Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : Nov 27, 2018 at 14:47:05 +00:00
Dependencies Scanned : 75 (54 unique)
Vulnerable Dependencies : 9
Vulnerabilities Found : 34
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 27/11/2018 09:08:21
NVD CVE 2003 : 22/11/2018 09:07:02
NVD CVE 2004 : 27/11/2018 09:05:51
NVD CVE 2005 : 27/11/2018 09:04:33
NVD CVE 2006 : 27/11/2018 14:17:24
NVD CVE 2007 : 27/11/2018 14:17:29
NVD CVE 2008 : 27/11/2018 08:55:49
NVD CVE 2009 : 27/11/2018 14:17:25
NVD CVE 2010 : 27/11/2018 08:49:00
NVD CVE 2011 : 27/11/2018 14:17:25
NVD CVE 2012 : 27/11/2018 08:39:42
NVD CVE 2013 : 27/11/2018 08:36:24
NVD CVE 2014 : 27/11/2018 08:32:59
NVD CVE 2015 : 27/11/2018 08:28:55
NVD CVE 2016 : 27/11/2018 08:24:50
NVD CVE 2017 : 27/11/2018 14:17:24
NVD CVE 2018 : 27/11/2018 14:17:28
NVD CVE Checked : 27/11/2018 14:45:55
NVD CVE Modified : 27/11/2018 13:01:45
VersionCheckOn : 1543329955984
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
javax.inject-1.jar
Description: The javax.inject API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid javax.inject Highest
Vendor file name javax.inject-1 High
Vendor pom artifactid javax.inject Low
Vendor jar package name inject Low
Vendor pom name javax.inject High
Vendor pom url http://code.google.com/p/atinject/ Highest
Vendor pom description The javax.inject API Medium
Vendor jar package name javax Low
Vendor central groupid javax.inject Highest
Product file name javax.inject-1 High
Product jar package name inject Low
Product pom name javax.inject High
Product central artifactid javax.inject Highest
Product pom artifactid javax.inject Highest
Product pom description The javax.inject API Medium
Product pom groupid javax.inject Low
Product pom url http://code.google.com/p/atinject/ Medium
Version file version 1 Medium
Version pom version 1 Highest
Version central version 1 Highest
commons-lang-2.6.jar
Description:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid commons-lang Highest
Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid commons-lang Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom name Commons Lang High
Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low
Vendor pom url http://commons.apache.org/lang/ Highest
Vendor file name commons-lang High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid commons-lang Low
Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product pom url http://commons.apache.org/lang/ Medium
Product pom name Commons Lang High
Product pom parent-groupid org.apache.commons Low
Product Manifest Implementation-Title Commons Lang High
Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest bundle-docurl http://commons.apache.org/lang/ Low
Product file name commons-lang High
Product central artifactid commons-lang Highest
Product Manifest bundle-symbolicname org.apache.commons.lang Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest Bundle-Name Commons Lang Medium
Product pom groupid commons-lang Low
Product pom artifactid commons-lang Highest
Product Manifest specification-title Commons Lang Medium
Version file version 2.6 Highest
Version Manifest Implementation-Version 2.6 High
Version pom version 2.6 Highest
Version central version 2.6 Highest
commons-collections-3.2.2.jar
Description: Types that extend and augment the Java Collections Framework.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor file name commons-collections High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low
Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Vendor pom description Types that extend and augment the Java Collections Framework. Medium
Vendor pom url http://commons.apache.org/collections/ Highest
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-collections Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor central groupid commons-collections Highest
Vendor Manifest implementation-url http://commons.apache.org/collections/ Low
Vendor pom name Apache Commons Collections High
Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low
Vendor pom artifactid commons-collections Low
Vendor manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium
Product file name commons-collections High
Product Manifest specification-title Apache Commons Collections Medium
Product Manifest bundle-symbolicname org.apache.commons.collections Medium
Product pom url http://commons.apache.org/collections/ Medium
Product pom artifactid commons-collections Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low
Product pom parent-groupid org.apache.commons Low
Product Manifest Bundle-Name Apache Commons Collections Medium
Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Product pom description Types that extend and augment the Java Collections Framework. Medium
Product Manifest Implementation-Title Apache Commons Collections High
Product pom parent-artifactid commons-parent Medium
Product Manifest implementation-url http://commons.apache.org/collections/ Low
Product pom groupid commons-collections Low
Product pom name Apache Commons Collections High
Product Manifest bundle-docurl http://commons.apache.org/collections/ Low
Product central artifactid commons-collections Highest
Product manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium
Version central version 3.2.2 Highest
Version Manifest Implementation-Version 3.2.2 High
Version pom version 3.2.2 Highest
Version file version 3.2.2 Highest
commons-fileupload-1.3.2.jar
Description:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/commons-fileupload/commons-fileupload/1.3.2/commons-fileupload-1.3.2.jar
MD5: f76891c36a08e87e3f806d3a83fcb4bc
SHA1: 5d7491ed6ebd02b6a8d2305f8e6b7fe5dbd95f72
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor file name commons-fileupload High
Vendor pom artifactid commons-fileupload Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest implementation-build tags/FILEUPLOAD_1_3_2_RC1@r1745203; 2016-05-23 14:47:52+0000 Low
Vendor pom name Apache Commons FileUpload High
Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest
Vendor pom groupid commons-fileupload Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor central groupid commons-fileupload Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Vendor manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product central artifactid commons-fileupload Highest
Product file name commons-fileupload High
Product Manifest specification-title Apache Commons FileUpload Medium
Product Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom artifactid commons-fileupload Highest
Product pom parent-groupid org.apache.commons Low
Product pom groupid commons-fileupload Low
Product Manifest implementation-build tags/FILEUPLOAD_1_3_2_RC1@r1745203; 2016-05-23 14:47:52+0000 Low
Product pom name Apache Commons FileUpload High
Product Manifest Bundle-Name Apache Commons FileUpload Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Product Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium
Product Manifest Implementation-Title Apache Commons FileUpload High
Product manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Version file version 1.3.2 Highest
Version Manifest Implementation-Version 1.3.2 High
Version pom version 1.3.2 Highest
Version central version 1.3.2 Highest
Published Vulnerabilities
CVE-2016-1000031 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Vulnerable Software & Versions:
commons-io-2.5.jar
Description:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/commons-io/commons-io/2.5/commons-io-2.5.jar
MD5: e2d74794fba570ec2115fb9d5b05dc9b
SHA1: 2852e6e05fbb95076fc091f6d1780f1f8fe35e0f
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low
Vendor pom url http://commons.apache.org/proper/commons-io/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-symbolicname org.apache.commons.io Medium
Vendor pom description
The Apache Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor pom parent-artifactid commons-parent Low
Vendor file name commons-io High
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low
Vendor pom groupid commons-io Highest
Vendor pom parent-groupid org.apache.commons Medium
Vendor manifest Bundle-Description The Apache Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor Manifest implementation-build tags/commons-io-2.5@r1739098; 2016-04-14 09:19:54-0400 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom artifactid commons-io Low
Vendor central groupid commons-io Highest
Vendor pom name Apache Commons IO High
Product pom groupid commons-io Low
Product Manifest specification-title Apache Commons IO Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low
Product pom artifactid commons-io Highest
Product Manifest bundle-symbolicname org.apache.commons.io Medium
Product pom description
The Apache Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product Manifest Bundle-Name Apache Commons IO Medium
Product pom url http://commons.apache.org/proper/commons-io/ Medium
Product file name commons-io High
Product Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low
Product pom parent-groupid org.apache.commons Low
Product Manifest Implementation-Title Apache Commons IO High
Product manifest Bundle-Description The Apache Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product Manifest implementation-build tags/commons-io-2.5@r1739098; 2016-04-14 09:19:54-0400 Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom parent-artifactid commons-parent Medium
Product pom name Apache Commons IO High
Product central artifactid commons-io Highest
Version Manifest Implementation-Version 2.5 High
Version file version 2.5 Highest
Version pom version 2.5 Highest
Version central version 2.5 Highest
commons-logging-1.2.jar
Description: Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid commons-logging Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor central groupid commons-logging Highest
Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low
Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest
Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium
