar package name common Highest Vendor jar package name google Highest Vendor Manifest automatic-module-name com.google.common Medium Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid guava Highest Vendor pom artifactid guava Low Vendor pom groupid com.google.guava Highest Vendor pom name Guava: Google Core Libraries for Java High Vendor pom parent-artifactid guava-parent Low Product file name guava High Product jar package name common Highest Product jar package name google Highest Product Manifest automatic-module-name com.google.common Medium Product Manifest bundle-docurl https://github.com/google/guava/ Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product Manifest bundle-symbolicname com.google.guava Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid guava Highest Product pom groupid com.google.guava Highest Product pom name Guava: Google Core Libraries for Java High Product pom parent-artifactid guava-parent Medium Version pom version 26.0-jre Highest
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
h2-1.4.200.jarDescription:
H2 Database Engine License:
MPL 2.0 or EPL 1.0: https://h2database.com/html/license.html File Path: /home/andrii/.m2/repository/com/h2database/h2/1.4.200/h2-1.4.200.jar
MD5: 18c05829a03b92c0880f22a3c4d1d11d
SHA1: f7533fe7cb8e99c87a43d325a77b4b678ad9031a
SHA256: 3ad9ac4b6aae9cd9d3ac1c447465e1ed06019b851b893dd6a8d76ddb6d85bca6
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name h2 High Vendor jar package name database Highest Vendor jar package name engine Highest Vendor jar package name h2 Highest Vendor Manifest automatic-module-name com.h2database Medium Vendor Manifest bundle-category jdbc Low Vendor Manifest bundle-symbolicname com.h2database Medium Vendor Manifest implementation-url https://h2database.com Low Vendor Manifest multi-release true Low Vendor Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Vendor pom artifactid h2 Highest Vendor pom artifactid h2 Low Vendor pom developer email thomas.tom.mueller at gmail dot com Low Vendor pom developer id thomas.tom.mueller Medium Vendor pom developer name Thomas Mueller Medium Vendor pom groupid com.h2database Highest Vendor pom name H2 Database Engine High Vendor pom url https://h2database.com Highest Product file name h2 High Product jar package name database Highest Product jar package name engine Highest Product jar package name h2 Highest Product jar package name jdbc Highest Product jar package name org Highest Product jar package name service Highest Product Manifest automatic-module-name com.h2database Medium Product Manifest bundle-category jdbc Low Product Manifest Bundle-Name H2 Database Engine Medium Product Manifest bundle-symbolicname com.h2database Medium Product Manifest Implementation-Title H2 Database Engine High Product Manifest implementation-url https://h2database.com Low Product Manifest multi-release true Low Product Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Product pom artifactid h2 Highest Product pom developer email thomas.tom.mueller at gmail dot com Low Product pom developer id thomas.tom.mueller Low Product pom developer name Thomas Mueller Low Product pom groupid com.h2database Highest Product pom name H2 Database Engine High Product pom url https://h2database.com Medium Version file version 1.4.200 High Version Manifest Bundle-Version 1.4.200 High Version Manifest Implementation-Version 1.4.200 High Version pom version 1.4.200 Highest
CVE-2021-42392 suppress
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-23221 suppress
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-23463 suppress
The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions:
h2-1.4.200.jar: data.zip: table.jsFile Path: /home/andrii/.m2/repository/com/h2database/h2/1.4.200/h2-1.4.200.jar/org/h2/util/data.zip/org/h2/server/web/res/table.jsMD5: 0e4b062032d1a5ea21b7ad0d878d3c31SHA1: c5efb4c787ace5210d545d68742f415d28a61bdcSHA256: 0e1bf9d8833063242e13836bd0fca607763676308acf8b6e6992e7d7d8008d45Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence
h2-1.4.200.jar: data.zip: tree.jsFile Path: /home/andrii/.m2/repository/com/h2database/h2/1.4.200/h2-1.4.200.jar/org/h2/util/data.zip/org/h2/server/web/res/tree.jsMD5: 98225c0658feee5efb09b28c76e25884SHA1: 6b84951f0a2febfbb1046e768d12f784047ce48cSHA256: e9ee4656df4c1db81dcf20b7dcdcf08701c3b63f929ae8d8af69c334212c169eReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence
ha-api-3.1.9.jarDescription:
Java.net - The Source for Java Technology Collaboration File Path: /home/andrii/.m2/repository/org/glassfish/ha/ha-api/3.1.9/ha-api-3.1.9.jarMD5: c347dede33d4a25276c7d6a4af22b8ffSHA1: c68b600634d4d4bae3fc54575ae850e734dc1af5SHA256: ef3c515399e7ff43836d58e76baa1e876cfdd27c358baab12a96a7e0032c30a3Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name ha-api High Vendor jar package name api Highest Vendor jar package name glassfish Highest Vendor jar package name ha Highest Vendor jar package name spi Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname org.glassfish.ha.ha-api Medium Vendor Manifest extension-name ha-api Medium Vendor Manifest hk2-class-path-id org.glassfish.hk2:hk2-core:jar:1.6.14 org.glassfish.hk2:class-model:jar:1.6.14 org.glassfish.hk2:config:jar:1.6.14 org.glassfish.hk2:auto-depends:jar:1.6.14 org.glassfish.hk2.external:javax.inject:jar:1.6.14 org.glassfish.hk2.external:asm-all-repackaged:jar:1.6.14 org.glassfish.hk2:hk2-api:jar:1.6.14 org.glassfish.hk2:osgi-resource-locator:jar:1.0.1 org.jvnet:tiger-types:jar:1.4 org.glassfish.hk2.external:bean-validator:jar:1.6.14 com.googlecode.jtype:jtype:jar:0.1.0 Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid ha-api Highest Vendor pom artifactid ha-api Low Vendor pom developer id mk111283 Medium Vendor pom developer name Mahesh Kannan Medium Vendor pom developer org Sun Microsystems, Inc. Medium Vendor pom groupid org.glassfish.ha Highest Vendor pom name GlassFish High Availability APIs and SPI High Vendor pom organization name Oracle Corporation High Vendor pom organization url http://www.oracle.com Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Product file name ha-api High Product jar package name api Highest Product jar package name glassfish Highest Product jar package name ha Highest Product jar package name spi Highest Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name GlassFish High Availability APIs and SPI Medium Product Manifest bundle-symbolicname org.glassfish.ha.ha-api Medium Product Manifest extension-name ha-api Medium Product Manifest hk2-class-path-id org.glassfish.hk2:hk2-core:jar:1.6.14 org.glassfish.hk2:class-model:jar:1.6.14 org.glassfish.hk2:config:jar:1.6.14 org.glassfish.hk2:auto-depends:jar:1.6.14 org.glassfish.hk2.external:javax.inject:jar:1.6.14 org.glassfish.hk2.external:asm-all-repackaged:jar:1.6.14 org.glassfish.hk2:hk2-api:jar:1.6.14 org.glassfish.hk2:osgi-resource-locator:jar:1.0.1 org.jvnet:tiger-types:jar:1.4 org.glassfish.hk2.external:bean-validator:jar:1.6.14 com.googlecode.jtype:jtype:jar:0.1.0 Low Product Manifest Implementation-Title ha-api High Product Manifest specification-title Java.net - The Source for Java Technology Collaboration Medium Product pom artifactid ha-api Highest Product pom developer id mk111283 Low Product pom developer name Mahesh Kannan Low Product pom developer org Sun Microsystems, Inc. Low Product pom groupid org.glassfish.ha Highest Product pom name GlassFish High Availability APIs and SPI High Product pom organization name Oracle Corporation Low Product pom organization url http://www.oracle.com Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Version file version 3.1.9 High Version Manifest Bundle-Version 3.1.9 High Version Manifest Implementation-Version 3.1.9 High Version pom parent-version 3.1.9 Low Version pom version 3.1.9 Highest
hibernate-2.1.8-atlassian-34.jarDescription:
Atlassian's fork of Hibernate 2.1.8. License:
LGPL 2.1 License: http://www.gnu.org/licenses/lgpl-2.1.txt File Path: /home/andrii/.m2/repository/hibernate/hibernate/2.1.8-atlassian-34/hibernate-2.1.8-atlassian-34.jar
MD5: e2f476aa6aca1f97a7370e7d5e7e5eda
SHA1: 320cf229f5d108767612337d03039b3c64a0793b
SHA256: 6560f94ebc9aa26784fc755842afcff221fd941230051a9a4a558c890a3f8edb
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate High Vendor jar package name atlassian Highest Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor jar package name net Low Vendor jar package name sf Low Vendor pom artifactid hibernate Highest Vendor pom artifactid hibernate Low Vendor pom groupid hibernate Highest Vendor pom name Hibernate 2.1.8 (Atlassian fork) High Product file name hibernate High Product jar package name atlassian Highest Product jar package name hibernate Highest Product jar package name hibernate Low Product jar package name sf Low Product pom artifactid hibernate Highest Product pom groupid hibernate Highest Product pom name Hibernate 2.1.8 (Atlassian fork) High Version pom version 2.1.8-atlassian-34 Highest
hibernate-commons-annotations-5.0.1.Final.jarDescription:
Common reflection code used in support of annotation processing License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html File Path: /home/andrii/.m2/repository/org/hibernate/common/hibernate-commons-annotations/5.0.1.Final/hibernate-commons-annotations-5.0.1.Final.jar
MD5: 2a9d6f5a4ece96557bc4300ecc4486fb
SHA1: 71e1cff3fcb20d3b3af4f3363c3ddb24d33c6879
SHA256: 9431ca05c335f9b6ec550f5d65ad56047a5f336e2d41cce4067591d20c4e51df
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate-commons-annotations High Vendor hint analyzer vendor redhat Highest Vendor jar package name annotations Highest Vendor jar package name common Highest Vendor jar package name hibernate Highest Vendor jar package name reflection Highest Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor pom artifactid hibernate-commons-annotations Highest Vendor pom artifactid hibernate-commons-annotations Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL http://hibernate.org Medium Vendor pom groupid org.hibernate.common Highest Vendor pom name Hibernate Commons Annotations High Vendor pom organization name Hibernate.org High Vendor pom organization url http://hibernate.org Medium Vendor pom url http://hibernate.org Highest Product file name hibernate-commons-annotations High Product jar package name annotations Highest Product jar package name common Highest Product jar package name hibernate Highest Product jar package name reflection Highest Product Manifest Bundle-Name hibernate-commons-annotations Medium Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium Product Manifest implementation-url http://hibernate.org Low Product pom artifactid hibernate-commons-annotations Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL http://hibernate.org Low Product pom groupid org.hibernate.common Highest Product pom name Hibernate Commons Annotations High Product pom organization name Hibernate.org Low Product pom organization url http://hibernate.org Low Product pom url http://hibernate.org Medium Version Manifest Bundle-Version 5.0.1.Final High Version Manifest Implementation-Version 5.0.1.Final High Version pom version 5.0.1.Final Highest
hibernate-core-5.2.18.Final.jarDescription:
The core O/RM functionality as provided by Hibernate License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html File Path: /home/andrii/.m2/repository/org/hibernate/hibernate-core/5.2.18.Final/hibernate-core-5.2.18.Final.jar
MD5: a5e6ac320c1b5fd739d213dc050cfc29
SHA1: c1861a015d47f55ffc6cb120216d17af177e0b90
SHA256: 4688003fc081063f0d73f43424b309bac9bd8589fecb5767e0ad26788a5bfdff
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate-core High Vendor hint analyzer vendor redhat Highest Vendor jar package name hibernate Highest Vendor Manifest bundle-symbolicname org.hibernate.core Medium Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Hibernate.org Low Vendor pom artifactid hibernate-core Highest Vendor pom artifactid hibernate-core Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL http://hibernate.org Medium Vendor pom groupid org.hibernate Highest Vendor pom name Core Hibernate O/RM functionality High Vendor pom organization name Hibernate.org High Vendor pom organization url http://hibernate.org Medium Vendor pom url http://hibernate.org Highest Product file name hibernate-core High Product hint analyzer product orm Highest Product jar package name filter Highest Product jar package name hibernate Highest Product jar package name version Highest Product Manifest Bundle-Name hibernate-core Medium Product Manifest bundle-symbolicname org.hibernate.core Medium Product Manifest Implementation-Title hibernate-core High Product Manifest implementation-url http://hibernate.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title hibernate-core Medium Product pom artifactid hibernate-core Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL http://hibernate.org Low Product pom groupid org.hibernate Highest Product pom name Core Hibernate O/RM functionality High Product pom organization name Hibernate.org Low Product pom organization url http://hibernate.org Low Product pom url http://hibernate.org Medium Version Manifest Bundle-Version 5.2.18.Final High Version Manifest Implementation-Version 5.2.18.Final High Version pom version 5.2.18.Final Highest
Related Dependencies hibernate-c3p0-5.2.18.Final.jarFile Path: /home/andrii/.m2/repository/org/hibernate/hibernate-c3p0/5.2.18.Final/hibernate-c3p0-5.2.18.Final.jar MD5: 841a10867b9706e7bfc14c24696ccd5d SHA1: 5c78318e41c523e12529c870e4d89d61ce06efa9 SHA256: d8e74bdeed6dd35e7b976311180dd7164562a3edcef62e5b85f2e434efb8f15d pkg:maven/org.hibernate/hibernate-c3p0@5.2.18.Final hibernate-hikaricp-5.2.18.Final.jarFile Path: /home/andrii/.m2/repository/org/hibernate/hibernate-hikaricp/5.2.18.Final/hibernate-hikaricp-5.2.18.Final.jar MD5: 53027798203a938d391cfecc2a08d68e SHA1: 32bf2df6bda97f9dcb1127b56b6bb0db262f5435 SHA256: 2e9c31ec8c4aa15402c91191dde8c4d079ec3f480e2b52161a20e1881c44c37d pkg:maven/org.hibernate/hibernate-hikaricp@5.2.18.Final CVE-2020-25638 suppress
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: HIGH (7.4) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-14900 suppress
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
hibernate-envers-5.2.2.Final.jarDescription:
ENtity VERSioning support License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html File Path: /home/andrii/.m2/repository/org/hibernate/hibernate-envers/5.2.2.Final/hibernate-envers-5.2.2.Final.jar
MD5: b481ebff6eef67cb2254fc4f41872ab8
SHA1: 34d9a72456f84269d1cd1d6ad01bab5e0c3f7828
SHA256: 728edc2d76ba799ccfe4d4008b6dc2027acd917097ac52bfd5d11349dcc81708
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate-envers High Vendor hint analyzer vendor redhat Highest Vendor jar package name envers Highest Vendor jar package name hibernate Highest Vendor Manifest bundle-symbolicname org.hibernate.envers Medium Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Hibernate.org Low Vendor pom artifactid hibernate-envers Highest Vendor pom artifactid hibernate-envers Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL http://hibernate.org Medium Vendor pom groupid org.hibernate Highest Vendor pom name ENtity VERSioning support High Vendor pom organization name Hibernate.org High Vendor pom organization url http://hibernate.org Medium Vendor pom url http://hibernate.org Highest Product file name hibernate-envers High Product hint analyzer product orm Highest Product jar package name envers Highest Product jar package name hibernate Highest Product Manifest Bundle-Name hibernate-envers Medium Product Manifest bundle-symbolicname org.hibernate.envers Medium Product Manifest Implementation-Title hibernate-envers High Product Manifest implementation-url http://hibernate.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title hibernate-envers Medium Product pom artifactid hibernate-envers Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL http://hibernate.org Low Product pom groupid org.hibernate Highest Product pom name ENtity VERSioning support High Product pom organization name Hibernate.org Low Product pom organization url http://hibernate.org Low Product pom url http://hibernate.org Medium Version Manifest Bundle-Version 5.2.2.Final High Version Manifest Implementation-Version 5.2.2.Final High Version pom version 5.2.2.Final Highest
CVE-2020-25638 suppress
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: HIGH (7.4) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-14900 suppress
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
hibernate-jpa-2.1-api-1.0.0.Final.jarDescription:
Clean-room definition of JPA APIs intended for use in developing Hibernate JPA implementation. See README.md for details License:
Eclipse Public License (EPL), Version 1.0: http://www.eclipse.org/legal/epl-v10.html
Eclipse Distribution License (EDL), Version 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/andrii/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.1-api/1.0.0.Final/hibernate-jpa-2.1-api-1.0.0.Final.jar
MD5: 01b091825023c97fdfd6d2bceebe03ff
SHA1: 5e731d961297e5a07290bfaf3db1fbc8bbbf405a
SHA256: ab46597e3a057f99c8339fffe14c1d27f9dbd2409ae840c62121b00d983c78bd
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate-jpa-2.1-api-1.0.0.Final High Vendor hint analyzer vendor redhat Highest Vendor jar package name javax Highest Vendor jar package name persistence Highest Vendor jar package name version Highest Vendor Manifest bundle-symbolicname org.hibernate.javax.persistence.hibernate-jpa-2.1-api Medium Vendor Manifest Implementation-Vendor hibernate.org High Vendor pom artifactid hibernate-jpa-2.1-api Highest Vendor pom artifactid hibernate-jpa-2.1-api Low Vendor pom developer email emmanuel@hibernate.org Low Vendor pom developer email hferents@redhat.com Low Vendor pom developer email steve@hibernate.org Low Vendor pom developer id epbernard Medium Vendor pom developer id hardy.ferentschik Medium Vendor pom developer id sebersole Medium Vendor pom developer name Emmanuel Bernard Medium Vendor pom developer name Hardy Ferentschik Medium Vendor pom developer name Steve Ebersole Medium Vendor pom developer org Red Hat, Inc. Medium Vendor pom groupid org.hibernate.javax.persistence Highest Vendor pom name Java Persistence API, Version 2.1 High Vendor pom url http://hibernate.org Highest Product file name hibernate-jpa-2.1-api-1.0.0.Final High Product jar package name javax Highest Product jar package name persistence Highest Product jar package name version Highest Product Manifest Bundle-Name hibernate-jpa-2.1-api Medium Product Manifest bundle-symbolicname org.hibernate.javax.persistence.hibernate-jpa-2.1-api Medium Product Manifest Implementation-Title Java Persistence API High Product Manifest specification-title Java Persistence API, Version 2.1 Medium Product pom artifactid hibernate-jpa-2.1-api Highest Product pom developer email emmanuel@hibernate.org Low Product pom developer email hferents@redhat.com Low Product pom developer email steve@hibernate.org Low Product pom developer id epbernard Low Product pom developer id hardy.ferentschik Low Product pom developer id sebersole Low Product pom developer name Emmanuel Bernard Low Product pom developer name Hardy Ferentschik Low Product pom developer name Steve Ebersole Low Product pom developer org Red Hat, Inc. Low Product pom groupid org.hibernate.javax.persistence Highest Product pom name Java Persistence API, Version 2.1 High Product pom url http://hibernate.org Medium Version Manifest Bundle-Version 1.0.0.Final High Version Manifest Implementation-Version 1.0.0.Final High Version pom version 1.0.0.Final Highest
hibernate-validator-6.0.21.Final.jarDescription:
Hibernate's Bean Validation (JSR-380) reference implementation. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/hibernate/validator/hibernate-validator/6.0.21.Final/hibernate-validator-6.0.21.Final.jar
MD5: d7889b64835a9134fe880d9f358a9d70
SHA1: 7a78bd29f9931b2d4fd92edd05085e664f357bfe
SHA256: 7010ca3c3a47626fa482ef5476ca2f1485fd0d7cb5f201419446fe265ec56755
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate-validator High Vendor hint analyzer vendor redhat Highest Vendor jar package name engine Highest Vendor jar package name hibernate Highest Vendor jar package name validator Highest Vendor Manifest automatic-module-name org.hibernate.validator Medium Vendor Manifest bundle-symbolicname org.hibernate.validator.hibernate-validator Medium Vendor Manifest implementation-url http://hibernate.org/validator/ Low Vendor Manifest Implementation-Vendor org.hibernate.validator High Vendor Manifest Implementation-Vendor-Id org.hibernate.validator Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid hibernate-validator Highest Vendor pom artifactid hibernate-validator Low Vendor pom groupid org.hibernate.validator Highest Vendor pom name Hibernate Validator Engine High Vendor pom parent-artifactid hibernate-validator-parent Low Product file name hibernate-validator High Product jar package name engine Highest Product jar package name hibernate Highest Product jar package name validator Highest Product Manifest automatic-module-name org.hibernate.validator Medium Product Manifest Bundle-Name Hibernate Validator Engine Medium Product Manifest bundle-symbolicname org.hibernate.validator.hibernate-validator Medium Product Manifest Implementation-Title hibernate-validator High Product Manifest implementation-url http://hibernate.org/validator/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Bean Validation Medium Product pom artifactid hibernate-validator Highest Product pom groupid org.hibernate.validator Highest Product pom name Hibernate Validator Engine High Product pom parent-artifactid hibernate-validator-parent Medium Version Manifest Bundle-Version 6.0.21.Final High Version Manifest Implementation-Version 6.0.21.Final High Version pom version 6.0.21.Final Highest
hibernate.adapter-1.0.3.jarLicense:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0
Atlassian Customer Agreement: https://www.atlassian.com/customer-agreement/ File Path: /home/andrii/.m2/repository/com/atlassian/hibernate/hibernate.adapter/1.0.3/hibernate.adapter-1.0.3.jar
MD5: b8c98d71fd21e9b8bddbea7a68de4907
SHA1: 9a10153a88a63d80324358a2e3e42d21e187e0f8
SHA256: 46efe609cd5b0f727a7eefb7e5b714c78759ba7593a18f6d928e864f844edde6
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hibernate.adapter High Vendor jar package name adapter Highest Vendor jar package name atlassian Highest Vendor jar package name hibernate Highest Vendor Manifest Implementation-Vendor Atlassian High Vendor Manifest Implementation-Vendor-Id com.atlassian.hibernate Medium Vendor Manifest specification-vendor Atlassian Low Vendor pom artifactid hibernate.adapter Highest Vendor pom artifactid hibernate.adapter Low Vendor pom groupid com.atlassian.hibernate Highest Vendor pom name Hibernate API adapter High Vendor pom parent-artifactid closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name hibernate.adapter High Product jar package name adapter Highest Product jar package name atlassian Highest Product jar package name hibernate Highest Product Manifest Implementation-Title Hibernate API adapter High Product Manifest specification-title Hibernate API adapter Medium Product pom artifactid hibernate.adapter Highest Product pom groupid com.atlassian.hibernate Highest Product pom name Hibernate API adapter High Product pom parent-artifactid closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.0.3 High Version Manifest Implementation-Version 1.0.3 High Version pom parent-version 1.0.3 Low Version pom version 1.0.3 Highest
hsqldb-2.3.0.jarDescription:
HSQLDB - Lightweight 100% Java SQL Database Engine License:
HSQLDB License, a BSD open source license: http://hsqldb.org/web/hsqlLicense.html File Path: /home/andrii/.m2/repository/org/hsqldb/hsqldb/2.3.0/hsqldb-2.3.0.jar
MD5: c168667de846cafe5bf2a4d268f4665d
SHA1: 93306187b1a782f2b929d12536022185487037d2
SHA256: ff82a3a8b768b237ff71d71f040b005e37d844a715d4b6205ded0fad1fc28019
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name hsqldb High Vendor jar package name database Highest Vendor jar package name hsqldb Highest Vendor jar package name java Highest Vendor Manifest build-vendor blaine Medium Vendor Manifest bundle-symbolicname org.hsqldb.hsqldb Medium Vendor Manifest Implementation-Vendor The HSQL Development Group High Vendor Manifest originally-created-by 1.6.0_30-b12 (Sun Microsystems Inc.) Low Vendor Manifest specification-vendor The HSQL Development Group Low Vendor pom artifactid hsqldb Highest Vendor pom artifactid hsqldb Low Vendor pom developer email blaine.simpson@admc.com Low Vendor pom developer id unsaved Medium Vendor pom developer name Blaine Simpson Medium Vendor pom groupid org.hsqldb Highest Vendor pom name HyperSQL Database High Vendor pom organization name The HSQL Development Group High Vendor pom organization url http://hsqldb.org Medium Vendor pom url http://hsqldb.org Highest Product file name hsqldb High Product jar package name database Highest Product jar package name hsqldb Highest Product jar package name java Highest Product Manifest Bundle-Name HSQLDB Medium Product Manifest bundle-symbolicname org.hsqldb.hsqldb Medium Product Manifest Implementation-Title Standard runtime High Product Manifest originally-created-by 1.6.0_30-b12 (Sun Microsystems Inc.) Low Product Manifest specification-title HSQLDB Medium Product pom artifactid hsqldb Highest Product pom developer email blaine.simpson@admc.com Low Product pom developer id unsaved Low Product pom developer name Blaine Simpson Low Product pom groupid org.hsqldb Highest Product pom name HyperSQL Database High Product pom organization name The HSQL Development Group Low Product pom organization url http://hsqldb.org Low Product pom url http://hsqldb.org Medium Version file version 2.3.0 High Version Manifest Bundle-Version 2.3.0 High Version Manifest Implementation-Version 2.3.0 High Version pom version 2.3.0 Highest
CVE-2022-41853 suppress
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
httpclient-4.5.5.jarDescription:
Apache HttpComponents Client
File Path: /home/andrii/.m2/repository/org/apache/httpcomponents/httpclient/4.5.5/httpclient-4.5.5.jarMD5: 97e7e5b135476b7d25a5ab31e1ea4922SHA1: 1603dfd56ebcd583ccdf337b6c3984ac55d89e58SHA256: 7e97724443ad2a25ad8c73183431d47cc7946271bcbbdfa91a8a17522a566573Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name httpclient High Vendor jar package name apache Highest Vendor jar package name client Highest Vendor jar package name httpclient Highest Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2018-01-18 11:52:14+0000 Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom artifactid httpclient Highest Vendor pom artifactid httpclient Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client Highest Product file name httpclient High Product jar package name apache Highest Product jar package name client Highest Product jar package name http Highest Product jar package name httpclient Highest Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2018-01-18 11:52:14+0000 Low Product Manifest Implementation-Title HttpComponents Apache HttpClient High Product Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Product Manifest specification-title HttpComponents Apache HttpClient Medium Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom artifactid httpclient Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client Medium Version file version 4.5.5 High Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
httpclient-cache-4.5.3.jarDescription:
Apache HttpComponents HttpClient - Cache
File Path: /home/andrii/.m2/repository/org/apache/httpcomponents/httpclient-cache/4.5.3/httpclient-cache-4.5.3.jarMD5: cf3f254ca1228dd59818a2dff708e247SHA1: baa6474c7f9b9f027a02fbbee375263ac482e343SHA256: 8c9cf6355ab7b3cfd812f9bfaddf8f8c02f1a3a59496abc0d6717b98ce989599Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name httpclient-cache High Vendor jar package name apache Highest Vendor jar package name cache Highest Vendor jar package name client Highest Vendor Manifest implementation-build tags/4.5.3-RC1/httpclient-cache@r1779741; 2017-01-21 16:58:35+0100 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom artifactid httpclient-cache Highest Vendor pom artifactid httpclient-cache Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient Cache High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client Highest Product file name httpclient-cache High Product jar package name apache Highest Product jar package name cache Highest Product jar package name client Highest Product jar package name http Highest Product Manifest implementation-build tags/4.5.3-RC1/httpclient-cache@r1779741; 2017-01-21 16:58:35+0100 Low Product Manifest Implementation-Title HttpComponents Apache HttpClient Cache High Product Manifest specification-title HttpComponents Apache HttpClient Cache Medium Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom artifactid httpclient-cache Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient Cache High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client Medium Version file version 4.5.3 High Version Manifest Implementation-Version 4.5.3 High Version pom version 4.5.3 Highest
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
httpcore-4.4.9.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /home/andrii/.m2/repository/org/apache/httpcomponents/httpcore/4.4.9/httpcore-4.4.9.jarMD5: b89455507839c09d6119661defd2166aSHA1: a86ce739e5a7175b4b234c290a00a5fdb80957a0SHA256: 1b4a1c0b9b4222eda70108d3c6e2befd4a6be3d9f78ff53dd7a94966fdf51fc5Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name httpcore High Vendor jar package name apache Highest Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2018-01-12 03:41:36+0000 Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor pom artifactid httpcore Highest Vendor pom artifactid httpcore Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpCore High Vendor pom parent-artifactid httpcomponents-core Low Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product file name httpcore High Product jar package name apache Highest Product jar package name http Highest Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2018-01-12 03:41:36+0000 Low Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product pom artifactid httpcore Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpCore High Product pom parent-artifactid httpcomponents-core Medium Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Version file version 4.4.9 High Version Manifest Implementation-Version 4.4.9 High Version pom version 4.4.9 Highest
httpmime-4.5.5.jarDescription:
Apache HttpComponents HttpClient - MIME coded entities
File Path: /home/andrii/.m2/repository/org/apache/httpcomponents/httpmime/4.5.5/httpmime-4.5.5.jarMD5: 519a5a3902d446926764f568784adbffSHA1: 8281b24b8a493374cd2aa8a90c4156588f7dbcb6SHA256: e46206931b7426102e658f086f74ee582761264a8f9977fba02c1e200c51a9c5Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name httpmime High Vendor jar package name apache Highest Vendor jar package name mime Highest Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2018-01-18 11:52:14+0000 Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-client Low Vendor pom artifactid httpmime Highest Vendor pom artifactid httpmime Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient Mime High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client Highest Product file name httpmime High Product jar package name apache Highest Product jar package name http Highest Product jar package name mime Highest Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2018-01-18 11:52:14+0000 Low Product Manifest Implementation-Title HttpComponents Apache HttpClient Mime High Product Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Product Manifest specification-title HttpComponents Apache HttpClient Mime Medium Product Manifest url http://hc.apache.org/httpcomponents-client Low Product pom artifactid httpmime Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient Mime High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client Medium Version file version 4.5.5 High Version Manifest Implementation-Version 4.5.5 High Version pom version 4.5.5 Highest
icu4j-64.1.jarDescription:
International Component for Unicode for Java (ICU4J) is a mature, widely used Java library
providing Unicode and Globalization support
License:
Unicode/ICU License: https://raw.githubusercontent.com/unicode-org/icu/master/icu4c/LICENSE File Path: /home/andrii/.m2/repository/com/ibm/icu/icu4j/64.1/icu4j-64.1.jar
MD5: 5135c14813b6bc28e8afd1b5ea5f4818
SHA1: 1ab5b994d5882dd949e2293e82973ed5decd3dc6
SHA256: c9f4093e5788dec652dfc0744ec1bfee7e68c0e13e36880712aeaea28cb9cd35
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name icu4j High Vendor file (hint) name icu-project High Vendor file (hint) name unicode High Vendor jar package name ibm Highest Vendor jar package name icu Highest Vendor Manifest automatic-module-name com.ibm.icu Medium Vendor Manifest bundle-copyright © 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html#License Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low Vendor Manifest bundle-symbolicname com.ibm.icu Medium Vendor Manifest Implementation-Vendor Unicode, Inc. High Vendor Manifest Implementation-Vendor-Id org.unicode Medium Vendor pom artifactid icu4j Highest Vendor pom artifactid icu4j Low Vendor pom developer id deborah Medium Vendor pom developer id dougfelt Medium Vendor pom developer id JCEmmons Medium Vendor pom developer id macchiati Medium Vendor pom developer id markusicu Medium Vendor pom developer id pedberg Medium Vendor pom developer id srl295 Medium Vendor pom developer id yumaoka Medium Vendor pom developer name Deborah Goldsmith Medium Vendor pom developer name Doug Felt Medium Vendor pom developer name John Emmons Medium Vendor pom developer name Mark Davis Medium Vendor pom developer name Markus Scherer Medium Vendor pom developer name Peter Edberg Medium Vendor pom developer name Steven Loomis Medium Vendor pom developer name Yoshito Umaoka Medium Vendor pom developer org Apple Medium Vendor pom developer org Google Medium Vendor pom developer org IBM Corporation Medium Vendor pom groupid com.ibm.icu Highest Vendor pom name ICU4J High Vendor pom url http://icu-project.org/ Highest Vendor pom (hint) artifactid icu-project Highest Vendor pom (hint) artifactid icu-project Low Vendor pom (hint) artifactid unicode Highest Vendor pom (hint) artifactid unicode Low Vendor pom (hint) name icu-project High Vendor pom (hint) name unicode High Product file name icu4j High Product hint analyzer product international_components_for_unicode Highest Product jar package name ibm Highest Product jar package name icu Highest Product Manifest automatic-module-name com.ibm.icu Medium Product Manifest bundle-copyright © 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html#License Low Product Manifest Bundle-Name ICU4J Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low Product Manifest bundle-symbolicname com.ibm.icu Medium Product Manifest Implementation-Title International Components for Unicode for Java High Product Manifest specification-title International Components for Unicode for Java Medium Product pom artifactid icu4j Highest Product pom developer id deborah Low Product pom developer id dougfelt Low Product pom developer id JCEmmons Low Product pom developer id macchiati Low Product pom developer id markusicu Low Product pom developer id pedberg Low Product pom developer id srl295 Low Product pom developer id yumaoka Low Product pom developer name Deborah Goldsmith Low Product pom developer name Doug Felt Low Product pom developer name John Emmons Low Product pom developer name Mark Davis Low Product pom developer name Markus Scherer Low Product pom developer name Peter Edberg Low Product pom developer name Steven Loomis Low Product pom developer name Yoshito Umaoka Low Product pom developer org Apple Low Product pom developer org Google Low Product pom developer org IBM Corporation Low Product pom groupid com.ibm.icu Highest Product pom name ICU4J High Product pom url http://icu-project.org/ Medium Version file version 64.1 High Version Manifest Bundle-Version 64.1 High Version Manifest Implementation-Version 64.1 High Version pom version 64.1 Highest
pkg:maven/com.ibm.icu/icu4j@64.1 (Confidence :High)cpe:2.3:a:icu-project:international_components_for_unicode:64.1:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:unicode:international_components_for_unicode:64.1:*:*:*:*:*:*:* (Confidence :Low) suppress imageio-core-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/imageio/imageio-core/3.4.1/imageio-core-3.4.1.jarMD5: f981bf55862728f35856a61e8789be28SHA1: e6a2ab00c5b39c70c024e85ed277698177cbf3e0SHA256: 21a42e88d3c9f7c8255ce77428f1f3bd377ea497ff4d42baec3b1ec68aba22b9Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name imageio-core High Vendor jar package name imageio Highest Vendor jar package name twelvemonkeys Highest Vendor Manifest implementation-url https://github.com/haraldk/TwelveMonkeys/imageio/imageio-core Low Vendor Manifest Implementation-Vendor TwelveMonkeys High Vendor pom artifactid imageio-core Highest Vendor pom artifactid imageio-core Low Vendor pom groupid com.twelvemonkeys.imageio Highest Vendor pom name TwelveMonkeys :: ImageIO :: Core High Vendor pom parent-artifactid imageio Low Product file name imageio-core High Product jar package name imageio Highest Product jar package name twelvemonkeys Highest Product Manifest Implementation-Title twelvemonkeys-imageio-core High Product Manifest implementation-url https://github.com/haraldk/TwelveMonkeys/imageio/imageio-core Low Product pom artifactid imageio-core Highest Product pom groupid com.twelvemonkeys.imageio Highest Product pom name TwelveMonkeys :: ImageIO :: Core High Product pom parent-artifactid imageio Medium Version file version 3.4.1 High Version Manifest Implementation-Version 3.4.1 High Version pom version 3.4.1 Highest
Related Dependencies imageio-bmp-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/imageio/imageio-bmp/3.4.1/imageio-bmp-3.4.1.jar MD5: ab027359caf5997f74cd3a00297699b7 SHA1: d57bb02c2a4029e08772ee7786bc8c0cd1207220 SHA256: 6bb7143216430e0f2e5b73cba47efe98946182c5de63d1245ac441ee81dc519a pkg:maven/com.twelvemonkeys.imageio/imageio-bmp@3.4.1 imageio-icns-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/imageio/imageio-icns/3.4.1/imageio-icns-3.4.1.jar MD5: 0029cfa04582f7f7fb300c40e202f036 SHA1: 285fa50aef37d32b0a308744bacb1b3922c5c789 SHA256: 0dfc4bce87b562101ed81d7d775d321ac82e63850256226da88f72c538cb0f6c pkg:maven/com.twelvemonkeys.imageio/imageio-icns@3.4.1 imageio-jpeg-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/imageio/imageio-jpeg/3.4.1/imageio-jpeg-3.4.1.jar MD5: 3f0f9bb9c5ab976542a4a20e73893d64 SHA1: ea993b71b2186b3b887bb19f75d23baf16b4d6c9 SHA256: 6ded3a04393b89cdf83726e80402f46c3ceaafcd59dfac9a23e703045a182b75 pkg:maven/com.twelvemonkeys.imageio/imageio-jpeg@3.4.1 imageio-metadata-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/imageio/imageio-metadata/3.4.1/imageio-metadata-3.4.1.jar MD5: 3614f6d6e3349f0621c96d40c8cd7bf1 SHA1: d83042685dea0584905f2157c4be93f1d34f24b0 SHA256: 56318cd28bd1900ff0d0e2dd54477898c32d0d243a66ca6a23f4e1fca87e329b pkg:maven/com.twelvemonkeys.imageio/imageio-metadata@3.4.1 imageio-tiff-3.4.1.jarFile Path: /home/andrii/.m2/repository/com/twelvemonkeys/imageio/imageio-tiff/3.4.1/imageio-tiff-3.4.1.jar MD5: 599b52d3ab218a1430ada0dcf0b6c63c SHA1: b88d400ff05a22aedfea8718892ffcf98a401787 SHA256: 3b293371fc84216ceee837a5ce91e37e4c43a2f0f07ac6fa26cfc52fe9e20eec pkg:maven/com.twelvemonkeys.imageio/imageio-tiff@3.4.1 CVE-2021-23792 suppress
The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when an online profile picture is processed) with a malicious XMP segment. If the XMP metadata of the uploaded image is parsed, then the XXE vulnerability is triggered. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
index-50b0b662.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/index-50b0b662.jsMD5: 8b2d3f1856f9199fde3105a515e92018SHA1: b1ac3668162d95555dd6397775ff525446e5f0b2SHA256: 996a0d7b2b1e089b83c3853c9a99f09473b97f103a2680f9c4430b05191a0570Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
index-a6389306.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/index-a6389306.jsMD5: d7caafac4fe58b83bf7a13f35ffc7f3fSHA1: a1883775e48b8c90e57553775c8266ff17a648a9SHA256: 111f01e1adfb3a9ece4cdf858f39626cb51508b0ce3db2b3e5da93f17a35ed69Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
index-ae389540.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/index-ae389540.jsMD5: 1ca37270eca588ace11108632349508fSHA1: 70e629a96532be92bbcc9f02910ca3ff53c9ed4fSHA256: d51674991097379c240821773053bff52ff46d53d70b7cf35f3f09a0684f1648Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
index-ed440ea1.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/index-ed440ea1.jsMD5: bc250d081983329a59b18e1359b2ad34SHA1: bd6943bf5293cef8b879f6e92477265720cdf6d2SHA256: 95885cd0cbbef7e21687a1bc64f28e62e84d653ccb612c02b49f09eced4198f0Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
index.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/src/index.jsMD5: ff15e4e69d6022f11f1b11ae1209a46bSHA1: b74f89799952aa9bc55e1857bd21b7c58ba0df1cSHA256: 245661b80984685b504d7fa7a008a55107ad3d8be93f7b61df1d1a1f95bf3797Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
istack-commons-runtime-3.0.7.jarDescription:
istack common utility code License:
https://glassfish.java.net/public/CDDL+GPL_1_1.html, https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/com/sun/istack/istack-commons-runtime/3.0.7/istack-commons-runtime-3.0.7.jar
MD5: 83e9617b86023b91bd54f65c09838f4b
SHA1: c197c86ceec7318b1284bffb49b54226ca774003
SHA256: 6443e10ba2e259fb821d9b6becf10db5316285fc30c53cec9d7b19a3877e7fdf
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name istack-commons-runtime High Vendor jar package name istack Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Vendor Manifest implementation-build-id 3.0.7-c8b5e20894f565780625d6f9b018ef7c458cd688, 2018-08-29T05:23:37-0700 Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid istack-commons-runtime Highest Vendor pom artifactid istack-commons-runtime Low Vendor pom groupid com.sun.istack Highest Vendor pom name istack common utility code runtime High Vendor pom parent-artifactid istack-commons Low Product file name istack-commons-runtime High Product jar package name istack Highest Product jar package name sun Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name istack common utility code runtime Medium Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Product Manifest implementation-build-id 3.0.7-c8b5e20894f565780625d6f9b018ef7c458cd688, 2018-08-29T05:23:37-0700 Low Product Manifest Implementation-Title istack common utility code runtime High Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid istack-commons-runtime Highest Product pom groupid com.sun.istack Highest Product pom name istack common utility code runtime High Product pom parent-artifactid istack-commons Medium Version file version 3.0.7 High Version Manifest Bundle-Version 3.0.7 High Version Manifest Implementation-Version 3.0.7 High Version pom version 3.0.7 Highest
j2objc-annotations-1.1.jarDescription:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/google/j2objc/j2objc-annotations/1.1/j2objc-annotations-1.1.jar
MD5: 49ae3204bb0bb9b2ac77062641f4a6d7
SHA1: ed28ded51a8b1c6b112568def5f4b455e6809019
SHA256: 2994a7eb78f2710bd3d3bfb639b2c94e219cedac0d4d084d516e78c16dddecf6
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name j2objc-annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name google Highest Vendor jar package name google Low Vendor jar package name j2objc Highest Vendor jar package name j2objc Low Vendor pom artifactid j2objc-annotations Highest Vendor pom artifactid j2objc-annotations Low Vendor pom groupid com.google.j2objc Highest Vendor pom name J2ObjC Annotations High Vendor pom url google/j2objc/ Highest Product file name j2objc-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name google Highest Product jar package name j2objc Highest Product jar package name j2objc Low Product pom artifactid j2objc-annotations Highest Product pom groupid com.google.j2objc Highest Product pom name J2ObjC Annotations High Product pom url google/j2objc/ High Version file version 1.1 High Version pom version 1.1 Highest
jackson-core-2.12.1.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.12.1/jackson-core-2.12.1.jar
MD5: 6a65df7a5e62df2754726857b4ab0257
SHA1: 7c5493930e439be6fcec80a9afd6516b8e5e8760
SHA256: cc899cb6eae0c80b87d590eea86528797369cc4feb7b79463207d6bb18f0c257
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor jar package name base Highest Vendor jar package name core Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name json Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest implementation-build-date 2021-01-09 01:12:40+0000 Low Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-core Highest Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-core High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-core Highest Product file name jackson-core High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name base Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product jar package name jackson Highest Product jar package name json Highest Product jar package name version Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest implementation-build-date 2021-01-09 01:12:40+0000 Low Product Manifest Implementation-Title Jackson-core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Jackson-core Medium Product pom artifactid jackson-core Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-core High Version file version 2.12.1 High Version Manifest Bundle-Version 2.12.1 High Version Manifest Implementation-Version 2.12.1 High Version pom version 2.12.1 Highest
Related Dependencies jackson-annotations-2.12.1.jarFile Path: /home/andrii/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.12.1/jackson-annotations-2.12.1.jar MD5: ac96cb6fdf09ba1e2c41f461047f1eb4 SHA1: aa079f822ddce5548018286d19ccb15c2fc202d7 SHA256: 203cefdfa6c81e6aa84e11f292f29ca97344a3c3bc0293abea065cd837592873 pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.12.1 jackson-core-asl-1.9.13-atlassian-5.jarDescription:
Jackson is a high-performance JSON processor (parser, generator)
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/codehaus/jackson/jackson-core-asl/1.9.13-atlassian-5/jackson-core-asl-1.9.13-atlassian-5.jar
MD5: c747f577dd55f7b19ee6231b98823525
SHA1: be9b997685e10367f5ad1b28c6e9483bde9b53f3
SHA256: 11153210bfdbd838165b4c97643a10f428620a150b9c43702b686fe584e2fdb5
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jackson-core-asl High Vendor jar package name codehaus Highest Vendor jar package name jackson Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Vendor Manifest bundle-symbolicname jackson-core-asl Medium Vendor Manifest Implementation-Vendor http://fasterxml.com High Vendor Manifest specification-vendor http://www.ietf.org/rfc/rfc4627.txt Low Vendor pom artifactid jackson-core-asl Highest Vendor pom artifactid jackson-core-asl Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id cowtowncoder Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid org.codehaus.jackson Highest Vendor pom name Jackson High Vendor pom organization name FasterXML High Vendor pom organization url http://fasterxml.com Medium Vendor pom url http://jackson.codehaus.org Highest Product file name jackson-core-asl High Product jar package name codehaus Highest Product jar package name jackson Highest Product Manifest Bundle-Name Jackson JSON processor Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Product Manifest bundle-symbolicname jackson-core-asl Medium Product Manifest Implementation-Title Jackson JSON processor High Product Manifest specification-title JSON - JavaScript Object Notation Medium Product pom artifactid jackson-core-asl Highest Product pom developer email tatu@fasterxml.com Low Product pom developer id cowtowncoder Low Product pom developer name Tatu Saloranta Low Product pom groupid org.codehaus.jackson Highest Product pom name Jackson High Product pom organization name FasterXML Low Product pom organization url http://fasterxml.com Low Product pom url http://jackson.codehaus.org Medium Version Manifest Implementation-Version 1.9.13-atlassian-5 High Version pom version 1.9.13-atlassian-5 Highest
jackson-databind-2.12.1.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.12.1/jackson-databind-2.12.1.jar
MD5: 1925b6e2feac7e63e164f57e6fb42c9d
SHA1: 8a97e00e429c42f74757b0a8cd1d39dddd41524f
SHA256: f2ca3c28ebded59c98447d51afe945323df961540af66a063c015597af936aa0
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-databind High Vendor jar package name databind Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest implementation-build-date 2021-01-09 01:30:19+0000 Low Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-databind Highest Vendor pom artifactid jackson-databind Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name jackson-databind High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url http://github.com/FasterXML/jackson Highest Product file name jackson-databind High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name databind Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest implementation-build-date 2021-01-09 01:30:19+0000 Low Product Manifest Implementation-Title jackson-databind High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title jackson-databind Medium Product pom artifactid jackson-databind Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name jackson-databind High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url http://github.com/FasterXML/jackson Medium Version file version 2.12.1 High Version Manifest Bundle-Version 2.12.1 High Version Manifest Implementation-Version 2.12.1 High Version pom version 2.12.1 Highest
CVE-2020-36518 suppress
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. CWE-787 Out-of-bounds Write
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-42003 suppress
In FasterXML jackson-databind before 2.14.0-rc1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. Additional fix version in 2.13.4.1 and 2.12.17.1 CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-42004 suppress
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jackson-dataformat-yaml-2.14.0.jarDescription:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-yaml/2.14.0/jackson-dataformat-yaml-2.14.0.jar
MD5: 7c7b82bb5c2332d9df899689bbcb93ef
SHA1: 06c635ef06d3e4e72a7e9868da41ffa1a0f98d28
SHA256: 76e8a33ef1f5f8cce9668ebaf8999626846ccacb36dea81bcdaf79e32443de33
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-dataformat-yaml High Vendor jar package name dataformat Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name yaml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-dataformat-yaml Highest Vendor pom artifactid jackson-dataformat-yaml Low Vendor pom groupid com.fasterxml.jackson.dataformat Highest Vendor pom name Jackson-dataformat-YAML High Vendor pom parent-artifactid jackson-dataformats-text Low Vendor pom url FasterXML/jackson-dataformats-text Highest Product file name jackson-dataformat-yaml High Product jar package name dataformat Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name yaml Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Product Manifest Bundle-Name Jackson-dataformat-YAML Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium Product Manifest Implementation-Title Jackson-dataformat-YAML High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson-dataformat-YAML Medium Product pom artifactid jackson-dataformat-yaml Highest Product pom groupid com.fasterxml.jackson.dataformat Highest Product pom name Jackson-dataformat-YAML High Product pom parent-artifactid jackson-dataformats-text Medium Product pom url FasterXML/jackson-dataformats-text High Version file version 2.14.0 High Version Manifest Bundle-Version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High Version pom version 2.14.0 Highest
jackson-datatype-joda-2.12.1.jarDescription:
Add-on module for Jackson (http://github.com/FasterXML/jackson) to support Joda (https://www.joda.org/joda-time/) data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-joda/2.12.1/jackson-datatype-joda-2.12.1.jar
MD5: 8461dd73c521b761fe789f6d024497a4
SHA1: d35d1de7d9651e849dfd76c602e0f4d19f68603d
SHA256: b5b90042bf1febbf4eb1cf5c8de5c76e12d2a3a8cf49dcc2a7e374c01430ef0e
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jackson-datatype-joda High Vendor jar package name datatype Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name joda Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-datatype-joda Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-joda Medium Vendor Manifest implementation-build-date 2021-01-09 03:13:47+0000 Low Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-datatype-joda Highest Vendor pom artifactid jackson-datatype-joda Low Vendor pom groupid com.fasterxml.jackson.datatype Highest Vendor pom name Jackson datatype: Joda High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-datatype-joda Highest Product file name jackson-datatype-joda High Product jar package name datatype Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name joda Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-datatype-joda Low Product Manifest Bundle-Name Jackson datatype: Joda Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-joda Medium Product Manifest implementation-build-date 2021-01-09 03:13:47+0000 Low Product Manifest Implementation-Title Jackson datatype: Joda High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Jackson datatype: Joda Medium Product pom artifactid jackson-datatype-joda Highest Product pom groupid com.fasterxml.jackson.datatype Highest Product pom name Jackson datatype: Joda High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-datatype-joda High Version file version 2.12.1 High Version Manifest Bundle-Version 2.12.1 High Version Manifest Implementation-Version 2.12.1 High Version pom version 2.12.1 Highest
jackson-jaxrs-1.9.2.jarDescription:
Jax-RS provider for JSON content type, based on
Jackson JSON processor's data binding functionality.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
GNU Lesser General Public License (LGPL), Version 2.1: http://www.fsf.org/licensing/licenses/lgpl.txt File Path: /home/andrii/.m2/repository/org/codehaus/jackson/jackson-jaxrs/1.9.2/jackson-jaxrs-1.9.2.jar
MD5: 98fad059e87a847a1ef8e2d278b17e74
SHA1: aedf43f1d5005561e531b6bf0d067e4d20f58aba
SHA256: 99c3cb687c2d1c458c34bc582f22bb34e8ee12eba532df47b849454aa2fd7092
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jackson-jaxrs High Vendor jar package name codehaus Highest Vendor jar package name jackson Highest Vendor jar package name jaxrs Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Vendor Manifest bundle-symbolicname jackson-jaxrs Medium Vendor Manifest Implementation-Vendor http://fasterxml.com High Vendor pom artifactid jackson-jaxrs Highest Vendor pom artifactid jackson-jaxrs Low Vendor pom groupid org.codehaus.jackson Highest Vendor pom name JAX-RS provider for JSON content type High Vendor pom organization name FasterXML High Vendor pom organization url http://fasterxml.com Medium Vendor pom url http://jackson.codehaus.org Highest Product file name jackson-jaxrs High Product jar package name codehaus Highest Product jar package name jackson Highest Product jar package name jaxrs Highest Product Manifest Bundle-Name JAX-RS provider for JSON content type, using Jackson data binding Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Product Manifest bundle-symbolicname jackson-jaxrs Medium Product Manifest Implementation-Title JAX-RS provider for JSON content type, using Jackson data binding High Product pom artifactid jackson-jaxrs Highest Product pom groupid org.codehaus.jackson Highest Product pom name JAX-RS provider for JSON content type High Product pom organization name FasterXML Low Product pom organization url http://fasterxml.com Low Product pom url http://jackson.codehaus.org Medium Version file version 1.9.2 High Version Manifest Bundle-Version 1.9.2 High Version Manifest Implementation-Version 1.9.2 High Version pom version 1.9.2 Highest
jackson-mapper-asl-1.9.13-atlassian-5.jarDescription:
Data Mapper package is a high-performance data binding package
built on Jackson JSON processor
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/codehaus/jackson/jackson-mapper-asl/1.9.13-atlassian-5/jackson-mapper-asl-1.9.13-atlassian-5.jar
MD5: d347ff5d0050debcd1243b2d729a2c1f
SHA1: 6986526440063c92f2a0c1268504f4e3b515d5c7
SHA256: 8f3103bf14416ed623c15ce86e5640424a7b32e375cea152bf2cf9186f97fb8f
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jackson-mapper-asl High Vendor jar package name codehaus Highest Vendor jar package name jackson Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Vendor Manifest bundle-symbolicname jackson-mapper-asl Medium Vendor Manifest Implementation-Vendor http://fasterxml.com High Vendor pom artifactid jackson-mapper-asl Highest Vendor pom artifactid jackson-mapper-asl Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id cowtowncoder Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid org.codehaus.jackson Highest Vendor pom name Data Mapper for Jackson High Vendor pom organization name FasterXML High Vendor pom organization url http://fasterxml.com Medium Vendor pom url http://jackson.codehaus.org Highest Product file name jackson-mapper-asl High Product jar package name codehaus Highest Product jar package name jackson Highest Product Manifest Bundle-Name Data mapper for Jackson JSON processor Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Product Manifest bundle-symbolicname jackson-mapper-asl Medium Product Manifest Implementation-Title Data mapper for Jackson JSON processor High Product pom artifactid jackson-mapper-asl Highest Product pom developer email tatu@fasterxml.com Low Product pom developer id cowtowncoder Low Product pom developer name Tatu Saloranta Low Product pom groupid org.codehaus.jackson Highest Product pom name Data Mapper for Jackson High Product pom organization name FasterXML Low Product pom organization url http://fasterxml.com Low Product pom url http://jackson.codehaus.org Medium Version Manifest Implementation-Version 1.9.13-atlassian-5 High Version pom version 1.9.13-atlassian-5 Highest
jackson-module-afterburner-2.14.0.jarDescription:
Jackson (https://github.com/FasterXML/jackson) extension module
used to enhance performance using bytecode generation to replace use of Reflection for
field access and method calls
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/jackson/module/jackson-module-afterburner/2.14.0/jackson-module-afterburner-2.14.0.jar
MD5: e6ae821f1eb230dbaf21ecaa6ab68f40