Vendor manifest Bundle-Description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Vendor pom name Apache Commons Logging High
Vendor pom artifactid commons-logging Low
Vendor file name commons-logging High
Product Manifest specification-title Apache Commons Logging Medium
Product pom description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product Manifest Bundle-Name Apache Commons Logging Medium
Product pom parent-groupid org.apache.commons Low
Product Manifest Implementation-Title Apache Commons Logging High
Product pom groupid commons-logging Low
Product pom artifactid commons-logging Highest
Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low
Product pom parent-artifactid commons-parent Medium
Product central artifactid commons-logging Highest
Product Manifest bundle-symbolicname org.apache.commons.logging Medium
Product manifest Bundle-Description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product pom name Apache Commons Logging High
Product pom url http://commons.apache.org/proper/commons-logging/ Medium
Product file name commons-logging High
Version central version 1.2 Highest
Version file version 1.2 Highest
Version pom version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
spring-core-4.3.12.RELEASE.jar
Description: Spring Core
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/travis/.m2/repository/org/springframework/spring-core/4.3.12.RELEASE/spring-core-4.3.12.RELEASE.jar
MD5: 01ab7f742861c65f7339acba6333326c
SHA1: 4cebc69478c6d350dbd5af28e3db7d5694f416e3
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid spring-core Low
Vendor file name spring-core High
Vendor hint analyzer vendor vmware High
Vendor pom name Spring Core High
Vendor hint analyzer vendor pivotal software High
Vendor pom organization url http://projects.spring.io/spring-framework Medium
Vendor hint analyzer vendor pivotal software Highest
Vendor pom url spring-projects/spring-framework Highest
Vendor pom organization name Spring IO High
Vendor pom groupid org.springframework Highest
Vendor hint analyzer vendor SpringSource High
Vendor central groupid org.springframework Highest
Vendor pom description Spring Core Medium
Vendor pom groupid springframework Highest
Product Manifest Implementation-Title spring-core High
Product pom groupid springframework Low
Product file name spring-core High
Product pom organization url http://projects.spring.io/spring-framework Low
Product pom name Spring Core High
Product pom organization name Spring IO Low
Product pom artifactid spring-core Highest
Product pom description Spring Core Medium
Product central artifactid spring-core Highest
Product pom url spring-projects/spring-framework High
Product hint analyzer product springsource_spring_framework High
Version pom version 4.3.12.RELEASE Highest
Version central version 4.3.12.RELEASE Highest
Version Manifest Implementation-Version 4.3.12.RELEASE High
Related Dependencies
spring-beans-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-beans/4.3.12.RELEASE/spring-beans-4.3.12.RELEASE.jar
SHA1: 0547dd432d47d0f01d9ccbedc4b705f9f7c1240a
MD5: 016d6b84ad5520b96b0d73ced6b729be
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-beans:4.3.12.RELEASE ✓
spring-tx-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-tx/4.3.12.RELEASE/spring-tx-4.3.12.RELEASE.jar
SHA1: 7147b6839b2bf9db3621b79c73b4dddbe69572b6
MD5: 65bb5f31f3254fc6d278ed8453583416
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-tx:4.3.12.RELEASE ✓
spring-web-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-web/4.3.12.RELEASE/spring-web-4.3.12.RELEASE.jar
SHA1: 86c29588cca74d0fc848b194cb13fcdfd12bc990
MD5: 7564e45fbffa0c682cc1575f98c04bd0
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-web:4.3.12.RELEASE ✓
spring-expression-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-expression/4.3.12.RELEASE/spring-expression-4.3.12.RELEASE.jar
SHA1: 790f69f6ad7f9da8d4a92c603ad7244c398c8309
MD5: 406bc89c8e55275190cc04e65fabc05d
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-expression:4.3.12.RELEASE ✓
spring-context-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-context/4.3.12.RELEASE/spring-context-4.3.12.RELEASE.jar
SHA1: 5e6d26f36636f36b7efec1d6a0c5991284fbd95b
MD5: e403d653908491418191f2c12c77a6b6
maven: org.springframework:spring-context:4.3.12.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
spring-webmvc-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-webmvc/4.3.12.RELEASE/spring-webmvc-4.3.12.RELEASE.jar
SHA1: 986e5dcd4435e780f6be64f8185eaa51523cf851
MD5: 71149ce3d60b8bf7bcd3ed5789d27040
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-webmvc:4.3.12.RELEASE ✓
spring-jdbc-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-jdbc/4.3.12.RELEASE/spring-jdbc-4.3.12.RELEASE.jar
SHA1: 5c840abbdc1a1dfd0f79c4a4c25eac0c98e6af22
MD5: 77bd83577d0e164b84d6fda6967a7798
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-jdbc:4.3.12.RELEASE ✓
spring-orm-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-orm/4.3.12.RELEASE/spring-orm-4.3.12.RELEASE.jar
SHA1: 47bbe35a92944aeedf06a388098581272f8db9bd
MD5: 5f514e4f10d23b108be01249e306ffbb
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-orm:4.3.12.RELEASE ✓
spring-aop-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-aop/4.3.12.RELEASE/spring-aop-4.3.12.RELEASE.jar
SHA1: b3fef085902993c2ef874c45c7bfd79296d5a5a4
MD5: 43f27fd377b41bd4c1d59fb17bdc3a4d
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-aop:4.3.12.RELEASE ✓
spring-context-support-4.3.12.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/spring-context-support/4.3.12.RELEASE/spring-context-support-4.3.12.RELEASE.jar
SHA1: 6f3a71b93b69f38ac545b6043fab7e474addee15
MD5: f5de29c45e3c0b4138ecb5eaeab4c966
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
maven: org.springframework:spring-context-support:4.3.12.RELEASE ✓
Published Vulnerabilities
CVE-2018-11039 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-20 Improper Input Validation
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11040 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-254 Security Features
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
Vulnerable Software & Versions: (show all )
CVE-2018-1199 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-20 Improper Input Validation
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Spring MVC static resource URLs to be bypassed.
Vulnerable Software & Versions: (show all )
CVE-2018-1257 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-1270 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-358 Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
Vulnerable Software & Versions: (show all )
CVE-2018-1271 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Vulnerable Software & Versions: (show all )
CVE-2018-1272 suppress
Severity:
Medium
CVSS Score: 6.0
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
CWE: CWE-264 Permissions, Privileges, and Access Controls
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.
Vulnerable Software & Versions: (show all )
CVE-2018-1275 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-358 Improperly Implemented Security Check for Standard
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.
Vulnerable Software & Versions: (show all )
slf4j-api-1.7.21.jar
Description: The slf4j API
File Path: /home/travis/.m2/repository/org/slf4j/slf4j-api/1.7.21/slf4j-api-1.7.21.jar
MD5: c9be56284a92dcb2576679282eff80bf
SHA1: 139535a69a4239db087de9bab0bee568bf8e0b70
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid slf4j Highest
Vendor pom artifactid slf4j-api Low
Vendor manifest Bundle-Description The slf4j API Medium
Vendor pom parent-groupid org.slf4j Medium
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom groupid org.slf4j Highest
Vendor pom url http://www.slf4j.org Highest
Vendor file name slf4j-api High
Vendor pom name SLF4J API Module High
Vendor central groupid org.slf4j Highest
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom description The slf4j API Medium
Product Manifest Implementation-Title slf4j-api High
Product pom url http://www.slf4j.org Medium
Product pom parent-groupid org.slf4j Low
Product manifest Bundle-Description The slf4j API Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product central artifactid slf4j-api Highest
Product pom artifactid slf4j-api Highest
Product file name slf4j-api High
Product pom groupid slf4j Low
Product pom parent-artifactid slf4j-parent Medium
Product pom name SLF4J API Module High
Product Manifest Bundle-Name slf4j-api Medium
Product pom description The slf4j API Medium
Version pom version 1.7.21 Highest
Version Manifest Implementation-Version 1.7.21 High
Version file version 1.7.21 Highest
Version central version 1.7.21 Highest
javax.servlet-api-3.1.0.jar
Description: Java(TM) Servlet 3.1 API Design Specification
License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/travis/.m2/repository/javax/servlet/javax.servlet-api/3.1.0/javax.servlet-api-3.1.0.jar
MD5: 79de69e9f5ed8c7fcb8342585732bbf7
SHA1: 3cd63d075497751784b2fa84be59432f4905bf7c
Referenced In Project/Scope:
spring-i18n-support-web:provided
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom name Java Servlet API High
Vendor pom parent-groupid net.java Medium
Vendor manifest Bundle-Description Java(TM) Servlet 3.1 API Design Specification Medium
Vendor file name javax.servlet-api High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor pom url http://servlet-spec.java.net Highest
Vendor pom artifactid javax.servlet-api Low
Vendor Manifest bundle-symbolicname javax.servlet-api Medium
Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low
Vendor pom organization name GlassFish Community High
Vendor Manifest specification-vendor Oracle Corporation Low
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor Manifest extension-name javax.servlet Medium
Vendor pom organization url https://glassfish.dev.java.net Medium
Vendor pom groupid javax.servlet Highest
Vendor central groupid javax.servlet Highest
Product pom artifactid javax.servlet-api Highest
Product pom organization url https://glassfish.dev.java.net Low
Product pom name Java Servlet API High
Product Manifest Bundle-Name Java Servlet API Medium
Product central artifactid javax.servlet-api Highest
Product manifest Bundle-Description Java(TM) Servlet 3.1 API Design Specification Medium
Product file name javax.servlet-api High
Product pom url http://servlet-spec.java.net Medium
Product Manifest bundle-symbolicname javax.servlet-api Medium
Product Manifest bundle-docurl https://glassfish.dev.java.net Low
Product pom parent-artifactid jvnet-parent Medium
Product pom groupid javax.servlet Low
Product Manifest extension-name javax.servlet Medium
Product pom organization name GlassFish Community Low
Product pom parent-groupid net.java Low
Version central version 3.1.0 Highest
Version Manifest Implementation-Version 3.1.0 High
Version file version 3.1.0 Highest
Version pom version 3.1.0 Highest
jsp-api-2.2.jar
File Path: /home/travis/.m2/repository/javax/servlet/jsp/jsp-api/2.2/jsp-api-2.2.jar
MD5: dd575c153ec55c650d2a66aefc5ba9d3
SHA1: 5bf0c26ef77df58c7c28be2d9d52246f2b437a54
Referenced In Project/Scope:
spring-i18n-support-web:provided
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jsp-api Low
Vendor pom parent-artifactid jsp Low
Vendor pom name JavaServer Pages(TM) API High
Vendor file name jsp-api High
Vendor pom parent-groupid org.glassfish.web Medium
Vendor central groupid javax.servlet.jsp Highest
Vendor jar package name javax Low
Vendor jar package name jsp Low
Vendor jar package name servlet Low
Vendor pom groupid javax.servlet.jsp Highest
Product pom groupid javax.servlet.jsp Low
Product pom parent-artifactid jsp Medium
Product pom name JavaServer Pages(TM) API High
Product pom artifactid jsp-api Highest
Product file name jsp-api High
Product pom parent-groupid org.glassfish.web Low
Product central artifactid jsp-api Highest
Product jar package name jsp Low
Product jar package name servlet Low
Version central version 2.2 Highest
Version pom version 2.2 Highest
Version file version 2.2 Highest
jstl-1.2.jar
File Path: /home/travis/.m2/repository/javax/servlet/jstl/1.2/jstl-1.2.jar
MD5: 51e15f798e69358cb893e38c50596b9b
SHA1: 74aca283cd4f4b4f3e425f5820cda58f44409547
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid jstl High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor central groupid javax.servlet High
Vendor pom artifactid jstl Low
Vendor pom groupid javax.servlet Highest
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor file name jstl High
Vendor Manifest extension-name javax.servlet.jsp.jstl Medium
Product pom groupid javax.servlet Low
Product pom artifactid jstl Highest
Product file name jstl High
Product Manifest extension-name javax.servlet.jsp.jstl Medium
Product central artifactid jstl High
Product Manifest specification-title JavaServer Pages(TM) Standard Tag Library Medium
Version central version 1.2 High
Version file version 1.2 Highest
Version pom version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
jackson-core-2.8.10.jar
Description: Core Jackson abstractions, basic JSON streaming API implementation
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.8.10/jackson-core-2.8.10.jar
MD5: de528504165730b13b66f461a85b341e
SHA1: eb21a035c66ad307e66ec8fce37f5d50fd62d039
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jackson-core Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom url FasterXML/jackson-core Highest
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor Manifest implementation-build-date 2017-08-24 04:24:19+0000 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor file name jackson-core High
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor pom parent-artifactid jackson-parent Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom description Core Jackson abstractions, basic JSON streaming API implementation Medium
Vendor pom name Jackson-core High
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor Manifest Implementation-Vendor FasterXML High
Product Manifest specification-title Jackson-core Medium
Product central artifactid jackson-core Highest
Product manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest implementation-build-date 2017-08-24 04:24:19+0000 Low
Product pom groupid fasterxml.jackson.core Low
Product pom parent-artifactid jackson-parent Medium
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product file name jackson-core High
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product pom url FasterXML/jackson-core High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom description Core Jackson abstractions, basic JSON streaming API implementation Medium
Product pom name Jackson-core High
Product pom parent-groupid com.fasterxml.jackson Low
Product pom artifactid jackson-core Highest
Version Manifest Implementation-Version 2.8.10 High
Version central version 2.8.10 Highest
Version file version 2.8.10 Highest
Version pom version 2.8.10 Highest
jackson-annotations-2.8.0.jar
Description: Core annotations used for value types, used by Jackson data binding package.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.8.0/jackson-annotations-2.8.0.jar
MD5: 288e6537849f0c63e76409b515c4fbe4
SHA1: 45b426f7796b741035581a176744d91090e2e6fb
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom parent-artifactid jackson-parent Low
Vendor pom name Jackson-annotations High
Vendor pom description Core annotations used for value types, used by Jackson data binding package.
Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom url http://github.com/FasterXML/jackson Highest
Vendor pom artifactid jackson-annotations Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor manifest Bundle-Description Core annotations used for value types, used by Jackson data binding package. Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor file name jackson-annotations High
Vendor Manifest implementation-build-date 2016-07-04 05:20:32+0000 Low
Vendor Manifest Implementation-Vendor FasterXML High
Product Manifest Implementation-Title Jackson-annotations High
Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low
Product pom groupid fasterxml.jackson.core Low
Product pom parent-artifactid jackson-parent Medium
Product pom artifactid jackson-annotations Highest
Product pom name Jackson-annotations High
Product pom description Core annotations used for value types, used by Jackson data binding package.
Medium
Product pom url http://github.com/FasterXML/jackson Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest Bundle-Name Jackson-annotations Medium
Product central artifactid jackson-annotations Highest
Product Manifest specification-title Jackson-annotations Medium
Product pom parent-groupid com.fasterxml.jackson Low
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product manifest Bundle-Description Core annotations used for value types, used by Jackson data binding package. Medium
Product file name jackson-annotations High
Product Manifest implementation-build-date 2016-07-04 05:20:32+0000 Low
Version Manifest Implementation-Version 2.8.0 High
Version pom version 2.8.0 Highest
Version central version 2.8.0 Highest
Version file version 2.8.0 Highest
jackson-databind-2.8.10.jar
Description: General data-binding functionality for Jackson: works on core streaming API
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.8.10/jackson-databind-2.8.10.jar
MD5: a3562f755da926bdae53d13c4f7687e9
SHA1: f7b83cb2bc4b88d53961e749e1ad32f49ef017b7
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom artifactid jackson-databind Low
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor Manifest implementation-build-date 2017-08-24 04:27:15+0000 Low
Vendor manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium
Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low
Vendor pom name jackson-databind High
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom parent-artifactid jackson-parent Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom url http://github.com/FasterXML/jackson Highest
Vendor pom description General data-binding functionality for Jackson: works on core streaming API Medium
Vendor file name jackson-databind High
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor Manifest Implementation-Vendor FasterXML High
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest specification-title jackson-databind Medium
Product Manifest implementation-build-date 2017-08-24 04:27:15+0000 Low
Product manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium
Product central artifactid jackson-databind Highest
Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low
Product pom groupid fasterxml.jackson.core Low
Product pom parent-artifactid jackson-parent Medium
Product pom name jackson-databind High
Product pom artifactid jackson-databind Highest
Product pom url http://github.com/FasterXML/jackson Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest Implementation-Title jackson-databind High
Product pom description General data-binding functionality for Jackson: works on core streaming API Medium
Product file name jackson-databind High
Product pom parent-groupid com.fasterxml.jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Version Manifest Implementation-Version 2.8.10 High
Version central version 2.8.10 Highest
Version file version 2.8.10 Highest
Version pom version 2.8.10 Highest
Published Vulnerabilities
CVE-2017-17485 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
Vulnerable Software & Versions: (show all )
CVE-2018-5968 suppress
Severity:
Medium
CVSS Score: 5.1
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-184 Incomplete Blacklist
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
Vulnerable Software & Versions: (show all )
CVE-2018-7489 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-184 Incomplete Blacklist
FasterXML jackson-databind before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.