SHA1: f613906269364011c225204dd1580f0dc0ae9bb8
SHA256: 8b226bd25f1ab3ceb83588ba9511007755d40efed48809885ca473b0cb3b3348
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-module-afterburner High Vendor jar package name afterburner Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name module Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-afterburner Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-module-afterburner Highest Vendor pom artifactid jackson-module-afterburner Low Vendor pom groupid com.fasterxml.jackson.module Highest Vendor pom name Jackson module: Afterburner High Vendor pom parent-artifactid jackson-modules-base Low Vendor pom url FasterXML/jackson-modules-base Highest Product file name jackson-module-afterburner High Product jar package name afterburner Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name module Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Product Manifest Bundle-Name Jackson module: Afterburner Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-afterburner Medium Product Manifest Implementation-Title Jackson module: Afterburner High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson module: Afterburner Medium Product pom artifactid jackson-module-afterburner Highest Product pom groupid com.fasterxml.jackson.module Highest Product pom name Jackson module: Afterburner High Product pom parent-artifactid jackson-modules-base Medium Product pom url FasterXML/jackson-modules-base High Version file version 2.14.0 High Version Manifest Bundle-Version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High Version pom version 2.14.0 Highest
jackson-module-blackbird-2.14.0.jarDescription:
Jackson (https://github.com/FasterXML/jackson) extension module
that uses LambdaMetafactory based code generation to replace reflection calls.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/fasterxml/jackson/module/jackson-module-blackbird/2.14.0/jackson-module-blackbird-2.14.0.jar
MD5: aaa5c88f79c1ba748a66c5a34cf7dcbf
SHA1: c7eca36524232173406b0caf7553f42a80c0ca8d
SHA256: ec7d98afad49b2264a216a7e6b7cd28035d40fe3ac5fa1229fc8be4a4a8ba451
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-module-blackbird High Vendor jar package name blackbird Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name module Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-blackbird Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-module-blackbird Highest Vendor pom artifactid jackson-module-blackbird Low Vendor pom groupid com.fasterxml.jackson.module Highest Vendor pom name Jackson module: Blackbird High Vendor pom parent-artifactid jackson-modules-base Low Vendor pom url FasterXML/jackson-modules-base Highest Product file name jackson-module-blackbird High Product jar package name blackbird Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name module Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Product Manifest Bundle-Name Jackson module: Blackbird Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-blackbird Medium Product Manifest Implementation-Title Jackson module: Blackbird High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson module: Blackbird Medium Product pom artifactid jackson-module-blackbird Highest Product pom groupid com.fasterxml.jackson.module Highest Product pom name Jackson module: Blackbird High Product pom parent-artifactid jackson-modules-base Medium Product pom url FasterXML/jackson-modules-base High Version file version 2.14.0 High Version Manifest Bundle-Version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High Version pom version 2.14.0 Highest
jackson-xc-1.9.2.jarDescription:
Extensions that provide interoperability support for
Jackson JSON processor's data binding functionality.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
GNU Lesser General Public License (LGPL), Version 2.1: http://www.fsf.org/licensing/licenses/lgpl.txt File Path: /home/andrii/.m2/repository/org/codehaus/jackson/jackson-xc/1.9.2/jackson-xc-1.9.2.jar
MD5: d9d4d69e16e45595f0542eb6f2cf1117
SHA1: 437c991a8eb2c8b69ef1dba2eba27fccb9b98448
SHA256: 97ddd164678c2705da7b22e9db3110c416b39cdfc50f385d23b586551d76a195
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jackson-xc High Vendor jar package name codehaus Highest Vendor jar package name jackson Highest Vendor jar package name xc Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Vendor Manifest bundle-symbolicname jackson-xc Medium Vendor Manifest Implementation-Vendor http://fasterxml.com High Vendor pom artifactid jackson-xc Highest Vendor pom artifactid jackson-xc Low Vendor pom groupid org.codehaus.jackson Highest Vendor pom name Xml Compatibility extensions for Jackson High Vendor pom organization name FasterXML High Vendor pom organization url http://fasterxml.com Medium Vendor pom url http://jackson.codehaus.org Highest Product file name jackson-xc High Product jar package name codehaus Highest Product jar package name jackson Highest Product jar package name xc Highest Product Manifest Bundle-Name XML Compatibility extensions for Jackson data binding Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low Product Manifest bundle-symbolicname jackson-xc Medium Product Manifest Implementation-Title XML Compatibility extensions for Jackson data binding High Product pom artifactid jackson-xc Highest Product pom groupid org.codehaus.jackson Highest Product pom name Xml Compatibility extensions for Jackson High Product pom organization name FasterXML Low Product pom organization url http://fasterxml.com Low Product pom url http://jackson.codehaus.org Medium Version file version 1.9.2 High Version Manifest Bundle-Version 1.9.2 High Version Manifest Implementation-Version 1.9.2 High Version pom version 1.9.2 Highest
CVE-2018-7489 suppress
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath. CWE-502 Deserialization of Untrusted Data, CWE-184 Incomplete Blacklist
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-36518 suppress
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. CWE-787 Out-of-bounds Write
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-42003 suppress
In FasterXML jackson-databind before 2.14.0-rc1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. Additional fix version in 2.13.4.1 and 2.12.17.1 CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-42004 suppress
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jai_codec-1.1.3.jarDescription:
Java Advanced Imaging Codec File Path: /home/andrii/.m2/repository/com/sun/jai_codec/1.1.3/jai_codec-1.1.3.jarMD5: 1b0f328c9eda0992167ce503b0a5afccSHA1: 34a67ba62097778e4695c951156bf189c2c8e016SHA256: 6d7824d972c0b6e10daa95f430f917d2256954535e62def9d287e79bf7824200Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jai_codec High Vendor jar package name codec Highest Vendor jar package name jai Highest Vendor jar package name media Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest extension-name com.sun.media.jai.codec Medium Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor pom artifactid jai_codec Highest Vendor pom artifactid jai_codec Low Vendor pom groupid com.sun Highest Product file name jai_codec High Product jar package name codec Highest Product jar package name jai Highest Product jar package name media Highest Product jar package name sun Highest Product Manifest extension-name com.sun.media.jai.codec Medium Product Manifest Implementation-Title com.sun.media.jai.codec High Product Manifest specification-title Java Advanced Imaging Codecs Medium Product pom artifactid jai_codec Highest Product pom groupid com.sun Highest Version file version 1.1.3 High Version Manifest Implementation-Version 1.1.3 High Version pom version 1.1.3 Highest
jai_core-1.1.3.jarDescription:
Java Advanced Imaging Core File Path: /home/andrii/.m2/repository/com/sun/jai_core/1.1.3/jai_core-1.1.3.jarMD5: f398bc038307ee434bac1b93ba3ab02dSHA1: b179d2efb1174658483e8b41bf4ac9d2eb5de438SHA256: 8b696cf067533545f44c2f68339e24ab1a2669153ed2081aa5be8749f4d592bfReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jai_core High Vendor jar package name jai Highest Vendor jar package name javax Highest Vendor jar package name media Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest extension-name javax.media.jai Medium Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor pom artifactid jai_core Highest Vendor pom artifactid jai_core Low Vendor pom groupid com.sun Highest Product file name jai_core High Product jar package name jai Highest Product jar package name javax Highest Product jar package name media Highest Product jar package name sun Highest Product Manifest extension-name javax.media.jai Medium Product Manifest Implementation-Title javax.media.jai High Product Manifest specification-title Java Advanced Imaging Medium Product pom artifactid jai_core Highest Product pom groupid com.sun Highest Version file version 1.1.3 High Version Manifest Implementation-Version 1.1.3 High Version pom version 1.1.3 Highest
jakarta-regexp-1.4.jarFile Path: /home/andrii/.m2/repository/jakarta-regexp/jakarta-regexp/1.4/jakarta-regexp-1.4.jarMD5: 5d8b8c601c21b37aa6142d38f45c0297SHA1: 0ea514a179ac1dd7e81c7e6594468b9b9910d298SHA256: 85ea3985d7fec552d6de6f02d8e18789c3fcd539081eb8c7c444eabf6cb3f7bcReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jakarta-regexp High Vendor jar package name apache Low Vendor jar package name regexp Highest Vendor jar package name regexp Low Vendor pom artifactid jakarta-regexp Highest Vendor pom artifactid jakarta-regexp Low Vendor pom groupid jakarta-regexp Highest Product file name jakarta-regexp High Product jar package name regexp Highest Product jar package name regexp Low Product pom artifactid jakarta-regexp Highest Product pom groupid jakarta-regexp Highest Version file version 1.4 High Version pom version 1.4 Highest
jakarta.mail-1.6.5.jarDescription:
Jakarta Mail API License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/andrii/.m2/repository/com/sun/mail/jakarta.mail/1.6.5/jakarta.mail-1.6.5.jar
MD5: 214c580ee5913b9c69926cec66919f64
SHA1: d08124137cf42397d00b71b5985fd1dc248ac07f
SHA256: f4b500a1dd9ffd03ed7d8b2062fa5fd10d5beca4c42611672764bf4365751b53
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jakarta.mail High Vendor jar package name mail Highest Vendor jar package name provider Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest automatic-module-name jakarta.mail Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname com.sun.mail.jakarta.mail Medium Vendor Manifest extension-name jakarta.mail Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid jakarta.mail Highest Vendor pom artifactid jakarta.mail Low Vendor pom groupid com.sun.mail Highest Vendor pom name Jakarta Mail API High Vendor pom parent-artifactid all Low Product file name jakarta.mail High Product jar package name javax Highest Product jar package name mail Highest Product jar package name provider Highest Product jar package name sun Highest Product jar package name version Highest Product Manifest automatic-module-name jakarta.mail Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name Jakarta Mail API Medium Product Manifest bundle-symbolicname com.sun.mail.jakarta.mail Medium Product Manifest extension-name jakarta.mail Medium Product Manifest Implementation-Title javax.mail High Product Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Jakarta Mail API Design Specification Medium Product pom artifactid jakarta.mail Highest Product pom groupid com.sun.mail Highest Product pom name Jakarta Mail API High Product pom parent-artifactid all Medium Version file version 1.6.5 High Version Manifest Bundle-Version 1.6.5 High Version Manifest Implementation-Version 1.6.5 High Version pom version 1.6.5 Highest
jandex-2.0.3.Final.jarDescription:
Parent POM for JBoss projects. Provides default project build configuration. License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/jboss/jandex/2.0.3.Final/jandex-2.0.3.Final.jar
MD5: 77db6e55da888349f5466d2dcf150b14
SHA1: bfc4d6257dbff7a33a357f0de116be6ff951d849
SHA256: a3a65250cf954f102e74bab23df12540780878231195b585a7a86f4364a53727
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jandex High Vendor hint analyzer vendor redhat Highest Vendor jar package name indexer Highest Vendor jar package name jandex Highest Vendor jar package name jboss Highest Vendor Manifest build-timestamp Tue, 2 Aug 2016 13:41:44 -0500 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.jandex Medium Vendor Manifest implementation-url http://www.jboss.org/jandex Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss Medium Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jandex Highest Vendor pom artifactid jandex Low Vendor pom groupid org.jboss Highest Vendor pom name Java Annotation Indexer High Vendor pom parent-artifactid jboss-parent Low Product file name jandex High Product jar package name indexer Highest Product jar package name jandex Highest Product jar package name jboss Highest Product Manifest build-timestamp Tue, 2 Aug 2016 13:41:44 -0500 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Java Annotation Indexer Medium Product Manifest bundle-symbolicname org.jboss.jandex Medium Product Manifest Implementation-Title Java Annotation Indexer High Product Manifest implementation-url http://www.jboss.org/jandex Low Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest specification-title Java Annotation Indexer Medium Product pom artifactid jandex Highest Product pom groupid org.jboss Highest Product pom name Java Annotation Indexer High Product pom parent-artifactid jboss-parent Medium Version Manifest Bundle-Version 2.0.3.Final High Version Manifest Implementation-Version 2.0.3.Final High Version pom parent-version 2.0.3.Final Low Version pom version 2.0.3.Final Highest
javassist-3.22.0-GA.jarDescription:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/ File Path: /home/andrii/.m2/repository/org/javassist/javassist/3.22.0-GA/javassist-3.22.0-GA.jar
MD5: 69f277ed4c6631e45ec4cacd0e6e46c6
SHA1: 3e83394258ae2089be7219b971ec21a8288528ad
SHA256: 59531c00f3e3aa1ff48b3a8cf4ead47d203ab0e2fd9e0ad401f764e05947e252
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javassist High Vendor jar package name bytecode Highest Vendor jar package name javassist Highest Vendor Manifest bundle-symbolicname javassist Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low Vendor pom artifactid javassist Highest Vendor pom artifactid javassist Low Vendor pom developer email adinn@redhat.com Low Vendor pom developer email chiba@javassist.org Low Vendor pom developer email kabir.khan@jboss.com Low Vendor pom developer email smarlow@redhat.com Low Vendor pom developer id adinn Medium Vendor pom developer id chiba Medium Vendor pom developer id kabir.khan@jboss.com Medium Vendor pom developer id scottmarlow Medium Vendor pom developer name Andrew Dinn Medium Vendor pom developer name Kabir Khan Medium Vendor pom developer name Scott Marlow Medium Vendor pom developer name Shigeru Chiba Medium Vendor pom developer org JBoss Medium Vendor pom developer org The Javassist Project Medium Vendor pom developer org URL http://www.javassist.org/ Medium Vendor pom developer org URL http://www.jboss.org/ Medium Vendor pom groupid org.javassist Highest Vendor pom name Javassist High Vendor pom organization name Shigeru Chiba, www.javassist.org High Vendor pom url http://www.javassist.org/ Highest Product file name javassist High Product jar package name bytecode Highest Product jar package name javassist Highest Product Manifest Bundle-Name Javassist Medium Product Manifest bundle-symbolicname javassist Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Javassist Medium Product pom artifactid javassist Highest Product pom developer email adinn@redhat.com Low Product pom developer email chiba@javassist.org Low Product pom developer email kabir.khan@jboss.com Low Product pom developer email smarlow@redhat.com Low Product pom developer id adinn Low Product pom developer id chiba Low Product pom developer id kabir.khan@jboss.com Low Product pom developer id scottmarlow Low Product pom developer name Andrew Dinn Low Product pom developer name Kabir Khan Low Product pom developer name Scott Marlow Low Product pom developer name Shigeru Chiba Low Product pom developer org JBoss Low Product pom developer org The Javassist Project Low Product pom developer org URL http://www.javassist.org/ Low Product pom developer org URL http://www.jboss.org/ Low Product pom groupid org.javassist Highest Product pom name Javassist High Product pom organization name Shigeru Chiba, www.javassist.org Low Product pom url http://www.javassist.org/ Medium Version Manifest specification-version 3.22.0-GA High Version pom version 3.22.0-GA Highest
javax.activation-1.2.0.jarDescription:
JavaBeans Activation Framework License:
https://github.com/javaee/activation/blob/master/LICENSE.txt File Path: /home/andrii/.m2/repository/com/sun/activation/javax.activation/1.2.0/javax.activation-1.2.0.jar
MD5: be7c430df50b330cffc4848a3abedbfb
SHA1: bf744c1e2776ed1de3c55c8dac1057ec331ef744
SHA256: 993302b16cd7056f21e779cc577d175a810bb4900ef73cd8fbf2b50f928ba9ce
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.activation High Vendor jar package name activation Highest Vendor jar package name javax Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest automatic-module-name java.activation Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname com.sun.activation.javax.activation Medium Vendor Manifest extension-name javax.activation Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid javax.activation Highest Vendor pom artifactid javax.activation Low Vendor pom groupid com.sun.activation Highest Vendor pom name JavaBeans Activation Framework High Vendor pom parent-artifactid all Low Product file name javax.activation High Product jar package name activation Highest Product jar package name javax Highest Product jar package name sun Highest Product Manifest automatic-module-name java.activation Medium Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JavaBeans Activation Framework Medium Product Manifest bundle-symbolicname com.sun.activation.javax.activation Medium Product Manifest extension-name javax.activation Medium Product Manifest Implementation-Title javax.activation High Product Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium Product pom artifactid javax.activation Highest Product pom groupid com.sun.activation Highest Product pom name JavaBeans Activation Framework High Product pom parent-artifactid all Medium Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High Version pom version 1.2.0 Highest
javax.activation-api-1.2.0.jarDescription:
JavaBeans Activation Framework API jar License:
https://github.com/javaee/activation/blob/master/LICENSE.txt File Path: /home/andrii/.m2/repository/javax/activation/javax.activation-api/1.2.0/javax.activation-api-1.2.0.jar
MD5: 5e50e56bcf4a3ef3bc758f69f7643c3b
SHA1: 85262acf3ca9816f9537ca47d5adeabaead7cb16
SHA256: 43fdef0b5b6ceb31b0424b208b930c74ab58fac2ceeb7b3f6fd3aeb8b5ca4393
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name javax.activation-api High Vendor jar package name activation Highest Vendor jar package name javax Highest Vendor Manifest automatic-module-name java.activation Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname javax.activation-api Medium Vendor Manifest extension-name javax.activation Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid javax.activation-api Highest Vendor pom artifactid javax.activation-api Low Vendor pom groupid javax.activation Highest Vendor pom name JavaBeans Activation Framework API jar High Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Product file name javax.activation-api High Product jar package name activation Highest Product jar package name javax Highest Product Manifest automatic-module-name java.activation Medium Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JavaBeans Activation Framework API jar Medium Product Manifest bundle-symbolicname javax.activation-api Medium Product Manifest extension-name javax.activation Medium Product Manifest Implementation-Title javax.activation.javax.activation-api High Product Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Product Manifest specification-title javax.activation.javax.activation-api Medium Product pom artifactid javax.activation-api Highest Product pom groupid javax.activation Highest Product pom name JavaBeans Activation Framework API jar High Product pom parent-artifactid all Medium Product pom parent-groupid com.sun.activation Medium Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High Version pom version 1.2.0 Highest
javax.annotation-api-1.3.2.jarDescription:
Common Annotations for the JavaTM Platform API License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.annotation/blob/master/LICENSE File Path: /home/andrii/.m2/repository/javax/annotation/javax.annotation-api/1.3.2/javax.annotation-api-1.3.2.jar
MD5: 2ab1973eefffaa2aeec47d50b9e40b9d
SHA1: 934c04d3cfef185a8008e7bf34331b79730a9d43
SHA256: e04ba5195bcd555dc95650f7cc614d151e4bcd52d29a10b8aa2197f3ab89ab9b
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.annotation-api High Vendor jar package name annotation Highest Vendor jar package name javax Highest Vendor Manifest automatic-module-name java.annotation Medium Vendor Manifest bundle-docurl https://javaee.github.io/glassfish Low Vendor Manifest bundle-symbolicname javax.annotation-api Medium Vendor Manifest extension-name javax.annotation Medium Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.annotation-api Highest Vendor pom artifactid javax.annotation-api Low Vendor pom developer id ldemichiel Medium Vendor pom developer name Linda De Michiel Medium Vendor pom developer org Oracle Corp. Medium Vendor pom groupid javax.annotation Highest Vendor pom name ${extension.name} API High Vendor pom organization name GlassFish Community High Vendor pom organization url https://javaee.github.io/glassfish Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://jcp.org/en/jsr/detail?id=250 Highest Product file name javax.annotation-api High Product jar package name annotation Highest Product jar package name javax Highest Product Manifest automatic-module-name java.annotation Medium Product Manifest bundle-docurl https://javaee.github.io/glassfish Low Product Manifest Bundle-Name javax.annotation API Medium Product Manifest bundle-symbolicname javax.annotation-api Medium Product Manifest extension-name javax.annotation Medium Product pom artifactid javax.annotation-api Highest Product pom developer id ldemichiel Low Product pom developer name Linda De Michiel Low Product pom developer org Oracle Corp. Low Product pom groupid javax.annotation Highest Product pom name ${extension.name} API High Product pom organization name GlassFish Community Low Product pom organization url https://javaee.github.io/glassfish Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://jcp.org/en/jsr/detail?id=250 Medium Version file version 1.3.2 High Version Manifest Bundle-Version 1.3.2 High Version Manifest Implementation-Version 1.3.2 High Version pom parent-version 1.3.2 Low Version pom version 1.3.2 Highest
javax.inject-1.jarDescription:
The javax.inject API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256: 91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.inject-1 High Vendor jar package name inject Highest Vendor jar package name inject Low Vendor jar package name javax Highest Vendor jar package name javax Low Vendor pom artifactid javax.inject Highest Vendor pom artifactid javax.inject Low Vendor pom groupid javax.inject Highest Vendor pom name javax.inject High Vendor pom url http://code.google.com/p/atinject/ Highest Product file name javax.inject-1 High Product jar package name inject Highest Product jar package name inject Low Product jar package name javax Highest Product pom artifactid javax.inject Highest Product pom groupid javax.inject Highest Product pom name javax.inject High Product pom url http://code.google.com/p/atinject/ Medium Version file version 1 Medium Version pom version 1 Highest
javax.json-1.1.4.jarDescription:
Default provider for JSR 374:Java API for Processing JSON License:
https://oss.oracle.com/licenses/CDDL+GPL-1.1 File Path: /home/andrii/.m2/repository/org/glassfish/javax.json/1.1.4/javax.json-1.1.4.jar
MD5: ac67218fb9716fec512be8d0d877bde2
SHA1: 943f240a509d3c70b448a55c6735591ecbd37c88
SHA256: 17fdeb7e22375a7fb40bb0551306f6dcf2b5743078668adcdf6c642c9a9ec955
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name javax.json High Vendor jar package name api Highest Vendor jar package name glassfish Highest Vendor jar package name javax Highest Vendor jar package name json Highest Vendor Manifest automatic-module-name java.json Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname org.glassfish.javax.json Medium Vendor Manifest extension-name javax.json Medium Vendor pom artifactid javax.json Highest Vendor pom artifactid javax.json Low Vendor pom groupid org.glassfish Highest Vendor pom name JSR 374 (JSON Processing) Default Provider High Vendor pom parent-artifactid json Low Vendor pom url https://javaee.github.io/jsonp Highest Product file name javax.json High Product jar package name api Highest Product jar package name glassfish Highest Product jar package name javax Highest Product jar package name json Highest Product Manifest automatic-module-name java.json Medium Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JSR 374 (JSON Processing) Default Provider Medium Product Manifest bundle-symbolicname org.glassfish.javax.json Medium Product Manifest extension-name javax.json Medium Product pom artifactid javax.json Highest Product pom groupid org.glassfish Highest Product pom name JSR 374 (JSON Processing) Default Provider High Product pom parent-artifactid json Medium Product pom url https://javaee.github.io/jsonp Medium Version file version 1.1.4 High Version Manifest Bundle-Version 1.1.4 High Version Manifest Implementation-Version 1.1.4 High Version pom version 1.1.4 Highest
javax.jws-api-1.1.jarDescription:
Java EE Web Services Metadata API License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html File Path: /home/andrii/.m2/repository/javax/jws/javax.jws-api/1.1/javax.jws-api-1.1.jar
MD5: 69723c79242ebda0d321b5ec8fbdf4fb
SHA1: c623941ebd225bb05ea546dc81590a62e40e4fce
SHA256: 9f20ab1fea3f9571ed52a9d98e3c651cc7c04c8a709addf238312b60987c6f2c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.jws-api High Vendor jar package name javax Highest Vendor jar package name jws Highest Vendor Manifest bundle-docurl https://glassfish.java.net Low Vendor Manifest bundle-symbolicname javax.jws-api Medium Vendor Manifest extension-name javax.jws Medium Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.jws-api Highest Vendor pom artifactid javax.jws-api Low Vendor pom developer id snajper Medium Vendor pom developer name Martin Grebac Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid javax.jws Highest Vendor pom name ${extension.name} API High Vendor pom organization name GlassFish Community High Vendor pom organization url https://glassfish.java.net Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://glassfish.java.net Highest Product file name javax.jws-api High Product jar package name javax Highest Product jar package name jws Highest Product Manifest bundle-docurl https://glassfish.java.net Low Product Manifest Bundle-Name javax.jws API Medium Product Manifest bundle-symbolicname javax.jws-api Medium Product Manifest extension-name javax.jws Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom artifactid javax.jws-api Highest Product pom developer id snajper Low Product pom developer name Martin Grebac Low Product pom developer org Oracle, Inc. Low Product pom groupid javax.jws Highest Product pom name ${extension.name} API High Product pom organization name GlassFish Community Low Product pom organization url https://glassfish.java.net Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://glassfish.java.net Medium Version file version 1.1 High Version Manifest Bundle-Version 1.1 High Version Manifest Implementation-Version 1.1 High Version pom parent-version 1.1 Low Version pom version 1.1 Highest
javax.mail-1.5.6.jarDescription:
JavaMail API License:
https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/com/sun/mail/javax.mail/1.5.6/javax.mail-1.5.6.jar
MD5: 5e6a70a6deed03bbbae6322af632b34c
SHA1: ab5daef2f881c42c8e280cbe918ec4d7fdfd7efe
SHA256: 40ca806a724848616d88461ea565bc597d92b8a90ba426ab92e4c471552dd097
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.mail High Vendor jar package name javax Highest Vendor jar package name mail Highest Vendor jar package name provider Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname com.sun.mail.javax.mail Medium Vendor Manifest extension-name javax.mail Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid javax.mail Highest Vendor pom artifactid javax.mail Low Vendor pom groupid com.sun.mail Highest Vendor pom name JavaMail API High Vendor pom parent-artifactid all Low Product file name javax.mail High Product jar package name javax Highest Product jar package name mail Highest Product jar package name provider Highest Product jar package name sun Highest Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JavaMail API Medium Product Manifest bundle-symbolicname com.sun.mail.javax.mail Medium Product Manifest extension-name javax.mail Medium Product Manifest Implementation-Title javax.mail High Product Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium Product Manifest specification-title JavaMail(TM) API Design Specification Medium Product pom artifactid javax.mail Highest Product pom groupid com.sun.mail Highest Product pom name JavaMail API High Product pom parent-artifactid all Medium Version file version 1.5.6 High Version Manifest Bundle-Version 1.5.6 High Version Manifest Implementation-Version 1.5.6 High Version pom version 1.5.6 Highest
javax.mail-api-1.5.6.jarDescription:
JavaMail API jar License:
https://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/javax/mail/javax.mail-api/1.5.6/javax.mail-api-1.5.6.jar
MD5: ef5bb8caf9c5e11c70e530272ae37d39
SHA1: 51c7a973efb1123558b62e95e31ab03cfa00fa7a
SHA256: bde0f921bb08ec62eca77eb61b39becf3072e9fcbdbc2aaade84b8e6394d7560
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.mail-api High Vendor jar package name javax Highest Vendor jar package name mail Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname javax.mail-api Medium Vendor Manifest extension-name javax.mail Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest originally-created-by 1.8.0_92 (Oracle Corporation) Low Vendor Manifest probe-provider-xml-file-names Medium Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid javax.mail-api Highest Vendor pom artifactid javax.mail-api Low Vendor pom groupid javax.mail Highest Vendor pom name JavaMail API jar High Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.mail Medium Product file name javax.mail-api High Product jar package name javax Highest Product jar package name mail Highest Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JavaMail API jar Medium Product Manifest bundle-symbolicname javax.mail-api Medium Product Manifest extension-name javax.mail Medium Product Manifest Implementation-Title javax.mail.javax.mail-api High Product Manifest originally-created-by 1.8.0_92 (Oracle Corporation) Low Product Manifest probe-provider-xml-file-names Medium Product Manifest specification-title javax.mail.javax.mail-api Medium Product pom artifactid javax.mail-api Highest Product pom groupid javax.mail Highest Product pom name JavaMail API jar High Product pom parent-artifactid all Medium Product pom parent-groupid com.sun.mail Medium Version file version 1.5.6 High Version Manifest Bundle-Version 1.5.6 High Version Manifest Implementation-Version 1.5.6 High Version pom version 1.5.6 Highest
javax.servlet-api-3.0.1.jarDescription:
Java.net - The Source for Java Technology Collaboration License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html File Path: /home/andrii/.m2/repository/javax/servlet/javax.servlet-api/3.0.1/javax.servlet-api-3.0.1.jar
MD5: 3ef236ac4c24850cd54abff60be25f35
SHA1: 6bf0ebb7efd993e222fc1112377b5e92a13b38dd
SHA256: 377d8bde87ac6bc7f83f27df8e02456d5870bb78c832dac656ceacc28b016e56
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.servlet-api High Vendor jar package name javax Highest Vendor jar package name servlet Highest Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low Vendor Manifest bundle-symbolicname javax.servlet-api Medium Vendor Manifest extension-name javax.servlet Medium Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid javax.servlet-api Highest Vendor pom artifactid javax.servlet-api Low Vendor pom developer id mode Medium Vendor pom developer id swchan2 Medium Vendor pom developer name Rajiv Mordani Medium Vendor pom developer name Shing Wai Chan Medium Vendor pom developer org Oracle Medium Vendor pom groupid javax.servlet Highest Vendor pom name Java Servlet API High Vendor pom organization name GlassFish Community High Vendor pom organization url https://glassfish.dev.java.net Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://servlet-spec.java.net Highest Vendor pom (hint) developer org sun Medium Product file name javax.servlet-api High Product jar package name javax Highest Product jar package name servlet Highest Product Manifest bundle-docurl https://glassfish.dev.java.net Low Product Manifest Bundle-Name Java Servlet API Medium Product Manifest bundle-symbolicname javax.servlet-api Medium Product Manifest extension-name javax.servlet Medium Product Manifest specification-title Java(TM) Servlet API Design Specification Medium Product pom artifactid javax.servlet-api Highest Product pom developer id mode Low Product pom developer id swchan2 Low Product pom developer name Rajiv Mordani Low Product pom developer name Shing Wai Chan Low Product pom developer org Oracle Low Product pom groupid javax.servlet Highest Product pom name Java Servlet API High Product pom organization name GlassFish Community Low Product pom organization url https://glassfish.dev.java.net Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://servlet-spec.java.net Medium Version file version 3.0.1 High Version Manifest Bundle-Version 3.0.1 High Version Manifest Implementation-Version 3.0.1 High Version pom parent-version 3.0.1 Low Version pom version 3.0.1 Highest
javax.transaction-api-1.2.jarDescription:
Project GlassFish Java Transaction API License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html File Path: /home/andrii/.m2/repository/javax/transaction/javax.transaction-api/1.2/javax.transaction-api-1.2.jar
MD5: 2dfee184286530e726ad155816e15b4c
SHA1: d81aff979d603edd90dcd8db2abc1f4ce6479e3e
SHA256: 9528449583c34d9d63aa1d8d15069790f925ae1f27b33784773b8099eff4c9ff
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.transaction-api High Vendor jar package name javax Highest Vendor jar package name transaction Highest Vendor Manifest bundle-docurl https://glassfish.java.net Low Vendor Manifest bundle-symbolicname javax.transaction-api Medium Vendor Manifest extension-name javax.transaction Medium Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.transaction-api Highest Vendor pom artifactid javax.transaction-api Low Vendor pom developer id paul_parkinson Medium Vendor pom developer name Paul Parkinson Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid javax.transaction Highest Vendor pom name ${extension.name} API High Vendor pom organization name GlassFish Community High Vendor pom organization url https://glassfish.java.net Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://jta-spec.java.net Highest Product file name javax.transaction-api High Product jar package name javax Highest Product jar package name transaction Highest Product Manifest bundle-docurl https://glassfish.java.net Low Product Manifest Bundle-Name javax.transaction API Medium Product Manifest bundle-symbolicname javax.transaction-api Medium Product Manifest extension-name javax.transaction Medium Product pom artifactid javax.transaction-api Highest Product pom developer id paul_parkinson Low Product pom developer name Paul Parkinson Low Product pom developer org Oracle, Inc. Low Product pom groupid javax.transaction Highest Product pom name ${extension.name} API High Product pom organization name GlassFish Community Low Product pom organization url https://glassfish.java.net Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://jta-spec.java.net Medium Version file version 1.2 High Version Manifest Bundle-Version 1.2 High Version Manifest Implementation-Version 1.2 High Version pom parent-version 1.2 Low Version pom version 1.2 Highest
javax.ws.rs-api-2.0.1.jarDescription:
Java API for RESTful Web Services (JAX-RS) License:
CDDL 1.1: http://glassfish.java.net/public/CDDL+GPL_1_1.html
GPL2 w/ CPE: http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/javax/ws/rs/javax.ws.rs-api/2.0.1/javax.ws.rs-api-2.0.1.jar
MD5: edcd111cf4d3ba8ac8e1f326efc37a17
SHA1: 104e9c2b5583cfcfeac0402316221648d6d8ea6b
SHA256: 38607d626f2288d8fbc1b1f8a62c369e63806d9a313ac7cbc5f9d6c94f4b466d
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name javax.ws.rs-api High Vendor hint analyzer vendor web services Medium Vendor jar package name javax Highest Vendor jar package name rs Highest Vendor jar package name ws Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname javax.ws.rs-api Medium Vendor Manifest extension-name javax.ws.rs Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.ws.rs-api Highest Vendor pom artifactid javax.ws.rs-api Low Vendor pom developer email m_potociar@java.net Low Vendor pom developer email spericas@java.net Low Vendor pom developer id Marek Medium Vendor pom developer id Santiago Medium Vendor pom developer name Marek Potociar Medium Vendor pom developer name Santiago Pericas-Geertsen Medium Vendor pom developer org Oracle Medium Vendor pom developer org URL http://jax-rs-spec.java.net Medium Vendor pom groupid javax.ws.rs Highest Vendor pom name javax.ws.rs-api High Vendor pom organization name Oracle Corporation High Vendor pom organization url http://www.oracle.com/ Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://jax-rs-spec.java.net Highest Vendor pom (hint) developer org sun Medium Product file name javax.ws.rs-api High Product hint analyzer product web services Medium Product jar package name javax Highest Product jar package name rs Highest Product jar package name ws Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name javax.ws.rs-api Medium Product Manifest bundle-symbolicname javax.ws.rs-api Medium Product Manifest extension-name javax.ws.rs Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom artifactid javax.ws.rs-api Highest Product pom developer email m_potociar@java.net Low Product pom developer email spericas@java.net Low Product pom developer id Marek Low Product pom developer id Santiago Low Product pom developer name Marek Potociar Low Product pom developer name Santiago Pericas-Geertsen Low Product pom developer org Oracle Low Product pom developer org URL http://jax-rs-spec.java.net Low Product pom groupid javax.ws.rs Highest Product pom name javax.ws.rs-api High Product pom organization name Oracle Corporation Low Product pom organization url http://www.oracle.com/ Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://jax-rs-spec.java.net Medium Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version Manifest Implementation-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version pom version 2.0.1 Highest
javax.xml.soap-api-1.4.0.jarDescription:
SAAJ API License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.xml.soap/blob/master/LICENSE File Path: /home/andrii/.m2/repository/javax/xml/soap/javax.xml.soap-api/1.4.0/javax.xml.soap-api-1.4.0.jar
MD5: fb8bbe2cdda8ff7bd945fcb9f0f6b61c
SHA1: 667ef2eee594ca7e05a1cbe0b37a428f7b57778f
SHA256: 141374e33be99768611a2d42b9d33571a0c5b9763beca9c2dc90900d8cc8f767
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name javax.xml.soap-api High Vendor jar package name javax Highest Vendor jar package name soap Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname javax.xml.soap-api Medium Vendor Manifest extension-name javax.xml.soap Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom artifactid javax.xml.soap-api Highest Vendor pom artifactid javax.xml.soap-api Low Vendor pom developer id jungicz Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid javax.xml.soap Highest Vendor pom name ${api.package} API High Vendor pom organization name Oracle High Vendor pom organization url http://www.oracle.com Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url https://javaee.github.io/javaee-spec/ Highest Vendor pom (hint) organization name sun High Product file name javax.xml.soap-api High Product jar package name javax Highest Product jar package name soap Highest Product jar package name xml Highest Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name javax.xml.soap API Medium Product Manifest bundle-symbolicname javax.xml.soap-api Medium Product Manifest extension-name javax.xml.soap Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid javax.xml.soap-api Highest Product pom developer id jungicz Low Product pom developer name Lukas Jungmann Low Product pom developer org Oracle, Inc. Low Product pom groupid javax.xml.soap Highest Product pom name ${api.package} API High Product pom organization name Oracle Low Product pom organization url http://www.oracle.com Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url https://javaee.github.io/javaee-spec/ Medium Version file version 1.4.0 High Version Manifest Bundle-Version 1.4.0 High Version Manifest Implementation-Version 1.4.0 High Version pom parent-version 1.4.0 Low Version pom version 1.4.0 Highest
jaxb-api-2.3.1.jarDescription:
JAXB (JSR 222) API License:
https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1 File Path: /home/andrii/.m2/repository/javax/xml/bind/jaxb-api/2.3.1/jaxb-api-2.3.1.jar
MD5: bcf270d320f645ad19f5edb60091e87f
SHA1: 8531ad5ac454cc2deb9d4d32c40c4d7451939b5d
SHA256: 88b955a0df57880a26a74708bc34f74dcaf8ebf4e78843a28b50eae945732b06
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jaxb-api High Vendor jar package name bind Highest Vendor jar package name javax Highest Vendor jar package name jaxb Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname jaxb-api Medium Vendor Manifest extension-name javax.xml.bind Medium Vendor Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version>=1.8))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid jaxb-api Highest Vendor pom artifactid jaxb-api Low Vendor pom groupid javax.xml.bind Highest Vendor pom parent-artifactid jaxb-api-parent Low Product file name jaxb-api High Product jar package name bind Highest Product jar package name javax Highest Product jar package name jaxb Highest Product jar package name xml Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name jaxb-api Medium Product Manifest bundle-symbolicname jaxb-api Medium Product Manifest extension-name javax.xml.bind Medium Product Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version>=1.8))" Low Product Manifest specification-title jaxb-api Medium Product pom artifactid jaxb-api Highest Product pom groupid javax.xml.bind Highest Product pom parent-artifactid jaxb-api-parent Medium Version file version 2.3.1 High Version Manifest Bundle-Version 2.3.1 High Version pom version 2.3.1 Highest
jaxb-runtime-2.3.1.jarDescription:
JAXB (JSR 222) Reference Implementation File Path: /home/andrii/.m2/repository/org/glassfish/jaxb/jaxb-runtime/2.3.1/jaxb-runtime-2.3.1.jarMD5: 848098e3eda0d37738d51a7acacd8e95SHA1: dd6dda9da676a54c5b36ca2806ff95ee017d8738SHA256: 45fecfa5c8217ce1f3652ab95179790ec8cc0dec0384bca51cbeb94a293d9f2fReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jaxb-runtime High Vendor jar package name bind Highest Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision ad5fa4c697632694cbcfa80177707db908cd98b2 Low Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom artifactid jaxb-runtime Highest Vendor pom artifactid jaxb-runtime Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Product file name jaxb-runtime High Product jar package name bind Highest Product jar package name sun Highest Product jar package name xml Highest Product Manifest git-revision ad5fa4c697632694cbcfa80177707db908cd98b2 Low Product Manifest Implementation-Title JAXB Implementation High Product Manifest specification-title Java Architecture for XML Binding Medium Product pom artifactid jaxb-runtime Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Runtime High Product pom parent-artifactid jaxb-runtime-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Version file version 2.3.1 High Version Manifest build-id 2.3.1 Medium Version Manifest Implementation-Version 2.3.1 High Version Manifest major-version 2.3.1 Medium Version pom version 2.3.1 Highest
jaxen-1.1.6.jarDescription:
Jaxen is a universal Java XPath engine. License:
http://jaxen.codehaus.org/license.html File Path: /home/andrii/.m2/repository/jaxen/jaxen/1.1.6/jaxen-1.1.6.jar
MD5: a140517286b56eea981e188dcc3a13f6
SHA1: 3f8c36d9a0578e8e98f030c662b69888b1430ac0
SHA256: 5ac9c74bbb3964b34a886ba6b1b6c0b0dc3ebeebc1dc4a44942a76634490b3eb
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jaxen High Vendor jar package name jaxen Highest Vendor jar package name xpath Highest Vendor Manifest bundle-docurl http://codehaus.org Low Vendor Manifest bundle-symbolicname jaxen Medium Vendor pom artifactid jaxen Highest Vendor pom artifactid jaxen Low Vendor pom developer email bob@eng.werken.com Low Vendor pom developer email brian.ewins@gmail.com Low Vendor pom developer email contact@megginson.com Low Vendor pom developer email elharo@ibiblio.org Low Vendor pom developer email erwin@klomp.org Low Vendor pom developer email james_strachan@yahoo.co.uk Low Vendor pom developer email jdvorak@users.sourceforge.net Low Vendor pom developer email mbelonga@users.sourceforge.net Low Vendor pom developer email peter.royal@pobox.com Low Vendor pom developer email purpletech@users.sourceforge.net Low Vendor pom developer email scott@dotnot.org Low Vendor pom developer email szegedia@users.sourceforge.net Low Vendor pom developer email xcut@users.sourceforge.net Low Vendor pom developer id bewins Medium Vendor pom developer id bob Medium Vendor pom developer id cnentwich Medium Vendor pom developer id dmegginson Medium Vendor pom developer id eboldwidt Medium Vendor pom developer id elharo Medium Vendor pom developer id jdvorak Medium Vendor pom developer id jstrachan Medium Vendor pom developer id mbelonga Medium Vendor pom developer id proyal Medium Vendor pom developer id purpletech Medium Vendor pom developer id ssanders Medium Vendor pom developer id szegedia Medium Vendor pom developer name Alexander Day Chaffee Medium Vendor pom developer name Attila Szegedi Medium Vendor pom developer name Bob McWhirter Medium Vendor pom developer name Brian Ewins Medium Vendor pom developer name Christian Nentwich Medium Vendor pom developer name David Megginson Medium Vendor pom developer name Elliotte Rusty Harold Medium Vendor pom developer name Erwin Bolwidt Medium Vendor pom developer name James Strachan Medium Vendor pom developer name Jan Dvorak Medium Vendor pom developer name Mark A. Belonga Medium Vendor pom developer name Peter Royal Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer org Cafe au Lait Medium Vendor pom developer org dotnot Medium Vendor pom developer org Megginson Technologies Medium Vendor pom developer org Purple Technologies Medium Vendor pom developer org Spiritsoft Medium Vendor pom developer org The Werken Company Medium Vendor pom groupid jaxen Highest Vendor pom name jaxen High Vendor pom organization name Codehaus High Vendor pom organization url http://codehaus.org Medium Vendor pom url http://jaxen.codehaus.org/ Highest Product file name jaxen High Product jar package name jaxen Highest Product jar package name xpath Highest Product Manifest bundle-docurl http://codehaus.org Low Product Manifest Bundle-Name jaxen Medium Product Manifest bundle-symbolicname jaxen Medium Product pom artifactid jaxen Highest Product pom developer email bob@eng.werken.com Low Product pom developer email brian.ewins@gmail.com Low Product pom developer email contact@megginson.com Low Product pom developer email elharo@ibiblio.org Low Product pom developer email erwin@klomp.org Low Product pom developer email james_strachan@yahoo.co.uk Low Product pom developer email jdvorak@users.sourceforge.net Low Product pom developer email mbelonga@users.sourceforge.net Low Product pom developer email peter.royal@pobox.com Low Product pom developer email purpletech@users.sourceforge.net Low Product pom developer email scott@dotnot.org Low Product pom developer email szegedia@users.sourceforge.net Low Product pom developer email xcut@users.sourceforge.net Low Product pom developer id bewins Low Product pom developer id bob Low Product pom developer id cnentwich Low Product pom developer id dmegginson Low Product pom developer id eboldwidt Low Product pom developer id elharo Low Product pom developer id jdvorak Low Product pom developer id jstrachan Low Product pom developer id mbelonga Low Product pom developer id proyal Low Product pom developer id purpletech Low Product pom developer id ssanders Low Product pom developer id szegedia Low Product pom developer name Alexander Day Chaffee Low Product pom developer name Attila Szegedi Low Product pom developer name Bob McWhirter Low Product pom developer name Brian Ewins Low Product pom developer name Christian Nentwich Low Product pom developer name David Megginson Low Product pom developer name Elliotte Rusty Harold Low Product pom developer name Erwin Bolwidt Low Product pom developer name James Strachan Low Product pom developer name Jan Dvorak Low Product pom developer name Mark A. Belonga Low Product pom developer name Peter Royal Low Product pom developer name Scott Sanders Low Product pom developer org Cafe au Lait Low Product pom developer org dotnot Low Product pom developer org Megginson Technologies Low Product pom developer org Purple Technologies Low Product pom developer org Spiritsoft Low Product pom developer org The Werken Company Low Product pom groupid jaxen Highest Product pom name jaxen High Product pom organization name Codehaus Low Product pom organization url http://codehaus.org Low Product pom url http://jaxen.codehaus.org/ Medium Version file version 1.1.6 High Version Manifest Bundle-Version 1.1.6 High Version pom version 1.1.6 Highest
jaxws-api-2.3.1.jarDescription:
JAX-WS (JSR 224) API License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/jax-ws-spec/blob/master/LICENSE.md File Path: /home/andrii/.m2/repository/javax/xml/ws/jaxws-api/2.3.1/jaxws-api-2.3.1.jar
MD5: 5a6f94e95cc2054bc840cc2f2fedc5d8
SHA1: 15e46dba25b1f767a3f517721badf6cce8dbb13d
SHA256: a447f84f95658ea68b347acffe156f7700c62a37ede15d81e5298fb8e5fe6dcf
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jaxws-api High Vendor hint analyzer vendor web services Medium Vendor jar package name javax Highest Vendor jar package name ws Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom artifactid jaxws-api Highest Vendor pom artifactid jaxws-api Low Vendor pom developer email jitendra.kotamraju@oracle.com Low Vendor pom developer email lukas.jungmann@oracle.com Low Vendor pom developer email martin.grebac@oracle.com Low Vendor pom developer name Jitendra Kotamraju Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer name Martin Grebac Medium Vendor pom developer org Oracle Corporation Medium Vendor pom groupid javax.xml.ws Highest Vendor pom name JAX-WS API High Vendor pom organization name Oracle High Vendor pom organization url http://www.oracle.com Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url javaee/jax-ws-spec Highest Vendor pom (hint) organization name sun High Product file name jaxws-api High Product hint analyzer product web services Medium Product jar package name http Highest Product jar package name javax Highest Product jar package name ws Highest Product jar package name xml Highest Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JAX-WS API Medium Product Manifest bundle-symbolicname Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom artifactid jaxws-api Highest Product pom developer email jitendra.kotamraju@oracle.com Low Product pom developer email lukas.jungmann@oracle.com Low Product pom developer email martin.grebac@oracle.com Low Product pom developer name Jitendra Kotamraju Low Product pom developer name Lukas Jungmann Low Product pom developer name Martin Grebac Low Product pom developer org Oracle Corporation Low Product pom groupid javax.xml.ws Highest Product pom name JAX-WS API High Product pom organization name Oracle Low Product pom organization url http://www.oracle.com Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url javaee/jax-ws-spec High Version file version 2.3.1 High Version pom parent-version 2.3.1 Low Version pom version 2.3.1 Highest
jaxws-rt-2.3.1.jar (shaded: com.sun.xml.ws:httpspi-servlet:2.3.1)Description:
HTTP SPI for JAX-WS RI File Path: /home/andrii/.m2/repository/com/sun/xml/ws/jaxws-rt/2.3.1/jaxws-rt-2.3.1.jar/META-INF/maven/com.sun.xml.ws/httpspi-servlet/pom.xmlMD5: b11888c915a4b1dce1722311c730f330SHA1: 0d9b69bfa23a03e1134ba10a14d02e069b037fc9SHA256: 67b176735bdb09cad0f157f8568c9a9098dafca2e33d71a76e854184164a9c8cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor pom artifactid httpspi-servlet Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name JAX-WS RI HTTP SPI (httpspi-servlet) High Vendor pom parent-artifactid project Low Product hint analyzer product web services Medium Product pom artifactid httpspi-servlet Highest Product pom groupid com.sun.xml.ws Highest Product pom name JAX-WS RI HTTP SPI (httpspi-servlet) High Product pom parent-artifactid project Medium Version pom version 2.3.1 Highest
jaxws-rt-2.3.1.jar (shaded: com.sun.xml.ws:jaxws-rt-bundle:2.3.1)Description:
JAXWS bundle with module descriptor File Path: /home/andrii/.m2/repository/com/sun/xml/ws/jaxws-rt/2.3.1/jaxws-rt-2.3.1.jar/META-INF/maven/com.sun.xml.ws/jaxws-rt-bundle/pom.xmlMD5: ebf9326f0c17f7ddfa6090bbbfb611b4SHA1: 58005377fe2930f46854ee9ada8656d811ce0c2bSHA256: 32254c8942284b86fe3a364b9210868766408cb146ce67debe7c470be707f2d3Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor pom artifactid jaxws-rt-bundle Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name JAX-WS RI Runtime Bundle aggregator High Vendor pom parent-artifactid project Low Product hint analyzer product web services Medium Product pom artifactid jaxws-rt-bundle Highest Product pom groupid com.sun.xml.ws Highest Product pom name JAX-WS RI Runtime Bundle aggregator High Product pom parent-artifactid project Medium Version pom version 2.3.1 Highest
jaxws-rt-2.3.1.jar (shaded: com.sun.xml.ws:rt-fi:2.3.1)Description:
Fast Infoset Support for JAX-WS RI File Path: /home/andrii/.m2/repository/com/sun/xml/ws/jaxws-rt/2.3.1/jaxws-rt-2.3.1.jar/META-INF/maven/com.sun.xml.ws/rt-fi/pom.xmlMD5: ae23371e47d9d33a25c3bebf6f5c6252SHA1: cfc70e00b3c0677ff68999e04e0f9a55abca9431SHA256: b327b50506d2e1b30587af89eea7281a41cd28dbf463315e33c886da55a62031Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor pom artifactid rt-fi Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name JAX-WS RI Fast Infoset Support (rt-fi) High Vendor pom parent-artifactid project Low Product hint analyzer product web services Medium Product pom artifactid rt-fi Highest Product pom groupid com.sun.xml.ws Highest Product pom name JAX-WS RI Fast Infoset Support (rt-fi) High Product pom parent-artifactid project Medium Version pom version 2.3.1 Highest
jaxws-rt-2.3.1.jar (shaded: com.sun.xml.ws:rt:2.3.1)Description:
JAX-WS Reference Implementation Runtime File Path: /home/andrii/.m2/repository/com/sun/xml/ws/jaxws-rt/2.3.1/jaxws-rt-2.3.1.jar/META-INF/maven/com.sun.xml.ws/rt/pom.xmlMD5: 156befd8a968e91ed22117b8c50159a4SHA1: 7e6fca97592b9480a681a5dc5df9a96ae12b826dSHA256: 1b79d5181a8e10058718c1d341e3540d8edab7702ffa50b4effa904e1779c761Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor pom artifactid rt Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name JAX-WS RI Runtime (rt) High Vendor pom parent-artifactid project Low Product hint analyzer product web services Medium Product pom artifactid rt Highest Product pom groupid com.sun.xml.ws Highest Product pom name JAX-WS RI Runtime (rt) High Product pom parent-artifactid project Medium Version pom version 2.3.1 Highest
jaxws-rt-2.3.1.jar (shaded: com.sun.xml.ws:servlet:2.3.1)Description:
Servlet Support for JAX-WS RI File Path: /home/andrii/.m2/repository/com/sun/xml/ws/jaxws-rt/2.3.1/jaxws-rt-2.3.1.jar/META-INF/maven/com.sun.xml.ws/servlet/pom.xmlMD5: 7588542d091a45765afae4f63f6c4b85SHA1: 03d29d8f253540b412db3888b8aab2581a7ec0c1SHA256: aae4fcdbdd7be2620ae1617bbe49aaeb343483f9eb32005a1014ebe91ca90a67Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor web services Medium Vendor pom artifactid servlet Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name JAX-WS RI Servlet Support (servlet) High Vendor pom parent-artifactid project Low Product hint analyzer product web services Medium Product pom artifactid servlet Highest Product pom groupid com.sun.xml.ws Highest Product pom name JAX-WS RI Servlet Support (servlet) High Product pom parent-artifactid project Medium Version pom version 2.3.1 Highest
jaxws-rt-2.3.1.jarFile Path: /home/andrii/.m2/repository/com/sun/xml/ws/jaxws-rt/2.3.1/jaxws-rt-2.3.1.jarMD5: 9db69eec606e9d3023d09256c2102d87SHA1: faada6fe82b87adf410bd0c59886fff0122d7512SHA256: 4f8d8d4008e0dffe575ce6d4a37cf1dc84ac32441679a4de13924202572d1b72Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jaxws-rt High Vendor hint analyzer vendor web services Medium Vendor jar package name com Highest Vendor jar package name runtime Highest Vendor jar package name sun Highest Vendor jar package name transport Highest Vendor jar package name ws Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest extension-name com.sun.xml.ws Medium Vendor Manifest git-revision 6ef5f7eb9a938dbc4562f25f8fa0b67cc4ff2dbb Low Vendor Manifest Implementation-Vendor Sun Microsystems Inc High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest multi-release true Low Vendor Manifest probe-provider-class-names com.sun.xml.ws.transport.http.servlet.JAXWSRIDeploymentProbeProvider Medium Vendor pom artifactid jaxws-rt Highest Vendor pom artifactid jaxws-rt Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name JAX-WS RI Runtime Bundle High Vendor pom parent-artifactid bundles Low Product file name jaxws-rt High Product hint analyzer product web services Medium Product jar package name api Highest Product jar package name com Highest Product jar package name runtime Highest Product jar package name sun Highest Product jar package name transport Highest Product jar package name ws Highest Product jar package name xml Highest Product Manifest extension-name com.sun.xml.ws Medium Product Manifest git-revision 6ef5f7eb9a938dbc4562f25f8fa0b67cc4ff2dbb Low Product Manifest Implementation-Title JAX-WS Implementation High Product Manifest multi-release true Low Product Manifest probe-provider-class-names com.sun.xml.ws.transport.http.servlet.JAXWSRIDeploymentProbeProvider Medium Product Manifest specification-title The Java API for XML Web Services Medium Product pom artifactid jaxws-rt Highest Product pom groupid com.sun.xml.ws Highest Product pom name JAX-WS RI Runtime Bundle High Product pom parent-artifactid bundles Medium Version file version 2.3.1 High Version Manifest build-id 2.3.1 Medium Version Manifest Implementation-Version 2.3.1 High Version Manifest major-version 2.3.1 Medium Version pom version 2.3.1 Highest