Vulnerable Software & Versions: (show all )
commons-codec-1.10.jar
Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid commons-codec Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom groupid commons-codec Highest
Vendor pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor file name commons-codec High
Vendor manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom artifactid commons-codec Low
Vendor pom name Apache Commons Codec High
Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest
Product pom artifactid commons-codec Highest
Product pom url http://commons.apache.org/proper/commons-codec/ Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Product pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product file name commons-codec High
Product manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product pom parent-groupid org.apache.commons Low
Product Manifest specification-title Apache Commons Codec Medium
Product Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Product Manifest bundle-symbolicname org.apache.commons.codec Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest Bundle-Name Apache Commons Codec Medium
Product pom parent-artifactid commons-parent Medium
Product pom name Apache Commons Codec High
Product central artifactid commons-codec Highest
Product Manifest Implementation-Title Apache Commons Codec High
Product pom groupid commons-codec Low
Version pom version 1.10 Highest
Version central version 1.10 Highest
Version file version 1.10 Highest
Version Manifest Implementation-Version 1.10 High
commons-collections4-4.1.jar
Description: The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/apache/commons/commons-collections4/4.1/commons-collections4-4.1.jar
MD5: 45af6a8e5b51d5945de6c7411e290bd1
SHA1: a4cf4688fe1c7e3a63aa636cc96d013af537768e
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.apache.commons.collections4 Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor manifest Bundle-Description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest implementation-build tags/COLLECTIONS_4_1_RC2@r1716550; 2015-11-25 22:53:13+0100 Low
Vendor central groupid org.apache.commons Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-collections/ Low
Vendor pom groupid apache.commons Highest
Vendor pom url http://commons.apache.org/proper/commons-collections/ Highest
Vendor pom artifactid commons-collections4 Low
Vendor pom description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low
Vendor pom name Apache Commons Collections High
Vendor file name commons-collections4 High
Vendor pom groupid org.apache.commons Highest
Product Manifest bundle-symbolicname org.apache.commons.collections4 Medium
Product Manifest specification-title Apache Commons Collections Medium
Product manifest Bundle-Description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low
Product pom parent-groupid org.apache.commons Low
Product pom artifactid commons-collections4 Highest
Product Manifest Bundle-Name Apache Commons Collections Medium
Product Manifest implementation-build tags/COLLECTIONS_4_1_RC2@r1716550; 2015-11-25 22:53:13+0100 Low
Product central artifactid commons-collections4 Highest
Product pom groupid apache.commons Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest Implementation-Title Apache Commons Collections High
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-collections/ Low
Product pom description The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. Low
Product pom name Apache Commons Collections High
Product file name commons-collections4 High
Product pom url http://commons.apache.org/proper/commons-collections/ Medium
Version pom version 4.1 Highest
Version central version 4.1 Highest
Version file version 4.1 Highest
Version Manifest Implementation-Version 4.1 High
poi-3.15.jar
Description: Apache POI - Java API To Access Microsoft Format Files
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/apache/poi/poi/3.15/poi-3.15.jar
MD5: 180cd5f6f178cbedd00316d44a42a171
SHA1: 965bba8899988008bb2341e300347de62aad5391
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom description Apache POI - Java API To Access Microsoft Format Files Medium
Vendor pom url http://poi.apache.org/ Highest
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom groupid org.apache.poi Highest
Vendor pom groupid apache.poi Highest
Vendor pom name Apache POI High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom organization name Apache Software Foundation High
Vendor pom artifactid poi Low
Vendor file name poi High
Vendor central groupid org.apache.poi Highest
Product pom name Apache POI High
Product pom description Apache POI - Java API To Access Microsoft Format Files Medium
Product central artifactid poi Highest
Product pom organization name Apache Software Foundation Low
Product Manifest Implementation-Title Apache POI High
Product Manifest specification-title Apache POI Medium
Product pom organization url http://www.apache.org/ Low
Product pom artifactid poi Highest
Product pom groupid apache.poi Low
Product file name poi High
Product pom url http://poi.apache.org/ Medium
Version central version 3.15 Highest
Version Manifest Implementation-Version 3.15 High
Version file version 3.15 Highest
Version pom version 3.15 Highest
Related Dependencies
poi-ooxml-schemas-3.15.jar
File Path: /home/travis/.m2/repository/org/apache/poi/poi-ooxml-schemas/3.15/poi-ooxml-schemas-3.15.jar
SHA1: de4a50ca39de48a19606b35644ecadb2f733c479
MD5: 327a013becf0b826c134c42b252e7766
maven: org.apache.poi:poi-ooxml-schemas:3.15 ✓
poi-ooxml-3.15.jar
File Path: /home/travis/.m2/repository/org/apache/poi/poi-ooxml/3.15/poi-ooxml-3.15.jar
SHA1: e2800856735b07b8edd417aee07685470216a00f
MD5: 6b95361cab76a22e60109010f22c6628
maven: org.apache.poi:poi-ooxml:3.15 ✓
stax-api-1.0.1.jar
Description: StAX API is the standard java XML processing API defined by JSR-173
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/stax/stax-api/1.0.1/stax-api-1.0.1.jar
MD5: 7d436a53c64490bee564c576babb36b4
SHA1: 49c100caf72d658aca8e58bd74a4ba90fa2b0d70
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom name StAX API High
Vendor file name stax-api High
Vendor central groupid stax Highest
Vendor pom artifactid stax-api Low
Vendor Manifest specification-vendor JCP-173 Low
Vendor pom groupid stax Highest
Vendor pom description StAX API is the standard java XML processing API defined by JSR-173 Medium
Vendor pom url http://stax.codehaus.org/ Highest
Vendor Manifest Implementation-Vendor JCP High
Product central artifactid stax-api Highest
Product pom name StAX API High
Product file name stax-api High
Product Manifest specification-title StAX Medium
Product pom groupid stax Low
Product pom url http://stax.codehaus.org/ Medium
Product pom artifactid stax-api Highest
Product pom description StAX API is the standard java XML processing API defined by JSR-173 Medium
Product Manifest Implementation-Title StAX 1.0 API High
Version Manifest Implementation-Version 1.0.1 High
Version pom version 1.0.1 Highest
Version central version 1.0.1 Highest
Version file version 1.0.1 Highest
cpe: cpe:/a:st_project:st:1.0.1
Confidence :Low
suppress
maven: stax:stax-api:1.0.1 ✓
Confidence :Highest
Published Vulnerabilities
CVE-2017-16224 suppress
Severity:
Medium
CVSS Score: 5.8
(AV:N/AC:M/Au:N/C:P/I:P/A:N)
CWE: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").
Vulnerable Software & Versions:
xmlbeans-2.6.0.jar
Description: XmlBeans main jar
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/apache/xmlbeans/xmlbeans/2.6.0/xmlbeans-2.6.0.jar
MD5: 6591c08682d613194dacb01e95c78c2c
SHA1: 29e80d2dd51f9dcdef8f9ffaee0d4dc1c9bbfc87
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor file name xmlbeans High
Vendor pom groupid apache.xmlbeans Highest
Vendor pom description XmlBeans main jar Medium
Vendor pom artifactid xmlbeans Low
Vendor pom organization url http://xmlbeans.apache.org/ Medium
Vendor pom groupid org.apache.xmlbeans Highest
Vendor pom name XmlBeans High
Vendor central groupid org.apache.xmlbeans Highest
Vendor pom organization name XmlBeans High
Vendor manifest: org/apache/xmlbeans/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom url http://xmlbeans.apache.org Highest
Product manifest: org/apache/xmlbeans/ Implementation-Title org.apache.xmlbeans Medium
Product file name xmlbeans High
Product pom organization name XmlBeans Low
Product pom description XmlBeans main jar Medium
Product pom organization url http://xmlbeans.apache.org/ Low
Product central artifactid xmlbeans Highest
Product pom groupid apache.xmlbeans Low
Product pom url http://xmlbeans.apache.org Medium
Product pom name XmlBeans High
Product pom artifactid xmlbeans Highest
Version central version 2.6.0 Highest
Version file version 2.6.0 Highest
Version pom version 2.6.0 Highest
curvesapi-1.04.jar
Description: Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS.
License:
BSD License: http://opensource.org/licenses/BSD-3-Clause
File Path: /home/travis/.m2/repository/com/github/virtuald/curvesapi/1.04/curvesapi-1.04.jar
MD5: 0dcbd9b7e498d1118c920d1d55046743
SHA1: 3386abf821719bc89c7685f9eaafaf4a842f0199
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support:compile
spring-i18n-support-web:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid curvesapi Low
Vendor pom groupid github.virtuald Highest
Vendor pom description Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS. Low
Vendor jar package name math Low
Vendor jar package name graphbuilder Low
Vendor pom groupid com.github.virtuald Highest
Vendor file name curvesapi High
Vendor central groupid com.github.virtuald Highest
Vendor pom url virtuald/curvesapi Highest
Vendor pom name curvesapi High
Product pom artifactid curvesapi Highest
Product pom url virtuald/curvesapi High
Product pom groupid github.virtuald Low
Product pom description Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS. Low
Product jar package name math Low
Product file name curvesapi High
Product central artifactid curvesapi Highest
Product pom name curvesapi High
Version pom version 1.04 Highest
Version central version 1.04 Highest
Version file version 1.04 Highest
spring-boot-1.5.8.RELEASE.jar
Description: Spring Boot
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot/1.5.8.RELEASE/spring-boot-1.5.8.RELEASE.jar
MD5: 675be87ce49c0b8ace3ebfcf984c11e8
SHA1: 748ebde51761e12627ad23d064024f342b18f9b4
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor Pivotal Software, Inc. Low
Vendor pom description Spring Boot Medium
Vendor pom artifactid spring-boot Low
Vendor Manifest Implementation-Vendor-Id org.springframework.boot Medium
Vendor Manifest implementation-url http://projects.spring.io/spring-boot/ Low
Vendor file name spring-boot High
Vendor pom parent-artifactid spring-boot-parent Low
Vendor pom groupid org.springframework.boot Highest
Vendor Manifest Implementation-Vendor Pivotal Software, Inc. High
Vendor pom groupid springframework.boot Highest
Vendor pom organization url http://www.spring.io Medium
Vendor pom url http://projects.spring.io/spring-boot/ Highest
Vendor central groupid org.springframework.boot Highest
Vendor pom organization name Pivotal Software, Inc. High
Vendor pom name Spring Boot High
Product pom parent-groupid org.springframework.boot Low
Product pom groupid springframework.boot Low
Product pom parent-artifactid spring-boot-parent Medium
Product Manifest specification-title Spring Boot Medium
Product pom description Spring Boot Medium
Product Manifest implementation-url http://projects.spring.io/spring-boot/ Low
Product file name spring-boot High
Product pom organization url http://www.spring.io Low
Product pom url http://projects.spring.io/spring-boot/ Medium
Product Manifest Implementation-Title Spring Boot High
Product central artifactid spring-boot Highest
Product pom organization name Pivotal Software, Inc. Low
Product pom artifactid spring-boot Highest
Product pom name Spring Boot High
Version central version 1.5.8.RELEASE Highest
Version Manifest Implementation-Version 1.5.8.RELEASE High
Version pom version 1.5.8.RELEASE Highest
Related Dependencies
spring-boot-starter-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-starter/1.5.8.RELEASE/spring-boot-starter-1.5.8.RELEASE.jar
SHA1: 18048efe1f06569022a53cc3fb2fe9c0162935a3
MD5: f1f15b6c0c1d8d0b3396eb02143e6aec
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
maven: org.springframework.boot:spring-boot-starter:1.5.8.RELEASE ✓
spring-boot-starter-web-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-starter-web/1.5.8.RELEASE/spring-boot-starter-web-1.5.8.RELEASE.jar
SHA1: 7e0dc79e3b47be4539ad3c033639133ae6b7a17e
MD5: 438d727721706551127010b294431fb5
maven: org.springframework.boot:spring-boot-starter-web:1.5.8.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
spring-boot-autoconfigure-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/1.5.8.RELEASE/spring-boot-autoconfigure-1.5.8.RELEASE.jar
SHA1: e4f2efa4c319f4e3613d94fbccfdb5ccda6873e3
MD5: 883725f77818b4142ae082cbcd95b86b
maven: org.springframework.boot:spring-boot-autoconfigure:1.5.8.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
spring-boot-starter-thymeleaf-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-starter-thymeleaf/1.5.8.RELEASE/spring-boot-starter-thymeleaf-1.5.8.RELEASE.jar
SHA1: 255b749537ca0fa48adeb0c15cf48734b9ffcf5e
MD5: 283873822e2d8230fa0e400f9bbbdf76
maven: org.springframework.boot:spring-boot-starter-thymeleaf:1.5.8.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
spring-boot-configuration-processor-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-configuration-processor/1.5.8.RELEASE/spring-boot-configuration-processor-1.5.8.RELEASE.jar
SHA1: 217b7bde102a9c51c51139ea02f0f99f5d34f799
MD5: b48877d3547755bf4e7091a31ebc1fa7
maven: org.springframework.boot:spring-boot-configuration-processor:1.5.8.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
spring-boot-starter-logging-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-starter-logging/1.5.8.RELEASE/spring-boot-starter-logging-1.5.8.RELEASE.jar
SHA1: ebc00a0e46753d90431fdcc5e3d6b9fd3bf1564a
MD5: 0382e6357210ce235ec4f7a6fbb78d9b
maven: org.springframework.boot:spring-boot-starter-logging:1.5.8.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
spring-boot-starter-tomcat-1.5.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat/1.5.8.RELEASE/spring-boot-starter-tomcat-1.5.8.RELEASE.jar
SHA1: cf3b7eb7e192a60ab1dd09e4f8bce82710a5feb0
MD5: f503ff9955fc1afc2e8419fd24750bbd
maven: org.springframework.boot:spring-boot-starter-tomcat:1.5.8.RELEASE ✓
cpe: cpe:/a:pivotal_software:spring_boot:1.5.8
Published Vulnerabilities
CVE-2017-8046 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
Vulnerable Software & Versions: (show all )
CVE-2018-1196 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
CWE: CWE-59 Improper Link Resolution Before File Access ('Link Following')
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the "run_user" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible.
Vulnerable Software & Versions: (show all )
logback-core-1.1.11.jar
Description: logback-core module
License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/travis/.m2/repository/ch/qos/logback/logback-core/1.1.11/logback-core-1.1.11.jar
MD5: cc7a8deacd26b0aa2668779ce2721c0f
SHA1: 88b8df40340eed549fb07e2613879bf6b006704d
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid ch.qos.logback Highest
Vendor pom parent-artifactid logback-parent Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom description logback-core module Medium
Vendor file name logback-core High
Vendor central groupid ch.qos.logback Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor manifest Bundle-Description logback-core module Medium
Vendor pom artifactid logback-core Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor pom name Logback Core Module High
Product pom artifactid logback-core Highest
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Product pom description logback-core module Medium
Product file name logback-core High
Product Manifest Bundle-Name Logback Core Module Medium
Product pom parent-artifactid logback-parent Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product manifest Bundle-Description logback-core module Medium
Product pom groupid ch.qos.logback Low
Product central artifactid logback-core Highest
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest bundle-symbolicname ch.qos.logback.core Medium
Product Manifest bundle-docurl http://www.qos.ch Low
Product pom name Logback Core Module High
Version central version 1.1.11 Highest
Version file version 1.1.11 Highest
Version pom version 1.1.11 Highest
Related Dependencies
logback-classic-1.1.11.jar
File Path: /home/travis/.m2/repository/ch/qos/logback/logback-classic/1.1.11/logback-classic-1.1.11.jar
SHA1: ccedfbacef4a6515d2983e3f89ed753d5d4fb665
MD5: 8064835579ddb2c86ae26b447b0c5f76
maven: ch.qos.logback:logback-classic:1.1.11 ✓
jcl-over-slf4j-1.7.25.jar
Description: JCL 1.2 implemented over SLF4J
File Path: /home/travis/.m2/repository/org/slf4j/jcl-over-slf4j/1.7.25/jcl-over-slf4j-1.7.25.jar
MD5: 56b22adc639b09b2e917f42d68b26600
SHA1: f8c32b13ff142a513eeb5b6330b1588dcb2c0461
Referenced In Projects/Scopes:
spring-i18n-support:runtime
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid slf4j Highest
Vendor file name jcl-over-slf4j High
Vendor pom artifactid jcl-over-slf4j Low
Vendor pom description JCL 1.2 implemented over SLF4J Medium
Vendor pom parent-groupid org.slf4j Medium
Vendor pom name JCL 1.2 implemented over SLF4J High
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom groupid org.slf4j Highest
Vendor pom url http://www.slf4j.org Highest
Vendor manifest Bundle-Description JCL 1.2 implemented over SLF4J Medium
Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium
Vendor central groupid org.slf4j Highest
Vendor pom parent-artifactid slf4j-parent Low
Product file name jcl-over-slf4j High
Product pom description JCL 1.2 implemented over SLF4J Medium
Product pom url http://www.slf4j.org Medium
Product Manifest Bundle-Name jcl-over-slf4j Medium
Product pom parent-groupid org.slf4j Low
Product Manifest Implementation-Title jcl-over-slf4j High
Product pom name JCL 1.2 implemented over SLF4J High
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom groupid slf4j Low
Product manifest Bundle-Description JCL 1.2 implemented over SLF4J Medium
Product pom parent-artifactid slf4j-parent Medium
Product pom artifactid jcl-over-slf4j Highest
Product Manifest bundle-symbolicname jcl.over.slf4j Medium
Product central artifactid jcl-over-slf4j Highest
Version central version 1.7.25 Highest
Version Manifest Implementation-Version 1.7.25 High
Version file version 1.7.25 Highest
Version pom version 1.7.25 Highest
jul-to-slf4j-1.7.25.jar
Description: JUL to SLF4J bridge
File Path: /home/travis/.m2/repository/org/slf4j/jul-to-slf4j/1.7.25/jul-to-slf4j-1.7.25.jar
MD5: ab28124cb05fec600f2ffe37b94629e0
SHA1: 0af5364cd6679bfffb114f0dec8a157aaa283b76
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid slf4j Highest
Vendor manifest Bundle-Description JUL to SLF4J bridge Medium
Vendor pom parent-groupid org.slf4j Medium