jboss-logging-3.3.1.Final.jarDescription:
The JBoss Logging Framework License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/jboss/logging/jboss-logging/3.3.1.Final/jboss-logging-3.3.1.Final.jar
MD5: 93cf8945ff84aaf9f0ed9a76991338fb
SHA1: c46217ab74b532568c0ed31dc599db3048bd1b67
SHA256: 9f7d8b884370763b131bf48a0fc91edec89ad80e0e40c47658098a686a905bb2
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name logging Highest Vendor Manifest build-timestamp Wed, 15 Mar 2017 13:22:07 -0700 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jboss-logging Highest Vendor pom artifactid jboss-logging Low Vendor pom groupid org.jboss.logging Highest Vendor pom name JBoss Logging 3 High Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Vendor pom url http://www.jboss.org Highest Product file name jboss-logging High Product jar package name jboss Highest Product jar package name logging Highest Product Manifest build-timestamp Wed, 15 Mar 2017 13:22:07 -0700 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest Implementation-Title JBoss Logging 3 High Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Logging 3 Medium Product pom artifactid jboss-logging Highest Product pom groupid org.jboss.logging Highest Product pom name JBoss Logging 3 High Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Product pom url http://www.jboss.org Medium Version Manifest Bundle-Version 3.3.1.Final High Version Manifest Implementation-Version 3.3.1.Final High Version pom parent-version 3.3.1.Final Low Version pom version 3.3.1.Final Highest
jboss-logging-annotations-2.0.0.Final.jarLicense:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/jboss/logging/jboss-logging-annotations/2.0.0.Final/jboss-logging-annotations-2.0.0.Final.jar
MD5: 9858a903b55d4f36ace8eaadf05541ab
SHA1: f69fbbab3a164589e1ac09e603a3948de56e31b1
SHA256: f8624863d3725359eac214aed1269935f5ba91260e7440aa7e5d854f3a87de23
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jboss-logging-annotations High Vendor hint analyzer vendor redhat Highest Vendor jar package name annotations Highest Vendor jar package name jboss Highest Vendor jar package name logging Highest Vendor Manifest build-timestamp Fri, 24 Apr 2015 19:59:22 -0700 Low Vendor Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jboss-logging-annotations Highest Vendor pom artifactid jboss-logging-annotations Low Vendor pom groupid org.jboss.logging Highest Vendor pom name JBoss Logging I18n Annotations High Vendor pom parent-artifactid jboss-logging-tools-parent Low Product file name jboss-logging-annotations High Product jar package name annotations Highest Product jar package name jboss Highest Product jar package name logging Highest Product Manifest build-timestamp Fri, 24 Apr 2015 19:59:22 -0700 Low Product Manifest Implementation-Title JBoss Logging I18n Annotations High Product Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Logging I18n Annotations Medium Product pom artifactid jboss-logging-annotations Highest Product pom groupid org.jboss.logging Highest Product pom name JBoss Logging I18n Annotations High Product pom parent-artifactid jboss-logging-tools-parent Medium Version Manifest Implementation-Version 2.0.0.Final High Version pom version 2.0.0.Final Highest
jcaptcha-api-2.0.0.jarFile Path: /home/andrii/.m2/repository/io/leopard/thirdparty/jcaptcha-api/2.0.0/jcaptcha-api-2.0.0.jarMD5: 622199963f8467668ffa14ca3350196bSHA1: aad8675f07d8923db2d1d558d2039d1cf6c2d51dSHA256: d8192d1146136f7eddc5962339daadcf989fa2b548ceab1a871470e07dd6eb57Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jcaptcha-api High Vendor jar package name captcha Low Vendor jar package name octo Low Vendor pom artifactid jcaptcha-api Highest Vendor pom artifactid jcaptcha-api Low Vendor pom groupid io.leopard.thirdparty Highest Vendor pom parent-artifactid jcaptcha Low Product file name jcaptcha-api High Product jar package name captcha Low Product pom artifactid jcaptcha-api Highest Product pom groupid io.leopard.thirdparty Highest Product pom parent-artifactid jcaptcha Medium Version file version 2.0.0 High Version pom version 2.0.0 Highest
jcaptcha-core-2.0.0.jarFile Path: /home/andrii/.m2/repository/io/leopard/thirdparty/jcaptcha-core/2.0.0/jcaptcha-core-2.0.0.jarMD5: 4d8703e3e0329002ef4d5764ec59fc38SHA1: bb9d5a295aabefcaf4957fca745bf4f13b8ec479SHA256: 4477976ef53ebbd730b1bb0c4a1bd93c064e247c33c10bd1ef93b5ccbc21bc51Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jcaptcha-core High Vendor jar package name captcha Low Vendor jar package name component Low Vendor jar package name octo Low Vendor pom artifactid jcaptcha-core Highest Vendor pom artifactid jcaptcha-core Low Vendor pom groupid io.leopard.thirdparty Highest Vendor pom name JCaptcha High Vendor pom parent-artifactid jcaptcha Low Product file name jcaptcha-core High Product jar package name captcha Low Product jar package name component Low Product jar package name image Low Product pom artifactid jcaptcha-core Highest Product pom groupid io.leopard.thirdparty Highest Product pom name JCaptcha High Product pom parent-artifactid jcaptcha Medium Version file version 2.0.0 High Version pom version 2.0.0 Highest
jcip-annotations-1.0.jarFile Path: /home/andrii/.m2/repository/net/jcip/jcip-annotations/1.0/jcip-annotations-1.0.jarMD5: ead9d5ffa6e89b529667d9f1bca26207SHA1: 6055a7559d9e7ba1ff8fa62b55f0eaad3af7046eSHA256: bfb83cc9e49f8d58275e19c53ff715193edcd7d69fa54ba2aff745be57926696Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jcip-annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name jcip Highest Vendor jar package name jcip Low Vendor jar package name net Highest Vendor jar package name net Low Vendor pom artifactid jcip-annotations Highest Vendor pom artifactid jcip-annotations Low Vendor pom groupid net.jcip Highest Product file name jcip-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name jcip Highest Product jar package name jcip Low Product jar package name net Highest Product pom artifactid jcip-annotations Highest Product pom groupid net.jcip Highest Version file version 1.0 High Version pom version 1.0 Highest
jcl-over-slf4j-1.7.25.jarDescription:
JCL 1.2 implemented over SLF4J File Path: /home/andrii/.m2/repository/org/slf4j/jcl-over-slf4j/1.7.25/jcl-over-slf4j-1.7.25.jarMD5: 56b22adc639b09b2e917f42d68b26600SHA1: f8c32b13ff142a513eeb5b6330b1588dcb2c0461SHA256: 5e938457e79efcbfb3ab64bc29c43ec6c3b95fffcda3c155f4a86cc320c11e14Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jcl-over-slf4j High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium Vendor pom artifactid jcl-over-slf4j Highest Vendor pom artifactid jcl-over-slf4j Low Vendor pom groupid org.slf4j Highest Vendor pom name JCL 1.2 implemented over SLF4J High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name jcl-over-slf4j High Product Manifest Bundle-Name jcl-over-slf4j Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname jcl.over.slf4j Medium Product Manifest Implementation-Title jcl-over-slf4j High Product pom artifactid jcl-over-slf4j Highest Product pom groupid org.slf4j Highest Product pom name JCL 1.2 implemented over SLF4J High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 1.7.25 High Version Manifest Bundle-Version 1.7.25 High Version Manifest Implementation-Version 1.7.25 High Version pom version 1.7.25 Highest
jdiagnostics-1.0.7.jarDescription:
Support bundle builder and classpath debugger for Java applications License:
Apache-2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/org/anarres/jdiagnostics/jdiagnostics/1.0.7/jdiagnostics-1.0.7.jar
MD5: 1b8cbb9aaab34e975a739cf7c4ae9226
SHA1: 80e5376cae663b057da66204cb5ff0d79b5a0f47
SHA256: 7c7fe5347ce2d147ff7bc372f4b2e110d60261fb0f2809e719e3c56ca52ee3d7
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jdiagnostics High Vendor jar package name anarres Highest Vendor jar package name jdiagnostics Highest Vendor Manifest branch master Low Vendor Manifest build-date 2021-09-13_21:41:00 Low Vendor Manifest build-host flame Low Vendor Manifest build-job LOCAL Low Vendor Manifest build-number LOCAL Low Vendor Manifest built-os Linux Low Vendor Manifest built-status integration Low Vendor Manifest change 01b7a79 Low Vendor Manifest module-origin shevek/jdiagnostics.git Low Vendor Manifest module-source Low Vendor pom artifactid jdiagnostics Highest Vendor pom artifactid jdiagnostics Low Vendor pom developer email github@anarres.org Low Vendor pom developer id shevek Medium Vendor pom developer name Shevek Medium Vendor pom groupid org.anarres.jdiagnostics Highest Vendor pom name jdiagnostics High Vendor pom url shevek/jdiagnostics Highest Product file name jdiagnostics High Product jar package name anarres Highest Product jar package name jdiagnostics Highest Product Manifest branch master Low Product Manifest build-date 2021-09-13_21:41:00 Low Product Manifest build-host flame Low Product Manifest build-job LOCAL Low Product Manifest build-number LOCAL Low Product Manifest built-os Linux Low Product Manifest built-status integration Low Product Manifest change 01b7a79 Low Product Manifest Implementation-Title org.anarres.jdiagnostics#jdiagnostics;1.0.7 High Product Manifest module-origin shevek/jdiagnostics.git Low Product Manifest module-source Low Product pom artifactid jdiagnostics Highest Product pom developer email github@anarres.org Low Product pom developer id shevek Low Product pom developer name Shevek Low Product pom groupid org.anarres.jdiagnostics Highest Product pom name jdiagnostics High Product pom url shevek/jdiagnostics High Version file version 1.0.7 High Version Manifest Implementation-Version 1.0.7 High Version pom version 1.0.7 Highest
jdom-1.1.3.jarDescription:
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
License:
Similar to Apache License but with the acknowledgment clause removed: https://raw.github.com/hunterhacker/jdom/master/LICENSE.txt File Path: /home/andrii/.m2/repository/org/jdom/jdom/1.1.3/jdom-1.1.3.jar
MD5: 140bfed13341fe2039eee0f26a16d705
SHA1: 8bdfeb39fa929c35f5e4f0b02d34350db39a1efc
SHA256: 02bd61a725e8af9b0176b43bf29816d0c748b8ab951385bd127be37489325a0a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jdom High Vendor jar package name jdom Highest Vendor manifest: org/jdom/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/adapters/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/filter/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/input/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/output/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/transform/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom/xpath/ Implementation-Vendor jdom.org Medium Vendor pom artifactid jdom Highest Vendor pom artifactid jdom Low Vendor pom developer email jdom@tuis.net Low Vendor pom developer email jhunter@servlets.com Low Vendor pom developer id hunterhacker Medium Vendor pom developer id rolfl Medium Vendor pom developer name Jason Hunter Medium Vendor pom developer name Rolf Lear Medium Vendor pom groupid org.jdom Highest Vendor pom name JDOM High Vendor pom organization name JDOM High Vendor pom organization url http://www.jdom.org Medium Vendor pom url http://www.jdom.org Highest Product file name jdom High Product jar package name adapters Highest Product jar package name filter Highest Product jar package name input Highest Product jar package name jdom Highest Product jar package name output Highest Product jar package name transform Highest Product jar package name xpath Highest Product manifest: org/jdom/ Implementation-Title org.jdom Medium Product manifest: org/jdom/ Specification-Title JDOM Classes Medium Product manifest: org/jdom/adapters/ Implementation-Title org.jdom.adapters Medium Product manifest: org/jdom/adapters/ Specification-Title JDOM Adapter Classes Medium Product manifest: org/jdom/filter/ Implementation-Title org.jdom.filter Medium Product manifest: org/jdom/filter/ Specification-Title JDOM Filter Classes Medium Product manifest: org/jdom/input/ Implementation-Title org.jdom.input Medium Product manifest: org/jdom/input/ Specification-Title JDOM Input Classes Medium Product manifest: org/jdom/output/ Implementation-Title org.jdom.output Medium Product manifest: org/jdom/output/ Specification-Title JDOM Output Classes Medium Product manifest: org/jdom/transform/ Implementation-Title org.jdom.transform Medium Product manifest: org/jdom/transform/ Specification-Title JDOM Transformation Classes Medium Product manifest: org/jdom/xpath/ Implementation-Title org.jdom.xpath Medium Product manifest: org/jdom/xpath/ Specification-Title JDOM XPath Classes Medium Product pom artifactid jdom Highest Product pom developer email jdom@tuis.net Low Product pom developer email jhunter@servlets.com Low Product pom developer id hunterhacker Low Product pom developer id rolfl Low Product pom developer name Jason Hunter Low Product pom developer name Rolf Lear Low Product pom groupid org.jdom Highest Product pom name JDOM High Product pom organization name JDOM Low Product pom organization url http://www.jdom.org Low Product pom url http://www.jdom.org Medium Version file version 1.1.3 High Version manifest: org/jdom/ Implementation-Version 1.1.3 Medium Version manifest: org/jdom/adapters/ Implementation-Version 1.1.3 Medium Version manifest: org/jdom/filter/ Implementation-Version 1.1.3 Medium Version manifest: org/jdom/input/ Implementation-Version 1.1.3 Medium Version manifest: org/jdom/output/ Implementation-Version 1.1.3 Medium Version manifest: org/jdom/transform/ Implementation-Version 1.1.3 Medium Version manifest: org/jdom/xpath/ Implementation-Version 1.1.3 Medium Version pom version 1.1.3 Highest
CVE-2021-33813 suppress
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jersey-core-1.19.4.jarDescription:
Jersey is the open source (under dual CDDL+GPL license) JAX-RS (JSR 311) production quality Reference Implementation for building RESTful Web services. License:
http://glassfish.java.net/public/CDDL+GPL_1_1.html, http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/com/sun/jersey/jersey-core/1.19.4/jersey-core-1.19.4.jar
MD5: cf0c3489cb307a1ef3bce3a5e63dde9b
SHA1: 21c5319c82ca29705715b315553a16f11b16655e
SHA256: 64b03198e0264849d0fc341857ebcc9c882b1909a2dc35a0972fe7d901b826e5
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jersey-core High Vendor jar package name core Highest Vendor jar package name jersey Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname com.sun.jersey.core Medium Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun.jersey Medium Vendor pom artifactid jersey-core Highest Vendor pom artifactid jersey-core Low Vendor pom groupid com.sun.jersey Highest Vendor pom name jersey-core High Vendor pom parent-artifactid jersey-project Low Product file name jersey-core High Product jar package name core Highest Product jar package name jersey Highest Product jar package name sun Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name jersey-core Medium Product Manifest bundle-symbolicname com.sun.jersey.core Medium Product Manifest Implementation-Title jersey-core High Product pom artifactid jersey-core Highest Product pom groupid com.sun.jersey Highest Product pom name jersey-core High Product pom parent-artifactid jersey-project Medium Version file version 1.19.4 High Version Manifest Bundle-Version 1.19.4 High Version Manifest Implementation-Version 1.19.4 High Version pom version 1.19.4 Highest
Related Dependencies jersey-client-1.19.4.jarFile Path: /home/andrii/.m2/repository/com/sun/jersey/jersey-client/1.19.4/jersey-client-1.19.4.jar MD5: 38e569bc5ff0615d82fac507da373973 SHA1: 9b1f3cf3fdd02d313018f1a67c42106e6ce9f60d SHA256: 639c825c5db580f8115bf49ffc893093526d2ed1079fbc929b6a5fbd0b2eda40 pkg:maven/com.sun.jersey/jersey-client@1.19.4 jersey-json-1.19.4.jarFile Path: /home/andrii/.m2/repository/com/sun/jersey/jersey-json/1.19.4/jersey-json-1.19.4.jar MD5: 3474220bc8e24927f78c1930c157e674 SHA1: 00ddbe9e3f8ac72c15ba0d7547edcb6a63ea4389 SHA256: d4bc92a7b552c4fd7976b8e1b40a32807e4b74d322ef1b4e9540f2a39848e8d3 pkg:maven/com.sun.jersey/jersey-json@1.19.4 jettison-1.1.jarDescription:
A StAX implementation for JSON. File Path: /home/andrii/.m2/repository/org/codehaus/jettison/jettison/1.1/jettison-1.1.jarMD5: fc80e0aabd516c54739262c3d618303aSHA1: 1a01a2a1218fcf9faa2cc2a6ced025bdea687262SHA256: 377940288b0643c48780137f6f68578937e1ea5ca2b73830a820c50a7b7ed801Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jettison High Vendor jar package name codehaus Highest Vendor jar package name jettison Highest Vendor jar package name json Highest Vendor Manifest bundle-symbolicname org.codehaus.jettison.jettison Medium Vendor pom artifactid jettison Highest Vendor pom artifactid jettison Low Vendor pom groupid org.codehaus.jettison Highest Vendor pom name Jettison High Product file name jettison High Product jar package name codehaus Highest Product jar package name jettison Highest Product jar package name json Highest Product Manifest Bundle-Name jettison Medium Product Manifest bundle-symbolicname org.codehaus.jettison.jettison Medium Product Manifest Implementation-Title Jettison High Product pom artifactid jettison Highest Product pom groupid org.codehaus.jettison Highest Product pom name Jettison High Version file version 1.1 High Version Manifest Bundle-Version 1.1 High Version Manifest Implementation-Version 1.1 High Version pom version 1.1 Highest
CVE-2022-40149 suppress
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-40150 suppress
Those using Jettison to parse untrusted XML or JSON data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by Out of memory. This effect may support a denial of service attack. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
jira-integration-spi-6.2.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/integration/jira/jira-integration-spi/6.2.4/jira-integration-spi-6.2.4.jarMD5: 57406d39a8c0f330d624e8f63e5105bcSHA1: 35e484faea06b38fc3a84c0cfd8a04fac16a44c4SHA256: b49d081d036d517987679a3adf7df6d4886fa2cc4581ee11307b363818b640eaReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jira-integration-spi High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name integration Highest Vendor jar package name integration Low Vendor jar package name jira Highest Vendor jar package name jira Low Vendor pom artifactid jira-integration-spi Highest Vendor pom artifactid jira-integration-spi Low Vendor pom groupid com.atlassian.integration.jira Highest Vendor pom name Jira Integration :: SPI High Vendor pom parent-artifactid jira-integration-parent Low Product file name jira-integration-spi High Product jar package name applinks Low Product jar package name atlassian Highest Product jar package name integration Highest Product jar package name integration Low Product jar package name jira Highest Product jar package name jira Low Product pom artifactid jira-integration-spi Highest Product pom groupid com.atlassian.integration.jira Highest Product pom name Jira Integration :: SPI High Product pom parent-artifactid jira-integration-parent Medium Version file version 6.2.4 High Version pom version 6.2.4 Highest
CVE-2017-5983 suppress
The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-11581 suppress
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions of Jira Server and Data Center from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3 are affected by this vulnerability. CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20409 suppress
The way in which velocity templates were used in Atlassian Jira Server and Data Center prior to version 8.8.0 allowed remote attackers to gain remote code execution if they were able to exploit a server side template injection vulnerability. CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-14172 suppress
This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if they were able to exploit a server side template injection vulnerability. The affected versions are before version 7.13.0, from version 8.0.0 before 8.5.0, and from version 8.6.0 before version 8.8.1. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2016-4319 suppress
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
CVE-2017-18113 suppress
The DefaultOSWorkflowConfigurator class in Jira Server and Jira Data Center before version 8.18.1 allows remote attackers who can trick a system administrator to import their malicious workflow to execute arbitrary code via a Remote Code Execution (RCE) vulnerability. The vulnerability allowed for various problematic OSWorkflow classes to be used as part of workflows. The fix for this issue blocks usage of unsafe conditions, validators, functions and registers that are build-in into OSWorkflow library and other Jira dependencies. Atlassian-made functions or functions provided by 3rd party plugins are not affected by this fix. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-8443 suppress
The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers who have obtained access to administrator's session to access the ViewUpgrades administrative resource without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2018-5231 suppress
The ForgotLoginDetails resource in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to perform a denial of service attack via sending requests to it. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20413 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability on the UserPickerBrowser.jspa page. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20898 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-3399 suppress
The BrowseProjects.jspa resource in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to see information for archived projects through a missing authorisation check. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-8442 suppress
The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to access files in the Jira webroot under the META-INF directory via a lax path access check. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14167 suppress
The MessageBundleResource resource in Jira Server and Data Center before version 7.13.4, from 8.5.0 before 8.5.5, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to impact the application's availability via an Denial of Service (DoS) vulnerability. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-14178 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39113 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected versions are before version 8.13.9, and from version 8.14.0 before 8.18.0. CWE-613 Insufficient Session Expiration
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39123 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the /rest/gadget/1.0/createdVsResolved/generate endpoint. The affected versions are before version 8.16.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-41305 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are before version 8.13.12.. CWE-639 Authorization Bypass Through User-Controlled Key
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-41306 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0. CWE-639 Authorization Bypass Through User-Controlled Key
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-41307 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.0. CWE-639 Authorization Bypass Through User-Controlled Key
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-41312 suppress
Affected versions of Atlassian Jira Server and Data Center allow a remote attacker who has had their access revoked from Jira Service Management to enable and disable Issue Collectors on Jira Service Management projects via an Improper Authentication vulnerability in the /secure/ViewCollectors endpoint. The affected versions are before version 8.19.1. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26070 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43947 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of https://jira.atlassian.com/browse/JSDSERVER-8665. The affected versions are before version 8.13.15, and from version 8.14.0 before 8.20.3. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2008-6531 suppress
The WebWork 1 web application framework in Atlassian JIRA before 3.13.2 allows remote attackers to invoke exposed public JIRA methods via a crafted URL that is dynamically transformed into method calls, aka "WebWork 1 Parameter Injection Hole." CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2017-18033 suppress
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions:
CVE-2017-18101 suppress
Various administrative external system import resources in Atlassian JIRA Server (including JIRA Core) before version 7.6.5, from version 7.7.0 before version 7.7.3, from version 7.8.0 before version 7.8.3 and before version 7.9.0 allow remote attackers to run import operations and to determine if an internal service exists through missing permission checks. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-11583 suppress
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name". NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2019-11587 suppress
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF). CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20410 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view sensitive information via an Information Disclosure vulnerability in the comment restriction feature. The affected versions are before version 7.6.17, from version 7.7.0 before 7.13.9, and from version 8.0.0 before 8.4.2. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20418 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to prevent users from accessing the instance via an Application Denial of Service vulnerability in the /rendering/wiki endpoint. The affected versions are before version 8.8.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20897 suppress
The avatar upload feature in affected versions of Atlassian Jira Server and Data Center allows remote attackers to achieve Denial of Service via a crafted PNG file. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1. CWE-434 Unrestricted Upload of File with Dangerous Type
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-41308 suppress
Affected versions of Atlassian Jira Server and Data Center allow authenticated yet non-administrator remote attackers to edit the File Replication settings via a Broken Access Control vulnerability in the `ReplicationSettings!default.jspa` endpoint. The affected versions are before version 8.6.0, from version 8.7.0 before 8.13.12, and from version 8.14.0 before 8.20.1. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2016-6285 suppress
Cross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-14594 suppress
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-16863 suppress
The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-16864 suppress
The issue search resource in Atlassian Jira before version 7.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the orderby parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18039 suppress
The IncomingMailServers resource in Atlassian Jira from version 6.2.1 before version 7.4.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18098 suppress
The searchrequest-xml resource in Atlassian Jira before version 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through various fields. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2017-18100 suppress
The agile wallboard gadget in Atlassian Jira before version 7.8.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of quick filters. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2018-13387 suppress
The IncomingMailServers resource in Atlassian JIRA Server before version 7.6.7, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3 and from version 7.10.0 before version 7.10.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the messagesThreshold parameter as the fix for CVE-2017-18039 was incomplete. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-13395 suppress
Various resources in Atlassian Jira before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and before version 7.11.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the epic colour field of an issue while an issue is being moved. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-13401 suppress
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allows remote attackers to obtain a user's Cross-site request forgery (CSRF) token through an open redirect vulnerability. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-13402 suppress
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via a open redirect vulnerability. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-20824 suppress
The WallboardServlet resource in Jira before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the cyclePeriod parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2018-5230 suppress
The issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version 7.8.4 and from version 7.9.0 before version 7.9.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the error message of custom fields when an invalid value is specified. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-5232 suppress
The EditIssue.jspa resource in Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.10.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the issuetype parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-11584 suppress
The MigratePriorityScheme resource in Jira before version 8.3.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the priority icon url of an issue priority. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2019-11585 suppress
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20417 suppress
NOTE: This candidate is a duplicate of CVE-2019-15011. All CVE users should reference CVE-2019-15011 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Vulnerable Software & Versions: (show all )
CVE-2019-20901 suppress
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-3402 suppress
The ConfigurePortalPages.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the searchOwnerUserName parameter. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14164 suppress
The WYSIWYG editor resource in Jira Server and Data Center before version 8.8.2 allows remote attackers to inject arbitrary HTML or JavaScript names via an Cross Site Scripting (XSS) vulnerability by pasting javascript code into the editor field. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14169 suppress
The quick search component in Atlassian Jira Server and Data Center before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36236 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the ViewWorkflowSchemes.jspa and ListWorkflows.jspa endpoints. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36288 suppress
The issue navigation and search view in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.1 allows remote attackers to inject arbitrary HTML or JavaScript via a DOM Cross-Site Scripting (XSS) vulnerability caused by parameter pollution. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-4022 suppress
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a mixed multipart content type. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26078 suppress
The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before version 8.13.6, and from version 8.14.0 before version 8.16.1 allows remote attackers inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26079 suppress
The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 before version 8.13.7, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39111 suppress
The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the handling of supplied content such as from a PDF when pasted into a field such as the description field. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-41304 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the /secure/admin/ImporterFinishedPage.jspa error message. The affected versions are before version 8.13.12, and from version 8.14.0 before 8.20.2. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-18104 suppress
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14168 suppress
The email client in Jira Server and Data Center before version 7.13.16, from 8.5.0 before 8.5.7, from 8.8.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to access outgoing emails between a Jira instance and the SMTP server via man-in-the-middle (MITM) vulnerability. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-18097 suppress
The Trello board importer resource in Atlassian Jira before version 7.6.1 allows remote attackers who can convince a Jira administrator to import their Trello board to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the title of a Trello card. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2018-13403 suppress
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of a saved filter when displayed on a Jira dashboard. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-20232 suppress
The labels widget gadget in Atlassian Jira before version 7.6.11 and from version 7.7.0 before version 7.13.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the rendering of retrieved content from a url location that could be manipulated by the up_projectid widget preference setting. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20414 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in Issue Navigator Basic Search. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14173 suppress
The file upload feature in Atlassian Jira Server and Data Center in affected versions allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability. The affected versions are before version 8.5.4, from version 8.6.0 before 8.6.2, and from version 8.7.0 before 8.7.1. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14184 suppress
Affected versions of Atlassian Jira Server allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in Jira issue filter export files. The affected versions are before 8.5.9, from version 8.6.0 before 8.12.3, and from version 8.13.0 before 8.13.1. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-4021 suppress
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-4024 suppress
The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a vnd.wap.xhtml+xml content type. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26082 suppress
The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.17.0 allows remote attackers to inject arbitrary HTML or JavaScript via a stored cross site scripting vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26083 suppress
Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-16865 suppress
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2018-13391 suppress
The ProfileLinkUserFormat component of Jira Server before version 7.6.8, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3 and from version 7.11.0 before version 7.11.2 allows remote attackers who can access & view an issue to obtain the email address of the reporter and assignee user of an issue despite the configured email visibility setting being set to hidden. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20101 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via a Broken Access Control vulnerability in the /rest/whitelist/<version>/check endpoint. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20408 suppress
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.7.0 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF) vulnerability due to a logic bug in the JiraWhitelist class. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2019-20412 suppress
The Convert Sub-Task to Issue page in affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate the following information via an Improper Authentication vulnerability: Workflow names; Project Key, if it is part of the workflow name; Issue Keys; Issue Types; Status Types. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20899 suppress
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2019-3401 suppress
The ManageFilters.jspa resource in Jira before version 7.13.3 and from version 8.0.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-3403 suppress
The /rest/api/2/user/picker rest resource in Jira before version 7.13.3, from version 8.0.0 before version 8.0.4, and from version 8.1.0 before version 8.1.1 allows remote attackers to enumerate usernames via an incorrect authorisation check. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-8449 suppress
The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate usernames via an information disclosure vulnerability. CWE-306 Missing Authentication for Critical Function
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2020-14165 suppress
The UniversalAvatarResource.getAvatars resource in Jira Server and Data Center before version 8.9.0 allows remote attackers to obtain information about custom project avatars names via an Improper authorization vulnerability. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14181 suppress
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the /ViewUserHover.jspa endpoint. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, and from version 8.6.0 before 8.12.0. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14185 suppress
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36235 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field and custom SLA names via an Information Disclosure vulnerability in the mobile site view. The affected versions are before version 8.13.2, and from version 8.14.0 before 8.14.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36237 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view custom field options via an Information Disclosure vulnerability in the /rest/api/2/customFieldOption/ endpoint. The affected versions are before version 8.15.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36238 suppress
The /rest/api/1.0/render resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a username is valid or not via a missing permissions check. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36286 suppress
The membersOf JQL search function in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to determine if a group exists & members of groups if they are assigned to publicly visible issue field. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36287 suppress
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to obtain gadget related settings via a missing permissions check. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36289 suppress
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Information Disclosure vulnerability in the QueryComponentRendererValue!Default.jspa endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-4028 suppress
Versions before 8.9.1, Various resources in Jira responded with a 404 instead of redirecting unauthenticated users to the login page, in some situations this may have allowed unauthorised attackers to determine if certain resources exist or not through an Information Disclosure vulnerability. CWE-203 Information Exposure Through Discrepancy
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26069 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary files and enumerate project keys via an Information Disclosure vulnerability in the /rest/api/1.0/issues/{id}/ActionsAndOperations API endpoint. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26081 suppress
REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1 allows remote attackers to enumerate usernames via a Sensitive Data Exposure vulnerability in the `/rest/api/latest/user/avatar/temporary` endpoint. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39118 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to discover the usernames and full names of users via an enumeration vulnerability in the /rest/api/1.0/render endpoint. The affected versions are before version 8.19.0. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39119 suppress
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature. The affected versions are before version 8.19.0. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39122 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view users' emails via an Information Disclosure vulnerability in the /rest/api/2/search endpoint. The affected versions are before version 8.5.13, from version 8.6.0 before 8.13.5, and from version 8.14.0 before 8.15.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39125 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to discover the usernames of users via an enumeration vulnerability in the password reset page. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39127 suppress
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL endpoint via a Broken Access Control vulnerability (BAC) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.1. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20402 suppress
Support zip files in Atlassian Jira Server and Data Center before version 8.6.0 could be downloaded by a System Administrator user without requiring the user to re-enter their password via an improper authorization vulnerability. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.9) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2016-4318 suppress
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2019-20416 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the project configuration feature. The affected versions are before version 8.3.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36234 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in the Screens Modal view. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.15.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-4025 suppress
The attachment download resource in Atlassian Jira Server and Data Center The attachment download resource in Atlassian Jira Server and Data Center before 8.5.5, and from 8.6.0 before 8.8.2, and from 8.9.0 before 8.9.1 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability issue attachments with a rdf content type. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39112 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to redirect users to a malicious URL via a reverse tabnapping vulnerability in the Project Shortcuts feature. The affected versions are before version 8.5.15, from version 8.6.0 before 8.13.7, from version 8.14.0 before 8.17.1, and from version 8.18.0 before 8.18.1. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (4.9) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39117 suppress
The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability via the name of a custom field. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43945 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers with Roadmaps Administrator permissions to inject arbitrary HTML or JavaScript via a Stored Cross-Site Scripting (SXSS) vulnerability in the /rest/jpo/1.0/hierarchyConfiguration endpoint. The affected versions are before version 8.20.3. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-13400 suppress
Several administrative resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and before version 7.13.1 allow remote attackers who have obtained access to administrator's session to access certain administrative resources without needing to re-authenticate to pass "WebSudo" through an improper access control vulnerability. CWE-269 Improper Privilege Management
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: MEDIUM (4.7) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2017-16862 suppress
The IncomingMailServers resource in Atlassian Jira before version 7.6.2 allows remote attackers to modify the "incoming mail" whitelist setting via a Cross-site request forgery (CSRF) vulnerability. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2018-20826 suppress
The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check. CWE-285 Improper Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2019-11586 suppress
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-11588 suppress
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2019-15005 suppress
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-15013 suppress
The WorkflowResource class removeStatus method in Jira before version 7.13.12, from version 8.0.0 before version 8.4.3, and from version 8.5.0 before version 8.5.2 allows authenticated remote attackers who do not have project administration access to remove a configured issue status from a project via a missing authorisation check. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20106 suppress
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting permissions via a broken access control bug. CWE-276 Incorrect Default Permissions
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20411 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify Wallboard settings via a Cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.9, and from version 8.0.0 before 8.4.2. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-20415 suppress
Atlassian Jira Server and Data Center in affected versions allows remote attackers to modify logging and profiling settings via a cross-site request forgery (CSRF) vulnerability. The affected versions are before version 7.13.3, and from version 8.0.0 before 8.1.0. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14174 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5.7, from version 8.6.0 before 8.9.2, and from version 8.10.0 before 8.10.1. CWE-639 Authorization Bypass Through User-Controlled Key
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-14183 suppress
Affected versions of Jira Server & Data Center allow a remote attacker with limited (non-admin) privileges to view a Jira instance's Support Entitlement Number (SEN) via an Information Disclosure vulnerability in the HTTP Response headers. The affected versions are before version 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before 8.12.1. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-29451 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate Jira projects via an Information Disclosure vulnerability in the Jira Projects plugin report page. The affected versions are before version 8.5.11, from version 8.6.0 before 8.13.3, and from version 8.14.0 before 8.14.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36231 suppress
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view the metadata of boards they should not have access to via an Insecure Direct Object References (IDOR) vulnerability. The affected versions are before version 8.5.10, and from version 8.6.0 before 8.13.2. CWE-639 Authorization Bypass Through User-Controlled Key
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-4029 suppress
The /rest/project-templates/1.0/createshared resource in Atlassian Jira Server and Data Center before version 8.5.5, from 8.6.0 before 8.7.2, and from 8.8.0 before 8.8.1 allows remote attackers to enumerate project names via an improper authorization vulnerability. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26075 suppress
The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before 8.13.4, and from version 8.14.0 before 8.15.1 allowed remote authenticated attackers to obtain the full path of the Jira application data directory via an information disclosure vulnerability in the error message when presented with an invalid filename. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39121 suppress
Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to enumerate the keys of private Jira projects via an Information Disclosure vulnerability in the /rest/api/latest/projectvalidate/key endpoint. The affected versions are before version 8.5.18, from version 8.6.0 before 8.13.10, and from version 8.14.0 before 8.18.2. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-39124 suppress
The Cross-Site Request Forgery (CSRF) failure retry feature of Atlassian Jira Server and Data Center before version 8.16.0 allows remote attackers who are able to trick a user into retrying a request to bypass CSRF protection and replay a crafted request. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43953 suppress
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread Contention and CPU monitoring settings via a Cross-Site Request Forgery (CSRF) vulnerability in the /secure/admin/ViewInstrumentation.jspa endpoint. The affected versions are before version 8.13.16, and from version 8.14.0 before 8.20.5. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L References:
Vulnerable Software & Versions: (show all )
CVE-2018-13404 suppress
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version 7.12.0 before version 7.12.3, and from version 7.13.0 before version 7.13.1 allows remote attackers who have administrator rights to determine the existence of internal hosts & open ports and in some cases obtain service information from internal network resources via a Server Side Request Forgery (SSRF) vulnerability. CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.1) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26076 suppress
The jira.editor.user.mode cookie set by the Jira Editor Plugin in Jira Server and Data Center before version 8.5.12, from version 8.6.0 before version 8.13.4, and from version 8.14.0 before version 8.15.0 allows remote anonymous attackers who can perform an attacker in the middle attack to learn which mode a user is editing in due to the cookie not being set with a secure attribute if Jira was configured to use https. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.7) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-26071 suppress
The SetFeatureEnabled.jspa resource in Jira Server and Data Center before version 8.5.13, from version 8.6.0 before version 8.13.5, and from version 8.14.0 before version 8.15.1 allows remote anonymous attackers to enable and disable Jira Software configuration via a cross-site request forgery (CSRF) vulnerability. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: LOW (3.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
jna-5.6.0.jarDescription:
Java Native Access License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/net/java/dev/jna/jna/5.6.0/jna-5.6.0.jar
MD5: 56892d6f4d27019833fd53b7cc57ec86
SHA1: 330f2244e9030119ab3030fc3fededc86713d9cc
SHA256: 5557e235a8aa2f9766d5dc609d67948f2a8832c2d796cea9ef1d6cbe0b3b7eaf
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jna High Vendor jar package name jna Highest Vendor jar package name native Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest automatic-module-name com.sun.jna Medium Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-category jni Low Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor Manifest bundle-symbolicname com.sun.jna Medium Vendor Manifest Implementation-Vendor JNA Development Team High Vendor Manifest specification-vendor JNA Development Team Low Vendor pom artifactid jna Highest Vendor pom artifactid jna Low Vendor pom developer email mblaesing@doppel-helix.eu Low Vendor pom developer id twall Medium Vendor pom developer name Matthias Bläsing Medium Vendor pom developer name Timothy Wall Medium Vendor pom groupid net.java.dev.jna Highest Vendor pom name Java Native Access High Vendor pom url java-native-access/jna Highest Product file name jna High Product jar package name jna Highest Product jar package name library Highest Product jar package name native Highest Product jar package name sun Highest Product jar package name win32 Highest Product Manifest automatic-module-name com.sun.jna Medium Product Manifest bundle-activationpolicy lazy Low Product Manifest bundle-category jni Low Product Manifest Bundle-Name jna Medium Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product Manifest bundle-symbolicname com.sun.jna Medium Product Manifest Implementation-Title com.sun.jna High Product Manifest specification-title Java Native Access (JNA) Medium Product pom artifactid jna Highest Product pom developer email mblaesing@doppel-helix.eu Low Product pom developer id twall Low Product pom developer name Matthias Bläsing Low Product pom developer name Timothy Wall Low Product pom groupid net.java.dev.jna Highest Product pom name Java Native Access High Product pom url java-native-access/jna High Version file version 5.6.0 High Version Manifest Bundle-Version 5.6.0 High Version pom version 5.6.0 Highest
jna-5.6.0.jar: jnidispatch.dllFile Path: /home/andrii/.m2/repository/net/java/dev/jna/jna/5.6.0/jna-5.6.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dllMD5: e02979ecd43bcc9061eb2b494ab5af50SHA1: 3122ac0e751660f646c73b10c4f79685aa65c545SHA256: a66959bec2ef5af730198db9f3b3f7cab0d4ae70ce01bec02bf1d738e6d1ee7aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-5.6.0.jar: jnidispatch.dllFile Path: /home/andrii/.m2/repository/net/java/dev/jna/jna/5.6.0/jna-5.6.0.jar/com/sun/jna/win32-x86/jnidispatch.dllMD5: 28d895a3cb7e9a0b6a5ae5ed6a62b254SHA1: 703d8604a8d04d29c52c0ebcde1e86f3bc8ff824SHA256: 04c9a8ab43d1eb616b84d0686c8ae1d881ef03fe4f3aa26511e5b19d35ef16afReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-platform-5.6.0.jarDescription:
Java Native Access Platform License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/net/java/dev/jna/jna-platform/5.6.0/jna-platform-5.6.0.jar
MD5: 3c345206c4f2243e5d1d7caceb9243cd
SHA1: d18424ffb8bbfd036d71bcaab9b546858f2ef986
SHA256: 9ecea8bf2b1b39963939d18b70464eef60c508fed8820f9dcaba0c35518eabf7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jna-platform High Vendor jar package name jna Highest Vendor jar package name platform Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest automatic-module-name com.sun.jna.platform Medium Vendor Manifest bundle-category jni Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor Manifest bundle-symbolicname com.sun.jna.platform Medium Vendor Manifest Implementation-Vendor JNA Development Team High Vendor Manifest require-bundle com.sun.jna;bundle-version="5.6.0" Low Vendor Manifest specification-vendor JNA Development Team Low Vendor pom artifactid jna-platform Highest Vendor pom artifactid jna-platform Low Vendor pom developer email mblaesing@doppel-helix.eu Low Vendor pom developer id twall Medium Vendor pom developer name Matthias Bläsing Medium Vendor pom developer name Timothy Wall Medium Vendor pom groupid net.java.dev.jna Highest Vendor pom name Java Native Access Platform High Vendor pom url java-native-access/jna Highest Product file name jna-platform High Product jar package name jna Highest Product jar package name platform Highest Product jar package name sun Highest Product Manifest automatic-module-name com.sun.jna.platform Medium Product Manifest bundle-category jni Low Product Manifest Bundle-Name jna-platform Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product Manifest bundle-symbolicname com.sun.jna.platform Medium Product Manifest Implementation-Title com.sun.jna.platform High Product Manifest require-bundle com.sun.jna;bundle-version="5.6.0" Low Product Manifest specification-title Java Native Access (JNA) Medium Product pom artifactid jna-platform Highest Product pom developer email mblaesing@doppel-helix.eu Low Product pom developer id twall Low Product pom developer name Matthias Bläsing Low Product pom developer name Timothy Wall Low Product pom groupid net.java.dev.jna Highest Product pom name Java Native Access Platform High Product pom url java-native-access/jna High Version file version 5.6.0 High Version Manifest Bundle-Version 5.6.0 High Version pom version 5.6.0 Highest
joda-time-2.10.9.jarDescription:
Date and time library to replace JDK date handling License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/joda-time/joda-time/2.10.9/joda-time-2.10.9.jar
MD5: f5a8839f853ba5ba8c7637f4d092afe4
SHA1: 2227c292c0ee4f57205dbdc65fd57a94694050ec
SHA256: b36dd8c325b7afa19e92cf5879a9fe6780bad42fdc18f67c93cafe1fcf6375ae
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name joda-time High Vendor jar package name joda Highest Vendor jar package name time Highest Vendor Manifest automatic-module-name org.joda.time Medium Vendor Manifest bundle-docurl https://www.joda.org/joda-time/ Low Vendor Manifest bundle-symbolicname joda-time Medium Vendor Manifest extension-name joda-time Medium Vendor Manifest implementation-url https://www.joda.org/joda-time/ Low Vendor Manifest Implementation-Vendor Joda.org High Vendor Manifest Implementation-Vendor-Id org.joda Medium Vendor Manifest specification-vendor Joda.org Low Vendor pom artifactid joda-time Highest Vendor pom artifactid joda-time Low Vendor pom developer id broneill Medium Vendor pom developer id jodastephen Medium Vendor pom developer name Brian S O'Neill Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom groupid joda-time Highest Vendor pom name Joda-Time High Vendor pom organization name Joda.org High Vendor pom organization url https://www.joda.org Medium Vendor pom url https://www.joda.org/joda-time/ Highest Product file name joda-time High Product jar package name joda Highest Product jar package name time Highest Product Manifest automatic-module-name org.joda.time Medium Product Manifest bundle-docurl https://www.joda.org/joda-time/ Low Product Manifest Bundle-Name Joda-Time Medium Product Manifest bundle-symbolicname joda-time Medium Product Manifest extension-name joda-time Medium Product Manifest Implementation-Title org.joda.time High Product Manifest implementation-url https://www.joda.org/joda-time/ Low Product Manifest specification-title Joda-Time Medium Product pom artifactid joda-time Highest Product pom developer id broneill Low Product pom developer id jodastephen Low Product pom developer name Brian S O'Neill Low Product pom developer name Stephen Colebourne Low Product pom groupid joda-time Highest Product pom name Joda-Time High Product pom organization name Joda.org Low Product pom organization url https://www.joda.org Low Product pom url https://www.joda.org/joda-time/ Medium Version file version 2.10.9 High Version Manifest Bundle-Version 2.10.9 High Version Manifest Implementation-Version 2.10.9 High Version pom version 2.10.9 Highest
jose4j-0.4.2.jarDescription:
The jose.4.j library is a robust and easy to use open source implementation of JSON Web Token (JWT) and the JOSE specification suite (JWS, JWE, and JWK).