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom description JUL to SLF4J bridge Medium
Vendor pom groupid org.slf4j Highest
Vendor pom url http://www.slf4j.org Highest
Vendor pom artifactid jul-to-slf4j Low
Vendor central groupid org.slf4j Highest
Vendor pom name JUL to SLF4J bridge High
Vendor Manifest bundle-symbolicname jul.to.slf4j Medium
Vendor file name jul-to-slf4j High
Vendor pom parent-artifactid slf4j-parent Low
Product Manifest Bundle-Name jul-to-slf4j Medium
Product manifest Bundle-Description JUL to SLF4J bridge Medium
Product central artifactid jul-to-slf4j Highest
Product pom url http://www.slf4j.org Medium
Product pom parent-groupid org.slf4j Low
Product pom artifactid jul-to-slf4j Highest
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom description JUL to SLF4J bridge Medium
Product pom groupid slf4j Low
Product pom parent-artifactid slf4j-parent Medium
Product pom name JUL to SLF4J bridge High
Product Manifest bundle-symbolicname jul.to.slf4j Medium
Product file name jul-to-slf4j High
Version central version 1.7.25 Highest
Version Manifest Implementation-Version 1.7.25 High
Version file version 1.7.25 Highest
Version pom version 1.7.25 Highest
log4j-over-slf4j-1.7.25.jar
Description: Log4j implemented over SLF4J
License:
Apache Software Licenses: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/slf4j/log4j-over-slf4j/1.7.25/log4j-over-slf4j-1.7.25.jar
MD5: fb818c7981d842875905587a61f2b942
SHA1: a87bb47468f47ee7aabbd54f93e133d4215769c3
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid slf4j Highest
Vendor Manifest bundle-symbolicname log4j.over.slf4j Medium
Vendor manifest Bundle-Description Log4j implemented over SLF4J Medium
Vendor pom parent-groupid org.slf4j Medium
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom artifactid log4j-over-slf4j Low
Vendor pom groupid org.slf4j Highest
Vendor pom url http://www.slf4j.org Highest
Vendor pom name Log4j Implemented Over SLF4J High
Vendor file name log4j-over-slf4j High
Vendor central groupid org.slf4j Highest
Vendor pom description Log4j implemented over SLF4J Medium
Vendor pom parent-artifactid slf4j-parent Low
Product Manifest Implementation-Title log4j-over-slf4j High
Product Manifest Bundle-Name log4j-over-slf4j Medium
Product Manifest bundle-symbolicname log4j.over.slf4j Medium
Product pom url http://www.slf4j.org Medium
Product manifest Bundle-Description Log4j implemented over SLF4J Medium
Product pom parent-groupid org.slf4j Low
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom name Log4j Implemented Over SLF4J High
Product pom groupid slf4j Low
Product file name log4j-over-slf4j High
Product pom artifactid log4j-over-slf4j Highest
Product pom parent-artifactid slf4j-parent Medium
Product central artifactid log4j-over-slf4j Highest
Product pom description Log4j implemented over SLF4J Medium
Version central version 1.7.25 Highest
Version Manifest Implementation-Version 1.7.25 High
Version file version 1.7.25 Highest
Version pom version 1.7.25 Highest
snakeyaml-1.17.jar
Description: YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/yaml/snakeyaml/1.17/snakeyaml-1.17.jar
MD5: ab621c3cee316236ad04a6f0fe4dd17c
SHA1: 7a27ea250c5130b2922b86dea63cbb1cc10a660c
Referenced In Projects/Scopes:
spring-i18n-support-starter:runtime
spring-i18n-support-samples-xml:runtime
spring-i18n-support-samples-starter:runtime
Evidence
Type Source Name Value Confidence
Vendor central groupid org.yaml Highest
Vendor manifest Bundle-Description YAML 1.1 parser and emitter for Java Medium
Vendor pom groupid org.yaml Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor file name snakeyaml High
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor pom artifactid snakeyaml Low
Vendor pom name SnakeYAML High
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom description YAML 1.1 parser and emitter for Java Medium
Vendor pom groupid yaml Highest
Vendor pom url http://www.snakeyaml.org Highest
Product pom url http://www.snakeyaml.org Medium
Product manifest Bundle-Description YAML 1.1 parser and emitter for Java Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product file name snakeyaml High
Product central artifactid snakeyaml Highest
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product pom artifactid snakeyaml Highest
Product Manifest Bundle-Name SnakeYAML Medium
Product pom groupid yaml Low
Product pom name SnakeYAML High
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom description YAML 1.1 parser and emitter for Java Medium
Version file version 1.17 Highest
Version central version 1.17 Highest
Version pom version 1.17 Highest
tomcat-annotations-api-8.5.23.jar
Description: Annotations Package
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/apache/tomcat/tomcat-annotations-api/8.5.23/tomcat-annotations-api-8.5.23.jar
MD5: a176f33b5656eb44675aacb1f50e8468
SHA1: aaf17df9fe0240e9e9d5375d24d5f177174b73d9
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.apache.tomcat Highest
Vendor pom url http://tomcat.apache.org/ Highest
Vendor file name tomcat-annotations-api High
Vendor manifest: javax/servlet/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom groupid apache.tomcat Highest
Vendor central groupid org.apache.tomcat Highest
Vendor pom artifactid tomcat-annotations-api Low
Vendor pom description Annotations Package Medium
Product manifest: javax/servlet/ Specification-Title Java API for Servlets (Annotations) Medium
Product pom url http://tomcat.apache.org/ Medium
Product pom artifactid tomcat-annotations-api Highest
Product file name tomcat-annotations-api High
Product manifest: javax/servlet/ Implementation-Title javax.servlet Medium
Product pom groupid apache.tomcat Low
Product central artifactid tomcat-annotations-api Highest
Product pom description Annotations Package Medium
Version central version 8.5.23 Highest
Version file version 8.5.23 Highest
Version pom version 8.5.23 Highest
Published Vulnerabilities
CVE-2016-5425 suppress
Severity:
High
CVSS Score: 7.2
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
Vulnerable Software & Versions:
CVE-2016-6325 suppress
Severity:
High
CVSS Score: 7.2
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Vulnerable Software & Versions:
CVE-2017-15706 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-358 Improperly Implemented Security Check for Standard
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected.
Vulnerable Software & Versions: (show all )
CVE-2017-6056 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-19 Data Handling
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
Vulnerable Software & Versions:
CVE-2018-1304 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-254 Security Features
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Vulnerable Software & Versions: (show all )
CVE-2018-1305 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-284 Improper Access Control
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
Vulnerable Software & Versions: (show all )
CVE-2018-1336 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Vulnerable Software & Versions: (show all )
CVE-2018-8014 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-254 Security Features
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Vulnerable Software & Versions: (show all )
CVE-2018-8034 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-295 Improper Certificate Validation
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
Vulnerable Software & Versions: (show all )
CVE-2018-8037 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.
Vulnerable Software & Versions: (show all )
tomcat-embed-core-8.5.23.jar
Description: Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/8.5.23/tomcat-embed-core-8.5.23.jar
MD5: ae9430c1a4fc4d0d8eee4f33f2f4da00
SHA1: 79261793a47f507890ee08f749b9d81774e4f7f0
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor pom url http://tomcat.apache.org/ Highest
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor central groupid org.apache.tomcat.embed Highest
Vendor pom groupid apache.tomcat.embed Highest
Vendor pom artifactid tomcat-embed-core Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor file name tomcat-embed-core High
Vendor pom description Core Tomcat implementation Medium
Product central artifactid tomcat-embed-core Highest
Product pom artifactid tomcat-embed-core Highest
Product pom groupid apache.tomcat.embed Low
Product pom url http://tomcat.apache.org/ Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest specification-title Apache Tomcat Medium
Product file name tomcat-embed-core High
Product pom description Core Tomcat implementation Medium
Version central version 8.5.23 Highest
Version file version 8.5.23 Highest
Version Manifest Implementation-Version 8.5.23 High
Version pom version 8.5.23 Highest
Related Dependencies
tomcat-embed-websocket-8.5.23.jar
File Path: /home/travis/.m2/repository/org/apache/tomcat/embed/tomcat-embed-websocket/8.5.23/tomcat-embed-websocket-8.5.23.jar
SHA1: 52f07abcae10dc7e1764304b0877def175c2c833
MD5: 03ac519ccda43a838b7b4aeb9ca2f1b5
maven: org.apache.tomcat.embed:tomcat-embed-websocket:8.5.23 ✓
cpe: cpe:/a:apache:tomcat:8.5.23
Published Vulnerabilities
CVE-2017-15706 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-358 Improperly Implemented Security Check for Standard
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected.
Vulnerable Software & Versions: (show all )
CVE-2018-1304 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-254 Security Features
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Vulnerable Software & Versions: (show all )
CVE-2018-1305 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-284 Improper Access Control
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
Vulnerable Software & Versions: (show all )
CVE-2018-1336 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Vulnerable Software & Versions: (show all )
CVE-2018-8014 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-254 Security Features
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Vulnerable Software & Versions: (show all )
CVE-2018-8034 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-295 Improper Certificate Validation
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
Vulnerable Software & Versions: (show all )
CVE-2018-8037 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.
Vulnerable Software & Versions: (show all )
tomcat-embed-el-8.5.23.jar
Description: Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/apache/tomcat/embed/tomcat-embed-el/8.5.23/tomcat-embed-el-8.5.23.jar
MD5: caf0fdf8c1a9d5dddb25d1d8f5c09442
SHA1: 98d979cde444dffa6d434c8377d0123b2dfa614c
Referenced In Projects/Scopes:
spring-i18n-support-starter:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor file name tomcat-embed-el High
Vendor pom url http://tomcat.apache.org/ Highest
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor central groupid org.apache.tomcat.embed Highest
Vendor pom artifactid tomcat-embed-el Low
Vendor pom groupid apache.tomcat.embed Highest
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom description Core Tomcat implementation Medium
Product file name tomcat-embed-el High
Product central artifactid tomcat-embed-el Highest
Product pom groupid apache.tomcat.embed Low
Product pom url http://tomcat.apache.org/ Medium
Product pom artifactid tomcat-embed-el Highest
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest specification-title Apache Tomcat Medium
Product pom description Core Tomcat implementation Medium
Version central version 8.5.23 Highest
Version file version 8.5.23 Highest
Version Manifest Implementation-Version 8.5.23 High
Version pom version 8.5.23 Highest
validation-api-1.1.0.Final.jar
Description:
Bean Validation API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/javax/validation/validation-api/1.1.0.Final/validation-api-1.1.0.Final.jar
MD5: 4c257f52462860b62ab3cdab45f53082
SHA1: 8613ae82954779d518631e05daa73a6a954817d5
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor file name validation-api High
Vendor Manifest bundle-symbolicname javax.validation.api Medium
Vendor pom description
Bean Validation API
Medium
Vendor pom name Bean Validation API High
Vendor pom url http://beanvalidation.org Highest
Vendor central groupid javax.validation Highest
Vendor pom groupid javax.validation Highest
Vendor pom artifactid validation-api Low
Vendor manifest Bundle-Description Bean Validation API Medium
Product file name validation-api High
Product pom url http://beanvalidation.org Medium
Product Manifest bundle-symbolicname javax.validation.api Medium
Product pom description
Bean Validation API
Medium
Product central artifactid validation-api Highest
Product pom name Bean Validation API High
Product Manifest Bundle-Name Bean Validation API Medium
Product pom groupid javax.validation Low
Product pom artifactid validation-api Highest
Product manifest Bundle-Description Bean Validation API Medium
Version central version 1.1.0.Final Highest
Version pom version 1.1.0.Final Highest
Version file version 1.1.0 Highest
jboss-logging-3.3.1.Final.jar
Description: The JBoss Logging Framework
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/jboss/logging/jboss-logging/3.3.1.Final/jboss-logging-3.3.1.Final.jar
MD5: 93cf8945ff84aaf9f0ed9a76991338fb
SHA1: c46217ab74b532568c0ed31dc599db3048bd1b67
Referenced In Projects/Scopes:
spring-i18n-support:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom groupid jboss.logging Highest
Vendor pom parent-artifactid jboss-parent Low
Vendor pom description The JBoss Logging Framework Medium
Vendor file name jboss-logging High
Vendor pom url http://www.jboss.org Highest
Vendor pom parent-groupid org.jboss Medium
Vendor Manifest build-timestamp Wed, 15 Mar 2017 13:22:07 -0700 Low
Vendor Manifest os-name Linux Medium
Vendor pom groupid org.jboss.logging Highest
Vendor pom artifactid jboss-logging Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Vendor manifest Bundle-Description The JBoss Logging Framework Medium
Vendor central groupid org.jboss.logging Highest
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor pom name JBoss Logging 3 High
Vendor Manifest implementation-url http://www.jboss.org Low
Product pom description The JBoss Logging Framework Medium
Product central artifactid jboss-logging Highest
Product pom artifactid jboss-logging Highest
Product file name jboss-logging High
Product Manifest specification-title JBoss Logging 3 Medium
Product Manifest build-timestamp Wed, 15 Mar 2017 13:22:07 -0700 Low
Product Manifest os-name Linux Medium
Product Manifest Bundle-Name JBoss Logging 3 Medium
Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Product manifest Bundle-Description The JBoss Logging Framework Medium
Product Manifest Implementation-Title JBoss Logging 3 High
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Low
Product Manifest bundle-docurl http://www.jboss.org Low
Product pom groupid jboss.logging Low
Product pom name JBoss Logging 3 High
Product pom url http://www.jboss.org Medium
Product Manifest implementation-url http://www.jboss.org Low
Version central version 3.3.1.Final Highest
Version Manifest Implementation-Version 3.3.1.Final High
Version pom version 3.3.1.Final Highest
Version file version 3.3.1 Highest
classmate-1.3.4.jar
Description: Library for introspecting types with full generic information
including resolving of field and method types.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/com/fasterxml/classmate/1.3.4/classmate-1.3.4.jar
MD5: 1e2e0fcc510753882683417e01895242
SHA1: 03d5f48f10bbe4eb7bd862f10c0583be2e0053c6
Referenced In Projects/Scopes:
spring-i18n-support:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://github.com/FasterXML/java-classmate Low
Vendor pom parent-artifactid oss-parent Low
Vendor pom url http://github.com/FasterXML/java-classmate Highest
Vendor Manifest specification-vendor fasterxml.com Low
Vendor central groupid com.fasterxml Highest
Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium
Vendor Manifest implementation-build-date 2017-09-09 21:47:22+0000 Low
Vendor pom groupid com.fasterxml Highest
Vendor Manifest automatic-module-name com.fasterxml.classmate Medium
Vendor pom groupid fasterxml Highest
Vendor pom organization url http://fasterxml.com Medium
Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium
Vendor pom description Library for introspecting types with full generic information including resolving of field and method types. Low
Vendor pom organization name fasterxml.com High
Vendor manifest Bundle-Description Library for introspecting types with full generic informationincluding resolving of field and method types. Low
Vendor pom artifactid classmate Low
Vendor Manifest Implementation-Vendor fasterxml.com High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor file name classmate High
Vendor pom parent-groupid com.fasterxml Medium
Vendor pom name ClassMate High
Product Manifest bundle-docurl http://github.com/FasterXML/java-classmate Low
Product Manifest Implementation-Title ClassMate High
Product Manifest bundle-symbolicname com.fasterxml.classmate Medium
Product Manifest implementation-build-date 2017-09-09 21:47:22+0000 Low
Product pom artifactid classmate Highest
Product Manifest automatic-module-name com.fasterxml.classmate Medium
Product Manifest Bundle-Name ClassMate Medium
Product pom groupid fasterxml Low
Product pom organization name fasterxml.com Low
Product pom organization url http://fasterxml.com Low
Product pom description Library for introspecting types with full generic information including resolving of field and method types. Low
Product manifest Bundle-Description Library for introspecting types with full generic informationincluding resolving of field and method types. Low
Product Manifest specification-title ClassMate Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom parent-groupid com.fasterxml Low
Product file name classmate High
Product pom parent-artifactid oss-parent Medium
Product pom url http://github.com/FasterXML/java-classmate Medium
Product central artifactid classmate Highest
Product pom name ClassMate High
Version pom version 1.3.4 Highest
Version central version 1.3.4 Highest
Version file version 1.3.4 Highest
Version Manifest Implementation-Version 1.3.4 High
hibernate-validator-5.3.5.Final.jar
Description: Hibernate's Bean Validation (JSR-303) reference implementation.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/hibernate/hibernate-validator/5.3.5.Final/hibernate-validator-5.3.5.Final.jar
MD5: bd241d9104768ad5ef698d58534c0bce
SHA1: 0622a9bcef2eed6d41b5b8e0662c36212009e375
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.hibernate Highest
Vendor Manifest implementation-url http://hibernate.org/validator/ Low
Vendor pom groupid org.hibernate Highest
Vendor manifest Bundle-Description Hibernate's Bean Validation (JSR-303) reference implementation. Medium
Vendor Manifest bundle-symbolicname org.hibernate.validator Medium
Vendor pom artifactid hibernate-validator Low
Vendor file name hibernate-validator High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor Manifest Implementation-Vendor org.hibernate High
Vendor pom name Hibernate Validator Engine High
Vendor pom parent-groupid org.hibernate Medium
Vendor pom groupid hibernate Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor pom parent-artifactid hibernate-validator-parent Low
Vendor pom description Hibernate's Bean Validation (JSR-303) reference implementation. Medium
Product Manifest Implementation-Title hibernate-validator High
Product Manifest implementation-url http://hibernate.org/validator/ Low
Product Manifest specification-title Bean Validation Medium
Product pom groupid hibernate Low
Product manifest Bundle-Description Hibernate's Bean Validation (JSR-303) reference implementation. Medium
Product Manifest bundle-symbolicname org.hibernate.validator Medium
Product file name hibernate-validator High
Product pom parent-artifactid hibernate-validator-parent Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest Bundle-Name Hibernate Validator Engine Medium
Product pom name Hibernate Validator Engine High
Product pom artifactid hibernate-validator Highest
Product pom parent-groupid org.hibernate Low
Product central artifactid hibernate-validator Highest
Product pom description Hibernate's Bean Validation (JSR-303) reference implementation. Medium
Version Manifest Implementation-Version 5.3.5.Final High
Version central version 5.3.5.Final Highest
Version file version 5.3.5 Highest
Version pom version 5.3.5.Final Highest
ognl-3.0.8.jar
Description: OGNL - Object Graph Navigation Library
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/ognl/ognl/3.0.8/ognl-3.0.8.jar
MD5: 6f2969f0eb541a6f4ecfa15faa8155d7
SHA1: 37e1aebfde7eb7baebc9ad4f85116ef9009c5fc5
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ognl Low
Vendor pom url http://ognl.org Highest
Vendor pom groupid ognl Highest
Vendor pom organization url http://www.opensymphony.com Medium
Vendor pom name OGNL - Object Graph Navigation Library High
Vendor pom organization name OpenSymphony High
Vendor pom description OGNL - Object Graph Navigation Library Medium
Vendor file name ognl High
Vendor jar package name ognl Low
Vendor central groupid ognl Highest
Product pom organization name OpenSymphony Low
Product pom organization url http://www.opensymphony.com Low
Product pom name OGNL - Object Graph Navigation Library High
Product central artifactid ognl Highest
Product pom url http://ognl.org Medium
Product pom groupid ognl Low
Product pom description OGNL - Object Graph Navigation Library Medium
Product pom artifactid ognl Highest
Product file name ognl High
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cpe: cpe:/a:ognl_project:ognl:3.0.8
Confidence :Low
suppress
maven: ognl:ognl:3.0.8 ✓
Confidence :Highest
Published Vulnerabilities
CVE-2016-3093 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.