It is written in Java and relies solely on the JCA APIs for cryptography.
Please see https://bitbucket.org/b_c/jose4j/wiki/Home for more info, examples, etc..
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/bitbucket/b_c/jose4j/0.4.2/jose4j-0.4.2.jar
MD5: 552e25826e1ef81643908c3e7258cb64
SHA1: 8bdb6e177b782c955f3e0c1cab413340a9bd7eeb
SHA256: f81622e546fe76fe689f2a18fa872e7f554d5d37a305e614b5717c15f9bf53ad
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jose4j High Vendor jar package name jose4j Highest Vendor jar package name jose4j Low Vendor jar package name json Highest Vendor jar package name jwe Highest Vendor jar package name jwk Highest Vendor jar package name jws Highest Vendor jar package name jwt Highest Vendor jar package name use Highest Vendor pom artifactid jose4j Highest Vendor pom artifactid jose4j Low Vendor pom developer email brian.d.campbell@gmail.com Low Vendor pom developer name Brian Campbell Medium Vendor pom groupid org.bitbucket.b_c Highest Vendor pom name jose4j High Vendor pom url https://bitbucket.org/b_c/jose4j/ Highest Product file name jose4j High Product jar package name jose4j Highest Product jar package name json Highest Product jar package name jwe Highest Product jar package name jwk Highest Product jar package name jws Highest Product jar package name jwt Highest Product jar package name use Highest Product pom artifactid jose4j Highest Product pom developer email brian.d.campbell@gmail.com Low Product pom developer name Brian Campbell Low Product pom groupid org.bitbucket.b_c Highest Product pom name jose4j High Product pom url https://bitbucket.org/b_c/jose4j/ Medium Version file version 0.4.2 High Version pom version 0.4.2 Highest
json-smart-1.3.1.jarDescription:
JSON (JavaScript Object Notation) is a lightweight data-interchange format.
It is easy for humans to read and write. It is easy for machines to parse and generate.
It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition
- December 1999. JSON is a text format that is completely language independent but uses
conventions that are familiar to programmers of the C-family of languages, including C, C++, C#,
Java, JavaScript, Perl, Python, and many others.
These properties make JSON an ideal data-interchange language.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/net/minidev/json-smart/1.3.1/json-smart-1.3.1.jar
MD5: b4f09b247c03cc2d091502d5b1db1f7f
SHA1: 69b3835e96d282ec85fc2e1517b8164c45ed639e
SHA256: ac3689112788e042088755e63ecd1f689adfeb04d7fb1cfd244513f94f82522c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name json-smart High Vendor jar package name json Highest Vendor jar package name minidev Highest Vendor jar package name net Highest Vendor jar package name parser Highest Vendor Manifest bundle-docurl http://www.minidev.net/ Low Vendor Manifest bundle-symbolicname net.minidev.json-smart Medium Vendor pom artifactid json-smart Highest Vendor pom artifactid json-smart Low Vendor pom groupid net.minidev Highest Vendor pom name JSON Small and Fast Parser High Vendor pom parent-artifactid parent Low Product file name json-smart High Product jar package name json Highest Product jar package name minidev Highest Product jar package name net Highest Product jar package name parser Highest Product Manifest bundle-docurl http://www.minidev.net/ Low Product Manifest Bundle-Name json-smart Medium Product Manifest bundle-symbolicname net.minidev.json-smart Medium Product pom artifactid json-smart Highest Product pom groupid net.minidev Highest Product pom name JSON Small and Fast Parser High Product pom parent-artifactid parent Medium Version file version 1.3.1 High Version Manifest Bundle-Version 1.3.1 High Version pom version 1.3.1 Highest
pkg:maven/net.minidev/json-smart@1.3.1 (Confidence :High)cpe:2.3:a:ini-parser_project:ini-parser:1.3.1:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:json-smart_project:json-smart-v1:1.3.1:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2021-27568 suppress
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information. CWE-754 Improper Check for Unusual or Exceptional Conditions
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-31684 suppress
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request. CWE-787 Out-of-bounds Write
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
jsoup-1.8.3.jarDescription:
jsoup HTML parser License:
The MIT License: http://jsoup.org/license File Path: /home/andrii/.m2/repository/org/jsoup/jsoup/1.8.3/jsoup-1.8.3.jar
MD5: 80adb5b301ed840a4b6db97abc02a8b0
SHA1: 65fd012581ded67bc20945d85c32b4598c3a9cf1
SHA256: abeaf34795a4de70f72aed6de5966d2955ec7eb348eeb813324f23c999575473
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jsoup High Vendor jar package name jsoup Highest Vendor jar package name parser Highest Vendor Manifest bundle-docurl http://jsoup.org/ Low Vendor Manifest bundle-symbolicname org.jsoup Medium Vendor Manifest originally-created-by 1.8.0_25 (Oracle Corporation) Low Vendor pom artifactid jsoup Highest Vendor pom artifactid jsoup Low Vendor pom developer email jonathan@hedley.net Low Vendor pom developer id jhy Medium Vendor pom developer name Jonathan Hedley Medium Vendor pom groupid org.jsoup Highest Vendor pom name jsoup High Vendor pom organization name Jonathan Hedley High Vendor pom organization url http://jonathanhedley.com/ Medium Vendor pom url http://jsoup.org/ Highest Product file name jsoup High Product jar package name jsoup Highest Product jar package name parser Highest Product Manifest bundle-docurl http://jsoup.org/ Low Product Manifest Bundle-Name jsoup Medium Product Manifest bundle-symbolicname org.jsoup Medium Product Manifest originally-created-by 1.8.0_25 (Oracle Corporation) Low Product pom artifactid jsoup Highest Product pom developer email jonathan@hedley.net Low Product pom developer id jhy Low Product pom developer name Jonathan Hedley Low Product pom groupid org.jsoup Highest Product pom name jsoup High Product pom organization name Jonathan Hedley Low Product pom organization url http://jonathanhedley.com/ Low Product pom url http://jsoup.org/ Medium Version file version 1.8.3 High Version Manifest Bundle-Version 1.8.3 High Version pom version 1.8.3 Highest
CVE-2021-37714 suppress
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes. CWE-248 Uncaught Exception, CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-36033 suppress
jsoup is a Java HTML parser, built for HTML editing, cleaning, scraping, and cross-site scripting (XSS) safety. jsoup may incorrectly sanitize HTML including `javascript:` URL expressions, which could allow XSS attacks when a reader subsequently clicks that link. If the non-default `SafeList.preserveRelativeLinks` option is enabled, HTML including `javascript:` URLs that have been crafted with control characters will not be sanitized. If the site that this HTML is published on does not set a Content Security Policy, an XSS attack is then possible. This issue is patched in jsoup 1.15.3. Users should upgrade to this version. Additionally, as the unsanitized input may have been persisted, old content should be cleaned again using the updated version. To remediate this issue without immediately upgrading: - disable `SafeList.preserveRelativeLinks`, which will rewrite input URLs as absolute URLs - ensure an appropriate [Content Security Policy](https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP) is defined. (This should be used regardless of upgrading, as a defence-in-depth best practice.) CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-87 Improper Neutralization of Alternate XSS Syntax
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
jsr305-3.0.2.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name jsr305 High Vendor Manifest bundle-symbolicname org.jsr-305 Medium Vendor pom artifactid jsr305 Highest Vendor pom artifactid jsr305 Low Vendor pom groupid com.google.code.findbugs Highest Vendor pom name FindBugs-jsr305 High Vendor pom url http://findbugs.sourceforge.net/ Highest Product file name jsr305 High Product Manifest Bundle-Name FindBugs-jsr305 Medium Product Manifest bundle-symbolicname org.jsr-305 Medium Product pom artifactid jsr305 Highest Product pom groupid com.google.code.findbugs Highest Product pom name FindBugs-jsr305 High Product pom url http://findbugs.sourceforge.net/ Medium Version file version 3.0.2 High Version Manifest Bundle-Version 3.0.2 High Version pom version 3.0.2 Highest
jsr311-api-1.1.1.jarLicense:
CDDL License
: http://www.opensource.org/licenses/cddl1.php File Path: /home/andrii/.m2/repository/javax/ws/rs/jsr311-api/1.1.1/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
SHA256: ab1534b73b5fa055808e6598a5e73b599ccda28c3159c3c0908977809422ee4a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jsr311-api High Vendor hint analyzer vendor web services Medium Vendor jar package name javax Highest Vendor jar package name rs Highest Vendor jar package name ws Highest Vendor Manifest bundle-docurl http://www.sun.com/ Low Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium Vendor Manifest extension-name javax.ws.rs Medium Vendor Manifest specification-vendor Sun Microsystems, Inc. Low Vendor pom artifactid jsr311-api Highest Vendor pom artifactid jsr311-api Low Vendor pom groupid javax.ws.rs Highest Vendor pom name jsr311-api High Vendor pom organization name Sun Microsystems, Inc High Vendor pom organization url http://www.sun.com/ Medium Vendor pom url https://jsr311.dev.java.net Highest Product file name jsr311-api High Product hint analyzer product web services Medium Product jar package name javax Highest Product jar package name rs Highest Product jar package name ws Highest Product Manifest bundle-docurl http://www.sun.com/ Low Product Manifest Bundle-Name jsr311-api Medium Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium Product Manifest extension-name javax.ws.rs Medium Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium Product pom artifactid jsr311-api Highest Product pom groupid javax.ws.rs Highest Product pom name jsr311-api High Product pom organization name Sun Microsystems, Inc Low Product pom organization url http://www.sun.com/ Low Product pom url https://jsr311.dev.java.net Medium Version file version 1.1.1 High Version Manifest Bundle-Version 1.1.1 High Version Manifest specification-version 1.1.1 High Version pom version 1.1.1 Highest
jstyleparser-1.16-atlassian-1.jarDescription:
jStyleParser is a CSS parser written in Java. It has its own application interface that is designed to allow an efficient CSS processing in Java and mapping the values to the Java data types. It parses CSS 2.1 style sheets into structures that can be efficiently assigned to DOM elements. It is intended be the primary CSS parser for the CSSBox library. While handling errors, it is user agent conforming according to the CSS specification. License:
GNU Lesser General Public License 3.0: http://www.gnu.org/licenses/lgpl-3.0.txt File Path: /home/andrii/.m2/repository/net/sf/cssbox/jstyleparser/1.16-atlassian-1/jstyleparser-1.16-atlassian-1.jar
MD5: 1f49d4c825b32ac75c401994e1710864
SHA1: 8c7f7afa8282801cfd00619ca19d090b6f8ab338
SHA256: 70056e30b51fab433ab98bb6fe0271e784d540cb1b8446c9e78d9a0336810297
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jstyleparser High Vendor jar package name css Highest Vendor jar package name cz Low Vendor jar package name net Highest Vendor jar package name vutbr Low Vendor jar package name web Low Vendor pom artifactid jstyleparser Highest Vendor pom artifactid jstyleparser Low Vendor pom developer name Bert Frees Medium Vendor pom developer name Jan Švercl Medium Vendor pom developer name Karel Piwko Medium Vendor pom developer name Philip Borlin Medium Vendor pom developer name Radek Burget Medium Vendor pom developer name Ron Kuhnert Medium Vendor pom groupid net.sf.cssbox Highest Vendor pom name jStyleParser High Vendor pom url http://cssbox.sourceforge.net/jstyleparser Highest Product file name jstyleparser High Product jar package name css Highest Product jar package name css Low Product jar package name net Highest Product jar package name vutbr Low Product jar package name web Low Product pom artifactid jstyleparser Highest Product pom developer name Bert Frees Low Product pom developer name Jan Švercl Low Product pom developer name Karel Piwko Low Product pom developer name Philip Borlin Low Product pom developer name Radek Burget Low Product pom developer name Ron Kuhnert Low Product pom groupid net.sf.cssbox Highest Product pom name jStyleParser High Product pom url http://cssbox.sourceforge.net/jstyleparser Medium Version pom version 1.16-atlassian-1 Highest
jtds-1.3.1.jarDescription:
jTDS is an open source 100% pure Java (type 4) JDBC 3.0 driver
for Microsoft SQL Server (6.5, 7, 2000, 2005, 2008, 2012) and Sybase ASE
(10, 11, 12, 15). jTDS is based on FreeTDS and is currently the fastest
production-ready JDBC driver for SQL Server and Sybase. jTDS is 100% JDBC
3.0 compatible, supporting forward-only and scrollable/updateable ResultSets
and implementing all the DatabaseMetaData and ResultSetMetaData methods.
License:
LGPL: http://www.gnu.org/copyleft/lesser.html File Path: /home/andrii/.m2/repository/net/sourceforge/jtds/jtds/1.3.1/jtds-1.3.1.jar
MD5: a0fe47907babf3bdb555e0b6f9dedd24
SHA1: 1527f2fc2f040898625370a1687d902aa0743bcc
SHA256: aac05ebf5504c91b29420129b02dd878a86c52f8fa6eccf9235e0bfd7a60bef1
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jtds High Vendor jar package name jdbc Highest Vendor jar package name jtds Highest Vendor jar package name net Highest Vendor jar package name sourceforge Highest Vendor Manifest implementation-url http://jtds.sourceforge.net Low Vendor pom artifactid jtds Highest Vendor pom artifactid jtds Low Vendor pom developer email ickzon@users.sourceforge.net Low Vendor pom developer id momo Medium Vendor pom developer name Holger Rehn Medium Vendor pom groupid net.sourceforge.jtds Highest Vendor pom name jTDS High Vendor pom url http://jtds.sourceforge.net Highest Product file name jtds High Product jar package name jdbc Highest Product jar package name jtds Highest Product jar package name net Highest Product jar package name sourceforge Highest Product Manifest Implementation-Title jTDS JDBC Driver High Product Manifest implementation-url http://jtds.sourceforge.net Low Product Manifest specification-title JDBC Medium Product pom artifactid jtds Highest Product pom developer email ickzon@users.sourceforge.net Low Product pom developer id momo Low Product pom developer name Holger Rehn Low Product pom groupid net.sourceforge.jtds Highest Product pom name jTDS High Product pom url http://jtds.sourceforge.net Medium Version file version 1.3.1 High Version Manifest Implementation-Version 1.3.1 High Version pom version 1.3.1 Highest
jtidy-r8-20060801.jarDescription:
JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be
used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the
document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML.
License:
Java HTML Tidy License: http://svn.sourceforge.net/viewvc/*checkout*/jtidy/trunk/jtidy/LICENSE.txt?revision=95 File Path: /home/andrii/.m2/repository/org/hibernate/jtidy/r8-20060801/jtidy-r8-20060801.jar
MD5: 3c0739c6778e4d3a53e2348b3147c727
SHA1: 788e89775eeaa0f4e77742ec8336c75b7cff6146
SHA256: 35ed23ae123627f91e200e2efbf7964749b72d514225ab954e34d5cbfb2bc9c2
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jtidy-r8-20060801 High Vendor hint analyzer vendor redhat Highest Vendor jar package name parser Highest Vendor jar package name tidy Low Vendor jar package name w3c Low Vendor pom artifactid jtidy Highest Vendor pom artifactid jtidy Low Vendor pom developer email atripp AT users.sourceforge.net Low Vendor pom developer email fgiust AT users.sourceforge.net Low Vendor pom developer email garypeskin AT users.sourceforge.net Low Vendor pom developer email lempinen AT users.sourceforge.net Low Vendor pom developer email russgold AT users.sourceforge.net Low Vendor pom developer id atripp Medium Vendor pom developer id fgiust Medium Vendor pom developer id garypeskin Medium Vendor pom developer id lempinen Medium Vendor pom developer id russgold Medium Vendor pom developer name Andy Tripp Medium Vendor pom developer name Fabrizio Giustina Medium Vendor pom developer name Gary L Peskin Medium Vendor pom developer name Russell Gold Medium Vendor pom developer name Sami Lempinen Medium Vendor pom developer org Sourceforge Medium Vendor pom groupid jtidy Highest Vendor pom groupid org.hibernate Highest Vendor pom name JTidy High Vendor pom organization name sourceforge High Vendor pom organization url http://sourceforge.net Medium Vendor pom url http://jtidy.sourceforge.net Highest Product file name jtidy-r8-20060801 High Product hint analyzer product orm Highest Product jar package name parser Highest Product jar package name tidy Low Product pom artifactid jtidy Highest Product pom developer email atripp AT users.sourceforge.net Low Product pom developer email fgiust AT users.sourceforge.net Low Product pom developer email garypeskin AT users.sourceforge.net Low Product pom developer email lempinen AT users.sourceforge.net Low Product pom developer email russgold AT users.sourceforge.net Low Product pom developer id atripp Low Product pom developer id fgiust Low Product pom developer id garypeskin Low Product pom developer id lempinen Low Product pom developer id russgold Low Product pom developer name Andy Tripp Low Product pom developer name Fabrizio Giustina Low Product pom developer name Gary L Peskin Low Product pom developer name Russell Gold Low Product pom developer name Sami Lempinen Low Product pom developer org Sourceforge Low Product pom groupid jtidy Highest Product pom groupid org.hibernate Highest Product pom name JTidy High Product pom organization name sourceforge Low Product pom organization url http://sourceforge.net Low Product pom url http://jtidy.sourceforge.net Medium Version pom version r8-20060801 Highest
jul-to-slf4j-1.7.25.jarDescription:
JUL to SLF4J bridge File Path: /home/andrii/.m2/repository/org/slf4j/jul-to-slf4j/1.7.25/jul-to-slf4j-1.7.25.jarMD5: ab28124cb05fec600f2ffe37b94629e0SHA1: 0af5364cd6679bfffb114f0dec8a157aaa283b76SHA256: 416c5a0c145ad19526e108d44b6bf77b75412d47982cce6ce8d43abdbdbb0facReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name jul-to-slf4j High Vendor jar package name bridge Highest Vendor jar package name slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname jul.to.slf4j Medium Vendor pom artifactid jul-to-slf4j Highest Vendor pom artifactid jul-to-slf4j Low Vendor pom groupid org.slf4j Highest Vendor pom name JUL to SLF4J bridge High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name jul-to-slf4j High Product jar package name bridge Highest Product jar package name slf4j Highest Product Manifest Bundle-Name jul-to-slf4j Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname jul.to.slf4j Medium Product pom artifactid jul-to-slf4j Highest Product pom groupid org.slf4j Highest Product pom name JUL to SLF4J bridge High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 1.7.25 High Version Manifest Bundle-Version 1.7.25 High Version Manifest Implementation-Version 1.7.25 High Version pom version 1.7.25 Highest
lang-tag-1.4.4.jarDescription:
Java implementation of "Tags for Identifying Languages"
(RFC 5646).
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/nimbusds/lang-tag/1.4.4/lang-tag-1.4.4.jar
MD5: 4eac3f24cee18edaae2cdd8b87f25b73
SHA1: 1db9a709239ae473a69b5424c7e78d0b7108229d
SHA256: e49d2c694bb80c7036c177f2aabf53b7156061a68bd19dfd60e2bd370709e0c5
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lang-tag High Vendor jar package name langtag Highest Vendor jar package name nimbusds Highest Vendor Manifest build-date ${timestamp} Low Vendor Manifest build-number ${buildNumber} Low Vendor Manifest build-tag 1.4.4 Low Vendor Manifest bundle-docurl http://connect2id.com/ Low Vendor Manifest bundle-symbolicname lang-tag Medium Vendor Manifest implementation-url https://bitbucket.org/connect2id/nimbus-language-tags Low Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor pom artifactid lang-tag Highest Vendor pom artifactid lang-tag Low Vendor pom developer email vladimir@dzhuvinov.com Low Vendor pom developer id vdzhuvinov Medium Vendor pom developer name Vladimir Dzhuvinov Medium Vendor pom groupid com.nimbusds Highest Vendor pom name Nimbus LangTag High Vendor pom organization name Connect2id Ltd. High Vendor pom organization url http://connect2id.com/ Medium Vendor pom url https://bitbucket.org/connect2id/nimbus-language-tags Highest Product file name lang-tag High Product jar package name langtag Highest Product jar package name nimbusds Highest Product Manifest build-date ${timestamp} Low Product Manifest build-number ${buildNumber} Low Product Manifest build-tag 1.4.4 Low Product Manifest bundle-docurl http://connect2id.com/ Low Product Manifest Bundle-Name Nimbus LangTag Medium Product Manifest bundle-symbolicname lang-tag Medium Product Manifest Implementation-Title Nimbus LangTag High Product Manifest implementation-url https://bitbucket.org/connect2id/nimbus-language-tags Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Nimbus LangTag Medium Product pom artifactid lang-tag Highest Product pom developer email vladimir@dzhuvinov.com Low Product pom developer id vdzhuvinov Low Product pom developer name Vladimir Dzhuvinov Low Product pom groupid com.nimbusds Highest Product pom name Nimbus LangTag High Product pom organization name Connect2id Ltd. Low Product pom organization url http://connect2id.com/ Low Product pom url https://bitbucket.org/connect2id/nimbus-language-tags Medium Version file version 1.4.4 High Version Manifest build-tag 1.4.4 Low Version Manifest Bundle-Version 1.4.4 High Version Manifest Implementation-Version 1.4.4 High Version pom version 1.4.4 Highest
libthrift-0.9.0.jarDescription:
Thrift is a software framework for scalable cross-language services development. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/thrift/libthrift/0.9.0/libthrift-0.9.0.jar
MD5: c47774349b7b58c1ac957f5591c192ba
SHA1: 9ba8df332b5db95ce7f3b7a83e44d796c3d014d3
SHA256: f94e32da1aff791566002345f3913fce7d1f68e4019719d515f8dcaa1364f97d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name libthrift High Vendor jar package name apache Highest Vendor jar package name thrift Highest Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-symbolicname org.apache.thrift Medium Vendor pom artifactid libthrift Highest Vendor pom artifactid libthrift Low Vendor pom developer id aditya Medium Vendor pom developer id bmaurer Medium Vendor pom developer id bryanduxbury Medium Vendor pom developer id cpiro Medium Vendor pom developer id dreiss Medium Vendor pom developer id esteve Medium Vendor pom developer id geechorama Medium Vendor pom developer id jake Medium Vendor pom developer id jfarrell Medium Vendor pom developer id jwang Medium Vendor pom developer id kclark Medium Vendor pom developer id marck Medium Vendor pom developer id mcslee Medium Vendor pom developer id molinaro Medium Vendor pom developer id roger Medium Vendor pom developer id todd Medium Vendor pom developer name Aditya Agarwal Medium Vendor pom developer name Andrew McGeachie Medium Vendor pom developer name Anthony Molinaro Medium Vendor pom developer name Ben Maurer Medium Vendor pom developer name Bryan Duxbury Medium Vendor pom developer name Chris Piro Medium Vendor pom developer name David Reiss Medium Vendor pom developer name Esteve Fernandez Medium Vendor pom developer name Jake Farrell Medium Vendor pom developer name Jake Luciani Medium Vendor pom developer name James Wang Medium Vendor pom developer name Kevin Clark Medium Vendor pom developer name Marc Kwiatkowski Medium Vendor pom developer name Mark Slee Medium Vendor pom developer name Roger Meier Medium Vendor pom developer name Todd Lipcon Medium Vendor pom groupid org.apache.thrift Highest Vendor pom name Apache Thrift High Vendor pom url http://thrift.apache.org Highest Product file name libthrift High Product jar package name apache Highest Product jar package name thrift Highest Product Manifest bundle-activationpolicy lazy Low Product Manifest Bundle-Name Apache Thrift Medium Product Manifest bundle-symbolicname org.apache.thrift Medium Product pom artifactid libthrift Highest Product pom developer id aditya Low Product pom developer id bmaurer Low Product pom developer id bryanduxbury Low Product pom developer id cpiro Low Product pom developer id dreiss Low Product pom developer id esteve Low Product pom developer id geechorama Low Product pom developer id jake Low Product pom developer id jfarrell Low Product pom developer id jwang Low Product pom developer id kclark Low Product pom developer id marck Low Product pom developer id mcslee Low Product pom developer id molinaro Low Product pom developer id roger Low Product pom developer id todd Low Product pom developer name Aditya Agarwal Low Product pom developer name Andrew McGeachie Low Product pom developer name Anthony Molinaro Low Product pom developer name Ben Maurer Low Product pom developer name Bryan Duxbury Low Product pom developer name Chris Piro Low Product pom developer name David Reiss Low Product pom developer name Esteve Fernandez Low Product pom developer name Jake Farrell Low Product pom developer name Jake Luciani Low Product pom developer name James Wang Low Product pom developer name Kevin Clark Low Product pom developer name Marc Kwiatkowski Low Product pom developer name Mark Slee Low Product pom developer name Roger Meier Low Product pom developer name Todd Lipcon Low Product pom groupid org.apache.thrift Highest Product pom name Apache Thrift High Product pom url http://thrift.apache.org Medium Version file version 0.9.0 High Version Manifest Bundle-Version 0.9.0 High Version Manifest Implementation-Version 0.9.0 High Version pom version 0.9.0 Highest
CVE-2016-5397 suppress
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0. CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
CVE-2018-1320 suppress
Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete. CWE-295 Improper Certificate Validation
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-0205 suppress
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: HIGH (7.8) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:C CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2015-3254 suppress
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
licensing-api-2.21.4.jarFile Path: /home/andrii/.m2/repository/com/atlassian/upm/licensing-api/2.21.4/licensing-api-2.21.4.jarMD5: 5d1615367d83fb8a53f47ca81ea072a8SHA1: 1063b85c0bbebd567d9753da64c37a875c26f321SHA256: c44160ac62cc0e180d05b78ea5a8508605b29677840d5a0ce8f85eb337068541Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name licensing-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name upm Highest Vendor jar package name upm Low Vendor pom artifactid licensing-api Highest Vendor pom artifactid licensing-api Low Vendor pom groupid com.atlassian.upm Highest Vendor pom name Universal Plugin Manager - Licensing API High Vendor pom parent-artifactid licensing-parent Low Product file name licensing-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name license Low Product jar package name upm Highest Product jar package name upm Low Product pom artifactid licensing-api Highest Product pom groupid com.atlassian.upm Highest Product pom name Universal Plugin Manager - Licensing API High Product pom parent-artifactid licensing-parent Medium Version file version 2.21.4 High Version pom version 2.21.4 Highest
CVE-2018-20233 suppress
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: MEDIUM (5.5) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2018-5229 suppress
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2019-14999 suppress
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
log4j-1.2-api-2.13.3.jarDescription:
The Apache Log4j 1.x Compatibility API License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/logging/log4j/log4j-1.2-api/2.13.3/log4j-1.2-api-2.13.3.jar
MD5: b7ef2435eee943221f4539b506af1854
SHA1: 6060aef755239b82bbc84bd92eb80ff9f4e48dd7
SHA256: 86cc75ae4b9f7c643412dda3bc2de05af6dfa760b80ab7ba96dc4ce505f8a05b
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name log4j-1.2-api-2.13.3 High Vendor jar package name apache Highest Vendor jar package name log4j Highest Vendor Manifest automatic-module-name org.apache.log4j Medium Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.1.2-api Medium Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-1.2-api/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-1.2-api Highest Vendor pom artifactid log4j-1.2-api Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j 1.x Compatibility API High Vendor pom parent-artifactid log4j Low Product file name log4j-1.2-api-2.13.3 High Product jar package name apache Highest Product jar package name filter Highest Product jar package name log4j Highest Product Manifest automatic-module-name org.apache.log4j Medium Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache Log4j 1.x Compatibility API Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.1.2-api Medium Product Manifest Implementation-Title Apache Log4j 1.x Compatibility API High Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-1.2-api/ Low Product Manifest log4jreleasekey B3D8E1BA Low Product Manifest log4jreleasemanager Ralph Goers Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Log4j 1.x Compatibility API Medium Product pom artifactid log4j-1.2-api Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j 1.x Compatibility API High Product pom parent-artifactid log4j Medium Version Manifest Bundle-Version 2.13.3 High Version Manifest Implementation-Version 2.13.3 High Version Manifest log4jreleaseversion 2.13.3 Medium Version pom version 2.13.3 Highest
CVE-2021-44228 suppress
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects. CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: CRITICAL (10.0) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-45046 suppress
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (5.1) Vector: /AV:N/AC:H/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.0) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-44832 suppress
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2. CWE-20 Improper Input Validation
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: MEDIUM (6.6) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-45105 suppress
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1. CWE-20 Improper Input Validation, CWE-674 Uncontrolled Recursion
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
log4j-1.2.7.jarFile Path: /home/andrii/.m2/repository/log4j/log4j/1.2.7/log4j-1.2.7.jarMD5: 8631619c6becebaac70862ac9c36af44SHA1: 5b8a2a161048eb7481407ef0a81c2d90489ed412SHA256: aa04b7d49d0c4c3c2d4605a3dda1796c440a1fdf1ea99d6fe2931ca3986dfd35Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name log4j High Vendor jar package name apache Highest Vendor jar package name log4j Highest Vendor manifest: org/apache/log4j/ Implementation-Vendor "Apache Software Foundation" Medium Vendor pom artifactid log4j Highest Vendor pom artifactid log4j Low Vendor pom groupid log4j Highest Product file name log4j High Product jar package name log4j Highest Product manifest: org/apache/log4j/ Implementation-Title log4j Medium Product pom artifactid log4j Highest Product pom groupid log4j Highest Version file version 1.2.7 High Version manifest: org/apache/log4j/ Implementation-Version 1.2.7 Medium Version pom version 1.2.7 Highest
CVE-2019-17571 suppress
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-9493 suppress
A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-23305 suppress
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or headers of an application that are logged allowing unintended SQL queries to be executed. Note this issue only affects Log4j 1.x when specifically configured to use the JDBCAppender, which is not the default. Beginning in version 2.0-beta8, the JDBCAppender was re-introduced with proper support for parameterized SQL queries and further customization over the columns written to in logs. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-23302 suppress
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-23307 suppress
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-4104 (OSSINDEX) suppress
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:H/Au:/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:log4j:log4j:1.2.7:*:*:*:*:*:*:* log4j-api-2.13.3.jarDescription:
The Apache Log4j API License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/logging/log4j/log4j-api/2.13.3/log4j-api-2.13.3.jar
MD5: 236b9969df6b394e88283a9f813b9b95
SHA1: ec1508160b93d274b1add34419b897bae84c6ca9
SHA256: 2b4b1965c9dce7f3732a0fbf5c8493199c1e6bf8cf65c3e235b57d98da5f36af
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name log4j-api High Vendor jar package name apache Highest Vendor jar package name log4j Highest Vendor jar package name logging Highest Vendor jar package name org Highest Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-api/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-api Highest Vendor pom artifactid log4j-api Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j API High Vendor pom parent-artifactid log4j Low Product file name log4j-api High Product jar package name apache Highest Product jar package name log4j Highest Product jar package name logging Highest Product jar package name org Highest Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache Log4j API Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Product Manifest Implementation-Title Apache Log4j API High Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-api/ Low Product Manifest log4jreleasekey B3D8E1BA Low Product Manifest log4jreleasemanager Ralph Goers Low Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Log4j API Medium Product pom artifactid log4j-api Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j API High Product pom parent-artifactid log4j Medium Version file version 2.13.3 High Version Manifest Bundle-Version 2.13.3 High Version Manifest Implementation-Version 2.13.3 High Version Manifest log4jreleaseversion 2.13.3 Medium Version pom version 2.13.3 Highest
lozenge.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/lozenge.jsMD5: 5b301fcc9786b05d42ed79fe10d4e8e9SHA1: f0d9957f52d6d32222f35a714491a5f5a4b77985SHA256: 5d74e303c271e1c50ecd7e729becb736f957686efecc7a91de2a61c91b77321eReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
lucene-analyzers-common-4.4.0-atlassian-4.jarDescription:
Additional Analyzers License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-analyzers-common/4.4.0-atlassian-4/lucene-analyzers-common-4.4.0-atlassian-4.jar
MD5: 9facfb5520ff5d48976a78a1fd3b8904
SHA1: 629204cbcbd80281b82fa3407c51fe0eb5e72979
SHA256: 8045e575e408163ad253033ad71daf0c3d362d256abf0e4a0e40d222603236f4
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name lucene-analyzers-common High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor Manifest bundle-symbolicname org.apache.lucene.analyzers-common Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-analyzers-common Highest Vendor pom artifactid lucene-analyzers-common Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Common Analyzers High Vendor pom parent-artifactid lucene-analyzers-parent Low Product file name lucene-analyzers-common High Product jar package name apache Highest Product jar package name lucene Highest Product Manifest Bundle-Name Lucene Common Analyzers Medium Product Manifest bundle-symbolicname org.apache.lucene.analyzers-common Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Common Analyzers Medium Product pom artifactid lucene-analyzers-common Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Common Analyzers High Product pom parent-artifactid lucene-analyzers-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-analyzers-kuromoji-4.4.0-atlassian-4.jarDescription:
Lucene Kuromoji Japanese Morphological Analyzer
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-analyzers-kuromoji/4.4.0-atlassian-4/lucene-analyzers-kuromoji-4.4.0-atlassian-4.jar
MD5: a7fc5d4797c3994853a8f13a33d0d50d
SHA1: 2cceb3f27d02e49a769e90fa003b1c425d3c2199
SHA256: a9ec93473b7f72e27cd4f8bf89db10fce6732fcb9f58380ac52da0d809db2d91
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lucene-analyzers-kuromoji High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor Manifest bundle-symbolicname org.apache.lucene.analyzers-kuromoji Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-analyzers-kuromoji Highest Vendor pom artifactid lucene-analyzers-kuromoji Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Kuromoji Japanese Morphological Analyzer High Vendor pom parent-artifactid lucene-analyzers-parent Low Product file name lucene-analyzers-kuromoji High Product jar package name apache Highest Product jar package name lucene Highest Product Manifest Bundle-Name Lucene Kuromoji Japanese Morphological Analyzer Medium Product Manifest bundle-symbolicname org.apache.lucene.analyzers-kuromoji Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Kuromoji Japanese Morphological Analyzer Medium Product pom artifactid lucene-analyzers-kuromoji Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Kuromoji Japanese Morphological Analyzer High Product pom parent-artifactid lucene-analyzers-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-analyzers-stempel-4.4.0-atlassian-4.jarDescription:
Stempel Analyzer License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-analyzers-stempel/4.4.0-atlassian-4/lucene-analyzers-stempel-4.4.0-atlassian-4.jar
MD5: 64ad16fc5b57b0ad02a35b3ec2fbbef6
SHA1: e91258abf9416608c2ad96dcaf34f03944605e13
SHA256: 8383f6649a7561acaa8ddf162a1ce155968e9303fa6a23d5a0b6d70d514125ee
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lucene-analyzers-stempel High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor jar package name stempel Highest Vendor Manifest bundle-symbolicname org.apache.lucene.analyzers-stempel Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-analyzers-stempel Highest Vendor pom artifactid lucene-analyzers-stempel Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Stempel Analyzer High Vendor pom parent-artifactid lucene-analyzers-parent Low Product file name lucene-analyzers-stempel High Product jar package name apache Highest Product jar package name lucene Highest Product jar package name stempel Highest Product Manifest Bundle-Name Lucene Stempel Analyzer Medium Product Manifest bundle-symbolicname org.apache.lucene.analyzers-stempel Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Stempel Analyzer Medium Product pom artifactid lucene-analyzers-stempel Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Stempel Analyzer High Product pom parent-artifactid lucene-analyzers-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-core-4.4.0-atlassian-4.jarDescription:
Apache Lucene Java Core License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-core/4.4.0-atlassian-4/lucene-core-4.4.0-atlassian-4.jar
MD5: da5424f9177346bb36be35532e76f134
SHA1: 14a15eaa24c1b29db1e7d61c93e84ba96d6c3415
SHA256: 1bda1c523f4cc3466baa5bad4b3094c1c8002e9448fed866df36ca07b98bdb86
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name lucene-core High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor Manifest bundle-symbolicname org.apache.lucene.core Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-core Highest Vendor pom artifactid lucene-core Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Core High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-core High Product jar package name apache Highest Product jar package name lucene Highest Product Manifest Bundle-Name Lucene Core Medium Product Manifest bundle-symbolicname org.apache.lucene.core Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Core Medium Product pom artifactid lucene-core Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Core High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-highlighter-4.4.0-atlassian-4.jarDescription:
This is the highlighter for apache lucene java
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-highlighter/4.4.0-atlassian-4/lucene-highlighter-4.4.0-atlassian-4.jar
MD5: 4fce411e57a5dfcbc4a19225d370aaca
SHA1: 7252546dea8644a2737a26c680a75e1aceb1ff61
SHA256: d4eb6785504c023817a6239aef88d851900f01a534a0e8e41735dce3dd9809e7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lucene-highlighter High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor Manifest bundle-symbolicname org.apache.lucene.highlighter Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-highlighter Highest Vendor pom artifactid lucene-highlighter Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Highlighter High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-highlighter High Product jar package name apache Highest Product jar package name lucene Highest Product Manifest Bundle-Name Lucene Highlighter Medium Product Manifest bundle-symbolicname org.apache.lucene.highlighter Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Highlighter Medium Product pom artifactid lucene-highlighter Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Highlighter High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-memory-4.4.0-atlassian-4.jarDescription:
High-performance single-document index to compare against Query
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-memory/4.4.0-atlassian-4/lucene-memory-4.4.0-atlassian-4.jar
MD5: 982928883d9c995649d4c7b6cc3822a3
SHA1: ee0f3d640b7219c322db1b8acb4a20d08b29e593
SHA256: 293d2c9e23694a16f490858de6315d70258d128ef4cfebf192f8bbc459f2c91d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lucene-memory High Vendor jar package name apache Highest Vendor jar package name index Highest Vendor jar package name lucene Highest Vendor jar package name memory Highest Vendor Manifest bundle-symbolicname org.apache.lucene.memory Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-memory Highest Vendor pom artifactid lucene-memory Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Memory High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-memory High Product jar package name apache Highest Product jar package name index Highest Product jar package name lucene Highest Product jar package name memory Highest Product Manifest Bundle-Name Lucene Memory Medium Product Manifest bundle-symbolicname org.apache.lucene.memory Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Memory Medium Product pom artifactid lucene-memory Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Memory High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-misc-4.4.0-atlassian-4.jarDescription:
Miscellaneous Lucene extensions License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-misc/4.4.0-atlassian-4/lucene-misc-4.4.0-atlassian-4.jar
MD5: 8ebadb813f3dd150f983b9cbe1f20bf5
SHA1: fa59e15d1db74bc5341280d3e1654a8631f1fda2
SHA256: dcab33a9fe71a2e64349299ee7c01eed6c727e698b1c13a5e61908dd48d07964
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lucene-misc High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor jar package name misc Highest Vendor Manifest bundle-symbolicname org.apache.lucene.misc Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-misc Highest Vendor pom artifactid lucene-misc Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Miscellaneous High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-misc High Product jar package name apache Highest Product jar package name lucene Highest Product jar package name misc Highest Product Manifest Bundle-Name Lucene Miscellaneous Medium Product Manifest bundle-symbolicname org.apache.lucene.misc Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Miscellaneous Medium Product pom artifactid lucene-misc Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Miscellaneous High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-queries-4.4.0-atlassian-4.jarDescription:
Lucene Queries Module License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-queries/4.4.0-atlassian-4/lucene-queries-4.4.0-atlassian-4.jar
MD5: 9a97168a0bdcf47dfb5b5820568bec46
SHA1: eab4d3870874b93ed9457c7b8d26322fe8acd1c7
SHA256: 50447ccd4c5c389ef942351a1873858725cc3114cef5cd5fa55a390f8b5da559
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name lucene-queries High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor jar package name queries Highest Vendor Manifest bundle-symbolicname org.apache.lucene.queries Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-queries Highest Vendor pom artifactid lucene-queries Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Queries High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-queries High Product jar package name apache Highest Product jar package name lucene Highest Product jar package name queries Highest Product Manifest Bundle-Name Lucene Queries Medium Product Manifest bundle-symbolicname org.apache.lucene.queries Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Queries Medium Product pom artifactid lucene-queries Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Queries High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-queryparser-4.4.0-atlassian-4.jarDescription:
Lucene QueryParsers module License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-queryparser/4.4.0-atlassian-4/lucene-queryparser-4.4.0-atlassian-4.jar
MD5: 58d9adbabedaee8c29ba51e177b6d9dc
SHA1: b99af1ebe794c199abcb1759dc210473ba2e2809
SHA256: 4ae4897d25d3edc4be8df252581be44abc285b2b53164070ce73f8aad4c1fa95
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name lucene-queryparser High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor jar package name queryparser Highest Vendor Manifest bundle-symbolicname org.apache.lucene.queryparser Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-queryparser Highest Vendor pom artifactid lucene-queryparser Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene QueryParsers High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-queryparser High Product jar package name apache Highest Product jar package name lucene Highest Product jar package name queryparser Highest Product Manifest Bundle-Name Lucene QueryParsers Medium Product Manifest bundle-symbolicname org.apache.lucene.queryparser Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene QueryParsers Medium Product pom artifactid lucene-queryparser Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene QueryParsers High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-sandbox-4.4.0-atlassian-4.jarDescription:
Lucene Sandbox License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/lucene/lucene-sandbox/4.4.0-atlassian-4/lucene-sandbox-4.4.0-atlassian-4.jar
MD5: db61c75fd04a96a8ed6e5b9a2de8dab7
SHA1: 3eaa2be6fa5e82677a6f2e47915be316a9f64092
SHA256: ab7ac9e01f577e440756e5ce561a95add6d0926baee846a3111a99c640f297b9
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name lucene-sandbox High Vendor jar package name apache Highest Vendor jar package name lucene Highest Vendor jar package name sandbox Highest Vendor Manifest bundle-symbolicname org.apache.lucene.sandbox Medium Vendor Manifest extension-name org.apache.lucene Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid lucene-sandbox Highest Vendor pom artifactid lucene-sandbox Low Vendor pom groupid org.apache.lucene Highest Vendor pom name Lucene Sandbox High Vendor pom parent-artifactid lucene-parent Low Product file name lucene-sandbox High Product jar package name apache Highest Product jar package name lucene Highest Product jar package name sandbox Highest Product Manifest Bundle-Name Lucene Sandbox Medium Product Manifest bundle-symbolicname org.apache.lucene.sandbox Medium Product Manifest extension-name org.apache.lucene Medium Product Manifest Implementation-Title org.apache.lucene High Product Manifest specification-title Lucene Sandbox Medium Product pom artifactid lucene-sandbox Highest Product pom groupid org.apache.lucene Highest Product pom name Lucene Sandbox High Product pom parent-artifactid lucene-parent Medium Version pom version 4.4.0-atlassian-4 Highest
lucene-upgrader-1.0-lucene36.jarFile Path: /home/andrii/.m2/repository/com/atlassian/bonnie/lucene-upgrader/1.0/lucene-upgrader-1.0-lucene36.jarMD5: bce5a43415951f91db0504878262506cSHA1: df318e96879f0d3f4e408557ab30f2c0ef21205cSHA256: 9fddbf4ec9867acf7573df836e99275d639dc0b2425bee6cf94835508a539c0cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name lucene-upgrader High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name bonnie Highest Vendor jar package name lucene36 Low Vendor jar package name upgrader Highest Vendor pom artifactid lucene-upgrader Highest Vendor pom artifactid lucene-upgrader Low Vendor pom groupid com.atlassian.bonnie Highest Vendor pom name lucene-upgrader High Vendor pom parent-artifactid atlassian-closedsource-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name lucene-upgrader High Product jar package name atlassian Highest Product jar package name bonnie Highest Product jar package name lucene36 Low Product jar package name upgrader Highest Product pom artifactid lucene-upgrader Highest Product pom groupid com.atlassian.bonnie Highest Product pom name lucene-upgrader High Product pom parent-artifactid atlassian-closedsource-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.0 High Version pom parent-version 1.0 Low Version pom version 1.0 Highest
management-api-3.0.0-b012.jarDescription:
GlassFish Common APIs License:
CDDL+GPL: https://glassfish.dev.java.net/public/CDDL+GPL.html File Path: /home/andrii/.m2/repository/org/glassfish/external/management-api/3.0.0-b012/management-api-3.0.0-b012.jar
MD5: 428636427bb6d92484320a9565f67394
SHA1: 707686d845faede060b79bdf018a25a469a611b4
SHA256: e114d4f4cf4261ab76d144c49d6ee1d75ddcfbb7c195260d1a782ebe0c34cb87
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name management-api High Vendor jar package name external Highest Vendor jar package name glassfish Highest Vendor Manifest bundle-symbolicname management-api Medium Vendor pom artifactid management-api Highest Vendor pom artifactid management-api Low Vendor pom groupid org.glassfish.external Highest Vendor pom name management-api High Vendor pom organization name Sun Microsystems High Vendor pom organization url http://www.sun.com Medium Vendor pom url http://kenai.com/hg/gmbal~gf_common Highest Product file name management-api High Product jar package name external Highest Product jar package name glassfish Highest Product Manifest Bundle-Name management-api Medium Product Manifest bundle-symbolicname management-api Medium Product pom artifactid management-api Highest Product pom groupid org.glassfish.external Highest Product pom name management-api High Product pom organization name Sun Microsystems Low Product pom organization url http://www.sun.com Low Product pom url http://kenai.com/hg/gmbal~gf_common Medium Version pom version 3.0.0-b012 Highest
maven-aether-provider-3.0.jarDescription:
This module provides extensions to Aether for utilizing the Maven POM and Maven metadata.
File Path: /home/andrii/.m2/repository/org/apache/maven/maven-aether-provider/3.0/maven-aether-provider-3.0.jarMD5: 859740166efa8857d7a598b05249ac24SHA1: 419f5eb63cf743a1a0f2a80ea5dde37fd1a4fec0SHA256: 1205a1f229999170dcadcfb885a278ad0bc2295540a251f4c438f887ead7bbd9Referenced In Project/Scope: space-comments:runtime
Evidence Type Source Name Value Confidence Vendor file name maven-aether-provider High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-aether-provider Highest Vendor pom artifactid maven-aether-provider Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Aether Provider High Vendor pom parent-artifactid maven Low Product file name maven-aether-provider High Product jar package name apache Highest Product jar package name maven Highest Product Manifest Implementation-Title Maven Aether Provider High Product Manifest specification-title Maven Aether Provider Medium Product pom artifactid maven-aether-provider Highest Product pom groupid org.apache.maven Highest Product pom name Maven Aether Provider High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-artifact-3.0.jarFile Path: /home/andrii/.m2/repository/org/apache/maven/maven-artifact/3.0/maven-artifact-3.0.jarMD5: 43e506190356b85edccfdc7db1f630d8SHA1: c29cfa43ce2ba09975a07c40d7241655d7c2fa29SHA256: 759079b9cf0cddae5ba06c96fd72347d82d0bc1d903c95d398c96522b139e470Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-artifact High Vendor jar package name apache Highest Vendor jar package name artifact Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-artifact Highest Vendor pom artifactid maven-artifact Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Artifact High Vendor pom parent-artifactid maven Low Product file name maven-artifact High Product jar package name apache Highest Product jar package name artifact Highest Product jar package name maven Highest Product Manifest Implementation-Title Maven Artifact High Product Manifest specification-title Maven Artifact Medium Product pom artifactid maven-artifact Highest Product pom groupid org.apache.maven Highest Product pom name Maven Artifact High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-artifact-transfer-0.13.1.jarDescription:
An API to install, deploy and resolving artifacts with Maven 3 File Path: /home/andrii/.m2/repository/org/apache/maven/shared/maven-artifact-transfer/0.13.1/maven-artifact-transfer-0.13.1.jarMD5: 5a73136d65cfc2dd8af0fd365dbda4fbSHA1: 9f6d2088ae64dd926b8ec445afdb7e148eb08060SHA256: 1ac88accde99ed71e65253bd130868c0e654f940f01ade073b895eb2f817cf06Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-artifact-transfer High Vendor jar package name apache Highest Vendor jar package name artifact Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor jar package name transfer Highest Vendor Manifest automatic-module-name org.apache.maven.shared.artifact.transfer Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-artifact-transfer Highest Vendor pom artifactid maven-artifact-transfer Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Artifact Transfer High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-artifact-transfer High Product jar package name apache Highest Product jar package name artifact Highest Product jar package name maven Highest Product jar package name shared Highest Product jar package name transfer Highest Product Manifest automatic-module-name org.apache.maven.shared.artifact.transfer Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Artifact Transfer High Product Manifest specification-title Apache Maven Artifact Transfer Medium Product pom artifactid maven-artifact-transfer Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Artifact Transfer High Product pom parent-artifactid maven-shared-components Medium Version file version 0.13.1 High Version Manifest Implementation-Version 0.13.1 High Version pom parent-version 0.13.1 Low Version pom version 0.13.1 Highest
maven-common-artifact-filters-3.1.0.jarDescription:
A collection of ready-made filters to control inclusion/exclusion of artifacts during dependency resolution. File Path: /home/andrii/.m2/repository/org/apache/maven/shared/maven-common-artifact-filters/3.1.0/maven-common-artifact-filters-3.1.0.jarMD5: fcd2e81ecc9836ba892333a299a9cd2eSHA1: 7d1eda9af6db77618766f31cb1971baed2ca3fa3SHA256: 82a584c58bd6a1b13861e2d4cc194b5afc09ca0adad9fda741f16337dcda2e96Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-common-artifact-filters High Vendor jar package name apache Highest Vendor jar package name artifact Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest implementation-url https://maven.apache.org/shared/maven-common-artifact-filters/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.shared Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-common-artifact-filters Highest Vendor pom artifactid maven-common-artifact-filters Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Common Artifact Filters High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-common-artifact-filters High Product jar package name apache Highest Product jar package name artifact Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest Implementation-Title Apache Maven Common Artifact Filters High Product Manifest implementation-url https://maven.apache.org/shared/maven-common-artifact-filters/ Low Product Manifest specification-title Apache Maven Common Artifact Filters Medium Product pom artifactid maven-common-artifact-filters Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Common Artifact Filters High Product pom parent-artifactid maven-shared-components Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
maven-core-3.0.jarFile Path: /home/andrii/.m2/repository/org/apache/maven/maven-core/3.0/maven-core-3.0.jarMD5: 9bd377874764a4fad7209021abfe7cf7SHA1: 73728ce32c9016c8bd05584301fa3ba3a6f5d20aSHA256: ba03294ee53e7ba31838e4950f280d033c7744c6c7b31253afc75aa351fbd989Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-core High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-core Highest Vendor pom artifactid maven-core Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Core High Vendor pom parent-artifactid maven Low Product file name maven-core High Product jar package name apache Highest Product jar package name maven Highest Product Manifest Implementation-Title Maven Core High Product Manifest specification-title Maven Core Medium Product pom artifactid maven-core Highest Product pom groupid org.apache.maven Highest Product pom name Maven Core High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
CVE-2021-26291 suppress
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html CWE-346 Origin Validation Error
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N References:
Vulnerable Software & Versions: (show all )
maven-dependency-tree-3.2.0.jarDescription:
A tree-based API for resolution of Maven project dependencies File Path: /home/andrii/.m2/repository/org/apache/maven/shared/maven-dependency-tree/3.2.0/maven-dependency-tree-3.2.0.jarMD5: 8ba689823847f668283077c69726d0a1SHA1: dc1dcdfbfbcca93ab165880538badd3d748bf59dSHA256: 03d3102672863761c2a39da09c444cc7dea74cc4a9efa2107f8f0bfd2519d330Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-dependency-tree High Vendor jar package name apache Highest Vendor jar package name dependency Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-dependency-tree Highest Vendor pom artifactid maven-dependency-tree Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Dependency Tree High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-dependency-tree High Product jar package name apache Highest Product jar package name dependency Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Dependency Tree High Product Manifest specification-title Apache Maven Dependency Tree Medium Product pom artifactid maven-dependency-tree Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Dependency Tree High Product pom parent-artifactid maven-shared-components Medium Version file version 3.2.0 High Version Manifest Implementation-Version 3.2.0 High Version pom parent-version 3.2.0 Low Version pom version 3.2.0 Highest
maven-model-3.0.jarDescription:
Maven Model File Path: /home/andrii/.m2/repository/org/apache/maven/maven-model/3.0/maven-model-3.0.jarMD5: 562636665b6ac87297513246c5bdccd2SHA1: 24ce598c94a78341c42556fe9192dad6a2822405SHA256: 27e426d73f8662b47f60df0e43439b3dec2909c42b89175a6e4431dfed3edafdReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-model High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name model Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-model Highest Vendor pom artifactid maven-model Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Model High Vendor pom parent-artifactid maven Low Product file name maven-model High Product jar package name apache Highest Product jar package name maven Highest Product jar package name model Highest Product Manifest Implementation-Title Maven Model High Product Manifest specification-title Maven Model Medium Product pom artifactid maven-model Highest Product pom groupid org.apache.maven Highest Product pom name Maven Model High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-model-builder-3.0.jarFile Path: /home/andrii/.m2/repository/org/apache/maven/maven-model-builder/3.0/maven-model-builder-3.0.jarMD5: b995b6ca151d6d74f5a64047807e6318SHA1: bedc161a3b07a4bcd175b9428cdf18725d292b37SHA256: 1c98a4ec9eb0cb86ecf01710aa75c0346ee3f96edc6edeabcb21ed984120e154Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-model-builder High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name model Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-model-builder Highest Vendor pom artifactid maven-model-builder Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Model Builder High Vendor pom parent-artifactid maven Low Product file name maven-model-builder High Product jar package name apache Highest Product jar package name maven Highest Product jar package name model Highest Product Manifest Implementation-Title Maven Model Builder High Product Manifest specification-title Maven Model Builder Medium Product pom artifactid maven-model-builder Highest Product pom groupid org.apache.maven Highest Product pom name Maven Model Builder High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-plugin-api-3.0.jarFile Path: /home/andrii/.m2/repository/org/apache/maven/maven-plugin-api/3.0/maven-plugin-api-3.0.jarMD5: 1d67a37a5822b12abc55e5133e47ca0eSHA1: 98f886f59bb0e69f8e86cdc082e69f2f4c13d648SHA256: f5ecc6eaa4a32ee0c115d31525f588f491b2cc75fdeb4ed3c0c662c12ac0c32fReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-plugin-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugin Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-plugin-api Highest Vendor pom artifactid maven-plugin-api Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Plugin API High Vendor pom parent-artifactid maven Low Product file name maven-plugin-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugin Highest Product Manifest Implementation-Title Maven Plugin API High Product Manifest specification-title Maven Plugin API Medium Product pom artifactid maven-plugin-api Highest Product pom groupid org.apache.maven Highest Product pom name Maven Plugin API High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-reporting-api-3.1.1.jarDescription:
API to manage report generation. File Path: /home/andrii/.m2/repository/org/apache/maven/reporting/maven-reporting-api/3.1.1/maven-reporting-api-3.1.1.jarMD5: 1e1e0b2f189c861995e33a2a746501bbSHA1: 74ca00a13e46d065071cdf6376d7d231e0208916SHA256: 25be6603c97d28fa3dcd122073054271c8fcaf667d220dce7a26a61a6f3cffd1Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-reporting-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name reporting Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-reporting-api Highest Vendor pom artifactid maven-reporting-api Low Vendor pom developer email vincent.siveton@gmail.com Low Vendor pom developer id vsiveton Medium Vendor pom developer name Vincent Siveton Medium Vendor pom groupid org.apache.maven.reporting Highest Vendor pom name Apache Maven Reporting API High Vendor pom parent-artifactid maven-shared-components Low Vendor pom parent-groupid org.apache.maven.shared Medium Product file name maven-reporting-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name reporting Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Reporting API High Product Manifest specification-title Apache Maven Reporting API Medium Product pom artifactid maven-reporting-api Highest Product pom developer email vincent.siveton@gmail.com Low Product pom developer id vsiveton Low Product pom developer name Vincent Siveton Low Product pom groupid org.apache.maven.reporting Highest Product pom name Apache Maven Reporting API High Product pom parent-artifactid maven-shared-components Medium Product pom parent-groupid org.apache.maven.shared Medium Version file version 3.1.1 High Version Manifest Implementation-Version 3.1.1 High Version pom parent-version 3.1.1 Low Version pom version 3.1.1 Highest
maven-repository-metadata-3.0.jarDescription:
Per-directory repository metadata. File Path: /home/andrii/.m2/repository/org/apache/maven/maven-repository-metadata/3.0/maven-repository-metadata-3.0.jarMD5: 5a8cee4b67ea39a141b9579323b70e27SHA1: e3c41f7565b1e189ff7a312796b9d2c470c09a8bSHA256: c938e4d8cdf0674496749a87e6d3b29aa41b1b35a39898a1ade2bc9eae214c17Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-repository-metadata High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name repository Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-repository-metadata Highest Vendor pom artifactid maven-repository-metadata Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Repository Metadata Model High Vendor pom parent-artifactid maven Low Product file name maven-repository-metadata High Product jar package name apache Highest Product jar package name maven Highest Product jar package name repository Highest Product Manifest Implementation-Title Maven Repository Metadata Model High Product Manifest specification-title Maven Repository Metadata Model Medium Product pom artifactid maven-repository-metadata Highest Product pom groupid org.apache.maven Highest Product pom name Maven Repository Metadata Model High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-settings-3.0.jarDescription:
Maven Settings File Path: /home/andrii/.m2/repository/org/apache/maven/maven-settings/3.0/maven-settings-3.0.jarMD5: 1ae2f464cfe3c9ba4bbfdfd3255b6ac7SHA1: 8ee129adae535dd610f2dc952fddce68ac42fd86SHA256: 3b1a46b4bc26a0176acaf99312ff2f3a631faf3224b0996af546aa48bd73c647Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-settings High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name settings Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-settings Highest Vendor pom artifactid maven-settings Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Settings High Vendor pom parent-artifactid maven Low Product file name maven-settings High Product jar package name apache Highest Product jar package name maven Highest Product jar package name settings Highest Product Manifest Implementation-Title Maven Settings High Product Manifest specification-title Maven Settings Medium Product pom artifactid maven-settings Highest Product pom groupid org.apache.maven Highest Product pom name Maven Settings High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
CVE-2021-26291 (OSSINDEX) suppress
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html CWE-346 Origin Validation Error
CVSSv2:
Base Score: HIGH (9.1) Vector: /AV:N/AC:L/Au:/C:H/I:H/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.apache.maven:maven-settings:3.0:*:*:*:*:*:*:* maven-settings-builder-3.0.jarFile Path: /home/andrii/.m2/repository/org/apache/maven/maven-settings-builder/3.0/maven-settings-builder-3.0.jarMD5: 134523c7b38175615b26504e642c960dSHA1: 08234c1bdf7a9a28c671b0abf11f8adaa66440cdSHA256: e17e706c6f03c453f6000599cab607c2af5f1cc6e3a3b1e6fce27e5ef4999eabReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-settings-builder High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name settings Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-settings-builder Highest Vendor pom artifactid maven-settings-builder Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Settings Builder High Vendor pom parent-artifactid maven Low Product file name maven-settings-builder High Product jar package name apache Highest Product jar package name maven Highest Product jar package name settings Highest Product Manifest Implementation-Title Maven Settings Builder High Product Manifest specification-title Maven Settings Builder Medium Product pom artifactid maven-settings-builder Highest Product pom groupid org.apache.maven Highest Product pom name Maven Settings Builder High Product pom parent-artifactid maven Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom version 3.0 Highest
maven-shared-utils-3.1.0.jarDescription:
Shared utils without any further dependencies File Path: /home/andrii/.m2/repository/org/apache/maven/shared/maven-shared-utils/3.1.0/maven-shared-utils-3.1.0.jarMD5: fae66822468c5f3e7853d1193f98b849SHA1: 78d8798fe84d5e095577221d299e9a3c8e696bcaSHA256: 88e5334c4c29a6e81c74a1d814c54a9a3b1e4fc6560a95da196fe16928095471Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name maven-shared-utils High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor jar package name utils Highest Vendor Manifest implementation-url https://maven.apache.org/shared/maven-shared-utils/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.shared Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-shared-utils Highest Vendor pom artifactid maven-shared-utils Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Shared Utils High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-shared-utils High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product jar package name utils Highest Product Manifest Implementation-Title Apache Maven Shared Utils High Product Manifest implementation-url https://maven.apache.org/shared/maven-shared-utils/ Low Product Manifest specification-title Apache Maven Shared Utils Medium Product pom artifactid maven-shared-utils Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Shared Utils High Product pom parent-artifactid maven-shared-components Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
CVE-2022-29599 suppress
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
mchange-commons-java-0.2.19.jarDescription:
mchange-commons-java License:
GNU Lesser General Public License, Version 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Eclipse Public License, Version 1.0: http://www.eclipse.org/org/documents/epl-v10.html File Path: /home/andrii/.m2/repository/com/mchange/mchange-commons-java/0.2.19/mchange-commons-java-0.2.19.jar
MD5: 795d7e75026388f4d90aa9719666e5db
SHA1: 7a4bee38ea02bd7dee776869b19fb3f6861d6acf
SHA256: 03761838ba2a7c9cce56ba84781633f107c8befb4e3607b336ee3010f915165d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name mchange-commons-java High Vendor jar package name mchange Highest Vendor Manifest Implementation-Vendor com.mchange High Vendor Manifest Implementation-Vendor-Id com.mchange Medium Vendor Manifest specification-vendor com.mchange Low Vendor pom artifactid mchange-commons-java Highest Vendor pom artifactid mchange-commons-java Low Vendor pom developer email swaldman@mchange.com Low Vendor pom developer id swaldman Medium Vendor pom developer name Steve Waldman Medium Vendor pom groupid com.mchange Highest Vendor pom name mchange-commons-java High Vendor pom organization name com.mchange High Vendor pom url swaldman/mchange-commons-java Highest Product file name mchange-commons-java High Product jar package name mchange Highest Product Manifest Implementation-Title mchange-commons-java High Product Manifest specification-title mchange-commons-java Medium Product pom artifactid mchange-commons-java Highest Product pom developer email swaldman@mchange.com Low Product pom developer id swaldman Low Product pom developer name Steve Waldman Low Product pom groupid com.mchange Highest Product pom name mchange-commons-java High Product pom organization name com.mchange Low Product pom url swaldman/mchange-commons-java High Version file version 0.2.19 High Version Manifest Implementation-Version 0.2.19 High Version pom version 0.2.19 Highest
memoize-one.esm-42a55c10.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/memoize-one.esm-42a55c10.jsMD5: a37a427d0a9b223d9fef26c824659b0aSHA1: 3a613116c1198880b8590e9346f0d32ccc56d7f3SHA256: 3dd205b86eb0bc59f4841faa0865700bd2464e6464a8b4fe7a2b25730dc92ff2Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
metrics-core-4.0.3.jarDescription:
Metrics is a Java library which gives you unparalleled insight into what your code does in
production. Metrics provides a powerful toolkit of ways to measure the behavior of critical
components in your production environment.
License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/io/dropwizard/metrics/metrics-core/4.0.3/metrics-core-4.0.3.jar
MD5: 051abff31424a2e6632c48f5ddf017d7
SHA1: bb562ee73f740bb6b2bf7955f97be6b870d9e9f0
SHA256: 7eff1a8d8cecbb2d3023b3d389d4d14a5212c4853199e39c094def46b6866cde
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name metrics-core High Vendor jar package name metrics Highest Vendor Manifest bundle-symbolicname io.dropwizard.metrics.core Medium Vendor Manifest implementation-url http://metrics.dropwizard.io/metrics-core Low Vendor Manifest Implementation-Vendor-Id io.dropwizard.metrics Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid metrics-core Highest Vendor pom artifactid metrics-core Low Vendor pom groupid io.dropwizard.metrics Highest Vendor pom name Metrics Core High Vendor pom parent-artifactid metrics-parent Low Product file name metrics-core High Product jar package name metrics Highest Product Manifest Bundle-Name Metrics Core Medium Product Manifest bundle-symbolicname io.dropwizard.metrics.core Medium Product Manifest Implementation-Title Metrics Core High Product Manifest implementation-url http://metrics.dropwizard.io/metrics-core Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid metrics-core Highest Product pom groupid io.dropwizard.metrics Highest Product pom name Metrics Core High Product pom parent-artifactid metrics-parent Medium Version file version 4.0.3 High Version Manifest Bundle-Version 4.0.3 High Version Manifest Implementation-Version 4.0.3 High Version pom version 4.0.3 Highest
metrics-jmx-4.0.6.jarDescription:
A set of classes which allow you to report metrics via JMX.
License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/io/dropwizard/metrics/metrics-jmx/4.0.6/metrics-jmx-4.0.6.jar
MD5: 9962568ea5bd6ea9c93c4a5a3b152b1d
SHA1: dc9b9de4649b54e770c15509a3403b34a5d5dc11
SHA256: 07cca8fe8b5dcc1d1d08a7b534179c7bd4f68e1510700a63a3106e37ac902dc3
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name metrics-jmx High Vendor jar package name jmx Highest Vendor jar package name metrics Highest Vendor Manifest bundle-symbolicname io.dropwizard.metrics.jmx Medium Vendor Manifest implementation-url http://metrics.dropwizard.io/metrics-jmx Low Vendor Manifest Implementation-Vendor-Id io.dropwizard.metrics Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid metrics-jmx Highest Vendor pom artifactid metrics-jmx Low Vendor pom groupid io.dropwizard.metrics Highest Vendor pom name Metrics Integration with JMX High Vendor pom parent-artifactid metrics-parent Low Product file name metrics-jmx High Product jar package name jmx Highest Product jar package name metrics Highest Product Manifest Bundle-Name Metrics Integration with JMX Medium Product Manifest bundle-symbolicname io.dropwizard.metrics.jmx Medium Product Manifest Implementation-Title Metrics Integration with JMX High Product Manifest implementation-url http://metrics.dropwizard.io/metrics-jmx Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid metrics-jmx Highest Product pom groupid io.dropwizard.metrics Highest Product pom name Metrics Integration with JMX High Product pom parent-artifactid metrics-parent Medium Version file version 4.0.6 High Version Manifest Bundle-Version 4.0.6 High Version Manifest Implementation-Version 4.0.6 High Version pom version 4.0.6 Highest
metrics-sql-3.1.0-atlassian-4.jarLicense:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/com/github/gquintana/metrics/metrics-sql/3.1.0-atlassian-4/metrics-sql-3.1.0-atlassian-4.jar
MD5: fdf6905a28f3b1cc269b09f70367f43e
SHA1: 82c0cd776bea41768095d8334164a697a3280b2b
SHA256: de37c0f4aa0fc24543595d3e9c920f130521ed8ede60a5929d4282f46b9acb6d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name metrics-sql High Vendor jar package name github Highest Vendor jar package name github Low Vendor jar package name gquintana Highest Vendor jar package name gquintana Low Vendor jar package name metrics Highest Vendor jar package name metrics Low Vendor jar package name sql Highest Vendor pom artifactid metrics-sql Highest Vendor pom artifactid metrics-sql Low Vendor pom developer email gerald.quintana@gmail.com Low Vendor pom developer id gquintana Medium Vendor pom developer name Gérald Quintana Medium Vendor pom groupid com.github.gquintana.metrics Highest Vendor pom name Metrics SQL High Vendor pom organization name Open-Source High Vendor pom organization url http://github.com/gquintana/metrics-sql Medium Product file name metrics-sql High Product jar package name github Highest Product jar package name gquintana Highest Product jar package name gquintana Low Product jar package name metrics Highest Product jar package name metrics Low Product jar package name sql Highest Product pom artifactid metrics-sql Highest Product pom developer email gerald.quintana@gmail.com Low Product pom developer id gquintana Low Product pom developer name Gérald Quintana Low Product pom groupid com.github.gquintana.metrics Highest Product pom name Metrics SQL High Product pom organization name Open-Source Low Product pom organization url http://github.com/gquintana/metrics-sql Low Version pom version 3.1.0-atlassian-4 Highest
micrometer-core-1.2.0.jar (shaded: org.pcollections:pcollections:3.0.3)Description:
A Persistent Java Collections Library License:
The MIT License: https://opensource.org/licenses/mit-license.php File Path: /home/andrii/.m2/repository/io/micrometer/micrometer-core/1.2.0/micrometer-core-1.2.0.jar/META-INF/maven/org.pcollections/pcollections/pom.xml
MD5: 35ba5e5a8572be83189294f2607ee97b
SHA1: 312cf913d2d027395cf9cb15a46af2e763e876c6
SHA256: dbd55a6571ebc17f31e4ba012d35aae6d6384d35287e12cb69a02a5597547a42
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor pom artifactid pcollections Low Vendor pom developer email hrldcpr@gmail.com Low Vendor pom developer id hrldcpr Medium Vendor pom developer name Harold Cooper Medium Vendor pom groupid org.pcollections Highest Vendor pom name PCollections High Vendor pom url https://pcollections.org Highest Product pom artifactid pcollections Highest Product pom developer email hrldcpr@gmail.com Low Product pom developer id hrldcpr Low Product pom developer name Harold Cooper Low Product pom groupid org.pcollections Highest Product pom name PCollections High Product pom url https://pcollections.org Medium Version pom version 3.0.3 Highest
micrometer-core-1.2.0.jarDescription:
Application monitoring instrumentation facade License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/io/micrometer/micrometer-core/1.2.0/micrometer-core-1.2.0.jar
MD5: 2d61ce6aa26bfe578bfbdc5c9fecfe78
SHA1: 0e085f337633b807020596b37dc9c9ccd3ee1a1f
SHA256: 9aacd657e0904f0b9c2f5bccbc92456b73debd2106cf0232b33f86dea57ab1c7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name micrometer-core High Vendor jar package name core Highest Vendor jar package name io Highest Vendor jar package name micrometer Highest Vendor Manifest branch e8f84afbcf819ec1edfe1fed99965f44948c0ce1 Low Vendor Manifest build-date 2019-06-29_20:19:42 Low Vendor Manifest build-host dfacc99b3d64 Low Vendor Manifest build-job LOCAL Low Vendor Manifest build-number LOCAL Low Vendor Manifest built-os Linux Low Vendor Manifest built-status integration Low Vendor Manifest change e8f84af Low Vendor Manifest module-email jschneider@pivotal.io Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner jschneider@pivotal.io Low Vendor Manifest module-source /micrometer-core Low Vendor pom artifactid micrometer-core Highest Vendor pom artifactid micrometer-core Low Vendor pom developer email jschneider@pivotal.io Low Vendor pom developer id jkschneider Medium Vendor pom developer name Jon Schneider Medium Vendor pom groupid io.micrometer Highest Vendor pom name micrometer-core High Vendor pom url micrometer-metrics/micrometer Highest Product file name micrometer-core High Product jar package name core Highest Product jar package name io Highest Product jar package name micrometer Highest Product Manifest branch e8f84afbcf819ec1edfe1fed99965f44948c0ce1 Low Product Manifest build-date 2019-06-29_20:19:42 Low Product Manifest build-host dfacc99b3d64 Low Product Manifest build-job LOCAL Low Product Manifest build-number LOCAL Low Product Manifest built-os Linux Low Product Manifest built-status integration Low Product Manifest change e8f84af Low Product Manifest Implementation-Title io.micrometer#micrometer-core;1.2.0 High Product Manifest module-email jschneider@pivotal.io Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner jschneider@pivotal.io Low Product Manifest module-source /micrometer-core Low Product pom artifactid micrometer-core Highest Product pom developer email jschneider@pivotal.io Low Product pom developer id jkschneider Low Product pom developer name Jon Schneider Low Product pom groupid io.micrometer Highest Product pom name micrometer-core High Product pom url micrometer-metrics/micrometer High Version file version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High Version pom version 1.2.0 Highest
micrometer-registry-influx-1.5.0.jarDescription:
Application monitoring instrumentation facade License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/io/micrometer/micrometer-registry-influx/1.5.0/micrometer-registry-influx-1.5.0.jar
MD5: a1e6255e2fe052587b48fd1a5db2cb29
SHA1: ac67b51c779906903f94246842c1cfd6f40e54ec
SHA256: 7c8d2107cf0d3e0f6d885e7bd99a8751b82bac495a339fb0cbc271ca1063c898
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name micrometer-registry-influx High Vendor jar package name influx Highest Vendor jar package name io Highest Vendor jar package name micrometer Highest Vendor Manifest automatic-module-name micrometer.registry.influx Medium Vendor Manifest branch 0f00416531eaebf1ec4fc48c054db7708738019e Low Vendor Manifest build-date 2020-04-29_08:06:21 Low Vendor Manifest build-host 17166d0abe77 Low Vendor Manifest build-job LOCAL Low Vendor Manifest build-number LOCAL Low Vendor Manifest built-os Linux Low Vendor Manifest built-status integration Low Vendor Manifest change 0f00416 Low Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest module-source /implementations/micrometer-registry-influx Low Vendor pom artifactid micrometer-registry-influx Highest Vendor pom artifactid micrometer-registry-influx Low Vendor pom developer email tludwig@vmware.com Low Vendor pom developer id shakuzen Medium Vendor pom developer name Tommy Ludwig Medium Vendor pom groupid io.micrometer Highest Vendor pom name micrometer-registry-influx High Vendor pom url micrometer-metrics/micrometer Highest Product file name micrometer-registry-influx High Product jar package name influx Highest Product jar package name io Highest Product jar package name micrometer Highest Product Manifest automatic-module-name micrometer.registry.influx Medium Product Manifest branch 0f00416531eaebf1ec4fc48c054db7708738019e Low Product Manifest build-date 2020-04-29_08:06:21 Low Product Manifest build-host 17166d0abe77 Low Product Manifest build-job LOCAL Low Product Manifest build-number LOCAL Low Product Manifest built-os Linux Low Product Manifest built-status integration Low Product Manifest change 0f00416 Low Product Manifest Implementation-Title io.micrometer#micrometer-registry-influx;1.5.0 High Product Manifest module-email tludwig@vmware.com Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest module-source /implementations/micrometer-registry-influx Low Product pom artifactid micrometer-registry-influx Highest Product pom developer email tludwig@vmware.com Low Product pom developer id shakuzen Low Product pom developer name Tommy Ludwig Low Product pom groupid io.micrometer Highest Product pom name micrometer-registry-influx High Product pom url micrometer-metrics/micrometer High Version file version 1.5.0 High Version Manifest Implementation-Version 1.5.0 High Version pom version 1.5.0 Highest
minlog-1.3.1.jarDescription:
Minimal overhead Java logging License:
3-Clause BSD License: https://opensource.org/licenses/BSD-3-Clause File Path: /home/andrii/.m2/repository/com/esotericsoftware/minlog/1.3.1/minlog-1.3.1.jar
MD5: 46908e11b408080d53246e4be44e66db
SHA1: a406e29d3a44d5f020d7b3218aee6d0952db4f73
SHA256: 5d4d632cfbebfe0a7644501cc303570b691406181bee65e9916b921c767d7c72
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name minlog High Vendor jar package name esotericsoftware Highest Vendor jar package name minlog Highest Vendor Manifest automatic-module-name com.esotericsoftware.minlog Medium Vendor Manifest bundle-symbolicname com.esotericsoftware.minlog Medium Vendor Manifest Implementation-Vendor-Id com.esotericsoftware Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid minlog Highest Vendor pom artifactid minlog Low Vendor pom developer email nathan.sweet@gmail.com Low Vendor pom developer id nathan.sweet Medium Vendor pom developer name Nathan Sweet Medium Vendor pom groupid com.esotericsoftware Highest Vendor pom name MinLog High Vendor pom url EsotericSoftware/minlog Highest Product file name minlog High Product jar package name esotericsoftware Highest Product jar package name minlog Highest Product Manifest automatic-module-name com.esotericsoftware.minlog Medium Product Manifest Bundle-Name MinLog Medium Product Manifest bundle-symbolicname com.esotericsoftware.minlog Medium Product Manifest Implementation-Title MinLog High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title MinLog Medium Product pom artifactid minlog Highest Product pom developer email nathan.sweet@gmail.com Low Product pom developer id nathan.sweet Low Product pom developer name Nathan Sweet Low Product pom groupid com.esotericsoftware Highest Product pom name MinLog High Product pom url EsotericSoftware/minlog High Version file version 1.3.1 High Version Manifest Bundle-Version 1.3.1 High Version Manifest Implementation-Version 1.3.1 High Version pom version 1.3.1 Highest
modz-detector-0.14.jarFile Path: /home/andrii/.m2/repository/com/atlassian/modzdetector/modz-detector/0.14/modz-detector-0.14.jarMD5: 4018ce198d12bb32fefc4252a598056aSHA1: 9b8b545d4f88de469acfb5813b236db53cb36a4eSHA256: 8944886d9da18766e0defed5eda5a3c8dbcc2a34e9e846c3cc0c92f6c88c349dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name modz-detector High Vendor jar package name ant Highest Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name modzdetector Highest Vendor jar package name modzdetector Low Vendor pom artifactid modz-detector Highest Vendor pom artifactid modz-detector Low Vendor pom groupid com.atlassian.modzdetector Highest Vendor pom name Atlassian Modz Detector - Core and Ant task High Vendor pom parent-artifactid modz-detector-parent Low Product file name modz-detector High Product jar package name ant Highest Product jar package name atlassian Highest Product jar package name modzdetector Highest Product jar package name modzdetector Low Product pom artifactid modz-detector Highest Product pom groupid com.atlassian.modzdetector Highest Product pom name Atlassian Modz Detector - Core and Ant task High Product pom parent-artifactid modz-detector-parent Medium Version file version 0.14 High Version pom version 0.14 Highest
mssql-jdbc-6.3.0.jre8-preview.jarDescription:
Microsoft JDBC Driver for SQL Server.
The Azure Key Vault feature in Microsoft JDBC Driver for SQL Server depends on
Azure SDK for JAVA and Azure Active Directory Library For Java.
License:
MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /home/andrii/.m2/repository/com/microsoft/sqlserver/mssql-jdbc/6.3.0.jre8-preview/mssql-jdbc-6.3.0.jre8-preview.jar
MD5: e100cd62bb083ba60321a72952d6ddac
SHA1: 21fcee593c8829ded0c0c5d3365e6698f7c5ed79
SHA256: 4bf49a73ed6a966ec742c9324614a9748da93f0979cdb6ff67fb47b8fa1e23ad
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name mssql-jdbc High Vendor jar package name jdbc Highest Vendor jar package name microsoft Highest Vendor jar package name mssql Highest Vendor jar package name sql Highest Vendor jar package name sqlserver Highest Vendor Manifest bundle-symbolicname com.microsoft.sqlserver.mssql-jdbc Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid mssql-jdbc Highest Vendor pom artifactid mssql-jdbc Low Vendor pom developer email andrela@microsoft.com Low Vendor pom developer name Andrea Lam Medium Vendor pom developer org Microsoft Medium Vendor pom developer org URL http://www.microsoft.com Medium Vendor pom groupid com.microsoft.sqlserver Highest Vendor pom name Microsoft JDBC Driver for SQL Server High Vendor pom organization name Microsoft Corporation High Vendor pom url Microsoft/mssql-jdbc Highest Product file name mssql-jdbc High Product jar package name jdbc Highest Product jar package name microsoft Highest Product jar package name mssql Highest Product jar package name sql Highest Product jar package name sqlserver Highest Product Manifest Bundle-Name Microsoft JDBC Driver for SQL Server Medium Product Manifest bundle-symbolicname com.microsoft.sqlserver.mssql-jdbc Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid mssql-jdbc Highest Product pom developer email andrela@microsoft.com Low Product pom developer name Andrea Lam Low Product pom developer org Microsoft Low Product pom developer org URL http://www.microsoft.com Low Product pom groupid com.microsoft.sqlserver Highest Product pom name Microsoft JDBC Driver for SQL Server High Product pom organization name Microsoft Corporation Low Product pom url Microsoft/mssql-jdbc High Version Manifest Bundle-Version 6.3.0.jre8-preview High Version pom version 6.3.0.jre8-preview Highest
mxparser-1.2.1.jarDescription:
MXParser is a fork of xpp3_min 1.1.7 containing only the parser with merged changes of the Plexus fork.
License:
Indiana University Extreme! Lab Software License: https://raw.githubusercontent.com/x-stream/mxparser/master/LICENSE.txt File Path: /home/andrii/.m2/repository/io/github/x-stream/mxparser/1.2.1/mxparser-1.2.1.jar
MD5: 06012e8b74cfef8f09149320272fccab
SHA1: 2a7e50b9831efc7785a4d276d94eadee343a4729
SHA256: 860eab19076fa6fe93643be7a0895a2ca698b514029734ec84eaf1f9de2468e2
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name mxparser High Vendor jar package name github Highest Vendor jar package name io Highest Vendor jar package name mxparser Highest Vendor jar package name xstream Highest Vendor Manifest automatic-module-name io.github.xstream.mxparser Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname mxparser Medium Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Vendor Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Vendor Manifest x-build-os Linux Low Vendor Manifest x-build-time 2021-03-11T23:10:16Z Low Vendor Manifest x-builder Maven 3.6.3 Low Vendor Manifest x-compile-source 1.4 Low Vendor Manifest x-compile-target 1.4 Low Vendor pom artifactid mxparser Highest Vendor pom artifactid mxparser Low Vendor pom developer id mxparser Medium Vendor pom developer name XStream Committers Medium Vendor pom groupid io.github.x-stream Highest Vendor pom name MXParser High Vendor pom url http://x-stream.github.io/mxparser Highest Product file name mxparser High Product jar package name github Highest Product jar package name io Highest Product jar package name mxparser Highest Product jar package name xstream Highest Product Manifest automatic-module-name io.github.xstream.mxparser Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name MXParser Medium Product Manifest bundle-symbolicname mxparser Medium Product Manifest Implementation-Title MXParser High Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Product Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Product Manifest specification-title MXParser Medium Product Manifest x-build-os Linux Low Product Manifest x-build-time 2021-03-11T23:10:16Z Low Product Manifest x-builder Maven 3.6.3 Low Product Manifest x-compile-source 1.4 Low Product Manifest x-compile-target 1.4 Low Product pom artifactid mxparser Highest Product pom developer id mxparser Low Product pom developer name XStream Committers Low Product pom groupid io.github.x-stream Highest Product pom name MXParser High Product pom url http://x-stream.github.io/mxparser Medium Version file version 1.2.1 High Version Manifest Bundle-Version 1.2.1 High Version Manifest Implementation-Version 1.2.1 High Version pom version 1.2.1 Highest
nekohtml-1.9.22.jarDescription:
An HTML parser and tag balancer. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.22/nekohtml-1.9.22.jar
MD5: a97dfe2d0ceb81ffbdd15436961b0f23
SHA1: 4f54af68ecb345f2453fb6884672ad08414154e3
SHA256: 452978e8b6667c7b8357fd3f0a2f2f405e4560a7148143a69181735da5d19045
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name nekohtml High Vendor jar package name html Highest Vendor manifest: org/cyberneko/html/ Implementation-Vendor Andy Clark, Marc Guillemot Medium Vendor pom artifactid nekohtml Highest Vendor pom artifactid nekohtml Low Vendor pom developer email mguillem@users.sourceforge.net Low Vendor pom developer id mguillem Medium Vendor pom developer name Andy Clark Medium Vendor pom developer name Marc Guillemot Medium Vendor pom groupid net.sourceforge.nekohtml Highest Vendor pom name Neko HTML High Vendor pom url http://nekohtml.sourceforge.net/ Highest Product file name nekohtml High Product jar package name cyberneko Highest Product jar package name html Highest Product manifest: org/cyberneko/html/ Implementation-Title CyberNeko HTML Parser Medium Product manifest: org/cyberneko/html/ Specification-Title Hyper-Text Markup Language (HTML) Medium Product pom artifactid nekohtml Highest Product pom developer email mguillem@users.sourceforge.net Low Product pom developer id mguillem Low Product pom developer name Andy Clark Low Product pom developer name Marc Guillemot Low Product pom groupid net.sourceforge.nekohtml Highest Product pom name Neko HTML High Product pom url http://nekohtml.sourceforge.net/ Medium Version file version 1.9.22 High Version manifest: org/cyberneko/html/ Implementation-Version 1.9.22 Medium Version pom version 1.9.22 Highest
CVE-2022-24839 suppress
org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer maintained. Nokogiri uses its own fork of this library located at https://github.com/sparklemotion/nekohtml and this CVE applies only to that fork. Other forks of nekohtml may have a similar vulnerability. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
nimbus-jose-jwt-8.14.1.jarDescription:
Java library for Javascript Object Signing and Encryption (JOSE) and
JSON Web Tokens (JWT)
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/nimbusds/nimbus-jose-jwt/8.14.1/nimbus-jose-jwt-8.14.1.jar
MD5: ca5294a5c21cc180924579050f6d07ee
SHA1: a5fd931fb5b0080f91cf3ac2f0ba347a2e285aa9
SHA256: 7327f0dec6f729a424e0a10316905aba7960d17a4daaa672bf76405fdc1d63ba
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name nimbus-jose-jwt High Vendor jar package name jose Highest Vendor jar package name jwt Highest Vendor jar package name nimbusds Highest Vendor Manifest build-date ${timestamp} Low Vendor Manifest build-number ${buildNumber} Low Vendor Manifest build-tag 8.14.1 Low Vendor Manifest bundle-docurl http://connect2id.com Low Vendor Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Vendor Manifest implementation-url https://bitbucket.org/connect2id/nimbus-jose-jwt Low Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor pom artifactid nimbus-jose-jwt Highest Vendor pom artifactid nimbus-jose-jwt Low Vendor pom developer email vladimir@dzhuvinov.com Low Vendor pom developer id vdzhuvinov Medium Vendor pom developer name Vladimir Dzhuvinov Medium Vendor pom groupid com.nimbusds Highest Vendor pom name Nimbus JOSE+JWT High Vendor pom organization name Connect2id Ltd. High Vendor pom organization url http://connect2id.com Medium Vendor pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Highest Product file name nimbus-jose-jwt High Product jar package name jose Highest Product jar package name jwt Highest Product jar package name nimbusds Highest Product Manifest build-date ${timestamp} Low Product Manifest build-number ${buildNumber} Low Product Manifest build-tag 8.14.1 Low Product Manifest bundle-docurl http://connect2id.com Low Product Manifest Bundle-Name Nimbus JOSE+JWT Medium Product Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Product Manifest Implementation-Title Nimbus JOSE+JWT High Product Manifest implementation-url https://bitbucket.org/connect2id/nimbus-jose-jwt Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Nimbus JOSE+JWT Medium Product pom artifactid nimbus-jose-jwt Highest Product pom developer email vladimir@dzhuvinov.com Low Product pom developer id vdzhuvinov Low Product pom developer name Vladimir Dzhuvinov Low Product pom groupid com.nimbusds Highest Product pom name Nimbus JOSE+JWT High Product pom organization name Connect2id Ltd. Low Product pom organization url http://connect2id.com Low Product pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Medium Version file version 8.14.1 High Version Manifest build-tag 8.14.1 Low Version Manifest Bundle-Version 8.14.1 High Version Manifest Implementation-Version 8.14.1 High Version pom version 8.14.1 Highest
oauth2-oidc-sdk-7.4.jarDescription:
OAuth 2.0 SDK with OpenID Connection extensions for developing
client and server applications.
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/com/nimbusds/oauth2-oidc-sdk/7.4/oauth2-oidc-sdk-7.4.jar
MD5: 4026895a3beb12199e7ff6da374f7b34
SHA1: bc205ffbfcabf0c8f451e8ffd5121e3b8769cd12
SHA256: c76c4255dbcdcebc215d2b40344ad9d1b2990961db034d0d3300258cf23b9a17
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name oauth2-oidc-sdk High Vendor jar package name client Highest Vendor jar package name connect Highest Vendor jar package name nimbusds Highest Vendor jar package name oauth2 Highest Vendor jar package name openid Highest Vendor jar package name sdk Highest Vendor Manifest build-date ${timestamp} Low Vendor Manifest build-number ${buildNumber} Low Vendor Manifest build-tag 7.4 Low Vendor Manifest bundle-docurl https://connect2id.com Low Vendor Manifest bundle-symbolicname oauth2-oidc-sdk Medium Vendor Manifest implementation-url https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Low Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor pom artifactid oauth2-oidc-sdk Highest Vendor pom artifactid oauth2-oidc-sdk Low Vendor pom developer email vd@connect2id.com Low Vendor pom developer id vdzhuvinov Medium Vendor pom developer name Vladimir Dzhuvinov Medium Vendor pom groupid com.nimbusds Highest Vendor pom name OAuth 2.0 SDK with OpenID Connect extensions High Vendor pom organization name Connect2id Ltd. High Vendor pom organization url https://connect2id.com Medium Vendor pom url https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Highest Product file name oauth2-oidc-sdk High Product jar package name client Highest Product jar package name connect Highest Product jar package name nimbusds Highest Product jar package name oauth2 Highest Product jar package name openid Highest Product jar package name sdk Highest Product Manifest build-date ${timestamp} Low Product Manifest build-number ${buildNumber} Low Product Manifest build-tag 7.4 Low Product Manifest bundle-docurl https://connect2id.com Low Product Manifest Bundle-Name OAuth 2.0 SDK with OpenID Connect extensions Medium Product Manifest bundle-symbolicname oauth2-oidc-sdk Medium Product Manifest Implementation-Title OAuth 2.0 SDK with OpenID Connect extensions High Product Manifest implementation-url https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title OAuth 2.0 SDK with OpenID Connect extensions Medium Product pom artifactid oauth2-oidc-sdk Highest Product pom developer email vd@connect2id.com Low Product pom developer id vdzhuvinov Low Product pom developer name Vladimir Dzhuvinov Low Product pom groupid com.nimbusds Highest Product pom name OAuth 2.0 SDK with OpenID Connect extensions High Product pom organization name Connect2id Ltd. Low Product pom organization url https://connect2id.com Low Product pom url https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions Medium Version file version 7.4 High Version Manifest build-tag 7.4 Low Version Manifest Bundle-Version 7.4 High Version Manifest Implementation-Version 7.4 High Version pom version 7.4 Highest
odmg-3.0.jarFile Path: /home/andrii/.m2/repository/odmg/odmg/3.0/odmg-3.0.jarMD5: 8c1bd7dfbf457c7302f62cd866f48877SHA1: 5f894225c221bd1e6f1f072caf911f7a2870ad9fSHA256: 0771a190536380f8cb63d4d070d9e2df60db047e12a1aaa6c9573f8c0fd0e5efReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name odmg High Vendor jar package name odmg Highest Vendor manifest: Implementation-Vendor Medium Vendor pom artifactid odmg Highest Vendor pom artifactid odmg Low Vendor pom groupid odmg Highest Product file name odmg High Product jar package name odmg Highest Product manifest: Implementation-Title Medium Product manifest: Specification-Title odmg Medium Product pom artifactid odmg Highest Product pom groupid odmg Highest Version file version 3.0 High Version manifest: Implementation-Version 3.0 Medium Version pom version 3.0 Highest
ognl-2.6.5-atlassian-3.jarFile Path: /home/andrii/.m2/repository/ognl/ognl/2.6.5-atlassian-3/ognl-2.6.5-atlassian-3.jarMD5: b94ed657ba28e75baad64075affc82bfSHA1: 87b6783e518dcf346991c75e8cebdba30231ea23SHA256: 385df86c3b8b047227255d5ebb16cbf315952ad9e54399b25b7f35cb68c1f82dReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name ognl High Vendor jar package name ognl Highest Vendor jar package name ognl Low Vendor pom artifactid ognl Highest Vendor pom artifactid ognl Low Vendor pom groupid ognl Highest Product file name ognl High Product jar package name ognl Highest Product pom artifactid ognl Highest Product pom groupid ognl Highest Version pom version 2.6.5-atlassian-3 Highest
CVE-2016-3093 suppress
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L References:
Vulnerable Software & Versions: (show all )
org.apache.felix.framework-5.6.12.jarDescription:
OSGi R6 framework implementation. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/felix/org.apache.felix.framework/5.6.12/org.apache.felix.framework-5.6.12.jar
MD5: f82d5e54b307719c46f39c1a6dbe013d
SHA1: dad6b36b87bced1536bf70ebda578b82a78f4173
SHA256: 326c58622ddc123016075ea62498bf7eb97d9d0ca2428bf83cfae4c1dfb8cbb1
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name org.apache.felix.framework High Vendor jar package name apache Highest Vendor jar package name felix Highest Vendor jar package name framework Highest Vendor Manifest bundle-docurl http://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.felix.framework Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid apache.felix.framework Low Vendor pom artifactid org.apache.felix.framework Highest Vendor pom groupid org.apache.felix Highest Vendor pom name Apache Felix Framework High Vendor pom parent-artifactid felix-parent Low Product file name org.apache.felix.framework High Product jar package name apache Highest Product jar package name felix Highest Product jar package name filter Highest Product jar package name framework Highest Product jar package name osgi Highest Product jar package name version Highest Product Manifest bundle-docurl http://www.apache.org/ Low Product Manifest Bundle-Name Apache Felix Framework Medium Product Manifest bundle-symbolicname org.apache.felix.framework Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom artifactid apache.felix.framework Highest Product pom artifactid org.apache.felix.framework Highest Product pom groupid org.apache.felix Highest Product pom name Apache Felix Framework High Product pom parent-artifactid felix-parent Medium Version file version 5.6.12 High Version Manifest Bundle-Version 5.6.12 High Version pom parent-version 5.6.12 Low Version pom version 5.6.12 Highest
oro-2.0.8.jarFile Path: /home/andrii/.m2/repository/oro/oro/2.0.8/oro-2.0.8.jarMD5: 42e940d5d2d822f4dc04c65053e630abSHA1: 5592374f834645c4ae250f4c9fbb314c9369d698SHA256: e00ccdad5df7eb43fdee44232ef64602bf63807c2d133a7be83ba09fd49af26eReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name oro High Vendor jar package name apache Highest Vendor jar package name oro Highest Vendor manifest: org/apache/oro Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid oro Highest Vendor pom artifactid oro Low Vendor pom groupid oro Highest Product file name oro High Product jar package name apache Highest Product jar package name oro Highest Product manifest: org/apache/oro Implementation-Title org.apache.oro Medium Product manifest: org/apache/oro Specification-Title Jakarta ORO Medium Product pom artifactid oro Highest Product pom groupid oro Highest Version file version 2.0.8 High Version pom version 2.0.8 Highest
oscache-2.2.jarFile Path: /home/andrii/.m2/repository/oscache/oscache/2.2/oscache-2.2.jarMD5: 5fc6eb8aaec7113f4df71cbbd0dc9397SHA1: dda31848632610cc8188fcebd53b4af16d9d5985SHA256: 6f7b95a21638f6849bf3fcda1925fc7d4711480b06eb25972b28f35d43bf7ad2Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name oscache High Vendor jar package name opensymphony Highest Vendor jar package name oscache Highest Vendor Manifest Implementation-Vendor OpenSymphony High Vendor pom artifactid oscache Highest Vendor pom artifactid oscache Low Vendor pom groupid oscache Highest Product file name oscache High Product jar package name oscache Highest Product Manifest Implementation-Title OSCache High Product pom artifactid oscache Highest Product pom groupid oscache Highest Version file version 2.2 High Version Manifest Implementation-Version 2.2 High Version pom version 2.2 Highest
oscore-2.2.7-atlassian-1.jarFile Path: /home/andrii/.m2/repository/opensymphony/oscore/2.2.7-atlassian-1/oscore-2.2.7-atlassian-1.jarMD5: 9cb0d387b65cd6447fc5776cf8b2dedaSHA1: 921a5768fffcb82bdf23bfb1b4a5b175a94a7dd5SHA256: 973d97ee731eb2d3099aad756ce8f78a5acca231ab6a68e46947a3a5ffd4baa0Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name oscore High Vendor jar package name opensymphony Highest Vendor Manifest Implementation-Vendor OpenSymphony High Vendor pom artifactid oscore Highest Vendor pom artifactid oscore Low Vendor pom groupid opensymphony Highest Product file name oscore High Product jar package name opensymphony Highest Product Manifest Implementation-Title OSCore High Product pom artifactid oscore Highest Product pom groupid opensymphony Highest Version Manifest Implementation-Version 2.2.7-atlassian-1 High Version pom version 2.2.7-atlassian-1 Highest
oshi-core-5.3.6.jarDescription:
A JNA-based (native) operating system information library for Java that aims to provide a cross-platform implementation to retrieve system information, such as version, memory, CPU, disk, battery, etc. License:
"MIT License";link="https://opensource.org/licenses/MIT" File Path: /home/andrii/.m2/repository/com/github/oshi/oshi-core/5.3.6/oshi-core-5.3.6.jar
MD5: ff3367c536b345d593f5a869ee5f2b24
SHA1: 0e69383dc7b7d84926262e90e720927f10d25f0a
SHA256: a65d3146085d42bbf19f76e561870f1d48b69977380c5c51e2da784691279feb
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name oshi-core High Vendor jar package name mac Highest Vendor jar package name os Highest Vendor jar package name oshi Highest Vendor Manifest automatic-module-name com.github.oshi Medium Vendor Manifest build-jdk-spec 15 Low Vendor Manifest build-time 2020-11-15 20:19:02 Low Vendor Manifest bundle-developers dblock;email="dblock@dblock.org";name="Daniel Doubrovkine";organization="dblock.org";organizationUrl="http://code.dblock.org/",dbwiddis;email="widdis@gmail.com";name="Daniel Widdis";organization="sometegroup.com";organizationUrl="https://github.com/dbwiddis/" Low Vendor Manifest bundle-docurl https://github.com/oshi/oshi/oshi-core Low Vendor Manifest bundle-symbolicname com.github.oshi.oshi-core Medium Vendor Manifest copyright 2010 - 2020 Low Vendor Manifest git-revision a909c8523dad2cd83f82d266a6f90f431775fd96 Low Vendor Manifest Implementation-Vendor oshi High Vendor Manifest os-arch x86_64 Low Vendor Manifest os-name Mac OS X Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor oshi Low Vendor pom artifactid oshi-core Highest Vendor pom artifactid oshi-core Low Vendor pom groupid com.github.oshi Highest Vendor pom name oshi-core High Vendor pom parent-artifactid oshi-parent Low Product file name oshi-core High Product jar package name disk Highest Product jar package name jna Highest Product jar package name mac Highest Product jar package name os Highest Product jar package name oshi Highest Product jar package name platform Highest Product Manifest automatic-module-name com.github.oshi Medium Product Manifest build-jdk-spec 15 Low Product Manifest build-time 2020-11-15 20:19:02 Low Product Manifest bundle-developers dblock;email="dblock@dblock.org";name="Daniel Doubrovkine";organization="dblock.org";organizationUrl="http://code.dblock.org/",dbwiddis;email="widdis@gmail.com";name="Daniel Widdis";organization="sometegroup.com";organizationUrl="https://github.com/dbwiddis/" Low Product Manifest bundle-docurl https://github.com/oshi/oshi/oshi-core Low Product Manifest Bundle-Name oshi-core Medium Product Manifest bundle-symbolicname com.github.oshi.oshi-core Medium Product Manifest copyright 2010 - 2020 Low Product Manifest git-revision a909c8523dad2cd83f82d266a6f90f431775fd96 Low Product Manifest Implementation-Title oshi-core High Product Manifest os-arch x86_64 Low Product Manifest os-name Mac OS X Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title oshi-core Medium Product pom artifactid oshi-core Highest Product pom groupid com.github.oshi Highest Product pom name oshi-core High Product pom parent-artifactid oshi-parent Medium Version file version 5.3.6 High Version Manifest Bundle-Version 5.3.6 High Version Manifest Implementation-Version 5.3.6 High Version pom version 5.3.6 Highest
ossindex-service-api-1.8.2.jarFile Path: /home/andrii/.m2/repository/org/sonatype/ossindex/ossindex-service-api/1.8.2/ossindex-service-api-1.8.2.jarMD5: 538c88889c560c0bcd8ded0a16c5dee6SHA1: b1eaa5940bed67fad9d596839500d2559bc57e36SHA256: 61fb04e93cf2991718057956f92534cbf1494ed5e74250b9dfd6c012bc379aa8Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name ossindex-service-api High Vendor jar package name api Highest Vendor jar package name ossindex Highest Vendor jar package name service Highest Vendor jar package name sonatype Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Sonatype, Inc. High Vendor pom artifactid ossindex-service-api Highest Vendor pom artifactid ossindex-service-api Low Vendor pom groupid org.sonatype.ossindex Highest Vendor pom parent-artifactid ossindex-service Low Product file name ossindex-service-api High Product jar package name api Highest Product jar package name ossindex Highest Product jar package name service Highest Product jar package name sonatype Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title org.sonatype.ossindex:ossindex-service-api High Product Manifest specification-title org.sonatype.ossindex:ossindex-service-api Medium Product pom artifactid ossindex-service-api Highest Product pom groupid org.sonatype.ossindex Highest Product pom parent-artifactid ossindex-service Medium Version file version 1.8.2 High Version Manifest Implementation-Version 1.8.2 High Version pom version 1.8.2 Highest
ossindex-service-client-1.8.2.jarFile Path: /home/andrii/.m2/repository/org/sonatype/ossindex/ossindex-service-client/1.8.2/ossindex-service-client-1.8.2.jarMD5: c9ecd5ddb7bc3ceecc33da606ec0d2f7SHA1: 3fc65bd57dbdfd40b62424feb22949095b20e4d0SHA256: ef692b99e11e558524036447daedf7cb98285407d4db7af579a5914c265f981bReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name ossindex-service-client High Vendor jar package name client Highest Vendor jar package name ossindex Highest Vendor jar package name service Highest Vendor jar package name sonatype Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Sonatype, Inc. High Vendor pom artifactid ossindex-service-client Highest Vendor pom artifactid ossindex-service-client Low Vendor pom groupid org.sonatype.ossindex Highest Vendor pom parent-artifactid ossindex-service Low Product file name ossindex-service-client High Product jar package name client Highest Product jar package name ossindex Highest Product jar package name service Highest Product jar package name sonatype Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title org.sonatype.ossindex:ossindex-service-client High Product Manifest specification-title org.sonatype.ossindex:ossindex-service-client Medium Product pom artifactid ossindex-service-client Highest Product pom groupid org.sonatype.ossindex Highest Product pom parent-artifactid ossindex-service Medium Version file version 1.8.2 High Version Manifest Implementation-Version 1.8.2 High Version pom version 1.8.2 Highest
osuser-atl.user.jarFile Path: /home/andrii/.m2/repository/osuser/osuser/atl.user/osuser-atl.user.jarMD5: 799f19e8dda07c74a7bb51affad9875fSHA1: e68810e3ba7d973ae4c4da9bfd56a551e593577dSHA256: 3e6ec30cf1a0cf17c1b438c93e5795a6e10cd6fe586124adabb9a7ce18d9debdReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name osuser-atl.user High Vendor jar package name opensymphony Low Vendor jar package name provider Low Vendor jar package name user Low Vendor pom artifactid osuser Highest Vendor pom artifactid osuser Low Vendor pom groupid osuser Highest Product file name osuser-atl.user High Product jar package name provider Low Product jar package name user Low Product pom artifactid osuser Highest Product pom groupid osuser Highest Version pom version atl.user Highest
package-scanner-0.9.5.jarFile Path: /home/andrii/.m2/repository/org/twdata/pkgscanner/package-scanner/0.9.5/package-scanner-0.9.5.jarMD5: 792f15883f0ddaded50410fc595a8b8dSHA1: 0bbf358db80c6db8f1bc8ad179e4f52542a2b5ebSHA256: 6ffb92fca267769047dbba925fe6bed2f4ad7a3788672b1d1b69e535151f903aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name package-scanner High Vendor jar package name pkgscanner Highest Vendor jar package name pkgscanner Low Vendor jar package name twdata Highest Vendor jar package name twdata Low Vendor pom artifactid package-scanner Highest Vendor pom artifactid package-scanner Low Vendor pom groupid org.twdata.pkgscanner Highest Vendor pom name Package Export Scanner High Vendor pom url http://maven.apache.org Highest Product file name package-scanner High Product jar package name pkgscanner Highest Product jar package name pkgscanner Low Product jar package name twdata Highest Product pom artifactid package-scanner Highest Product pom groupid org.twdata.pkgscanner Highest Product pom name Package Export Scanner High Product pom url http://maven.apache.org Medium Version file version 0.9.5 High Version pom version 0.9.5 Highest
package-url-java-1.1.1.jarLicense:
ASL2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/sonatype/goodies/package-url-java/1.1.1/package-url-java-1.1.1.jar
MD5: f1536b94a22379278b0480ea89e7028a
SHA1: d6822ea23182ce388cb67086d92ba40fad6f8e16
SHA256: 15297862342b494a535742fba90ea8a321cd13e1d0dc4c61b7a3b18ce385e1a8
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name package-url-java High Vendor jar package name goodies Highest Vendor jar package name sonatype Highest Vendor Manifest implementation-url https://sonatype.github.io/package-url-java/ Low Vendor Manifest Implementation-Vendor Sonatype, Inc. High Vendor Manifest Implementation-Vendor-Id org.sonatype.goodies Medium Vendor pom artifactid package-url-java Highest Vendor pom artifactid package-url-java Low Vendor pom groupid org.sonatype.goodies Highest Vendor pom parent-artifactid public-parent Low Vendor pom parent-groupid org.sonatype.buildsupport Medium Vendor pom url https://sonatype.github.io/package-url-java/ Highest Product file name package-url-java High Product jar package name goodies Highest Product jar package name sonatype Highest Product Manifest Implementation-Title org.sonatype.goodies:package-url-java High Product Manifest implementation-url https://sonatype.github.io/package-url-java/ Low Product Manifest specification-title org.sonatype.goodies:package-url-java Medium Product pom artifactid package-url-java Highest Product pom groupid org.sonatype.goodies Highest Product pom parent-artifactid public-parent Medium Product pom parent-groupid org.sonatype.buildsupport Medium Product pom url https://sonatype.github.io/package-url-java/ Medium Version file version 1.1.1 High Version Manifest Implementation-Version 1.1.1 High Version pom parent-version 1.1.1 Low Version pom version 1.1.1 Highest
packager-core-0.19.0.jarDescription:
Work with software packagers. License:
http://www.eclipse.org/legal/epl-2.0 File Path: /home/andrii/.m2/repository/org/eclipse/packager/packager-core/0.19.0/packager-core-0.19.0.jar
MD5: 1c9bcf1fb9c82adf9e52c3d33fccb1ef
SHA1: be78989d7ad07e1a81b41e3ba3705eeaaffcec52
SHA256: f57988a8b36da005353ba5d5a3414766e198aa54e1fb7d363aff1e3dd847d48a
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name packager-core High Vendor jar package name eclipse Highest Vendor jar package name packager Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://www.eclipse.org/ Low Vendor Manifest bundle-symbolicname org.eclipse.packager.core Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid packager-core Highest Vendor pom artifactid packager-core Low Vendor pom groupid org.eclipse.packager Highest Vendor pom name Eclipse Packager :: Core High Vendor pom parent-artifactid packager Low Product file name packager-core High Product jar package name eclipse Highest Product jar package name packager Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://www.eclipse.org/ Low Product Manifest Bundle-Name Eclipse Packager :: Core Medium Product Manifest bundle-symbolicname org.eclipse.packager.core Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid packager-core Highest Product pom groupid org.eclipse.packager Highest Product pom name Eclipse Packager :: Core High Product pom parent-artifactid packager Medium Version file version 0.19.0 High Version Manifest Bundle-Version 0.19.0 High Version pom version 0.19.0 Highest
packager-rpm-0.19.0.jarFile Path: /home/andrii/.m2/repository/org/eclipse/packager/packager-rpm/0.19.0/packager-rpm-0.19.0.jarMD5: 57eee2da2e2c2e949a66ee22586ad235SHA1: fd59d3de5d77cf2ac49a808eb60a9b1d28853769SHA256: f2550b2f4eb1d667e766815d98a3d43c95a3de7e68cb19065515980be689f13dReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name packager-rpm High Vendor jar package name eclipse Highest Vendor jar package name packager Highest Vendor jar package name rpm Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid packager-rpm Highest Vendor pom artifactid packager-rpm Low Vendor pom groupid org.eclipse.packager Highest Vendor pom name Eclipse Packager :: RPM High Vendor pom parent-artifactid packager Low Product file name packager-rpm High Product jar package name eclipse Highest Product jar package name packager Highest Product jar package name rpm Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid packager-rpm Highest Product pom groupid org.eclipse.packager Highest Product pom name Eclipse Packager :: RPM High Product pom parent-artifactid packager Medium Version file version 0.19.0 High Version pom version 0.19.0 Highest
packageurl-java-1.4.1.jarDescription:
The official Java implementation of the PackageURL specification. PackageURL (purl) is a minimal
specification for describing a package via a "mostly universal" URL.