Vulnerable Software & Versions: (show all )
javassist-3.21.0-GA.jar
Description:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/
File Path: /home/travis/.m2/repository/org/javassist/javassist/3.21.0-GA/javassist-3.21.0-GA.jar
MD5: 3dba2305f842c2891df0a0926e18bcfa
SHA1: 598244f595db5c5fb713731eddbb1c91a58d959b
Referenced In Projects/Scopes:
spring-i18n-support:compile
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low
Vendor Manifest bundle-symbolicname javassist Medium
Vendor manifest Bundle-Description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Vendor pom name Javassist High
Vendor pom groupid org.javassist Highest
Vendor pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Vendor pom organization name Shigeru Chiba, www.javassist.org High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom artifactid javassist Low
Vendor pom groupid javassist Highest
Vendor central groupid org.javassist Highest
Vendor pom url http://www.javassist.org/ Highest
Vendor file name javassist High
Product pom artifactid javassist Highest
Product Manifest Bundle-Name Javassist Medium
Product pom groupid javassist Low
Product pom url http://www.javassist.org/ Medium
Product Manifest bundle-symbolicname javassist Medium
Product manifest Bundle-Description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Product pom name Javassist High
Product central artifactid javassist Highest
Product pom organization name Shigeru Chiba, www.javassist.org Low
Product pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product file name javassist High
Product Manifest specification-title Javassist Medium
Version file version 3.21.0 Highest
Version pom version 3.21.0-GA Highest
Version central version 3.21.0-GA Highest
unbescape-1.1.0.RELEASE.jar
Description: Advanced yet easy-to-use escape/unescape library for Java
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/unbescape/unbescape/1.1.0.RELEASE/unbescape-1.1.0.RELEASE.jar
MD5: 9bccbc680238d9352156891cf53b96b4
SHA1: ab0db4fe0a6fa89fb8da2a40008a4e63a7f3f5b9
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom name unbescape High
Vendor pom organization name The UNBESCAPE team High
Vendor pom groupid org.unbescape Highest
Vendor Manifest Implementation-Vendor The UNBESCAPE team High
Vendor pom artifactid unbescape Low
Vendor central groupid org.unbescape Highest
Vendor pom url http://www.unbescape.org Highest
Vendor manifest Bundle-Description Advanced yet easy-to-use escape/unescape library for Java Medium
Vendor file name unbescape High
Vendor Manifest specification-vendor The UNBESCAPE team Low
Vendor Manifest Implementation-Vendor-Id org.unbescape Medium
Vendor Manifest bundle-symbolicname org.unbescape Medium
Vendor pom groupid unbescape Highest
Vendor pom organization url http://www.unbescape.org Medium
Vendor pom description Advanced yet easy-to-use escape/unescape library for Java Medium
Vendor Manifest bundle-docurl http://www.unbescape.org Low
Product pom name unbescape High
Product pom groupid unbescape Low
Product Manifest Bundle-Name unbescape Medium
Product pom url http://www.unbescape.org Medium
Product central artifactid unbescape Highest
Product manifest Bundle-Description Advanced yet easy-to-use escape/unescape library for Java Medium
Product file name unbescape High
Product Manifest specification-title unbescape Medium
Product Manifest bundle-symbolicname org.unbescape Medium
Product pom organization name The UNBESCAPE team Low
Product pom description Advanced yet easy-to-use escape/unescape library for Java Medium
Product pom organization url http://www.unbescape.org Low
Product pom artifactid unbescape Highest
Product Manifest bundle-docurl http://www.unbescape.org Low
Product Manifest Implementation-Title unbescape High
Version central version 1.1.0.RELEASE Highest
Version Manifest Implementation-Version 1.1.0.RELEASE High
Version pom version 1.1.0.RELEASE Highest
thymeleaf-2.1.5.RELEASE.jar
Description: XML/XHTML/HTML5 template engine for Java
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/thymeleaf/thymeleaf/2.1.5.RELEASE/thymeleaf-2.1.5.RELEASE.jar
MD5: a7e95d2915820f069a220b66ba65232f
SHA1: 513bffa3daaac277460c1a0a2dccb228fa40569e
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid thymeleaf Low
Vendor central groupid org.thymeleaf Highest
Vendor pom groupid org.thymeleaf Highest
Vendor Manifest Implementation-Vendor The THYMELEAF team High
Vendor pom organization name The THYMELEAF team High
Vendor Manifest Implementation-Vendor-Id org.thymeleaf Medium
Vendor pom url http://www.thymeleaf.org Highest
Vendor pom description XML/XHTML/HTML5 template engine for Java Medium
Vendor pom groupid thymeleaf Highest
Vendor pom organization url http://www.thymeleaf.org Medium
Vendor pom name thymeleaf High
Vendor Manifest specification-vendor The THYMELEAF team Low
Vendor file name thymeleaf High
Product Manifest specification-title thymeleaf Medium
Product pom description XML/XHTML/HTML5 template engine for Java Medium
Product Manifest Implementation-Title thymeleaf High
Product pom organization name The THYMELEAF team Low
Product pom url http://www.thymeleaf.org Medium
Product central artifactid thymeleaf Highest
Product pom name thymeleaf High
Product pom groupid thymeleaf Low
Product pom artifactid thymeleaf Highest
Product pom organization url http://www.thymeleaf.org Low
Product file name thymeleaf High
Version pom version 2.1.5.RELEASE Highest
Version central version 2.1.5.RELEASE Highest
Version Manifest Implementation-Version 2.1.5.RELEASE High
thymeleaf-spring4-2.1.5.RELEASE.jar
Description: XML/XHTML/HTML5 template engine for Java
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/thymeleaf/thymeleaf-spring4/2.1.5.RELEASE/thymeleaf-spring4-2.1.5.RELEASE.jar
MD5: 3fd4f26581a703c6a8a698356d14216a
SHA1: 74cb9028e99597b5d71a98e919fd531a7fc290b4
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.thymeleaf Highest
Vendor pom groupid org.thymeleaf Highest
Vendor Manifest Implementation-Vendor The THYMELEAF team High
Vendor pom organization name The THYMELEAF team High
Vendor pom name thymeleaf-spring4 High
Vendor file name thymeleaf-spring4 High
Vendor Manifest Implementation-Vendor-Id org.thymeleaf Medium
Vendor pom artifactid thymeleaf-spring4 Low
Vendor pom url http://www.thymeleaf.org Highest
Vendor pom description XML/XHTML/HTML5 template engine for Java Medium
Vendor pom groupid thymeleaf Highest
Vendor pom organization url http://www.thymeleaf.org Medium
Vendor Manifest specification-vendor The THYMELEAF team Low
Product pom description XML/XHTML/HTML5 template engine for Java Medium
Product pom artifactid thymeleaf-spring4 Highest
Product pom organization name The THYMELEAF team Low
Product pom url http://www.thymeleaf.org Medium
Product central artifactid thymeleaf-spring4 Highest
Product pom name thymeleaf-spring4 High
Product file name thymeleaf-spring4 High
Product pom groupid thymeleaf Low
Product pom organization url http://www.thymeleaf.org Low
Product Manifest Implementation-Title thymeleaf-spring4 High
Product Manifest specification-title thymeleaf-spring4 Medium
Version pom version 2.1.5.RELEASE Highest
Version central version 2.1.5.RELEASE Highest
Version Manifest Implementation-Version 2.1.5.RELEASE High
groovy-2.4.12.jar
Description: Groovy: A powerful, dynamic language for the JVM
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/codehaus/groovy/groovy/2.4.12/groovy-2.4.12.jar
MD5: 873d89f2fe8ef387da7a9190f6735c8f
SHA1: a43be367110c491787219f1c128b5b5fc54f1e70
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest extension-name groovy Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-symbolicname groovy Medium
Vendor central groupid org.codehaus.groovy Highest
Vendor manifest Bundle-Description Groovy Runtime Medium
Vendor pom name Apache Groovy High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom url http://groovy-lang.org