License:
MIT: https://opensource.org/licenses/MIT File Path: /home/andrii/.m2/repository/com/github/package-url/packageurl-java/1.4.1/packageurl-java-1.4.1.jar
MD5: f8b3a23e6402d317b612251c83d292e7
SHA1: 0a0d1009191c1cf6b04f40d26e4717596f3a90e0
SHA256: 8e23280221afd1e6561d433dfb133252cd287167acb0eca5a991667118ff10a2
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name packageurl-java High Vendor jar package name github Highest Vendor jar package name packageurl Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid packageurl-java Highest Vendor pom artifactid packageurl-java Low Vendor pom developer email Steve.Springett@owasp.org Low Vendor pom developer name Steve Springett Medium Vendor pom developer org OWASP Medium Vendor pom developer org URL http://www.owasp.org/ Medium Vendor pom groupid com.github.package-url Highest Vendor pom name Package URL High Vendor pom url package-url/packageurl-java Highest Product file name packageurl-java High Product jar package name github Highest Product jar package name packageurl Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid packageurl-java Highest Product pom developer email Steve.Springett@owasp.org Low Product pom developer name Steve Springett Low Product pom developer org OWASP Low Product pom developer org URL http://www.owasp.org/ Low Product pom groupid com.github.package-url Highest Product pom name Package URL High Product pom url package-url/packageurl-java High Version file version 1.4.1 High Version pom version 1.4.1 Highest
pagination-1f6ff1e0.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/pagination-1f6ff1e0.jsMD5: b9801badbec1a79668fd4e016dd38cebSHA1: dd9f790794ab2b1bcc3d8ef81836793671ef7edaSHA256: db9f4f2ad4e53dd7c66217674f7641789f410ac09d39576027f9699ba395ab9cReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
pagination.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/pagination.jsMD5: c58053687f2fde941b07ce381bf3cc5eSHA1: 4b49fd4e7533d40dc09bb1ffbe4a5669c54bd1ebSHA256: 6b9a624a51b879838a481c3fa4b6868c32356b746e25e96ae1a1a0dc0f5dcc20Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
panopticon-api-1.0.3.jarDescription:
This is the module exposing APIs related to Panopticon File Path: /home/andrii/.m2/repository/com/atlassian/plugins/panopticon-api/1.0.3/panopticon-api-1.0.3.jarMD5: 540fdf25ed9de58dd62c218d11f4c4ceSHA1: 3f546a43a64ce31370c9419c797315fd29184130SHA256: b252fd86852eadea678ba168e3d8f437c578b0613f4281a1a94132a4e7bf0279Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name panopticon-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name entity Low Vendor jar package name plugins Highest Vendor jar package name plugins Low Vendor pom artifactid panopticon-api Highest Vendor pom artifactid panopticon-api Low Vendor pom groupid com.atlassian.plugins Highest Vendor pom name Atlassian Crowd License Management - Panopticon (API) High Vendor pom parent-artifactid panopticon-parent Low Product file name panopticon-api High Product jar package name atlassian Highest Product jar package name entity Low Product jar package name plugins Highest Product jar package name plugins Low Product pom artifactid panopticon-api Highest Product pom groupid com.atlassian.plugins Highest Product pom name Atlassian Crowd License Management - Panopticon (API) High Product pom parent-artifactid panopticon-parent Medium Version file version 1.0.3 High Version pom version 1.0.3 Highest
CVE-2016-6496 suppress
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning. CWE-20 Improper Input Validation
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-26136 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in authentication bypass and cross-site scripting. Atlassian has released updates that fix the root cause of this vulnerability, but has not exhaustively enumerated all potential consequences of this vulnerability. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-287 Improper Authentication
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2012-2926 suppress
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible before 2.5.8, 2.6 before 2.6.8, and 2.7 before 2.7.12; Bamboo before 3.3.4 and 3.4.x before 3.4.5; and Crowd before 2.0.9, 2.1 before 2.1.2, 2.2 before 2.2.9, 2.3 before 2.3.7, and 2.4 before 2.4.1 do not properly restrict the capabilities of third-party XML parsers, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via unspecified vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-26137 suppress
A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Filters to be invoked when the application processes requests or responses. Atlassian has confirmed and fixed the only known security issue associated with this vulnerability: Cross-origin resource sharing (CORS) bypass. Sending a specially crafted HTTP request can invoke the Servlet Filter used to respond to CORS requests, resulting in a CORS bypass. An attacker that can trick a user into requesting a malicious URL can access the vulnerable application with the victim’s permissions. Atlassian Bamboo versions are affected before 8.0.9, from 8.1.0 before 8.1.8, and from 8.2.0 before 8.2.4. Atlassian Bitbucket versions are affected before 7.6.16, from 7.7.0 before 7.17.8, from 7.18.0 before 7.19.5, from 7.20.0 before 7.20.2, from 7.21.0 before 7.21.2, and versions 8.0.0 and 8.1.0. Atlassian Confluence versions are affected before 7.4.17, from 7.5.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and version 7.21.0. Atlassian Crowd versions are affected before 4.3.8, from 4.4.0 before 4.4.2, and version 5.0.0. Atlassian Fisheye and Crucible versions before 4.8.10 are affected. Atlassian Jira versions are affected before 8.13.22, from 8.14.0 before 8.20.10, and from 8.21.0 before 8.22.4. Atlassian Jira Service Management versions are affected before 4.13.22, from 4.14.0 before 4.20.10, and from 4.21.0 before 4.22.4. CWE-346 Origin Validation Error
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2017-18105 suppress
The console login resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers, who have previously obtained a user's JSESSIONID cookie, to gain access to some of the built-in and potentially third party rest resources via a session fixation vulnerability. CWE-384 Session Fixation
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2018-20238 suppress
Various rest resources in Atlassian Crowd before version 3.2.7 and from version 3.3.0 before version 3.3.4 allow remote attackers to authenticate using an expired user session via an insufficient session expiration vulnerability. CWE-384 Session Fixation
CVSSv2:
Base Score: MEDIUM (5.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-18106 suppress
The identifier_hash for a session token in Atlassian Crowd before version 2.9.1 could potentially collide with an identifier_hash for another user or a user in a different directory, this allows remote attackers who can authenticate to Crowd or an application using Crowd for authentication to gain access to another user's session provided they can make their identifier hash collide with another user's session identifier hash. CWE-287 Improper Authentication
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
CVE-2019-20104 suppress
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote attackers to perform a Denial of Service attack via an XML Entity Expansion vulnerability. CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2019-20902 suppress
Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from before version 3.4.6 and from 3.5.0 before 3.5.1. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-18108 suppress
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
CVE-2017-18107 suppress
Various resources in the Crowd Demo application of Atlassian Crowd before version 3.1.1 allow remote attackers to modify add, modify and delete users & groups via a Cross-site request forgery (CSRF) vulnerability. Please be aware that the Demo application is not enabled by default. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions:
CVE-2017-18110 suppress
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to read files from the filesystem via a XXE vulnerability. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2017-18109 suppress
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect. CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-20239 suppress
Application Links before version 5.0.11, from version 5.1.0 before 5.2.10, from version 5.3.0 before 5.3.6, from version 5.4.0 before 5.4.12, and from version 6.0.0 before 6.0.4 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the applinkStartingUrl parameter. The product is used as a plugin in various Atlassian products where the following are affected: Confluence before version 6.15.2, Crucible before version 4.7.0, Crowd before version 3.4.3, Fisheye before version 4.7.0, Jira before version 7.13.3 and 8.x before 8.1.0. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-36240 suppress
The ResourceDownloadRewriteRule class in Crowd before version 4.0.4, and from version 4.1.0 before 4.1.2 allowed unauthenticated remote attackers to read arbitrary files within WEB-INF and META-INF directories via an incorrect path access check. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2016-10740 suppress
Various resources in Atlassian Crowd before version 2.10.1 allow remote attackers with administration rights to learn the passwords of configured LDAP directories by examining the responses to requests for these resources. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.9) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2019-15005 suppress
The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate periodic log scans and send the results to a user-specified email address due to a missing authorization check. The email message may contain configuration information about the application that the plugin is installed into. A vulnerable version of the plugin is included with Bitbucket Server / Data Center before 6.6.0, Confluence Server / Data Center before 7.0.1, Jira Server / Data Center before 8.3.2, Crowd / Crowd Data Center before 3.6.0, Fisheye before 4.7.2, Crucible before 4.7.2, and Bamboo before 6.10.2. CWE-862 Missing Authorization
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
pdfbox-2.0.24.jarDescription:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/pdfbox/pdfbox/2.0.24/pdfbox-2.0.24.jar
MD5: 9e97fc59c662738a5fb82dcc447d1e2f
SHA1: cb562ee5f43e29415af4477e62fbe668ef88d18b
SHA256: 3c2c0553ec0e7533c490b4c952e1af113621de5275af6e380e11d0d9a0a4f3d6
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name pdfbox High Vendor jar package name apache Highest Vendor jar package name pdfbox Highest Vendor Manifest automatic-module-name org.apache.pdfbox Medium Vendor Manifest bundle-docurl http://pdfbox.apache.org Low Vendor Manifest bundle-symbolicname org.apache.pdfbox Medium Vendor Manifest implementation-url https://www.apache.org/pdfbox-parent/pdfbox/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid pdfbox Highest Vendor pom artifactid pdfbox Low Vendor pom groupid org.apache.pdfbox Highest Vendor pom name Apache PDFBox High Vendor pom parent-artifactid pdfbox-parent Low Product file name pdfbox High Product jar package name apache Highest Product jar package name filter Highest Product jar package name pdfbox Highest Product jar package name version Highest Product Manifest automatic-module-name org.apache.pdfbox Medium Product Manifest bundle-docurl http://pdfbox.apache.org Low Product Manifest Bundle-Name Apache PDFBox Medium Product Manifest bundle-symbolicname org.apache.pdfbox Medium Product Manifest Implementation-Title Apache PDFBox High Product Manifest implementation-url https://www.apache.org/pdfbox-parent/pdfbox/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache PDFBox Medium Product pom artifactid pdfbox Highest Product pom groupid org.apache.pdfbox Highest Product pom name Apache PDFBox High Product pom parent-artifactid pdfbox-parent Medium Version file version 2.0.24 High Version Manifest Bundle-Version 2.0.24 High Version Manifest Implementation-Version 2.0.24 High Version pom version 2.0.24 Highest
pecoff4j-0.0.2.1.jarDescription:
PE/COFF 4J is a java engineering library for portable executables, the format used by Windows. License:
Common Public 1.0: https://github.com/kichik/pecoff4j/blob/master/cpl-v10.html File Path: /home/andrii/.m2/repository/org/whitesource/pecoff4j/0.0.2.1/pecoff4j-0.0.2.1.jar
MD5: b7cfcbf8cd6adb01bbe4c2df9b15be60
SHA1: a1ff9aa49167ae52e42dcc532f9e81728e057a45
SHA256: 847373828e0490babdfaed2b048ed3908dc1a8de82d4c8e6ebab9bfd0a294ed6
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name pecoff4j High Vendor jar package name boris Low Vendor jar package name pe Highest Vendor jar package name pecoff4j Highest Vendor jar package name pecoff4j Low Vendor pom artifactid pecoff4j Highest Vendor pom artifactid pecoff4j Low Vendor pom developer id adutra Medium Vendor pom developer name Amir Szekely Medium Vendor pom groupid org.whitesource Highest Vendor pom name pecoff4j High Vendor pom url whitesource/pecoff4j-maven Highest Product file name pecoff4j High Product jar package name pe Highest Product jar package name pecoff4j Highest Product jar package name pecoff4j Low Product pom artifactid pecoff4j Highest Product pom developer id adutra Low Product pom developer name Amir Szekely Low Product pom groupid org.whitesource Highest Product pom name pecoff4j High Product pom url whitesource/pecoff4j-maven High Version file version 0.0.2.1 High Version pom version 0.0.2.1 Highest
plexus-cipher-1.4.jarFile Path: /home/andrii/.m2/repository/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.jarMD5: 7b2d6fcf0d5800d5b1ce09d98d98dcafSHA1: 50ade46f23bb38cd984b4ec560c46223432aac38SHA256: 5a15fdba22669e0fdd06e10dcce6320879e1f7398fbc910cd0677b50672a78c4Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-cipher High Vendor jar package name cipher Highest Vendor jar package name components Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor pom artifactid plexus-cipher Highest Vendor pom artifactid plexus-cipher Low Vendor pom groupid org.sonatype.plexus Highest Vendor pom name Plexus Cipher: encryption/decryption Component High Vendor pom parent-artifactid spice-parent Low Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom url http://spice.sonatype.org/${project.artifactId} Highest Product file name plexus-cipher High Product jar package name cipher Highest Product jar package name cipher Low Product jar package name components Low Product jar package name plexus Highest Product jar package name plexus Low Product jar package name sonatype Highest Product pom artifactid plexus-cipher Highest Product pom groupid org.sonatype.plexus Highest Product pom name Plexus Cipher: encryption/decryption Component High Product pom parent-artifactid spice-parent Medium Product pom parent-groupid org.sonatype.spice Medium Product pom url http://spice.sonatype.org/${project.artifactId} Medium Version file version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest
plexus-classworlds-2.2.3.jarDescription:
A class loader framework File Path: /home/andrii/.m2/repository/org/codehaus/plexus/plexus-classworlds/2.2.3/plexus-classworlds-2.2.3.jarMD5: e6673b3089c11931211b77d24bbc4f8eSHA1: 93b34d7a40ed56fe33274480c5792b656d3697a9SHA256: 7d95ad21733b060bfda2142b62439a196bde7644f9f127c299ae86d92179b518Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-classworlds High Vendor jar package name classworlds Highest Vendor jar package name classworlds Low Vendor jar package name codehaus Highest Vendor jar package name codehaus Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor pom artifactid plexus-classworlds Highest Vendor pom artifactid plexus-classworlds Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Classworlds High Vendor pom parent-artifactid plexus Low Product file name plexus-classworlds High Product jar package name classworlds Highest Product jar package name classworlds Low Product jar package name codehaus Highest Product jar package name plexus Highest Product jar package name plexus Low Product pom artifactid plexus-classworlds Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Classworlds High Product pom parent-artifactid plexus Medium Version file version 2.2.3 High Version pom parent-version 2.2.3 Low Version pom version 2.2.3 Highest
plexus-component-annotations-2.0.0.jarDescription:
Plexus Component "Java 5" Annotations, to describe plexus components properties in java sources with
standard annotations instead of javadoc annotations.
File Path: /home/andrii/.m2/repository/org/codehaus/plexus/plexus-component-annotations/2.0.0/plexus-component-annotations-2.0.0.jarMD5: be18d50372002ba958de0ae4850b18a7SHA1: 6897b9fa8b67c900b52996f845e2d179eea13441SHA256: 405eef6fc9188241ec88579c3e473f5c8997455c69bcd62e142492aca15106bcReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-component-annotations High Vendor jar package name annotations Highest Vendor jar package name codehaus Highest Vendor jar package name codehaus Low Vendor jar package name component Highest Vendor jar package name component Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor pom artifactid plexus-component-annotations Highest Vendor pom artifactid plexus-component-annotations Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus :: Component Annotations High Vendor pom parent-artifactid plexus-containers Low Product file name plexus-component-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name codehaus Highest Product jar package name component Highest Product jar package name component Low Product jar package name plexus Highest Product jar package name plexus Low Product pom artifactid plexus-component-annotations Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus :: Component Annotations High Product pom parent-artifactid plexus-containers Medium Version file version 2.0.0 High Version pom version 2.0.0 Highest
plexus-interpolation-1.14.jarFile Path: /home/andrii/.m2/repository/org/codehaus/plexus/plexus-interpolation/1.14/plexus-interpolation-1.14.jarMD5: f92db8b194fc417d72cc74c428afacf8SHA1: c88dd864fe8b8256c25558ce7cd63be66ba07693SHA256: 7fc63378d3e84663619b9bedace9f9fe78b276c2be3c62ca2245449294c84176Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-interpolation High Vendor jar package name codehaus Highest Vendor jar package name codehaus Low Vendor jar package name interpolation Highest Vendor jar package name interpolation Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor pom artifactid plexus-interpolation Highest Vendor pom artifactid plexus-interpolation Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Interpolation API High Vendor pom parent-artifactid plexus-components Low Product file name plexus-interpolation High Product jar package name codehaus Highest Product jar package name interpolation Highest Product jar package name interpolation Low Product jar package name plexus Highest Product jar package name plexus Low Product pom artifactid plexus-interpolation Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Interpolation API High Product pom parent-artifactid plexus-components Medium Version file version 1.14 High Version pom parent-version 1.14 Low Version pom version 1.14 Highest
plexus-sec-dispatcher-1.4.jarFile Path: /home/andrii/.m2/repository/org/sonatype/plexus/plexus-sec-dispatcher/1.4/plexus-sec-dispatcher-1.4.jarMD5: 0a46e5bc9bc2fbd3b68091066aff2737SHA1: 43fde524e9b94c883727a9fddb8669181b890ea7SHA256: da73e32b58132e64daf12269fd9d011c0b303f234840f179908725a632b6b57cReferenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-sec-dispatcher High Vendor jar package name components Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor jar package name sec Highest Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor pom artifactid plexus-sec-dispatcher Highest Vendor pom artifactid plexus-sec-dispatcher Low Vendor pom groupid org.sonatype.plexus Highest Vendor pom name Plexus Security Dispatcher Component High Vendor pom parent-artifactid spice-parent Low Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom url http://spice.sonatype.org/${project.artifactId} Highest Product file name plexus-sec-dispatcher High Product jar package name components Low Product jar package name plexus Highest Product jar package name plexus Low Product jar package name sec Highest Product jar package name sec Low Product jar package name sonatype Highest Product pom artifactid plexus-sec-dispatcher Highest Product pom groupid org.sonatype.plexus Highest Product pom name Plexus Security Dispatcher Component High Product pom parent-artifactid spice-parent Medium Product pom parent-groupid org.sonatype.spice Medium Product pom url http://spice.sonatype.org/${project.artifactId} Medium Version file version 1.4 High Version pom parent-version 1.4 Low Version pom version 1.4 Highest
plexus-utils-3.5.0.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines, XML and
more.
File Path: /home/andrii/.m2/repository/org/codehaus/plexus/plexus-utils/3.5.0/plexus-utils-3.5.0.jarMD5: a692f46bd0bb8e23a76f254077fbb085SHA1: ff9f0881396a06b31ff548048256e9a7c8f1207aSHA256: e5182eb3e5e73cf89d6426ca7f5cbae2e72819b9bed68d872f80f3b535269cb8Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-utils High Vendor jar package name codehaus Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest multi-release true Low Vendor pom artifactid plexus-utils Highest Vendor pom artifactid plexus-utils Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Product file name plexus-utils High Product jar package name codehaus Highest Product jar package name org Highest Product jar package name plexus Highest Product jar package name xml Highest Product Manifest build-jdk-spec 11 Low Product Manifest multi-release true Low Product pom artifactid plexus-utils Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Common Utilities High Product pom parent-artifactid plexus Medium Version file version 3.5.0 High Version pom parent-version 3.5.0 Low Version pom version 3.5.0 Highest
policy-2.7.5.jarDescription:
WS-Policy implementation for Project Metro License:
Dual License: CDDL 1.0 and GPL V2 with Classpath Exception: http://glassfish.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/com/sun/xml/ws/policy/2.7.5/policy-2.7.5.jar
MD5: 5d3ce1646312f2e5dde0fde0c3028edd
SHA1: 5e3ec7b4a9d6b3ae800e382de16e4663fab67f41
SHA256: 34e254f415b94eab04bad700e9109359b60e01bcb9a7873bc2c934c424a2f965
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name policy High Vendor hint analyzer vendor web services Medium Vendor jar package name policy Highest Vendor jar package name sun Highest Vendor jar package name ws Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname com.sun.xml.ws.policy Medium Vendor Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Vendor Manifest implementation-url http://policy.java.net/ Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id com.sun.xml.ws Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor pom artifactid policy Highest Vendor pom artifactid policy Low Vendor pom groupid com.sun.xml.ws Highest Vendor pom name policy High Vendor pom organization name Oracle Corporation High Vendor pom organization url http://www.oracle.com/ Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://policy.java.net/ Highest Product file name policy High Product hint analyzer product web services Medium Product jar package name policy Highest Product jar package name sun Highest Product jar package name ws Highest Product jar package name xml Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name policy Medium Product Manifest bundle-symbolicname com.sun.xml.ws.policy Medium Product Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Product Manifest Implementation-Title policy High Product Manifest implementation-url http://policy.java.net/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom artifactid policy Highest Product pom groupid com.sun.xml.ws Highest Product pom name policy High Product pom organization name Oracle Corporation Low Product pom organization url http://www.oracle.com/ Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://policy.java.net/ Medium Version file version 2.7.5 High Version Manifest Bundle-Version 2.7.5 High Version Manifest Implementation-Version 2.7.5 High Version pom parent-version 2.7.5 Low Version pom version 2.7.5 Highest
postgresql-42.2.18.jarDescription:
PostgreSQL JDBC Driver Postgresql License:
BSD-2-Clause: https://jdbc.postgresql.org/about/license.html File Path: /home/andrii/.m2/repository/org/postgresql/postgresql/42.2.18/postgresql-42.2.18.jar
MD5: d6895bb05ac7b9c85c4e89f3880127e3
SHA1: a0a9c1d43c7727eeaf1b729477891185d3c71751
SHA256: 0c891979f1eb2fe44432da114d09760b5063dad9e669ac0ac6b0b6bfb91bb3ba
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name postgresql High Vendor jar package name driver Highest Vendor jar package name jdbc Highest Vendor jar package name postgresql Highest Vendor Manifest automatic-module-name org.postgresql.jdbc Medium Vendor Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High Vendor Manifest Implementation-Vendor-Id org.postgresql Medium Vendor Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Vendor Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.8))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid postgresql Highest Vendor pom artifactid postgresql Low Vendor pom developer id bokken Medium Vendor pom developer id davecramer Medium Vendor pom developer id jurka Medium Vendor pom developer id oliver Medium Vendor pom developer id ringerc Medium Vendor pom developer id vlsi Medium Vendor pom developer name Brett Okken Medium Vendor pom developer name Craig Ringer Medium Vendor pom developer name Dave Cramer Medium Vendor pom developer name Kris Jurka Medium Vendor pom developer name Oliver Jowett Medium Vendor pom developer name Vladimir Sitnikov Medium Vendor pom groupid org.postgresql Highest Vendor pom name PostgreSQL JDBC Driver High Vendor pom organization name PostgreSQL Global Development Group High Vendor pom organization url https://jdbc.postgresql.org/ Medium Vendor pom url https://jdbc.postgresql.org Highest Product file name postgresql High Product hint analyzer product pgjdbc Highest Product hint analyzer product postgresql_jdbc_driver Highest Product jar package name driver Highest Product jar package name jdbc Highest Product jar package name osgi Highest Product jar package name postgresql Highest Product jar package name version Highest Product Manifest automatic-module-name org.postgresql.jdbc Medium Product Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium Product Manifest bundle-symbolicname org.postgresql.jdbc Medium Product Manifest Implementation-Title PostgreSQL JDBC Driver High Product Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Product Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.8))" Low Product Manifest specification-title JDBC Medium Product pom artifactid postgresql Highest Product pom developer id bokken Low Product pom developer id davecramer Low Product pom developer id jurka Low Product pom developer id oliver Low Product pom developer id ringerc Low Product pom developer id vlsi Low Product pom developer name Brett Okken Low Product pom developer name Craig Ringer Low Product pom developer name Dave Cramer Low Product pom developer name Kris Jurka Low Product pom developer name Oliver Jowett Low Product pom developer name Vladimir Sitnikov Low Product pom groupid org.postgresql Highest Product pom name PostgreSQL JDBC Driver High Product pom organization name PostgreSQL Global Development Group Low Product pom organization url https://jdbc.postgresql.org/ Low Product pom url https://jdbc.postgresql.org Medium Version file version 42.2.18 High Version Manifest Bundle-Version 42.2.18 High Version Manifest Implementation-Version 42.2.18 High Version pom version 42.2.18 Highest
CVE-2022-21724 suppress
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue. CWE-665 Improper Initialization
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-26520 (OSSINDEX) suppress
** DISPUTED ** In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties. CWE-20 Improper Input Validation
CVSSv2:
Base Score: HIGH (9.8) Vector: /AV:N/AC:L/Au:/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.postgresql:postgresql:42.2.18:*:*:*:*:*:*:* CVE-2022-31197 suppress
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to SQL injection. This could lead to executing additional SQL commands as the application's JDBC user. User applications that do not invoke the `ResultSet.refreshRow()` method are not impacted. User application that do invoke that method are impacted if the underlying database that they are querying via their JDBC application may be under the control of an attacker. The attack requires the attacker to trick the user into executing SQL against a table name who's column names would contain the malicious SQL and subsequently invoke the `refreshRow()` method on the ResultSet. Note that the application's JDBC user and the schema owner need not be the same. A JDBC application that executes as a privileged user querying database schemas owned by potentially malicious less-privileged users would be vulnerable. In that situation it may be possible for the malicious user to craft a schema that causes the application to execute commands as the privileged user. Patched versions will be released as `42.2.26` and `42.4.1`. Users are advised to upgrade. There are no known workarounds for this issue. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.0) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
propertyset-1.3-21Nov03.jarFile Path: /home/andrii/.m2/repository/opensymphony/propertyset/1.3-21Nov03/propertyset-1.3-21Nov03.jarMD5: 32a2861ca3da31870e5477d2e881b8d5SHA1: 32f4c621ec0c300e3f616fdd231cf06dfecfd481SHA256: df71d0ebe127dbbca0b51a3eaffdc8e779363748a7dd8e947a9458f2e484131bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name propertyset High Vendor jar package name module Low Vendor jar package name opensymphony Highest Vendor jar package name opensymphony Low Vendor jar package name propertyset Highest Vendor jar package name propertyset Low Vendor pom artifactid propertyset Highest Vendor pom artifactid propertyset Low Vendor pom groupid opensymphony Highest Vendor pom name OS Property Set High Vendor pom url http://www.opensymphony.com/propertyset/ Highest Product file name propertyset High Product jar package name module Low Product jar package name opensymphony Highest Product jar package name propertyset Highest Product jar package name propertyset Low Product pom artifactid propertyset Highest Product pom groupid opensymphony Highest Product pom name OS Property Set High Product pom url http://www.opensymphony.com/propertyset/ Medium Version pom version 1.3-21Nov03 Highest
quartz-1.8.7-atlassian-3.jarFile Path: /home/andrii/.m2/repository/org/quartz-scheduler/quartz/1.8.7-atlassian-3/quartz-1.8.7-atlassian-3.jarMD5: e04fd26979dc7316859cb11caa64ffb9SHA1: 5746835468ac6f0270cf947c0865cd844bc58233SHA256: 1be790d79170ca293d00c626b7bee32ed2e84be839289e57f063b724b55709a3Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name quartz High Vendor hint analyzer vendor softwareag Highest Vendor jar package name job Highest Vendor jar package name quartz Highest Vendor jar package name quartz Low Vendor jar package name scheduler Highest Vendor pom artifactid quartz Highest Vendor pom artifactid quartz Low Vendor pom groupid org.quartz-scheduler Highest Vendor pom name Quartz Enterprise Job Scheduler High Vendor pom parent-artifactid quartz-parent Low Product file name quartz High Product jar package name job Highest Product jar package name quartz Highest Product jar package name scheduler Highest Product pom artifactid quartz Highest Product pom groupid org.quartz-scheduler Highest Product pom name Quartz Enterprise Job Scheduler High Product pom parent-artifactid quartz-parent Medium Version pom version 1.8.7-atlassian-3 Highest
CVE-2019-13990 suppress
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
radeox-1.0b2-forked-22Apr2004.jarFile Path: /home/andrii/.m2/repository/radeox/radeox/1.0b2-forked-22Apr2004/radeox-1.0b2-forked-22Apr2004.jarMD5: 627cda3b3e1c3e85500b9e403b92e5a4SHA1: f42bc7d5da8cd90b291bef9319f77676aa3360c4SHA256: e10dc6d5bb70aaf78cf054105f6c46035b0b852b914b10dbe069e6cb2961ed33Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name radeox High Vendor jar package name radeox Highest Vendor jar package name radeox Low Vendor pom artifactid radeox Highest Vendor pom artifactid radeox Low Vendor pom groupid radeox Highest Product file name radeox High Product jar package name radeox Highest Product pom artifactid radeox Highest Product pom groupid radeox Highest Version pom version 1.0b2-forked-22Apr2004 Highest
react-dom.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/react-dom.jsMD5: c75579608761cc3abf37385e21581d91SHA1: b17fc559e153353c62d6e48e73c45441eda786b1SHA256: 33fe01204d07db14efee015c2487eaaf82a12c5033052884339b59a569e664a8Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
react.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/react.jsMD5: a5a6549f21d56efcd4568562b1ec6bd3SHA1: 10b3c1232656fd8bf890a6b90df0db5c00cd7163SHA256: f2fd2080b86c03a7e574a8e0dcfa57fef206afb513fd869f18d72269d3e63424Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
retirejs-core-3.0.4.jarFile Path: /home/andrii/.m2/repository/com/h3xstream/retirejs/retirejs-core/3.0.4/retirejs-core-3.0.4.jarMD5: ed40efbc46913c245e5a29e11f74eba4SHA1: 47e3a13cf17e40f03b8f5713f261f164d63bee9aSHA256: ef429049b1e828bfce0a98869765a7f10d7daf41acb03201fcd3404f424d0c37Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name retirejs-core High Vendor jar package name h3xstream Highest Vendor jar package name h3xstream Low Vendor jar package name repo Low Vendor jar package name retirejs Highest Vendor jar package name retirejs Low Vendor pom artifactid retirejs-core Highest Vendor pom artifactid retirejs-core Low Vendor pom groupid com.h3xstream.retirejs Highest Vendor pom parent-artifactid retirejs-root-pom Low Product file name retirejs-core High Product jar package name h3xstream Highest Product jar package name repo Low Product jar package name retirejs Highest Product jar package name retirejs Low Product pom artifactid retirejs-core Highest Product pom groupid com.h3xstream.retirejs Highest Product pom parent-artifactid retirejs-root-pom Medium Version file version 3.0.4 High Version pom version 3.0.4 Highest
rome-1.0.jarDescription:
All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it
easy to work in Java with most syndication formats. Today it accepts all flavors of RSS
(0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes
a set of parsers and generators for the various flavors of feeds, as well as converters
to convert from one format to another. The parsers can give you back Java objects that
are either specific for the format you want to work with, or a generic normalized
SyndFeed object that lets you work on with the data without bothering about the
underlying format. File Path: /home/andrii/.m2/repository/rome/rome/1.0/rome-1.0.jarMD5: 53d38c030287b939f4e6d745ba1269a7SHA1: 022b33347f315833e9348cec2751af1a5d5656e4SHA256: cd2cfd3b4e2af9eb8fb09d6a2384328e5b9cf1138bccaf7e31f971e5f7678c6cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name rome High Vendor jar package name atom Highest Vendor jar package name rss Highest Vendor jar package name sun Highest Vendor jar package name syndication Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl http://java.sun.com/ Low Vendor Manifest bundle-symbolicname rome.rome Medium Vendor Manifest embed-directory META-INF/lib Low Vendor Manifest embed-transitive true Low Vendor Manifest originally-created-by 1.6.0_10 (Sun Microsystems Inc.) Low Vendor pom artifactid rome Highest Vendor pom artifactid rome Low Vendor pom developer name Alejandro Abdelnur Medium Vendor pom developer name Elaine Chien Medium Vendor pom developer name Patrick Chanezon Medium Vendor pom groupid rome Highest Vendor pom name ROME, RSS and atOM utilitiEs for Java High Vendor pom organization name Sun Microsystems High Vendor pom organization url http://java.sun.com/ Medium Vendor pom url https://rome.dev.java.net/ Highest Product file name rome High Product jar package name atom Highest Product jar package name rss Highest Product jar package name sun Highest Product jar package name syndication Highest Product Manifest bundle-docurl http://java.sun.com/ Low Product Manifest Bundle-Name ROME, RSS and atOM utilitiEs for Java Medium Product Manifest bundle-symbolicname rome.rome Medium Product Manifest embed-directory META-INF/lib Low Product Manifest embed-transitive true Low Product Manifest originally-created-by 1.6.0_10 (Sun Microsystems Inc.) Low Product pom artifactid rome Highest Product pom developer name Alejandro Abdelnur Low Product pom developer name Elaine Chien Low Product pom developer name Patrick Chanezon Low Product pom groupid rome Highest Product pom name ROME, RSS and atOM utilitiEs for Java High Product pom organization name Sun Microsystems Low Product pom organization url http://java.sun.com/ Low Product pom url https://rome.dev.java.net/ Medium Version file version 1.0 High Version Manifest Bundle-Version 1.0 High Version pom version 1.0 Highest
pkg:maven/rome/rome@1.0 (Confidence :High)cpe:2.3:a:oracle:system_utilities:1.0:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:oracle:utilities_framework:1.0:*:*:*:*:*:*:* (Confidence :Low) suppress runtime-20070801.jarFile Path: /home/andrii/.m2/repository/org/eclipse/core/runtime/20070801/runtime-20070801.jarMD5: 5bb33b1c934e4a6c6536b31e73e2f9f0SHA1: 474e99ed838d5721569d658b68025134f920278fSHA256: 7bdc0ec00ed11f7413f979120ef34639536a2341671b7956cf635c762cdc20abReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name runtime-20070801 High Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name runtime Highest Vendor jar package name runtime Low Vendor pom artifactid runtime Highest Vendor pom artifactid runtime Low Vendor pom groupid org.eclipse.core Highest Product file name runtime-20070801 High Product jar package name core Highest Product jar package name core Low Product jar package name eclipse Highest Product jar package name runtime Highest Product jar package name runtime Low Product pom artifactid runtime Highest Product pom groupid org.eclipse.core Highest Version file version 20070801 Medium Version pom version 20070801 Highest
saaj-impl-1.5.0.jarDescription:
Open source Reference Implementation of JSR-67: SOAP with Attachments API for Java (SAAJ MR: 1.4)
License:
CDDL + GPLv2 with classpath exception: https://oss.oracle.com/licenses/CDDL+GPL-1.1 File Path: /home/andrii/.m2/repository/com/sun/xml/messaging/saaj/saaj-impl/1.5.0/saaj-impl-1.5.0.jar
MD5: 26c5736bd15fa374c231238683d475a2
SHA1: 83fe72c41bab1acc351185bdbfea6a3e67c4960b
SHA256: 24b944ff858055c0c5680bce947b9bec8283bef1132058d4d47ff5478b543c9f
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name saaj-impl High Vendor jar package name messaging Highest Vendor jar package name messaging Low Vendor jar package name saaj Highest Vendor jar package name sun Highest Vendor jar package name sun Low Vendor jar package name xml Highest Vendor jar package name xml Low Vendor jar (hint) package name oracle Highest Vendor jar (hint) package name oracle Low Vendor pom artifactid saaj-impl Highest Vendor pom artifactid saaj-impl Low Vendor pom developer email Lukas.Jungmann@oracle.com Low Vendor pom developer email Roman.Grigoriadi@oracle.com Low Vendor pom developer id bravehorsie Medium Vendor pom developer id lukasj Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer name Roman Grigoriadi Medium Vendor pom groupid com.sun.xml.messaging.saaj Highest Vendor pom organization name Oracle High Vendor pom organization url http://www.oracle.com/ Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom (hint) organization name sun High Product file name saaj-impl High Product jar package name messaging Highest Product jar package name messaging Low Product jar package name saaj Highest Product jar package name saaj Low Product jar package name sun Highest Product jar package name xml Highest Product jar package name xml Low Product pom artifactid saaj-impl Highest Product pom developer email Lukas.Jungmann@oracle.com Low Product pom developer email Roman.Grigoriadi@oracle.com Low Product pom developer id bravehorsie Low Product pom developer id lukasj Low Product pom developer name Lukas Jungmann Low Product pom developer name Roman Grigoriadi Low Product pom groupid com.sun.xml.messaging.saaj Highest Product pom organization name Oracle Low Product pom organization url http://www.oracle.com/ Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Version file version 1.5.0 High Version pom parent-version 1.5.0 Low Version pom version 1.5.0 Highest
sal-core-4.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/sal/sal-core/4.1.0/sal-core-4.1.0.jarMD5: 0c18cf6f17a2e455cceb4d17b79f7950SHA1: 281b6a08c9d280ce000024d7107a754b332b8a27SHA256: fd21a273de2f7fa89adb8b7206357e7a7b522abd71a6177bc8df3a30fa6c9812Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name sal-core High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name sal Highest Vendor jar package name sal Low Vendor pom artifactid sal-core Highest Vendor pom artifactid sal-core Low Vendor pom groupid com.atlassian.sal Highest Vendor pom name Shared Application Access Layer Core High Vendor pom parent-artifactid sal-parent Low Product file name sal-core High Product jar package name atlassian Highest Product jar package name core Highest Product jar package name core Low Product jar package name sal Highest Product jar package name sal Low Product pom artifactid sal-core Highest Product pom groupid com.atlassian.sal Highest Product pom name Shared Application Access Layer Core High Product pom parent-artifactid sal-parent Medium Version file version 4.1.0 High Version pom version 4.1.0 Highest
Related Dependencies sal-api-4.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/sal/sal-api/4.1.0/sal-api-4.1.0.jar MD5: 4dd54dbf99ca93267778bdb7561c08d4 SHA1: 7e07fa2e2bafebde00a435692444d2c2d68ca008 SHA256: 6329cdd82ae8d6cb00858ff41772083370239e2b415c6819fbde36c57f2c6d8d pkg:maven/com.atlassian.sal/sal-api@4.1.0 sal-spi-4.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/sal/sal-spi/4.1.0/sal-spi-4.1.0.jar MD5: be660992bf60e0a177e9b013f5f4acba SHA1: 63c6e607e265efac96f2be59852342847e9fcd04 SHA256: 95ce05e63c967ed6f62ea38dacf7b88e541b66e31edf69a591e8cf1672fc3f0a pkg:maven/com.atlassian.sal/sal-spi@4.1.0 sal-spring-4.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/sal/sal-spring/4.1.0/sal-spring-4.1.0.jar MD5: da10adb459b7c5b3611a48fc6b396c75 SHA1: 81c081e9e02909dea1e50d17f966ac87cbe54015 SHA256: 18caee3b798e6ff4caf26db7306a0dc83d9c68a95019a87654e1bbbbffb168df pkg:maven/com.atlassian.sal/sal-spring@4.1.0 sal-trust-api-4.1.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/sal/sal-trust-api/4.1.0/sal-trust-api-4.1.0.jar MD5: 46b2f6492b2045f5001939d87dedefca SHA1: 8fa4e4a419989ca89266b1f333c0a58c1cc2bf48 SHA256: f4f683f32b664a2785c8a8b4d3b1acc32a6de7570605b495767e58aae6c72b7a pkg:maven/com.atlassian.sal/sal-trust-api@4.1.0 CVE-2020-26205 suppress
Sal is a multi-tenanted reporting dashboard for Munki with the ability to display information from Facter. In Sal through version 4.1.6 there is an XSS vulnerability on the machine_list view. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
select.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/select.jsMD5: 5eee816de5fc74668397fba29a806034SHA1: 4fd66d40d82d478bf6158a4df46e57a390953c9fSHA256: fb9f9c059d6c52e0a5548f47a74daf85fb56838a76e991d3c8a39ad32f2890dcReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
semver4j-3.1.0.jarDescription:
Semantic versioning for Java apps. License:
The MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /home/andrii/.m2/repository/com/vdurmont/semver4j/3.1.0/semver4j-3.1.0.jar
MD5: b39112afda0af7dba1f160f7284d402f
SHA1: 0de1248f09dfe8df3b021c84e0642ee222cceb13
SHA256: 0f33724dd012099f0737e3d9203e28f4a804435526998d4f5841993058651cb8
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name semver4j High Vendor jar package name semver4j Highest Vendor jar package name semver4j Low Vendor jar package name vdurmont Highest Vendor jar package name vdurmont Low Vendor pom artifactid semver4j Highest Vendor pom artifactid semver4j Low Vendor pom developer email vdurmont@gmail.com Low Vendor pom developer name Vincent DURMONT Medium Vendor pom groupid com.vdurmont Highest Vendor pom name semver4j High Vendor pom url vdurmont/semver4j Highest Product file name semver4j High Product jar package name semver4j Highest Product jar package name semver4j Low Product jar package name vdurmont Highest Product pom artifactid semver4j Highest Product pom developer email vdurmont@gmail.com Low Product pom developer name Vincent DURMONT Low Product pom groupid com.vdurmont Highest Product pom name semver4j High Product pom url vdurmont/semver4j High Version file version 3.1.0 High Version pom version 3.1.0 Highest
serializer-2.7.2.jarDescription:
Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input
SAX events.
File Path: /home/andrii/.m2/repository/xalan/serializer/2.7.2/serializer-2.7.2.jarMD5: e8325763fd4235f174ab7b72ed815db1SHA1: 24247f3bb052ee068971393bdb83e04512bb1c3cSHA256: e8f5b4340d3b12a0cfa44ac2db4be4e0639e479ae847df04c4ed8b521734bb4aReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name serializer High Vendor jar package name apache Highest Vendor jar package name serializer Highest Vendor jar package name xml Highest Vendor manifest: org/apache/xml/serializer/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xml/serializer/utils/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid serializer Highest Vendor pom artifactid serializer Low Vendor pom groupid xalan Highest Vendor pom name Xalan Java Serializer High Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://xml.apache.org/xalan-j/ Highest Product file name serializer High Product jar package name apache Highest Product jar package name serializer Highest Product jar package name utils Highest Product jar package name xml Highest Product manifest: org/apache/xml/serializer/ Implementation-Title org.apache.xml.serializer Medium Product manifest: org/apache/xml/serializer/ Specification-Title XSL Transformations (XSLT), at http://www.w3.org/TR/xslt Medium Product manifest: org/apache/xml/serializer/utils/ Implementation-Title org.apache.xml.serializer.utils Medium Product pom artifactid serializer Highest Product pom groupid xalan Highest Product pom name Xalan Java Serializer High Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://xml.apache.org/xalan-j/ Medium Version file version 2.7.2 High Version manifest: org/apache/xml/serializer/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/xml/serializer/utils/ Implementation-Version 2.7.2 Medium Version pom parent-version 2.7.2 Low Version pom version 2.7.2 Highest
CVE-2022-34169 suppress
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. The Apache Xalan Java project is dormant and in the process of being retired. No future releases of Apache Xalan Java to address this issue are expected. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan. CWE-681 Incorrect Conversion between Numeric Types
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
servlet-api-2.4.jarFile Path: /home/andrii/.m2/repository/javax/servlet/servlet-api/2.4/servlet-api-2.4.jarMD5: f6cf3fde0b992589ed3d87fa9674015fSHA1: 3fc542fe8bb8164e8d3e840fe7403bc0518053c0SHA256: 243f8b5577f59bffdd30fd15cc25fc13004a6b08773a61cc32e48726c3633b7cReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name servlet-api High Vendor jar package name javax Highest Vendor jar package name servlet Highest Vendor manifest: javax/servlet/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid servlet-api Highest Vendor pom artifactid servlet-api Low Vendor pom groupid javax.servlet Highest Product file name servlet-api High Product jar package name javax Highest Product jar package name servlet Highest Product manifest: javax/servlet/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/ Specification-Title Java API for Servlets Medium Product pom artifactid servlet-api Highest Product pom groupid javax.servlet Highest Version file version 2.4 High Version pom version 2.4 Highest
sisu-guice-2.1.7-noaop.jarDescription:
Guice is a lightweight dependency injection framework for Java 5 and above License:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/org/sonatype/sisu/sisu-guice/2.1.7/sisu-guice-2.1.7-noaop.jar
MD5: f1d341b68fc25c53321eb00cf87b82b0
SHA1: 8cb56e976b8e0e7b23f2969c32bef7b830c6d6ed
SHA256: 240113a2f22fd1f0b182b32baecf0e7876b3a8e41f3c4da3335eeb9ffb24b9f4
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name sisu-guice High Vendor jar package name google Low Vendor jar package name guice Highest Vendor jar package name inject Low Vendor jar package name internal Low Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Vendor Manifest bundle-symbolicname org.sonatype.sisu.sisu-guice-noaop Medium Vendor pom artifactid sisu-guice Highest Vendor pom groupid org.sonatype.sisu Highest Product file name sisu-guice High Product jar package name dependency Highest Product jar package name google Highest Product jar package name guice Highest Product jar package name inject Low Product jar package name internal Low Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Product Manifest Bundle-Name sisu-guice-noaop Medium Product Manifest bundle-symbolicname org.sonatype.sisu.sisu-guice-noaop Medium Product pom artifactid sisu-guice Highest Version file version 2.1.7 High Version pom version 2.1.7 Highest
sisu-inject-bean-1.4.2.jarLicense:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/sonatype/sisu/sisu-inject-bean/1.4.2/sisu-inject-bean-1.4.2.jar
MD5: 400f9ca3cb77d34f159127769cb89e92
SHA1: 5cf37202afbaae899d63dd51b46d173df650af1b
SHA256: fb3160e1e3a7852b441016dbcc97a34e3cf4eeb8ceb9e82edf2729439858f080
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name sisu-inject-bean High Vendor jar package name bean Highest Vendor jar package name guice Highest Vendor jar package name inject Highest Vendor jar package name sonatype Highest Vendor Manifest bundle-docurl http://www.sonatype.com Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor Manifest bundle-symbolicname org.sonatype.inject Medium Vendor pom artifactid sisu-inject-bean Highest Vendor pom artifactid sisu-inject-bean Low Vendor pom groupid org.sonatype.sisu Highest Vendor pom name Sisu - Inject (JSR330 bean support) High Vendor pom parent-artifactid guice-bean Low Vendor pom parent-groupid org.sonatype.sisu.inject Medium Product file name sisu-inject-bean High Product jar package name bean Highest Product jar package name guice Highest Product jar package name inject Highest Product jar package name sonatype Highest Product Manifest bundle-docurl http://www.sonatype.com Low Product Manifest Bundle-Name Sisu - Inject (JSR330 bean support) Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product Manifest bundle-symbolicname org.sonatype.inject Medium Product pom artifactid sisu-inject-bean Highest Product pom groupid org.sonatype.sisu Highest Product pom name Sisu - Inject (JSR330 bean support) High Product pom parent-artifactid guice-bean Medium Product pom parent-groupid org.sonatype.sisu.inject Medium Version file version 1.4.2 High Version Manifest Bundle-Version 1.4.2 High Version pom version 1.4.2 Highest
sisu-inject-plexus-1.4.2.jarLicense:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/sonatype/sisu/sisu-inject-plexus/1.4.2/sisu-inject-plexus-1.4.2.jar
MD5: 9c1bfd74a76af0757b348554d9a1facc
SHA1: 53d863ed4879d4a43ad7aee7bc63f935cc513353
SHA256: a65e27aefbe74102d73cd7e3c5c7637021d294a9e7f33132f3c782a76714d0a3
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name sisu-inject-plexus High Vendor jar package name guice Highest Vendor jar package name plexus Highest Vendor jar package name sonatype Highest Vendor Manifest bundle-docurl http://www.sonatype.com Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor Manifest bundle-symbolicname org.sonatype.inject.plexus Medium Vendor pom artifactid sisu-inject-plexus Highest Vendor pom artifactid sisu-inject-plexus Low Vendor pom groupid org.sonatype.sisu Highest Vendor pom name Sisu - Inject (Plexus bean support) High Vendor pom parent-artifactid guice-plexus Low Vendor pom parent-groupid org.sonatype.sisu.inject Medium Product file name sisu-inject-plexus High Product jar package name guice Highest Product jar package name plexus Highest Product jar package name sonatype Highest Product Manifest bundle-docurl http://www.sonatype.com Low Product Manifest Bundle-Name Sisu - Inject (Plexus bean support) Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product Manifest bundle-symbolicname org.sonatype.inject.plexus Medium Product pom artifactid sisu-inject-plexus Highest Product pom groupid org.sonatype.sisu Highest Product pom name Sisu - Inject (Plexus bean support) High Product pom parent-artifactid guice-plexus Medium Product pom parent-groupid org.sonatype.sisu.inject Medium Version file version 1.4.2 High Version Manifest Bundle-Version 1.4.2 High Version pom version 1.4.2 Highest
sitemesh-2.5-atlassian-6.jarDescription:
Atlassian's fork of SiteMesh File Path: /home/andrii/.m2/repository/opensymphony/sitemesh/2.5-atlassian-6/sitemesh-2.5-atlassian-6.jarMD5: 830e6bb6e62ff95b3733d69dbc60b643SHA1: daf95200790e362a39beab3a1243fbcae2177415SHA256: 0f57d14ce26088860c63fdd6bc7d7693d30f9a0528c9b93de73a431dc98bd97bReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name sitemesh High Vendor jar package name module Low Vendor jar package name opensymphony Highest Vendor jar package name opensymphony Low Vendor jar package name sitemesh Highest Vendor jar package name sitemesh Low Vendor pom artifactid sitemesh Highest Vendor pom artifactid sitemesh Low Vendor pom groupid opensymphony Highest Vendor pom name SiteMesh High Vendor pom url atlassian/sitemesh2 Highest Product file name sitemesh High Product jar package name module Low Product jar package name opensymphony Highest Product jar package name sitemesh Highest Product jar package name sitemesh Low Product pom artifactid sitemesh Highest Product pom groupid opensymphony Highest Product pom name SiteMesh High Product pom url atlassian/sitemesh2 High Version pom version 2.5-atlassian-6 Highest
slf4j-api-1.7.25.jarDescription:
The slf4j API File Path: /home/andrii/.m2/repository/org/slf4j/slf4j-api/1.7.25/slf4j-api-1.7.25.jarMD5: caafe376afb7086dcbee79f780394ca3SHA1: da76ca59f6a57ee3102f8f9bd9cee742973efa8aSHA256: 18c4a0095d5c1da6b817592e767bb23d29dd2f560ad74df75ff3961dbde25b79Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor jar package name slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor pom artifactid slf4j-api Highest Vendor pom artifactid slf4j-api Low Vendor pom groupid org.slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name slf4j-api High Product jar package name slf4j Highest Product Manifest Bundle-Name slf4j-api Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product pom artifactid slf4j-api Highest Product pom groupid org.slf4j Highest Product pom name SLF4J API Module High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 1.7.25 High Version Manifest Bundle-Version 1.7.25 High Version Manifest Implementation-Version 1.7.25 High Version pom version 1.7.25 Highest
slicedToArray-a5de7267.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/slicedToArray-a5de7267.jsMD5: 4128a05be008958384918a5c64970c97SHA1: 8a246c3b907a05b3005a0149d8e388cf9427351fSHA256: 110298bb05848f58b8b5712bff5f24622849cb7eceaeb8ecd043c244e43851bfReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
snakeyaml-1.33.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/yaml/snakeyaml/1.33/snakeyaml-1.33.jar
MD5: e0164a637c691c8cf01d29f90a709c02
SHA1: 2cd0a87ff7df953f810c344bdf2fe3340b954c69
SHA256: 11ff459788f0a2d781f56a4a86d7e69202cebacd0273d5269c4ae9f02f3fd8f0
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name snakeyaml High Vendor jar package name emitter Highest Vendor jar package name parser Highest Vendor jar package name snakeyaml Highest Vendor jar package name yaml Highest Vendor Manifest automatic-module-name org.yaml.snakeyaml Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid snakeyaml Highest Vendor pom artifactid snakeyaml Low Vendor pom developer email alexander.maslov@gmail.com Low Vendor pom developer email public.somov@gmail.com Low Vendor pom developer id asomov Medium Vendor pom developer id maslovalex Medium Vendor pom developer name Alexander Maslov Medium Vendor pom developer name Andrey Somov Medium Vendor pom groupid org.yaml Highest Vendor pom name SnakeYAML High Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest Product file name snakeyaml High Product jar package name emitter Highest Product jar package name parser Highest Product jar package name snakeyaml Highest Product jar package name yaml Highest Product Manifest automatic-module-name org.yaml.snakeyaml Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid snakeyaml Highest Product pom developer email alexander.maslov@gmail.com Low Product pom developer email public.somov@gmail.com Low Product pom developer id asomov Low Product pom developer id maslovalex Low Product pom developer name Alexander Maslov Low Product pom developer name Andrey Somov Low Product pom groupid org.yaml Highest Product pom name SnakeYAML High Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium Version file version 1.33 High Version pom version 1.33 Highest
snappy-java-1.1.1.7.jarDescription:
snappy-java: A fast compression/decompression library License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/xerial/snappy/snappy-java/1.1.1.7/snappy-java-1.1.1.7.jar
MD5: 99cc452eb056539a99709fd60f191239
SHA1: 33b6965e9364145972035c30a45a996aad2bf789
SHA256: 121e54a8a376fd85b3cbae2e4113cd6275039ecc584dd13652bfc404168c5726
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name snappy-java High Vendor jar package name snappy Highest Vendor jar package name xerial Highest Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-docurl http://www.xerial.org/ Low Vendor Manifest bundle-nativecode org/xerial/snappy/native/Windows/x86_64/snappyjava.dll;osname=win32;processor=x86-64,org/xerial/snappy/native/Windows/x86/snappyjava.dll;osname=win32;processor=x86,org/xerial/snappy/native/Mac/x86/libsnappyjava.jnilib;osname=macosx;processor=x86,org/xerial/snappy/native/Mac/x86_64/libsnappyjava.jnilib;osname=macosx;processor=x86-64,org/xerial/snappy/native/Linux/x86_64/libsnappyjava.so;osname=linux;processor=x86-64,org/xerial/snappy/native/Linux/x86/libsnappyjava.so;osname=linux;processor=x86,org/xerial/snappy/native/Linux/aarch64/libsnappyjava.so;osname=linux;processor=aarch64,org/xerial/snappy/native/Linux/arm/libsnappyjava.so;osname=linux;processor=arm,org/xerial/snappy/native/Linux/ppc64/libsnappyjava.so;osname=linux;processor=ppc64,org/xerial/snappy/native/Linux/ppc64le/libsnappyjava.so;osname=linux;processor=ppc64le,org/xerial/snappy/native/AIX/ppc64/libsnappyjava.a;osname=aix;processor=ppc64,org/xerial/snappy/native/SunOS/x86/libsnappyjava.so;osname=sunos;processor=x86,org/xerial/snappy/native/SunOS/x86_64/libsnappyjava.so;osname=sunos;processor=x86-64,org/xerial/snappy/native/SunOS/sparc/libsnappyjava.so;osname=sunos;processor=sparc Low Vendor Manifest bundle-symbolicname org.xerial.snappy.snappy-java Medium Vendor pom artifactid snappy-java Highest Vendor pom artifactid snappy-java Low Vendor pom developer email leo@xerial.org Low Vendor pom developer id leo Medium Vendor pom developer name Taro L. Saito Medium Vendor pom developer org Xerial Project Medium Vendor pom groupid org.xerial.snappy Highest Vendor pom name snappy-java High Vendor pom organization name xerial.org High Vendor pom url https://github.comm/xerial/snappy-java Highest Product file name snappy-java High Product jar package name snappy Highest Product jar package name xerial Highest Product Manifest bundle-activationpolicy lazy Low Product Manifest bundle-docurl http://www.xerial.org/ Low Product Manifest Bundle-Name snappy-java: A fast compression/decompression library Medium Product Manifest bundle-nativecode org/xerial/snappy/native/Windows/x86_64/snappyjava.dll;osname=win32;processor=x86-64,org/xerial/snappy/native/Windows/x86/snappyjava.dll;osname=win32;processor=x86,org/xerial/snappy/native/Mac/x86/libsnappyjava.jnilib;osname=macosx;processor=x86,org/xerial/snappy/native/Mac/x86_64/libsnappyjava.jnilib;osname=macosx;processor=x86-64,org/xerial/snappy/native/Linux/x86_64/libsnappyjava.so;osname=linux;processor=x86-64,org/xerial/snappy/native/Linux/x86/libsnappyjava.so;osname=linux;processor=x86,org/xerial/snappy/native/Linux/aarch64/libsnappyjava.so;osname=linux;processor=aarch64,org/xerial/snappy/native/Linux/arm/libsnappyjava.so;osname=linux;processor=arm,org/xerial/snappy/native/Linux/ppc64/libsnappyjava.so;osname=linux;processor=ppc64,org/xerial/snappy/native/Linux/ppc64le/libsnappyjava.so;osname=linux;processor=ppc64le,org/xerial/snappy/native/AIX/ppc64/libsnappyjava.a;osname=aix;processor=ppc64,org/xerial/snappy/native/SunOS/x86/libsnappyjava.so;osname=sunos;processor=x86,org/xerial/snappy/native/SunOS/x86_64/libsnappyjava.so;osname=sunos;processor=x86-64,org/xerial/snappy/native/SunOS/sparc/libsnappyjava.so;osname=sunos;processor=sparc Low Product Manifest bundle-symbolicname org.xerial.snappy.snappy-java Medium Product pom artifactid snappy-java Highest Product pom developer email leo@xerial.org Low Product pom developer id leo Low Product pom developer name Taro L. Saito Low Product pom developer org Xerial Project Low Product pom groupid org.xerial.snappy Highest Product pom name snappy-java High Product pom organization name xerial.org Low Product pom url https://github.comm/xerial/snappy-java Medium Version file version 1.1.1.7 High Version Manifest Bundle-Version 1.1.1.7 High Version pom version 1.1.1.7 Highest
snappy-java-1.1.1.7.jar: snappyjava.dllFile Path: /home/andrii/.m2/repository/org/xerial/snappy/snappy-java/1.1.1.7/snappy-java-1.1.1.7.jar/org/xerial/snappy/native/Windows/x86/snappyjava.dllMD5: c35f7d232d05fd0b8440153cb4224a5aSHA1: 45b5f3fdd2bac156b8d100ce2c29ac7126454fefSHA256: 15fb95c2168bb78cf94f61bbff7fc0bb5611db9d8509dd1322a40d735c3109bcReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name snappyjava High Product file name snappyjava High
snappy-java-1.1.1.7.jar: snappyjava.dllFile Path: /home/andrii/.m2/repository/org/xerial/snappy/snappy-java/1.1.1.7/snappy-java-1.1.1.7.jar/org/xerial/snappy/native/Windows/x86_64/snappyjava.dllMD5: eae816277d795d3397f08ad43d236576SHA1: 283068f6b5cd8bb3449867558624fe19c432d909SHA256: dfcc13605edabf70e7bec87f68bc2a1c7d06bebecd72a0d4e122eee2e695948eReferenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name snappyjava High Product file name snappyjava High
sourcemap-1.7.6.jarLicense:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/atlassian/sourcemap/sourcemap/1.7.6/sourcemap-1.7.6.jar
MD5: d6ec092a031dfb3cf7d55ddf9ac60983
SHA1: 62eb5eab3be06f7e24b6426b08764e7d27d78c63
SHA256: 31ab400839405f40879f200d0a25cb70e8c1a1aa182f00548a057ee1c33c8142
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name sourcemap High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name sourcemap Highest Vendor jar package name sourcemap Low Vendor pom artifactid sourcemap Highest Vendor pom artifactid sourcemap Low Vendor pom groupid com.atlassian.sourcemap Highest Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name sourcemap High Product jar package name atlassian Highest Product jar package name sourcemap Highest Product jar package name sourcemap Low Product pom artifactid sourcemap Highest Product pom groupid com.atlassian.sourcemap Highest Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 1.7.6 High Version pom parent-version 1.7.6 Low Version pom version 1.7.6 Highest
soy-template-renderer-api-5.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/soy/soy-template-renderer-api/5.0.0/soy-template-renderer-api-5.0.0.jarMD5: ab2d35cf92369cc24a6c2c09cee3a05aSHA1: 9a8d191e4ec2b3ea58b65d7a249fc6b363874bcbSHA256: 1c09252bfceed337b85890fcba95dbb423e625d41146068e484e2f7f2138a451Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name soy-template-renderer-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name renderer Highest Vendor jar package name renderer Low Vendor jar package name soy Highest Vendor jar package name soy Low Vendor pom artifactid soy-template-renderer-api Highest Vendor pom artifactid soy-template-renderer-api Low Vendor pom groupid com.atlassian.soy Highest Vendor pom name Atlassian Soy - API High Vendor pom parent-artifactid soy-templates-parent Low Product file name soy-template-renderer-api High Product jar package name atlassian Highest Product jar package name renderer Highest Product jar package name renderer Low Product jar package name soy Highest Product jar package name soy Low Product pom artifactid soy-template-renderer-api Highest Product pom groupid com.atlassian.soy Highest Product pom name Atlassian Soy - API High Product pom parent-artifactid soy-templates-parent Medium Version file version 5.0.0 High Version pom version 5.0.0 Highest
soy-template-renderer-plugin-api-5.0.0.jarFile Path: /home/andrii/.m2/repository/com/atlassian/soy/soy-template-renderer-plugin-api/5.0.0/soy-template-renderer-plugin-api-5.0.0.jarMD5: f8415f9dec51c5a72bb0d5cfe77c4c40SHA1: 77c6be361378a59e1c0c4fd6a8bbe010cd7b1508SHA256: 08801a4e067378d248f9e841ee8e1c4b231470a5b2dfb70c9a88c0ae42b62d27Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name soy-template-renderer-plugin-api High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name renderer Highest Vendor jar package name renderer Low Vendor jar package name soy Highest Vendor jar package name soy Low Vendor pom artifactid soy-template-renderer-plugin-api Highest Vendor pom artifactid soy-template-renderer-plugin-api Low Vendor pom groupid com.atlassian.soy Highest Vendor pom name Atlassian Soy - Plugin API High Vendor pom parent-artifactid soy-templates-parent Low Product file name soy-template-renderer-plugin-api High Product jar package name atlassian Highest Product jar package name renderer Highest Product jar package name renderer Low Product jar package name soy Highest Product jar package name soy Low Product pom artifactid soy-template-renderer-plugin-api Highest Product pom groupid com.atlassian.soy Highest Product pom name Atlassian Soy - Plugin API High Product pom parent-artifactid soy-templates-parent Medium Version file version 5.0.0 High Version pom version 5.0.0 Highest
space-comments.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/space-comments.jsMD5: d41d8cd98f00b204e9800998ecf8427eSHA1: da39a3ee5e6b4b0d3255bfef95601890afd80709SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
spinner-b9bead52.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/spinner-b9bead52.jsMD5: 436dbf7e35410abd0edbd32a486a2b98SHA1: 3421a7c844f2486ee2234e8cca728f0d71e0e397SHA256: d26a73d8ce94ac2035c18aab0790eaeb05b0b4ce33dfa13eb1cf59efa26dde2eReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
spinner.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/@atlaskit/spinner.jsMD5: 0bc5f3f57eb9677c70f767a648a75288SHA1: 8e485d2b7fd88f8a86ad70a89e0e2b187c880d71SHA256: 34f9a6b4bf87ffdd8eb77939d62e0dbeaa785a36c99451fa0c1cf4d6ab5c9996Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
spring-context-support-5.0.10.RELEASE.jarDescription:
Spring Context Support License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/org/springframework/spring-context-support/5.0.10.RELEASE/spring-context-support-5.0.10.RELEASE.jar
MD5: c81b39196eec95eaca85e20f4f09d91a
SHA1: 61b3159aceaae05118bfe2a7fcd4141921986a78
SHA256: 6a74c0402a4d2150acb7ff6695ffddb5fed110a0a533fcf25ca84de06866b427
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-context-support High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.context.support Medium Vendor pom artifactid spring-context-support Highest Vendor pom artifactid spring-context-support Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Context Support High Vendor pom organization name Spring IO High Vendor pom organization url http://projects.spring.io/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-context-support High Product hint analyzer product springsource_spring_framework Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.context.support Medium Product Manifest Implementation-Title spring-context-support High Product pom artifactid spring-context-support Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Context Support High Product pom organization name Spring IO Low Product pom organization url http://projects.spring.io/spring-framework Low Product pom url spring-projects/spring-framework High Version Manifest Implementation-Version 5.0.10.RELEASE High Version pom version 5.0.10.RELEASE Highest
CVE-2022-22965 suppress
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5398 suppress
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. CWE-494 Download of Code Without Integrity Check
CVSSv2:
Base Score: HIGH (7.6) Vector: /AV:N/AC:H/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5421 suppress
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22950 suppress
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-22968 suppress
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. CWE-178 Improper Handling of Case Sensitivity
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22970 suppress
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
spring-core-5.3.20.jarDescription:
Spring Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/org/springframework/spring-core/5.3.20/spring-core-5.3.20.jar
MD5: 2716746463c37172898010391db93ef2
SHA1: 4b88aa3c401ede3d6c8ac78ea0c646cf326ec24b
SHA256: 42d70d78b8822601a3b61c88dadf4be6a0021dde169a772c3fd4a6b8b2b61c90
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name io Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.core Medium Vendor pom artifactid spring-core Highest Vendor pom artifactid spring-core Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Core High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-core High Product hint analyzer product springsource_spring_framework Highest Product jar package name core Highest Product jar package name io Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.core Medium Product Manifest Implementation-Title spring-core High Product pom artifactid spring-core Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Core High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 5.3.20 High Version Manifest Implementation-Version 5.3.20 High Version pom version 5.3.20 Highest
Related Dependencies spring-aop-5.3.20.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-aop/5.3.20/spring-aop-5.3.20.jar MD5: 588d64fb912ed0c637e55c0878c18c4f SHA1: c82f17997ab18ecafa8d08ce34a7c7aa4a04ef9e SHA256: 00c680bef629e09f0d5fec1fe872452d9e18a14435faaaf284e51b3b1fb77e19 pkg:maven/org.springframework/spring-aop@5.3.20 spring-beans-5.3.20.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-beans/5.3.20/spring-beans-5.3.20.jar MD5: 53515694bf34d29522adf7c9e8b5164c SHA1: 0ab88bd9e3a8307f5c0516c15d295c88ec318659 SHA256: 940dc731aedb1b194ab6db0e879437adb9f7c14af825dfa7596ccd3d69bba7e8 pkg:maven/org.springframework/spring-beans@5.3.20 spring-context-5.3.20.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-context/5.3.20/spring-context-5.3.20.jar MD5: f54a37b6c4b217cdb0482b286ccf0bf0 SHA1: 517a42165221ea944c8b794154c10b69c0128281 SHA256: 2b5405c2baeab005300713bfd2ffad228b9cccf4dc8c8f757897831278362eee pkg:maven/org.springframework/spring-context@5.3.20 spring-expression-5.3.20.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-expression/5.3.20/spring-expression-5.3.20.jar MD5: b37937ea560f8801a31217b93484681f SHA1: 20e179f0dfabf0a46428f22c2150c9c4850fd15d SHA256: 6238aa974f63cd0f92da31446d4abd3fb69496785624cd02c5adaea703b0c5c7 pkg:maven/org.springframework/spring-expression@5.3.20 spring-jcl-5.3.20.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-jcl/5.3.20/spring-jcl-5.3.20.jar MD5: 5960098d2253e57c262e243b996de56f SHA1: 35119231d09863699567ce579c21512ddcbc5407 SHA256: fb6c6bf524b19a03103812e0104eaf0bcbc178ae8f425db8b547963b13483e28 pkg:maven/org.springframework/spring-jcl@5.3.20 spring-dao-2.0.6.jarDescription:
Spring Framework: DAO License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/springframework/spring-dao/2.0.6/spring-dao-2.0.6.jar
MD5: f2d3ed5024f794486fd0d45324f08990
SHA1: facdcd4a06cd1a1b516aef8bf8f2188843ac5df1
SHA256: e13657283a0fb2547ead221de605415d7696bc78597274e24a34c4655913b17d
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-dao High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name dao Highest Vendor jar package name springframework Highest Vendor pom artifactid spring-dao Highest Vendor pom artifactid spring-dao Low Vendor pom groupid org.springframework Highest Vendor pom name Spring Framework: DAO High Vendor pom organization name Spring Framework High Vendor pom organization url http://www.springframework.org/ Medium Vendor pom url http://www.springframework.org Highest Product file name spring-dao High Product hint analyzer product springsource_spring_framework Highest Product jar package name dao Highest Product jar package name springframework Highest Product Manifest Implementation-Title Spring Framework High Product pom artifactid spring-dao Highest Product pom groupid org.springframework Highest Product pom name Spring Framework: DAO High Product pom organization name Spring Framework Low Product pom organization url http://www.springframework.org/ Low Product pom url http://www.springframework.org Medium Version file version 2.0.6 High Version Manifest Implementation-Version 2.0.6 High Version Manifest spring-version 2.0.6 Medium Version pom version 2.0.6 Highest
Related Dependencies spring-hibernate2-2.0.6.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-hibernate2/2.0.6/spring-hibernate2-2.0.6.jar MD5: 5edc41e5b8b33ee89b3e65665e44d722 SHA1: 2e788066bf67150d34884acd2a2f88e25c3c1fda SHA256: 10d60c03ddb4288b795f7bd1dc9aa26b8220a1441ea860c4d2a8c66c74ec5fc1 pkg:maven/org.springframework/spring-hibernate2@2.0.6 spring-jdbc-2.0.6.jarFile Path: /home/andrii/.m2/repository/org/springframework/spring-jdbc/2.0.6/spring-jdbc-2.0.6.jar MD5: b8ec9f9da1513a66c7d9388b8bec2e12 SHA1: 2d207c40d0d29941858093aa830362d60a4f7e0e SHA256: 9e45ece4637383e3fad7217beb976263eebf6997e511f9a8b3b6739dd0e201b6 pkg:maven/org.springframework/spring-jdbc@2.0.6 CVE-2018-1270 suppress
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-22965 suppress
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2011-2730 suppress
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection." CWE-16 Configuration
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2016-9878 suppress
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-11040 suppress
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests. CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2013-4152 suppress
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2013-7315 suppress
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0054 suppress
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2018-1257 suppress
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5421 suppress
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22950 suppress
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2018-11039 suppress
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22968 suppress
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. CWE-178 Improper Handling of Case Sensitivity
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22970 suppress
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
spring-ldap-core-2.3.3.RELEASE.jarDescription:
spring-ldap-core License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/springframework/ldap/spring-ldap-core/2.3.3.RELEASE/spring-ldap-core-2.3.3.RELEASE.jar
MD5: d0370c7db5aa126571a435aab1999b0d
SHA1: fe9f87fb96056662bfb5d41365f796bf6644c325
SHA256: 1aee8707b3ff29e9de22767a3a7edd992978d652679fdfbd1bf3e7153811aeb6
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-ldap-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name ldap Highest Vendor jar package name springframework Highest Vendor pom artifactid spring-ldap-core Highest Vendor pom artifactid spring-ldap-core Low Vendor pom developer email mattias@261consulting.com Low Vendor pom developer email rwinch@gopivotal.com Low Vendor pom developer email ulrik.sandberg@jayway.com Low Vendor pom developer id marthursson Medium Vendor pom developer id rwinch Medium Vendor pom developer id ulsa Medium Vendor pom developer name Mattias Hellborg Arthursson Medium Vendor pom developer name Rob Winch Medium Vendor pom developer name Ulrik Sandberg Medium Vendor pom developer org 261 Consulting Medium Vendor pom developer org Jayway Medium Vendor pom developer org URL http://www.261consulting.com Medium Vendor pom developer org URL https://www.jayway.com Medium Vendor pom groupid org.springframework.ldap Highest Vendor pom name spring-ldap-core High Vendor pom organization name SpringSource High Vendor pom organization url https://spring.io Medium Vendor pom url https://www.springframework.org/ldap Highest Product file name spring-ldap-core High Product jar package name core Highest Product jar package name ldap Highest Product jar package name springframework Highest Product Manifest Implementation-Title spring-ldap-core High Product pom artifactid spring-ldap-core Highest Product pom developer email mattias@261consulting.com Low Product pom developer email rwinch@gopivotal.com Low Product pom developer email ulrik.sandberg@jayway.com Low Product pom developer id marthursson Low Product pom developer id rwinch Low Product pom developer id ulsa Low Product pom developer name Mattias Hellborg Arthursson Low Product pom developer name Rob Winch Low Product pom developer name Ulrik Sandberg Low Product pom developer org 261 Consulting Low Product pom developer org Jayway Low Product pom developer org URL http://www.261consulting.com Low Product pom developer org URL https://www.jayway.com Low Product pom groupid org.springframework.ldap Highest Product pom name spring-ldap-core High Product pom organization name SpringSource Low Product pom organization url https://spring.io Low Product pom url https://www.springframework.org/ldap Medium Version Manifest Implementation-Version 2.3.3.RELEASE High Version pom version 2.3.3.RELEASE Highest
spring-quartz1-0.1.2.jarDescription:
Forward port of the Spring 4.0.9 Quartz Scheduler library, to keep Quartz 1.8.x support working License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/com/atlassian/spring/spring-quartz1/0.1.2/spring-quartz1-0.1.2.jar
MD5: c3810c35a3565cc795daa98775de3171
SHA1: f803048a33fa6ed44658aa6d0e4c46ddbd5dc820
SHA256: b84bc5c3785c34606b625ceed90f710ca8f005cc9059e55f05aedd2ae653042b
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-quartz1 High Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name quartz1 Highest Vendor jar package name quartz1 Low Vendor jar package name spring Highest Vendor jar package name spring Low Vendor pom artifactid spring-quartz1 Highest Vendor pom artifactid spring-quartz1 Low Vendor pom groupid com.atlassian.spring Highest Vendor pom name Spring Quartz 1.x Compatibility High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name spring-quartz1 High Product jar package name atlassian Highest Product jar package name quartz1 Highest Product jar package name quartz1 Low Product jar package name spring Highest Product jar package name spring Low Product pom artifactid spring-quartz1 Highest Product pom groupid com.atlassian.spring Highest Product pom name Spring Quartz 1.x Compatibility High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 0.1.2 High Version pom parent-version 0.1.2 Low Version pom version 0.1.2 Highest
spring-security-core-4.2.16.RELEASE.jarDescription:
spring-security-core License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/springframework/security/spring-security-core/4.2.16.RELEASE/spring-security-core-4.2.16.RELEASE.jar
MD5: d5c53f8cd55d3169ab674f45145dec8e
SHA1: 003cbf6e020b5ee6e039c4e4086fdb356f4529fe
SHA256: f2e3948a96d142406f66da9d36417cc39da72a86274d455890f4e3ff54b1140f
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-security-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor Manifest agent-class true Low Vendor Manifest can-redefine-classes true Low Vendor Manifest can-retransform-classes true Low Vendor Manifest can-set-native-method-prefix false Low Vendor Manifest premain-class true Low Vendor pom artifactid spring-security-core Highest Vendor pom artifactid spring-security-core Low Vendor pom developer email rwinch@gopivotal.com Low Vendor pom developer id rwinch Medium Vendor pom developer name Rob Winch Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-core High Vendor pom organization name spring.io High Vendor pom organization url https://spring.io/ Medium Vendor pom url https://spring.io/spring-security Highest Product file name spring-security-core High Product jar package name core Highest Product jar package name security Highest Product jar package name springframework Highest Product Manifest agent-class true Low Product Manifest can-redefine-classes true Low Product Manifest can-retransform-classes true Low Product Manifest can-set-native-method-prefix false Low Product Manifest Implementation-Title spring-security-core High Product Manifest premain-class true Low Product pom artifactid spring-security-core Highest Product pom developer email rwinch@gopivotal.com Low Product pom developer id rwinch Low Product pom developer name Rob Winch Low Product pom groupid org.springframework.security Highest Product pom name spring-security-core High Product pom organization name spring.io Low Product pom organization url https://spring.io/ Low Product pom url https://spring.io/spring-security Medium Version Manifest Implementation-Version 4.2.16.RELEASE High Version pom version 4.2.16.RELEASE Highest
CVE-2022-22978 suppress
In Spring Security versions 5.5.6 and 5.6.3 and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass CWE-863 Incorrect Authorization
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-22112 suppress
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-22976 suppress
Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE. CWE-190 Integer Overflow or Wraparound
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
spring-tx-4.3.27.RELEASE.jarDescription:
Spring Transaction License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/org/springframework/spring-tx/4.3.27.RELEASE/spring-tx-4.3.27.RELEASE.jar
MD5: bf29945418ac3e492685824282077570
SHA1: d3acbba626f3d45062201ed27a17a7f2c08e2ab0
SHA256: c2b1e6e747c00e8060d13b53d2a2e12c31332f791b5d22507f2753df4b4dc546
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-tx High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name springframework Highest Vendor jar package name transaction Highest Vendor pom artifactid spring-tx Highest Vendor pom artifactid spring-tx Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Transaction High Vendor pom organization name Spring IO High Vendor pom organization url https://projects.spring.io/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-tx High Product hint analyzer product springsource_spring_framework Highest Product jar package name springframework Highest Product jar package name transaction Highest Product Manifest Implementation-Title spring-tx High Product pom artifactid spring-tx Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Transaction High Product pom organization name Spring IO Low Product pom organization url https://projects.spring.io/spring-framework Low Product pom url spring-projects/spring-framework High Version Manifest Implementation-Version 4.3.27.RELEASE High Version pom version 4.3.27.RELEASE Highest
CVE-2022-22965 suppress
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5421 suppress
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22950 suppress
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-22968 suppress
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. CWE-178 Improper Handling of Case Sensitivity
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22970 suppress
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
spring-web-2.0.6.jarDescription:
Spring Framework: Web License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/springframework/spring-web/2.0.6/spring-web-2.0.6.jar
MD5: b518cca93d4ebb2ed49189979773c867
SHA1: 19ef5a0c1558fe83816106507b2461c18b6ddf5c
SHA256: ceea1e117633f0f42bfa4ee97bb54ddf404e68e8a174634984f81b3e3b4895c0
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-web High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor pom artifactid spring-web Highest Vendor pom artifactid spring-web Low Vendor pom groupid org.springframework Highest Vendor pom name Spring Framework: Web High Vendor pom organization name Spring Framework High Vendor pom organization url http://www.springframework.org/ Medium Vendor pom url http://www.springframework.org Highest Product file name spring-web High Product hint analyzer product springsource_spring_framework Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest Implementation-Title Spring Framework High Product pom artifactid spring-web Highest Product pom groupid org.springframework Highest Product pom name Spring Framework: Web High Product pom organization name Spring Framework Low Product pom organization url http://www.springframework.org/ Low Product pom url http://www.springframework.org Medium Version file version 2.0.6 High Version Manifest Implementation-Version 2.0.6 High Version Manifest spring-version 2.0.6 Medium Version pom version 2.0.6 Highest
CVE-2016-1000027 suppress
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
CVE-2018-1270 suppress
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-22965 suppress
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2011-2730 suppress
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection." CWE-16 Configuration
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
CONFIRM - http://support.springsource.com/security/cve-2011-2730 CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html DEBIAN - DSA-2504 MISC - http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814 MISC - https://docs.google.com/document/d/1dc1xxO8UMFaGLOwgkykYdghGWm_2Gn0iCrxFsympqcE/edit OSSINDEX - [CVE-2011-2730] VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection." OSSIndex - http://danamodio.com/appsec/research/spring-remote-code-with-expression-language-injection/ OSSIndex - http://support.springsource.com/security/cve-2011-2730 OSSIndex - http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2730 REDHAT - RHSA-2013:0191 REDHAT - RHSA-2013:0192 REDHAT - RHSA-2013:0193 REDHAT - RHSA-2013:0194 REDHAT - RHSA-2013:0195 REDHAT - RHSA-2013:0196 REDHAT - RHSA-2013:0197 REDHAT - RHSA-2013:0198 REDHAT - RHSA-2013:0221 REDHAT - RHSA-2013:0533 SECTRACK - 1029151 SECUNIA - 51984 SECUNIA - 52054 SECUNIA - 55155 Vulnerable Software & Versions: (show all )
CVE-2016-9878 suppress
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2018-11040 suppress
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests. CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2013-4152 suppress
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) StreamSource, aka an XML External Entity (XXE) issue. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2013-7315 suppress
The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0054 suppress
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2018-1257 suppress
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5421 suppress
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22950 suppress
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2018-11039 suppress
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack. NVD-CWE-noinfo
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2013-6430 (OSSINDEX) suppress
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (5.4) Vector: /AV:N/AC:L/Au:/C:L/I:L/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.springframework:spring-web:2.0.6:*:*:*:*:*:*:* CVE-2022-22968 suppress
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. CWE-178 Improper Handling of Case Sensitivity
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22970 suppress
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
spring-webmvc-5.0.10.RELEASE.jarDescription:
Spring Web MVC License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /home/andrii/.m2/repository/org/springframework/spring-webmvc/5.0.10.RELEASE/spring-webmvc-5.0.10.RELEASE.jar
MD5: df6301cd4b866ce3aa56ed0872410919
SHA1: 88a601321e2b4e3b84eed0909c24b9dd8e453b5f
SHA256: e55751061b496106777739938c89c1eca943d962db76fb149b5cb9303ec72e54
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name spring-webmvc High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name mvc Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name spring.webmvc Medium Vendor pom artifactid spring-webmvc Highest Vendor pom artifactid spring-webmvc Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Web MVC High Vendor pom organization name Spring IO High Vendor pom organization url http://projects.spring.io/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-webmvc High Product hint analyzer product springsource_spring_framework Highest Product jar package name mvc Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest automatic-module-name spring.webmvc Medium Product Manifest Implementation-Title spring-webmvc High Product pom artifactid spring-webmvc Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Web MVC High Product pom organization name Spring IO Low Product pom organization url http://projects.spring.io/spring-framework Low Product pom url spring-projects/spring-framework High Version Manifest Implementation-Version 5.0.10.RELEASE High Version pom version 5.0.10.RELEASE Highest
CVE-2022-22965 suppress
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5398 suppress
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. CWE-494 Download of Code Without Integrity Check
CVSSv2:
Base Score: HIGH (7.6) Vector: /AV:N/AC:H/Au:N/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5421 suppress
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter. NVD-CWE-noinfo
CVSSv2:
Base Score: LOW (3.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22950 suppress
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-5397 (OSSINDEX) suppress
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (5.3) Vector: /AV:N/AC:L/Au:/C:N/I:L/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.springframework:spring-webmvc:5.0.10.RELEASE:*:*:*:*:*:*:* CVE-2022-22968 suppress
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. CWE-178 Improper Handling of Case Sensitivity
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-22970 suppress
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-22060 (OSSINDEX) suppress
In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase. CWE-117 Improper Output Neutralization for Logs
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:L/Au:/C:N/I:L/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.springframework:spring-webmvc:5.0.10.RELEASE:*:*:*:*:*:*:* stax-ex-1.8.jarDescription:
Extensions to JSR-173 StAX API. License:
Dual license consisting of the CDDL v1.1 and GPL v2
: https://glassfish.dev.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/org/jvnet/staxex/stax-ex/1.8/stax-ex-1.8.jar
MD5: a0ebfdbc6b5a34b174a1d1f732d1bdda
SHA1: 8cc35f73da321c29973191f2cf143d29d26a1df7
SHA256: 95b05d9590af4154c6513b9c5dc1fb2e55b539972ba0a9ef28e9a0c01d83ad77
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name stax-ex High Vendor jar package name jvnet Highest Vendor jar package name staxex Highest Vendor Manifest bundle-symbolicname org.jvnet.staxex.stax-ex Medium Vendor Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Vendor Manifest implementation-url http://stax-ex.java.net/ Low Vendor Manifest Implementation-Vendor-Id org.jvnet.staxex Medium Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor pom artifactid stax-ex Highest Vendor pom artifactid stax-ex Low Vendor pom developer email Roman.Grigoriadi@oracle.com Low Vendor pom developer email Zheng.Jun.Li@oracle.com Low Vendor pom developer id bravehorsie Medium Vendor pom developer id zhengjl Medium Vendor pom developer name Roman Grigoriadi Medium Vendor pom developer name Zheng Jun Li Medium Vendor pom groupid org.jvnet.staxex Highest Vendor pom name Extended StAX API High Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://stax-ex.java.net/ Highest Product file name stax-ex High Product jar package name jvnet Highest Product jar package name staxex Highest Product Manifest Bundle-Name Extended StAX API Medium Product Manifest bundle-symbolicname org.jvnet.staxex.stax-ex Medium Product Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Product Manifest Implementation-Title Extended StAX API High Product Manifest implementation-url http://stax-ex.java.net/ Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom artifactid stax-ex Highest Product pom developer email Roman.Grigoriadi@oracle.com Low Product pom developer email Zheng.Jun.Li@oracle.com Low Product pom developer id bravehorsie Low Product pom developer id zhengjl Low Product pom developer name Roman Grigoriadi Low Product pom developer name Zheng Jun Li Low Product pom groupid org.jvnet.staxex Highest Product pom name Extended StAX API High Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://stax-ex.java.net/ Medium Version file version 1.8 High Version Manifest Implementation-Version 1.8 High Version pom parent-version 1.8 Low Version pom version 1.8 Highest
streambuffer-1.5.6.jarDescription:
Stream based representation for XML infoset License:
Dual license consisting of the CDDL v1.1 and GPL v2
: https://glassfish.dev.java.net/public/CDDL+GPL_1_1.html File Path: /home/andrii/.m2/repository/com/sun/xml/stream/buffer/streambuffer/1.5.6/streambuffer-1.5.6.jar
MD5: b0c5ef33eaf97577cc2ea48cdf26796a
SHA1: 8288761f6f6b8cd110b32ce32e8dfd7c4b1c5f7f
SHA256: d7bc9543b33a40e9f90cfbd02cf45f7b454a11d4a2703569a457438dab626a59
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name streambuffer High Vendor jar package name buffer Highest Vendor jar package name stream Highest Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-symbolicname com.sun.xml.stream.buffer.streambuffer Medium Vendor Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Vendor Manifest implementation-url http://xmlstreambuffer.java.net/ Low Vendor Manifest Implementation-Vendor-Id com.sun.xml.stream.buffer Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor pom artifactid streambuffer Highest Vendor pom artifactid streambuffer Low Vendor pom developer email iaroslav.savytskyi@oracle.com Low Vendor pom developer email lukas.jungmann@oracle.com Low Vendor pom developer email martin.grebac@oracle.com Low Vendor pom developer email miroslav.kos@oracle.com Low Vendor pom developer name Jaroslav Savytskyi Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer name Martin Grebac Medium Vendor pom developer name Miroslav Kos Medium Vendor pom developer org Oracle Corporation Medium Vendor pom groupid com.sun.xml.stream.buffer Highest Vendor pom name xmlstreambuffer High Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://xmlstreambuffer.java.net/ Highest Product file name streambuffer High Product jar package name buffer Highest Product jar package name stream Highest Product jar package name sun Highest Product jar package name xml Highest Product Manifest Bundle-Name xmlstreambuffer Medium Product Manifest bundle-symbolicname com.sun.xml.stream.buffer.streambuffer Medium Product Manifest implementation-build-id ${scmBranch}-${buildNumber}, ${timestamp} Low Product Manifest Implementation-Title xmlstreambuffer High Product Manifest implementation-url http://xmlstreambuffer.java.net/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom artifactid streambuffer Highest Product pom developer email iaroslav.savytskyi@oracle.com Low Product pom developer email lukas.jungmann@oracle.com Low Product pom developer email martin.grebac@oracle.com Low Product pom developer email miroslav.kos@oracle.com Low Product pom developer name Jaroslav Savytskyi Low Product pom developer name Lukas Jungmann Low Product pom developer name Martin Grebac Low Product pom developer name Miroslav Kos Low Product pom developer org Oracle Corporation Low Product pom groupid com.sun.xml.stream.buffer Highest Product pom name xmlstreambuffer High Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://xmlstreambuffer.java.net/ Medium Version file version 1.5.6 High Version Manifest Bundle-Version 1.5.6 High Version Manifest Implementation-Version 1.5.6 High Version pom parent-version 1.5.6 Low Version pom version 1.5.6 Highest
super-csv-2.1.0.jarDescription:
Super CSV is a fast, programmer-friendly, free CSV package for Java License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /home/andrii/.m2/repository/net/sf/supercsv/super-csv/2.1.0/super-csv-2.1.0.jar
MD5: a069a5578c574f715facf22da805fb11
SHA1: c6466dd0e28c034272b9f70a3f1896c03f1f2b27
SHA256: 5e8efd1b42eced204fb350ca9b54358683f424e444fc9896ed4a15150aa80103
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name super-csv High Vendor jar package name supercsv Highest Vendor Manifest bundle-docurl http://supercsv.sourceforge.net/ Low Vendor Manifest bundle-symbolicname net.sf.supercsv.super-csv Medium Vendor pom artifactid super-csv Highest Vendor pom artifactid super-csv Low Vendor pom groupid net.sf.supercsv Highest Vendor pom name Super CSV Core High Vendor pom parent-artifactid super-csv-parent Low Product file name super-csv High Product jar package name supercsv Highest Product Manifest bundle-docurl http://supercsv.sourceforge.net/ Low Product Manifest Bundle-Name Super CSV Core Medium Product Manifest bundle-symbolicname net.sf.supercsv.super-csv Medium Product pom artifactid super-csv Highest Product pom groupid net.sf.supercsv Highest Product pom name Super CSV Core High Product pom parent-artifactid super-csv-parent Medium Version file version 2.1.0 High Version Manifest Bundle-Version 2.1.0 High Version pom version 2.1.0 Highest
taggedTemplateLiteral-12969f7e.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/taggedTemplateLiteral-12969f7e.jsMD5: 95365d42834383e9cb049156f3c6dcbaSHA1: 6647ba0a745f872ec2c3fbf114d341d3889cd100SHA256: 1584bf7722fdfabfdafddb1df02d59229a180293d6587abc7c82c5d4fdb15112Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
theme-742e153b.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/theme-742e153b.jsMD5: 3fe6002bdde264373fccba8b3bbd8f02SHA1: b6e5b32778de72a62d52a628a7c6c986411f487fSHA256: ef879a19f75abe070afe662e5e8a55e1984ac9ea0dc632b074767964e32abfb2Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
tika-core-1.22.jarDescription:
This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also
includes the core facades for the Tika API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/tika/tika-core/1.22/tika-core-1.22.jar
MD5: 078d3798a32e444b3e3425457402dce3
SHA1: b193f1f977e64ff77025a4cecd7997cff344c4bc
SHA256: 81a9e28c9fa9d6b00d1e5d85795403fb773d4c571175487b35b83a8c02599dd7
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name tika-core High Vendor jar package name apache Highest Vendor jar package name tika Highest Vendor Manifest automatic-module-name org.apache.tika.core Medium Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-docurl http://tika.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.tika.core Medium Vendor Manifest implementation-url http://tika.apache.org/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.tika Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid tika-core Highest Vendor pom artifactid tika-core Low Vendor pom groupid org.apache.tika Highest Vendor pom name Apache Tika core High Vendor pom organization name The Apache Software Foundation High Vendor pom organization url http://www.apache.org Medium Vendor pom parent-artifactid tika-parent Low Vendor pom url http://tika.apache.org/ Highest Product file name tika-core High Product jar package name apache Highest Product jar package name tika Highest Product Manifest automatic-module-name org.apache.tika.core Medium Product Manifest bundle-activationpolicy lazy Low Product Manifest bundle-docurl http://tika.apache.org/ Low Product Manifest Bundle-Name Apache Tika core Medium Product Manifest bundle-symbolicname org.apache.tika.core Medium Product Manifest Implementation-Title Apache Tika core High Product Manifest implementation-url http://tika.apache.org/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Tika core Medium Product pom artifactid tika-core Highest Product pom groupid org.apache.tika Highest Product pom name Apache Tika core High Product pom organization name The Apache Software Foundation Low Product pom organization url http://www.apache.org Low Product pom parent-artifactid tika-parent Medium Product pom url http://tika.apache.org/ Medium Version file version 1.22 High Version Manifest Implementation-Version 1.22 High Version pom version 1.22 Highest
CVE-2020-1950 suppress
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2020-1951 suppress
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-28657 suppress
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-25169 suppress
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-30126 suppress
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0 NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-30973 suppress
We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.3. NVD-CWE-Other
CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-33879 suppress
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insufficient, and we found a separate, new regex DoS in a different regex in the StandardsExtractingContentHandler. These are now fixed in 1.28.4 and 2.4.1. NVD-CWE-Other
CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L References:
Vulnerable Software & Versions: (show all )
toml4j-0.7.2.jarDescription:
A parser for TOML License:
The MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /home/andrii/.m2/repository/com/moandjiezana/toml/toml4j/0.7.2/toml4j-0.7.2.jar
MD5: efaec2fac998dce5bc118362bf724527
SHA1: 0a03337911d0bd2c40932aca3946edb30d0e7d0c
SHA256: f5475e63e7e89e5db62223489aec7a56bd303543772077a17c2cb54c19ca3a20
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name toml4j High Vendor jar package name moandjiezana Highest Vendor jar package name moandjiezana Low Vendor jar package name toml Highest Vendor jar package name toml Low Vendor pom artifactid toml4j Highest Vendor pom artifactid toml4j Low Vendor pom developer email mwanji@gmail.com Low Vendor pom developer id moandji.ezana Medium Vendor pom developer name Moandji Ezana Medium Vendor pom groupid com.moandjiezana.toml Highest Vendor pom name toml4j High Vendor pom url http://moandjiezana.com/toml/toml4j Highest Product file name toml4j High Product jar package name moandjiezana Highest Product jar package name toml Highest Product jar package name toml Low Product pom artifactid toml4j Highest Product pom developer email mwanji@gmail.com Low Product pom developer id moandji.ezana Low Product pom developer name Moandji Ezana Low Product pom groupid com.moandjiezana.toml Highest Product pom name toml4j High Product pom url http://moandjiezana.com/toml/toml4j Medium Version file version 0.7.2 High Version pom version 0.7.2 Highest
txw2-2.3.1.jarDescription:
TXW is a library that allows you to write XML documents.
File Path: /home/andrii/.m2/repository/org/glassfish/jaxb/txw2/2.3.1/txw2-2.3.1.jarMD5: 0fed730907ba86376ef392ee7eb42d5fSHA1: a09d2c48d3285f206fafbffe0e50619284e92126SHA256: 34975dde1c6920f1a39791142235689bc3cd357e24d05edd8ff93b885bd68d60Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name txw2 High Vendor jar package name sun Highest Vendor jar package name txw Highest Vendor jar package name txw2 Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision ad5fa4c697632694cbcfa80177707db908cd98b2 Low Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor Manifest (hint) Implementation-Vendor sun High Vendor pom artifactid txw2 Highest Vendor pom artifactid txw2 Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name TXW2 Runtime High Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Product file name txw2 High Product jar package name sun Highest Product jar package name txw Highest Product jar package name txw2 Highest Product jar package name xml Highest Product Manifest git-revision ad5fa4c697632694cbcfa80177707db908cd98b2 Low Product Manifest Implementation-Title TXW Runtime High Product Manifest specification-title Java Architecture for XML Binding Medium Product pom artifactid txw2 Highest Product pom groupid org.glassfish.jaxb Highest Product pom name TXW2 Runtime High Product pom parent-artifactid jaxb-txw-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Version file version 2.3.1 High Version Manifest build-id 2.3.1 Medium Version Manifest Implementation-Version 2.3.1 High Version Manifest major-version 2.3.1 Medium Version pom version 2.3.1 Highest
upm-api-2.21.jarFile Path: /home/andrii/.m2/repository/com/atlassian/upm/upm-api/2.21/upm-api-2.21.jarMD5: befab820657442f0269193432838e9f7SHA1: b32d5e709d23e7abc014cf1f288fdf5105d1aef6SHA256: c0fb75b067047eee6d295ad541dc2c8916bd3174e6018d86ebd249db77b18c56Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name upm-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name atlassian Highest Vendor jar package name atlassian Low Vendor jar package name upm Highest Vendor jar package name upm Low Vendor pom artifactid upm-api Highest Vendor pom artifactid upm-api Low Vendor pom groupid com.atlassian.upm Highest Vendor pom name Universal Plugin Manager - API High Vendor pom parent-artifactid atlassian-universal-plugin-manager Low Product file name upm-api High Product jar package name api Highest Product jar package name api Low Product jar package name atlassian Highest Product jar package name upm Highest Product jar package name upm Low Product jar package name util Low Product pom artifactid upm-api Highest Product pom groupid com.atlassian.upm Highest Product pom name Universal Plugin Manager - API High Product pom parent-artifactid atlassian-universal-plugin-manager Medium Version file version 2.21 High Version pom version 2.21 Highest
CVE-2018-20233 suppress
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privileges to read files, make network requests and perform a denial of service attack via an XML External Entity vulnerability in the parsing of atlassian plugin xml files in an uploaded JAR. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: MEDIUM (5.5) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:P CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2018-5229 suppress
The NotificationRepresentationFactoryImpl class in Atlassian Universal Plugin Manager before version 2.22.9 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the name of user submitted add-on names. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
CVE-2019-14999 suppress
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator. CWE-352 Cross-Site Request Forgery (CSRF)
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N References:
Vulnerable Software & Versions: (show all )
urlrewritefilter-4.0.4.jarDescription:
A Java Web Filter for any J2EE compliant web application server (such as Resin, Orion or Tomcat), which
allows you to rewrite URLs before they get to your code. It is a very powerful tool just like Apache's
mod_rewrite.
License:
BSD: http://www.opensource.org/licenses/bsd-license.php File Path: /home/andrii/.m2/repository/org/tuckey/urlrewritefilter/4.0.4/urlrewritefilter-4.0.4.jar
MD5: b2440a8fb96bf2e2634216067a5db0b1
SHA1: b22c2658a325688bb87903033ae9f041f668aad2
SHA256: aeba8c192abe336af1a0d426ab4bcdbf657e518983cc4cb51c1cce462781e2db
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name urlrewritefilter High Vendor jar package name tuckey Highest Vendor jar package name web Highest Vendor Manifest implementation-build 432 Low Vendor Manifest Implementation-Vendor Paul Tuckey High Vendor Manifest Implementation-Vendor-Id org.tuckey Medium Vendor Manifest specification-vendor Paul Tuckey Low Vendor pom artifactid urlrewritefilter Highest Vendor pom artifactid urlrewritefilter Low Vendor pom developer name Paul Tuckey Medium Vendor pom groupid org.tuckey Highest Vendor pom name UrlRewriteFilter High Vendor pom organization name Paul Tuckey High Vendor pom url http://www.tuckey.org/urlrewrite/ Highest Product file name urlrewritefilter High Product jar package name tuckey Highest Product jar package name web Highest Product Manifest implementation-build 432 Low Product Manifest Implementation-Title UrlRewriteFilter High Product Manifest specification-title UrlRewriteFilter Medium Product pom artifactid urlrewritefilter Highest Product pom developer name Paul Tuckey Low Product pom groupid org.tuckey Highest Product pom name UrlRewriteFilter High Product pom organization name Paul Tuckey Low Product pom url http://www.tuckey.org/urlrewrite/ Medium Version file version 4.0.4 High Version Manifest Implementation-Version 4.0.4 High Version pom version 4.0.4 Highest
use-controlled-d7253071.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/use-controlled-d7253071.jsMD5: 27a3085d3bae388751fc76f5a6bcd1e3SHA1: 14422298aec3e60cad0716ad4663ae28c243095bSHA256: 58c874360e43db7c477cad972e7823204133f8c421d11bd88373f42ca16b2902Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
useAnalyticsEvents-2e16b30c.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/useAnalyticsEvents-2e16b30c.jsMD5: 2e6969e831de8d3a9d579dbcfc25ed71SHA1: 0d319f17e22420f3a935c6a9208d9b7035e9ebacSHA256: 98a8a4eecef3b6c8b244d6b96f46dd254eb64bbe3c3dba8447c40d733023a581Referenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
useTrackedRef-308a7e05.jsFile Path: /home/andrii/IdeaProjects/confluence-comments-server/src/main/resources/js/build/_snowpack/pkg/common/useTrackedRef-308a7e05.jsMD5: bef33f5652eb286bf4ae7fe165ebbfc4SHA1: eff3f44c4142c29323b789d497c5de177d777a81SHA256: 490f82db80dbf3a5f9d65ae090662c13d8685681abac33b41526033943e9562cReferenced In Project/Scope: space-comments
Evidence Type Source Name Value Confidence
validation-api-2.0.1.Final.jarDescription:
Bean Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/javax/validation/validation-api/2.0.1.Final/validation-api-2.0.1.Final.jar
MD5: 5d02c034034a7a16725ceff787e191d6
SHA1: cb855558e6271b1b32e716d24cb85c7f583ce09e
SHA256: 9873b46df1833c9ee8f5bc1ff6853375115dadd8897bcb5a0dffb5848835ee6c
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name validation-api High Vendor jar package name javax Highest Vendor jar package name validation Highest Vendor Manifest automatic-module-name java.validation Medium Vendor Manifest bundle-symbolicname javax.validation.api Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid validation-api Highest Vendor pom artifactid validation-api Low Vendor pom developer email emmanuel@hibernate.org Low Vendor pom developer email guillaume.smet@hibernate.org Low Vendor pom developer email gunnar@hibernate.org Low Vendor pom developer email hferents@redhat.com Low Vendor pom developer id emmanuelbernard Medium Vendor pom developer id epbernard Medium Vendor pom developer id guillaume.smet Medium Vendor pom developer id gunnar.morling Medium Vendor pom developer id hardy.ferentschik Medium Vendor pom developer name Emmanuel Bernard Medium Vendor pom developer name Guillaume Smet Medium Vendor pom developer name Gunnar Morling Medium Vendor pom developer name Hardy Ferentschik Medium Vendor pom developer org Red Hat, Inc. Medium Vendor pom groupid javax.validation Highest Vendor pom name Bean Validation API High Vendor pom url http://beanvalidation.org Highest Product file name validation-api High Product jar package name javax Highest Product jar package name validation Highest Product Manifest automatic-module-name java.validation Medium Product Manifest Bundle-Name Bean Validation API Medium Product Manifest bundle-symbolicname javax.validation.api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid validation-api Highest Product pom developer email emmanuel@hibernate.org Low Product pom developer email guillaume.smet@hibernate.org Low Product pom developer email gunnar@hibernate.org Low Product pom developer email hferents@redhat.com Low Product pom developer id emmanuelbernard Low Product pom developer id epbernard Low Product pom developer id guillaume.smet Low Product pom developer id gunnar.morling Low Product pom developer id hardy.ferentschik Low Product pom developer name Emmanuel Bernard Low Product pom developer name Guillaume Smet Low Product pom developer name Gunnar Morling Low Product pom developer name Hardy Ferentschik Low Product pom developer org Red Hat, Inc. Low Product pom groupid javax.validation Highest Product pom name Bean Validation API High Product pom url http://beanvalidation.org Medium Version Manifest Bundle-Version 2.0.1.Final High Version pom version 2.0.1.Final Highest
velocity-1.6.4-atlassian-21.jarDescription:
Apache Velocity is a general purpose template engine. File Path: /home/andrii/.m2/repository/org/apache/velocity/velocity/1.6.4-atlassian-21/velocity-1.6.4-atlassian-21.jarMD5: b4f23e994b43a5e952b1b3f77422a1c0SHA1: 34a2ac32e2bf8f470a63189d75216c2e6bd5381fSHA256: 937057094c37870adae489664179aa7622157be2857819999e64b1704ce33305Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name velocity High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name runtime Low Vendor jar package name template Highest Vendor jar package name velocity Highest Vendor jar package name velocity Low Vendor pom artifactid velocity Highest Vendor pom artifactid velocity Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email geirm@optonline.net Low Vendor pom developer email hps@intermeta.de Low Vendor pom developer email nathan@esha.com Low Vendor pom developer email wglass@forio.com Low Vendor pom developer id dlr Medium Vendor pom developer id geirm Medium Vendor pom developer id henning Medium Vendor pom developer id nbubna Medium Vendor pom developer id wglass Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Geir Magnusson Jr. Medium Vendor pom developer name Henning P. Schmiedehausen Medium Vendor pom developer name Nathan Bubna Medium Vendor pom developer name Will Glass-Husain Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org ESHA Research Medium Vendor pom developer org Forio Business Simulations Medium Vendor pom developer org Independent (DVSL Maven) Medium Vendor pom developer org INTERMETA - Gesellschaft für Mehrwertdienste mbH Medium Vendor pom groupid org.apache.velocity Highest Vendor pom name Apache Velocity High Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://velocity.apache.org/engine/releases/velocity-1.6.4/ Highest Product file name velocity High Product jar package name apache Highest Product jar package name runtime Low Product jar package name template Highest Product jar package name velocity Highest Product jar package name velocity Low Product pom artifactid velocity Highest Product pom developer email dlr@finemaltcoding.com Low Product pom developer email geirm@optonline.net Low Product pom developer email hps@intermeta.de Low Product pom developer email nathan@esha.com Low Product pom developer email wglass@forio.com Low Product pom developer id dlr Low Product pom developer id geirm Low Product pom developer id henning Low Product pom developer id nbubna Low Product pom developer id wglass Low Product pom developer name Daniel Rall Low Product pom developer name Geir Magnusson Jr. Low Product pom developer name Henning P. Schmiedehausen Low Product pom developer name Nathan Bubna Low Product pom developer name Will Glass-Husain Low Product pom developer org CollabNet, Inc. Low Product pom developer org ESHA Research Low Product pom developer org Forio Business Simulations Low Product pom developer org Independent (DVSL Maven) Low Product pom developer org INTERMETA - Gesellschaft für Mehrwertdienste mbH Low Product pom groupid org.apache.velocity Highest Product pom name Apache Velocity High Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://velocity.apache.org/engine/releases/velocity-1.6.4/ Medium Version pom parent-version 1.6.4-atlassian-21 Low Version pom version 1.6.4-atlassian-21 Highest
CVE-2020-13936 suppress
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
velocity-engine-core-2.3.jarDescription:
Apache Velocity is a general purpose template engine. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/velocity/velocity-engine-core/2.3/velocity-engine-core-2.3.jar
MD5: e761e6088b946b42289c5d676a515581
SHA1: e2133b723d0e42be74880d34de6bf6538ea7f915
SHA256: b086cee8fd8183e240b4afcf54fe38ec33dd8eb0da414636e5bf7aa4d9856629
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name velocity-engine-core High Vendor jar package name apache Highest Vendor jar package name velocity Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.velocity.engine-core Medium Vendor Manifest implementation-url http://velocity.apache.org/engine/devel/velocity-engine-core/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.velocity Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid velocity-engine-core Highest Vendor pom artifactid velocity-engine-core Low Vendor pom groupid org.apache.velocity Highest Vendor pom name Apache Velocity - Engine High Vendor pom parent-artifactid velocity-engine-parent Low Product file name velocity-engine-core High Product jar package name apache Highest Product jar package name filter Highest Product jar package name template Highest Product jar package name velocity Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache Velocity - Engine Medium Product Manifest bundle-symbolicname org.apache.velocity.engine-core Medium Product Manifest Implementation-Title Apache Velocity - Engine High Product Manifest implementation-url http://velocity.apache.org/engine/devel/velocity-engine-core/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Velocity - Engine Medium Product pom artifactid velocity-engine-core Highest Product pom groupid org.apache.velocity Highest Product pom name Apache Velocity - Engine High Product pom parent-artifactid velocity-engine-parent Medium Version file version 2.3 High Version Manifest Implementation-Version 2.3 High Version pom version 2.3 Highest
velocity-htmlsafe-3.1.1.jarDescription:
Base POM for Atlassian projects License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/atlassian/velocity/htmlsafe/velocity-htmlsafe/3.1.1/velocity-htmlsafe-3.1.1.jar
MD5: 3c3fc9882fad7f1068d9cac6604a76e9
SHA1: 5a8f18e0f9b6200d8ea1f9e62a04fbd97d4c1b87
SHA256: ff249a061c9cf3f7afa752fde2dbbdbc8e29c99920f82cb5521bb866994aa04a
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name velocity-htmlsafe High Vendor jar package name atlassian Highest Vendor jar package name htmlsafe Highest Vendor jar package name velocity Highest Vendor Manifest bundle-docurl https://www.atlassian.com/ Low Vendor Manifest bundle-symbolicname com.atlassian.velocity.htmlsafe.velocity-htmlsafe Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid velocity-htmlsafe Highest Vendor pom artifactid velocity-htmlsafe Low Vendor pom groupid com.atlassian.velocity.htmlsafe Highest Vendor pom name Velocity HtmlSafe High Vendor pom parent-artifactid public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name velocity-htmlsafe High Product jar package name atlassian Highest Product jar package name htmlsafe Highest Product jar package name velocity Highest Product Manifest bundle-docurl https://www.atlassian.com/ Low Product Manifest Bundle-Name Velocity HtmlSafe Medium Product Manifest bundle-symbolicname com.atlassian.velocity.htmlsafe.velocity-htmlsafe Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid velocity-htmlsafe Highest Product pom groupid com.atlassian.velocity.htmlsafe Highest Product pom name Velocity HtmlSafe High Product pom parent-artifactid public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 3.1.1 High Version Manifest Bundle-Version 3.1.1 High Version pom parent-version 3.1.1 Low Version pom version 3.1.1 Highest
velocity-tools-1.4.jarFile Path: /home/andrii/.m2/repository/velocity-tools/velocity-tools/1.4/velocity-tools-1.4.jarMD5: 2ef7ed8b728186558b5d587c38900b84SHA1: 4e1f4d507030a00959f4c0c7fcc60b3565617d08SHA256: 0736bd626e343ee4c5837fb64f8ac4a4dcb06afba811dbfaf2d8aa5fcad850f3Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name velocity-tools High Vendor jar package name apache Highest Vendor jar package name tools Highest Vendor jar package name velocity Highest Vendor Manifest extension-name velocity-tools Medium Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor Apache Software Foundation Low Vendor pom artifactid velocity-tools Highest Vendor pom artifactid velocity-tools Low Vendor pom groupid velocity-tools Highest Product file name velocity-tools High Product jar package name apache Highest Product jar package name struts Highest Product jar package name tools Highest Product jar package name velocity Highest Product Manifest extension-name velocity-tools Medium Product Manifest Implementation-Title org.apache.velocity High Product Manifest specification-title VelocityTools is a set of utilities for use with the Velocity template engine and Struts web framework Medium Product pom artifactid velocity-tools Highest Product pom groupid velocity-tools Highest Version file version 1.4 High Version Manifest Implementation-Version 1.4 High Version pom version 1.4 Highest
CVE-2020-13959 suppress
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in the URL which results in this payload being executed. XSS vulnerabilities allow attackers to execute arbitrary JavaScript in the context of the attacked website and the attacked user. This can be abused to steal session cookies, perform requests in the name of the victim or for phishing attacks. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N References:
Vulnerable Software & Versions:
webwork-2.1.5-atlassian-3.jarFile Path: /home/andrii/.m2/repository/opensymphony/webwork/2.1.5-atlassian-3/webwork-2.1.5-atlassian-3.jarMD5: 348ea1f5a0ebd5ab23827d551ef33fceSHA1: c9f58dd800c9b525be6d3f6fe4642720446e91c7SHA256: b40db1a8a0e3b1d24f3b205c8de4b66c5795ab319e54ef309eec6e5f7c95edb1Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name webwork High Vendor jar package name opensymphony Highest Vendor jar package name opensymphony Low Vendor jar package name views Low Vendor jar package name webwork Highest Vendor jar package name webwork Low Vendor pom artifactid webwork Highest Vendor pom artifactid webwork Low Vendor pom groupid opensymphony Highest Product file name webwork High Product jar package name opensymphony Highest Product jar package name views Low Product jar package name webwork Highest Product jar package name webwork Low Product pom artifactid webwork Highest Product pom groupid opensymphony Highest Version pom version 2.1.5-atlassian-3 Highest
CVE-2016-3082 (OSSINDEX) suppress
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter. CWE-20 Improper Input Validation
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:webwork:2.1.5-atlassian-3:*:*:*:*:*:*:* CVE-2017-12611 (OSSINDEX) suppress
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack. CWE-20 Improper Input Validation
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:webwork:2.1.5-atlassian-3:*:*:*:*:*:*:* CVE-2018-11776 (OSSINDEX) suppress
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace. CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:webwork:2.1.5-atlassian-3:*:*:*:*:*:*:* CVE-2011-1772 suppress
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
wsdl4j-1.6.3.jarDescription:
Java stub generator for WSDL License:
CPL: http://www.opensource.org/licenses/cpl1.0.txt File Path: /home/andrii/.m2/repository/wsdl4j/wsdl4j/1.6.3/wsdl4j-1.6.3.jar
MD5: cfc28d89625c5e88589aec7a9aee0208
SHA1: 6d106a6845a3d3477a1560008479312888e94f2f
SHA256: 740f448e6b3bc110e02f4a1e56fb57672e732d2ecaf29ae15835051ae8af4725
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name wsdl4j High Vendor jar package name ibm Highest Vendor jar package name wsdl Highest Vendor Manifest Implementation-Vendor IBM High Vendor Manifest specification-vendor IBM (Java Community Process) Low Vendor pom artifactid wsdl4j Highest Vendor pom artifactid wsdl4j Low Vendor pom developer email wsdl4j-discuss@sourceforge.net Low Vendor pom developer id wsdl4j Medium Vendor pom developer name WSDL4J Medium Vendor pom groupid wsdl4j Highest Vendor pom name WSDL4J High Vendor pom url http://sf.net/projects/wsdl4j Highest Product file name wsdl4j High Product jar package name wsdl Highest Product Manifest Implementation-Title WSDL4J High Product Manifest specification-title JWSDL Medium Product pom artifactid wsdl4j Highest Product pom developer email wsdl4j-discuss@sourceforge.net Low Product pom developer id wsdl4j Low Product pom developer name WSDL4J Low Product pom groupid wsdl4j Highest Product pom name WSDL4J High Product pom url http://sf.net/projects/wsdl4j Medium Version file version 1.6.3 High Version Manifest Implementation-Version 1.6.3 High Version pom version 1.6.3 Highest
wstx-asl-3.2.9-atlassian-1.jarDescription:
Woodstox is a high-performance XML processor that implements Stax (JSR-173) API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/codehaus/woodstox/wstx-asl/3.2.9-atlassian-1/wstx-asl-3.2.9-atlassian-1.jar
MD5: ad41a90de4c140189d5a1171bc5efa57
SHA1: b600b9192823aaac229b438d9f798ab062cf3798
SHA256: cf6c04db9a4c0c89b59afdc8bb346839b18cfa99472d44e1c6180b236e2454b3
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name wstx-asl High Vendor jar package name api Highest Vendor jar package name codehaus Highest Vendor jar package name ctc Low Vendor jar package name stax Highest Vendor jar package name wstx Highest Vendor jar package name wstx Low Vendor pom artifactid wstx-asl Highest Vendor pom artifactid wstx-asl Low Vendor pom groupid org.codehaus.woodstox Highest Vendor pom name Woodstox High Vendor pom organization name Codehaus High Vendor pom organization url http://www.codehaus.org/ Medium Vendor pom url http://woodstox.codehaus.org Highest Product file name wstx-asl High Product jar package name api Highest Product jar package name codehaus Highest Product jar package name stax Highest Product jar package name wstx Highest Product jar package name wstx Low Product pom artifactid wstx-asl Highest Product pom groupid org.codehaus.woodstox Highest Product pom name Woodstox High Product pom organization name Codehaus Low Product pom organization url http://www.codehaus.org/ Low Product pom url http://woodstox.codehaus.org Medium Version pom version 3.2.9-atlassian-1 Highest
CVE-2019-12401 (OSSINDEX) suppress
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a.k.a. Lol Bomb) via it’s update handler.?By leveraging XML DOCTYPE and ENTITY type elements, the attacker can create a pattern that will expand when the server parses the XML causing OOMs. CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:/C:N/I:N/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.codehaus.woodstox:wstx-asl:3.2.9-atlassian-1:*:*:*:*:*:*:* xalan-2.7.2.jarDescription:
Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types. It implements XSL Transformations (XSLT)
Version 1.0 and XML Path Language (XPath) Version 1.0 and can be used from
the command line, in an applet or a servlet, or as a module in other program.
File Path: /home/andrii/.m2/repository/xalan/xalan/2.7.2/xalan-2.7.2.jarMD5: 6aa6607802502c8016b676f25f8e4873SHA1: d55d3f02a56ec4c25695fe67e1334ff8c2ecea23SHA256: a44bd80e82cb0f4cfac0dac8575746223802514e3cec9dc75235bc0de646af14Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xalan High Vendor jar package name and Highest Vendor jar package name apache Highest Vendor jar package name processor Highest Vendor jar package name version Highest Vendor jar package name xalan Highest Vendor jar package name xml Highest Vendor jar package name xpath Highest Vendor jar package name xslt Highest Vendor manifest: java_cup/runtime/ Implementation-Vendor Princeton University Medium Vendor manifest: org/apache/bcel/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/regexp/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xalan/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xalan/xsltc/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xml/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid xalan Highest Vendor pom artifactid xalan Low Vendor pom groupid xalan Highest Vendor pom name Xalan Java High Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://xml.apache.org/xalan-j/ Highest Product file name xalan High Product jar package name and Highest Product jar package name apache Highest Product jar package name bcel Highest Product jar package name code Highest Product jar package name expression Highest Product jar package name processor Highest Product jar package name regexp Highest Product jar package name runtime Highest Product jar package name version Highest Product jar package name xalan Highest Product jar package name xml Highest Product jar package name xpath Highest Product jar package name xslt Highest Product jar package name xsltc Highest Product manifest: java_cup/runtime/ Implementation-Title runtime Medium Product manifest: java_cup/runtime/ Specification-Title Runtime component of JCup Medium Product manifest: org/apache/bcel/ Implementation-Title org.apache.bcel Medium Product manifest: org/apache/bcel/ Specification-Title Byte Code Engineering Library Medium Product manifest: org/apache/regexp/ Implementation-Title org.apache.regexp Medium Product manifest: org/apache/regexp/ Specification-Title Java Regular Expression package Medium Product manifest: org/apache/xalan/ Implementation-Title org.apache.xalan Medium Product manifest: org/apache/xalan/ Specification-Title Java API for XML Processing Medium Product manifest: org/apache/xalan/xsltc/ Implementation-Title org.apache.xalan.xsltc Medium Product manifest: org/apache/xalan/xsltc/ Specification-Title Java API for XML Processing Medium Product manifest: org/apache/xml/ Implementation-Title org.apache.xml Medium Product manifest: org/apache/xpath/ Implementation-Title org.apache.xpath Medium Product pom artifactid xalan Highest Product pom groupid xalan Highest Product pom name Xalan Java High Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://xml.apache.org/xalan-j/ Medium Version file version 2.7.2 High Version manifest: java_cup/runtime/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/bcel/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/regexp/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/xalan/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/xalan/xsltc/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/xml/ Implementation-Version 2.7.2 Medium Version manifest: org/apache/xpath/ Implementation-Version 2.7.2 Medium Version pom parent-version 2.7.2 Low Version pom version 2.7.2 Highest
CVE-2022-34169 suppress
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. The Apache Xalan Java project is dormant and in the process of being retired. No future releases of Apache Xalan Java to address this issue are expected. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan. CWE-681 Incorrect Conversion between Numeric Types
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
xercesImpl-2.12.0.jarDescription:
Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program.
The Apache Xerces2 parser is the reference implementation of XNI but other parser components, configurations, and parsers can be written using the Xerces Native Interface. For complete design and implementation documents, refer to the XNI Manual.
Xerces2 is a fully conforming XML Schema 1.0 processor. A partial experimental implementation of the XML Schema 1.1 Structures and Datatypes Working Drafts (December 2009) and an experimental implementation of the XML Schema Definition Language (XSD): Component Designators (SCD) Candidate Recommendation (January 2010) are provided for evaluation. For more information, refer to the XML Schema page.
Xerces2 also provides a complete implementation of the Document Object Model Level 3 Core and Load/Save W3C Recommendations and provides a complete implementation of the XML Inclusions (XInclude) W3C Recommendation. It also provides support for OASIS XML Catalogs v1.1.
Xerces2 is able to parse documents written according to the XML 1.1 Recommendation, except that it does not yet provide an option to enable normalization checking as described in section 2.13 of this specification. It also handles namespaces according to the XML Namespaces 1.1 Recommendation, and will correctly serialize XML 1.1 documents if the DOM level 3 load/save APIs are in use.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/xerces/xercesImpl/2.12.0/xercesImpl-2.12.0.jar
MD5: b89632b53c4939a2982bcb52806f6dec
SHA1: f02c844149fd306601f20e0b34853a670bef7fa2
SHA256: b50d3a4ca502faa4d1c838acb8aa9480446953421f7327e338c5dda3da5e76d0
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xercesImpl High Vendor jar package name apache Highest Vendor jar package name datatypes Highest Vendor jar package name dom Highest Vendor jar package name parsers Highest Vendor jar package name serialize Highest Vendor jar package name version Highest Vendor jar package name w3c Highest Vendor jar package name xerces Highest Vendor jar package name xinclude Highest Vendor jar package name xml Highest Vendor jar package name xni Highest Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/namespace/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/stream/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xerces/impl/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor pom artifactid xercesImpl Highest Vendor pom artifactid xercesImpl Low Vendor pom developer email j-dev@xerces.apache.org Low Vendor pom developer id xerces Medium Vendor pom developer name Apache Software Foundation Medium Vendor pom developer org Apache Software Foundation Medium Vendor pom developer org URL http://www.apache.org Medium Vendor pom groupid xerces Highest Vendor pom name Xerces2-j High Vendor pom url https://xerces.apache.org/xerces2-j/ Highest Product file name xercesImpl High Product hint analyzer product xerces-j Highest Product jar package name apache Highest Product jar package name datatype Highest Product jar package name datatypes Highest Product jar package name dom Highest Product jar package name impl Highest Product jar package name parsers Highest Product jar package name serialize Highest Product jar package name validation Highest Product jar package name version Highest Product jar package name w3c Highest Product jar package name xerces Highest Product jar package name xinclude Highest Product jar package name xml Highest Product jar package name xni Highest Product jar package name xpath Highest Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/namespace/ Implementation-Title javax.xml.namespace Medium Product manifest: javax/xml/namespace/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/stream/ Implementation-Title javax.xml.stream Medium Product manifest: javax/xml/stream/ Specification-Title Streaming API for XML Medium Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium Product manifest: org/apache/xerces/impl/ Implementation-Title org.apache.xerces.impl.Version Medium Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product pom artifactid xercesImpl Highest Product pom developer email j-dev@xerces.apache.org Low Product pom developer id xerces Low Product pom developer name Apache Software Foundation Low Product pom developer org Apache Software Foundation Low Product pom developer org URL http://www.apache.org Low Product pom groupid xerces Highest Product pom name Xerces2-j High Product pom url https://xerces.apache.org/xerces2-j/ Medium Version file version 2.12.0 High Version manifest: org/apache/xerces/impl/ Implementation-Version 2.12.0 Medium Version pom version 2.12.0 Highest
pkg:maven/xerces/xercesImpl@2.12.0 (Confidence :High)cpe:2.3:a:apache:xerces-j:2.12.0:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:apache:xerces2_java:2.12.0:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2022-23437 suppress
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions. CWE-91 XML Injection (aka Blind XPath Injection)
CVSSv2:
Base Score: HIGH (7.1) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:C CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2017-10355 (OSSINDEX) suppress
sonatype-2017-0348 - xerces:xercesImpl - Denial of Service (DoS)
The software contains multiple threads or executable segments that are waiting for each other to release a necessary lock, resulting in deadlock. CWE-833 Deadlock
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:xerces:xercesImpl:2.12.0:*:*:*:*:*:*:* xml-apis-1.4.01.jarDescription:
xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier. The External Components portion of xml-commons contains
interfaces that are defined by external standards organizations. For DOM,
that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for
JAXP it's Sun. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
The SAX License: http://www.saxproject.org/copying.html
The W3C License: http://www.w3.org/TR/2004/REC-DOM-Level-3-Core-20040407/java-binding.zip File Path: /home/andrii/.m2/repository/xml-apis/xml-apis/1.4.01/xml-apis-1.4.01.jar
MD5: 7eaad6fea5925cca6c36ee8b3e02ac9d
SHA1: 3789d9fada2d3d458c4ba2de349d48780f381ee3
SHA256: a840968176645684bb01aed376e067ab39614885f9eee44abe35a5f20ebe7fad
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name xml-apis High Vendor jar package name apache Highest Vendor jar package name dom Highest Vendor jar package name sax Highest Vendor jar package name version Highest Vendor jar package name w3c Highest Vendor jar package name xml Highest Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/namespace/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/stream/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium Vendor pom artifactid xml-apis Highest Vendor pom artifactid xml-apis Low Vendor pom developer email commons-dev@xml.apache.org Low Vendor pom developer id xml-apis Medium Vendor pom developer name Apache Software Foundation Medium Vendor pom developer org Apache Software Foundation Medium Vendor pom developer org URL http://www.apache.org Medium Vendor pom groupid xml-apis Highest Vendor pom name XML Commons External Components XML APIs High Vendor pom url http://xml.apache.org/commons/components/external/ Highest Product file name xml-apis High Product jar package name apache Highest Product jar package name datatype Highest Product jar package name document Highest Product jar package name dom Highest Product jar package name javax Highest Product jar package name ls Highest Product jar package name namespace Highest Product jar package name parsers Highest Product jar package name sax Highest Product jar package name stax Highest Product jar package name stream Highest Product jar package name transform Highest Product jar package name validation Highest Product jar package name version Highest Product jar package name w3c Highest Product jar package name xml Highest Product jar package name xmlcommons Highest Product jar package name xpath Highest Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium Product manifest: javax/xml/namespace/ Implementation-Title javax.xml.namespace Medium Product manifest: javax/xml/namespace/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium Product manifest: javax/xml/stream/ Implementation-Title javax.xml.stream Medium Product manifest: javax/xml/stream/ Specification-Title Streaming API for XML (StAX) 1.0 Medium Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium Product manifest: org/w3c/dom/ Specification-Title Document Object Model (DOM) Level 3 Core Medium Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model (DOM) Level 3 Load and Save Medium Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium Product pom artifactid xml-apis Highest Product pom developer email commons-dev@xml.apache.org Low Product pom developer id xml-apis Low Product pom developer name Apache Software Foundation Low Product pom developer org Apache Software Foundation Low Product pom developer org URL http://www.apache.org Low Product pom groupid xml-apis Highest Product pom name XML Commons External Components XML APIs High Product pom url http://xml.apache.org/commons/components/external/ Medium Version file version 1.4.01 High Version manifest: javax/xml/datatype/ Implementation-Version 1.4.01 Medium Version manifest: javax/xml/namespace/ Implementation-Version 1.4.01 Medium Version manifest: javax/xml/parsers/ Implementation-Version 1.4.01 Medium Version manifest: javax/xml/stream/ Implementation-Version 1.4.01 Medium Version manifest: javax/xml/transform/ Implementation-Version 1.4.01 Medium Version manifest: javax/xml/validation/ Implementation-Version 1.4.01 Medium Version manifest: javax/xml/xpath/ Implementation-Version 1.4.01 Medium Version manifest: org/apache/xmlcommons/Version Implementation-Version 1.4.01 Medium Version pom version 1.4.01 Highest
xml-apis-ext-1.3.04.jarDescription:
xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier. The External Components portion of xml-commons contains
interfaces that are defined by external standards organizations. For DOM,
that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for
JAXP it's Sun. File Path: /home/andrii/.m2/repository/xml-apis/xml-apis-ext/1.3.04/xml-apis-ext-1.3.04.jarMD5: bcb07d3b8d2397db7a3013b6465d347bSHA1: 41a8b86b358e87f3f13cf46069721719105aff66SHA256: d0b4887dc34d57de49074a58affad439a013d0baffa1a8034f8ef2a5ea191646Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xml-apis-ext High Vendor jar package name dom Highest Vendor jar package name w3c Highest Vendor manifest: org/w3c/css/sac/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/smil/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/svg/ Implementation-Vendor World Wide Web Consortium Medium Vendor pom artifactid xml-apis-ext Highest Vendor pom artifactid xml-apis-ext Low Vendor pom groupid xml-apis Highest Vendor pom name XML Commons External Components XML APIs Extensions High Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://xml.apache.org/commons/components/external/ Highest Product file name xml-apis-ext High Product jar package name css Highest Product jar package name dom Highest Product jar package name sac Highest Product jar package name smil Highest Product jar package name svg Highest Product jar package name w3c Highest Product manifest: org/w3c/css/sac/ Implementation-Title org.w3c.css.sac Medium Product manifest: org/w3c/css/sac/ Specification-Title Simple API for CSS Medium Product manifest: org/w3c/dom/smil/ Implementation-Title org.w3c.dom.smil Medium Product manifest: org/w3c/dom/smil/ Specification-Title Document Object Model (DOM) for Synchronized Multimedia Integration Language (SMIL) Medium Product manifest: org/w3c/dom/svg/ Implementation-Title org.w3c.dom.svg Medium Product manifest: org/w3c/dom/svg/ Specification-Title Document Object Model (DOM) for Scalable Vector Graphics (SVG) Medium Product pom artifactid xml-apis-ext Highest Product pom groupid xml-apis Highest Product pom name XML Commons External Components XML APIs Extensions High Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://xml.apache.org/commons/components/external/ Medium Version file version 1.3.04 High Version pom parent-version 1.3.04 Low Version pom version 1.3.04 Highest
xmlgraphics-commons-2.6.jarDescription:
Apache XML Graphics Commons is a library that consists of several reusable
components used by Apache Batik and Apache FOP. Many of these components
can easily be used separately outside the domains of SVG and XSL-FO.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/xmlgraphics/xmlgraphics-commons/2.6/xmlgraphics-commons-2.6.jar
MD5: e10f2ebebd7e2790add49a7303ac630f
SHA1: 8779b8d8f426f24fdb4a512f8bc4248cb3775bd2
SHA256: 25f21c93462d767d05e340f1dc754862995b9bf8b4618ab5b07cd703d400d413
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xmlgraphics-commons High Vendor jar package name apache Highest Vendor jar package name xmlgraphics Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation (http://xmlgraphics.apache.org/) High Vendor pom artifactid xmlgraphics-commons Highest Vendor pom artifactid xmlgraphics-commons Low Vendor pom groupid org.apache.xmlgraphics Highest Vendor pom name Apache XML Graphics Commons High Vendor pom organization name Apache Software Foundation High Vendor pom organization url http://www.apache.org/ Medium Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://xmlgraphics.apache.org/commons/ Highest Product file name xmlgraphics-commons High Product jar package name apache Highest Product jar package name xmlgraphics Highest Product Manifest Implementation-Title Apache XML Graphics Commons High Product pom artifactid xmlgraphics-commons Highest Product pom groupid org.apache.xmlgraphics Highest Product pom name Apache XML Graphics Commons High Product pom organization name Apache Software Foundation Low Product pom organization url http://www.apache.org/ Low Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://xmlgraphics.apache.org/commons/ Medium Version file version 2.6 High Version Manifest Implementation-Version 2.6 High Version pom parent-version 2.6 Low Version pom version 2.6 Highest
xmlpull-1.1.3.1.jarLicense:
Public Domain: http://www.xmlpull.org/v1/download/unpacked/LICENSE.txt File Path: /home/andrii/.m2/repository/xmlpull/xmlpull/1.1.3.1/xmlpull-1.1.3.1.jar
MD5: cc57dacc720eca721a50e78934b822d2
SHA1: 2b8e230d2ab644e4ecaa94db7cdedbc40c805dfa
SHA256: 34e08ee62116071cbb69c0ed70d15a7a5b208d62798c59f2120bb8929324cb63
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xmlpull High Vendor jar package name v1 Low Vendor jar package name xmlpull Highest Vendor jar package name xmlpull Low Vendor pom artifactid xmlpull Highest Vendor pom artifactid xmlpull Low Vendor pom groupid xmlpull Highest Vendor pom name XML Pull Parsing API High Vendor pom url http://www.xmlpull.org Highest Product file name xmlpull High Product jar package name v1 Low Product jar package name xmlpull Highest Product pom artifactid xmlpull Highest Product pom groupid xmlpull Highest Product pom name XML Pull Parsing API High Product pom url http://www.xmlpull.org Medium Version file version 1.1.3.1 High Version pom version 1.1.3.1 Highest
xmlrpc-2.0+xmlrpc61.1+sbfix.jarFile Path: /home/andrii/.m2/repository/xmlrpc/xmlrpc/2.0+xmlrpc61.1+sbfix/xmlrpc-2.0+xmlrpc61.1+sbfix.jarMD5: e05e11c783b9226d867d73f48b8f4c2eSHA1: 9f283031cccc87b6a797cb4dfc9851d8337e5e00SHA256: e80f5f9e230c53ec08c2b6d6464f5b44d6e975414b950072887664c5a19e7948Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xmlrpc-2.0+xmlrpc61.1+sbfix High Vendor jar package name apache Low Vendor jar package name xmlrpc Highest Vendor jar package name xmlrpc Low Vendor pom artifactid xmlrpc Highest Vendor pom artifactid xmlrpc Low Vendor pom groupid xmlrpc Highest Product file name xmlrpc-2.0+xmlrpc61.1+sbfix High Product jar package name xmlrpc Highest Product jar package name xmlrpc Low Product pom artifactid xmlrpc Highest Product pom groupid xmlrpc Highest Version pom version 2.0+xmlrpc61.1+sbfix Highest
xmlrpc-supplementary-character-support-0.2.jarLicense:
Apache License Version 2.0: https://maven.atlassian.com/public/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/com/atlassian/xmlrpc/xmlrpc-supplementary-character-support/0.2/xmlrpc-supplementary-character-support-0.2.jar
MD5: b0c0b142a4f006beeef6e3268721ade1
SHA1: cc8b5f4d04a2d3e05fdbee173fb560f00515cfef
SHA256: e4a4f62352293f3dfab2557d3a664f1a9c088decf254e1fd2ad15690a18d4974
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xmlrpc-supplementary-character-support High Vendor jar package name apache Low Vendor jar package name xmlrpc Highest Vendor jar package name xmlrpc Low Vendor pom artifactid xmlrpc-supplementary-character-support Highest Vendor pom artifactid xmlrpc-supplementary-character-support Low Vendor pom groupid com.atlassian.xmlrpc Highest Vendor pom name xmlrpc-supplementary-character-support High Vendor pom parent-artifactid atlassian-public-pom Low Vendor pom parent-groupid com.atlassian.pom Medium Product file name xmlrpc-supplementary-character-support High Product jar package name xmlrpc Highest Product jar package name xmlrpc Low Product pom artifactid xmlrpc-supplementary-character-support Highest Product pom groupid com.atlassian.xmlrpc Highest Product pom name xmlrpc-supplementary-character-support High Product pom parent-artifactid atlassian-public-pom Medium Product pom parent-groupid com.atlassian.pom Medium Version file version 0.2 High Version pom parent-version 0.2 Low Version pom version 0.2 Highest
xmpbox-2.0.24.jarDescription:
The Apache XmpBox library is an open source Java tool that implements Adobe's XMP(TM)
specification. It can be used to parse, validate and create xmp contents.
It is mainly used by subproject preflight of Apache PDFBox.
XmpBox is a subproject of Apache PDFBox.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/andrii/.m2/repository/org/apache/pdfbox/xmpbox/2.0.24/xmpbox-2.0.24.jar
MD5: b540c277bcbd8061dcef2629c8581057
SHA1: df8b7a6a363281f9f1365ed4b37580aa5d3f38f1
SHA256: 27383df2285b9e228c39f2c755adeebbef774793d33c4f20f0dc99e9ebaaf673
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xmpbox High Vendor jar package name apache Highest Vendor jar package name xmpbox Highest Vendor Manifest automatic-module-name org.apache.xmpbox Medium Vendor Manifest bundle-docurl http://pdfbox.apache.org Low Vendor Manifest bundle-symbolicname org.apache.pdfbox.xmpbox Medium Vendor Manifest implementation-url https://www.apache.org/pdfbox-parent/xmpbox/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid xmpbox Highest Vendor pom artifactid xmpbox Low Vendor pom groupid org.apache.pdfbox Highest Vendor pom name Apache XmpBox High Vendor pom parent-artifactid pdfbox-parent Low Product file name xmpbox High Product jar package name apache Highest Product jar package name xmpbox Highest Product Manifest automatic-module-name org.apache.xmpbox Medium Product Manifest bundle-docurl http://pdfbox.apache.org Low Product Manifest Bundle-Name Apache XmpBox Medium Product Manifest bundle-symbolicname org.apache.pdfbox.xmpbox Medium Product Manifest Implementation-Title Apache XmpBox High Product Manifest implementation-url https://www.apache.org/pdfbox-parent/xmpbox/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Apache XmpBox Medium Product pom artifactid xmpbox Highest Product pom groupid org.apache.pdfbox Highest Product pom name Apache XmpBox High Product pom parent-artifactid pdfbox-parent Medium Version file version 2.0.24 High Version Manifest Bundle-Version 2.0.24 High Version Manifest Implementation-Version 2.0.24 High Version pom version 2.0.24 Highest
xstream-1.4.17.jarDescription:
XStream is a serialization library from Java objects to XML and back. License:
BSD-3-Clause File Path: /home/andrii/.m2/repository/com/thoughtworks/xstream/xstream/1.4.17/xstream-1.4.17.jar
MD5: 6c756db449d3f22367b0297d78ec4ff9
SHA1: 646da0e0fa6c56ff2f1b81601fb8934393718217
SHA256: 0dd5e24bdaf2a8782cd3642d18e6f01cca8867ae243c74d9445d06269f612844
Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xstream High Vendor jar package name core Highest Vendor jar package name thoughtworks Highest Vendor jar package name xstream Highest Vendor Manifest bundle-docurl http://x-stream.github.io Low Vendor Manifest bundle-symbolicname xstream Medium Vendor Manifest Implementation-Vendor XStream High Vendor Manifest Implementation-Vendor-Id com.thoughtworks.xstream Medium Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Vendor Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Vendor Manifest specification-vendor XStream Low Vendor Manifest x-build-os Linux Low Vendor Manifest x-build-time 2021-05-14T08:20:36Z Low Vendor Manifest x-builder Maven 3.8.1 Low Vendor Manifest x-compile-source 1.4 Low Vendor Manifest x-compile-target 1.4 Low Vendor pom artifactid xstream Highest Vendor pom artifactid xstream Low Vendor pom groupid com.thoughtworks.xstream Highest Vendor pom name XStream Core High Vendor pom parent-artifactid xstream-parent Low Product file name xstream High Product jar package name core Highest Product jar package name io Highest Product jar package name thoughtworks Highest Product jar package name xml Highest Product jar package name xstream Highest Product Manifest bundle-docurl http://x-stream.github.io Low Product Manifest Bundle-Name XStream Core Medium Product Manifest bundle-symbolicname xstream Medium Product Manifest Implementation-Title XStream Core High Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Product Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Product Manifest specification-title XStream Core Medium Product Manifest x-build-os Linux Low Product Manifest x-build-time 2021-05-14T08:20:36Z Low Product Manifest x-builder Maven 3.8.1 Low Product Manifest x-compile-source 1.4 Low Product Manifest x-compile-target 1.4 Low Product pom artifactid xstream Highest Product pom groupid com.thoughtworks.xstream Highest Product pom name XStream Core High Product pom parent-artifactid xstream-parent Medium Version file version 1.4.17 High Version Manifest Bundle-Version 1.4.17 High Version Manifest Implementation-Version 1.4.17 High Version pom version 1.4.17 Highest
CVE-2021-39139 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario can be adjusted easily to an external Xalan that works regardless of the version of the Java runtime. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39141 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39144 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-502 Deserialization of Untrusted Data, CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39145 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39146 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39147 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39148 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39149 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39150 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18. CWE-502 Deserialization of Untrusted Data, CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39151 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39152 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18. CWE-502 Deserialization of Untrusted Data, CWE-918 Server-Side Request Forgery (SSRF)
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39153 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-39154 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-434 Unrestricted Upload of File with Dangerous Type, CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
Base Score: HIGH (8.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2021-43859 suppress
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2022-40151 suppress
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-40152 suppress
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-40153 suppress
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-40154 suppress
Those using Xstream to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-40155 suppress
Those using Xstream to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-40156 suppress
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2021-39140 suppress
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. CWE-502 Deserialization of Untrusted Data, CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv2:
Base Score: MEDIUM (6.3) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:C CVSSv3:
Base Score: MEDIUM (6.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
xwork-1.0.3.6.jarFile Path: /home/andrii/.m2/repository/opensymphony/xwork/1.0.3.6/xwork-1.0.3.6.jarMD5: 59c8950b1129637bb63aea94b4139d7fSHA1: 6ce687ad0967100e8c9031e51de1888b4ed7ff0dSHA256: b548454dcf030646478131f67614a8475330d1894de34e7bc57a47e7202516f3Referenced In Project/Scope: space-comments:provided
Evidence Type Source Name Value Confidence Vendor file name xwork High Vendor jar package name opensymphony Highest Vendor jar package name opensymphony Low Vendor jar package name xwork Highest Vendor jar package name xwork Low Vendor pom artifactid xwork Highest Vendor pom artifactid xwork Low Vendor pom groupid opensymphony Highest Product file name xwork High Product jar package name opensymphony Highest Product jar package name xwork Highest Product jar package name xwork Low Product pom artifactid xwork Highest Product pom groupid opensymphony Highest Version file version 1.0.3.6 High Version pom version 1.0.3.6 Highest
CVE-2012-0838 (OSSINDEX) suppress
Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field. CWE-20 Improper Input Validation
CVSSv2:
Base Score: HIGH (10.0) Vector: /AV:N/AC:L/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2011-3923 (OSSINDEX) suppress
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: HIGH (9.8) Vector: /AV:N/AC:L/Au:/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2016-4461 (OSSINDEX) suppress
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785. CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2007-4556 suppress
Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2012-0392 (OSSINDEX) suppress
The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2008-6504 (OSSINDEX) suppress
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2010-1870 (OSSINDEX) suppress
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504. CWE-285 Improper Authorization
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2011-2088 (OSSINDEX) suppress
XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote attackers to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3. CWE-200 Information Exposure
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2012-4387 (OSSINDEX) suppress
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:opensymphony:xwork:1.0.3.6:*:*:*:*:*:*:* CVE-2011-1772 suppress
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
xz-1.9.jarDescription:
XZ data compression License:
Public Domain File Path: /home/andrii/.m2/repository/org/tukaani/xz/1.9/xz-1.9.jar
MD5: 57c2fbfeb55e307ccae52e5322082e02
SHA1: 1ea4bec1a921180164852c65006d928617bd2caf
SHA256: 211b306cfc44f8f96df3a0a3ddaf75ba8c5289eed77d60d72f889bb855f535e5
Referenced In Project/Scope: space-comments:compile
Evidence Type Source Name Value Confidence Vendor file name xz High Vendor jar package name tukaani Highest Vendor jar package name xz Highest Vendor Manifest bundle-docurl https://tukaani.org/xz/java.html Low Vendor Manifest bundle-symbolicname org.tukaani.xz Medium Vendor Manifest implementation-url https://tukaani.org/xz/java.html Low Vendor Manifest multi-release true Low Vendor pom artifactid xz Highest Vendor pom artifactid xz Low Vendor pom developer email lasse.collin@tukaani.org Low Vendor pom developer name Lasse Collin Medium Vendor pom groupid org.tukaani Highest Vendor pom name XZ for Java High Vendor pom url https://tukaani.org/xz/java.html Highest Product file name xz High Product jar package name tukaani Highest Product jar package name xz Highest Product Manifest bundle-docurl https://tukaani.org/xz/java.html Low Product Manifest Bundle-Name XZ data compression Medium Product Manifest bundle-symbolicname org.tukaani.xz Medium Product Manifest Implementation-Title XZ data compression High Product Manifest implementation-url https://tukaani.org/xz/java.html Low Product Manifest multi-release true Low Product pom artifactid xz Highest Product pom developer email lasse.collin@tukaani.org Low Product pom developer name Lasse Collin Low Product pom groupid org.tukaani Highest Product pom name XZ for Java High Product pom url https://tukaani.org/xz/java.html Medium Version file version 1.9 High Version Manifest Bundle-Version 1.9 High Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest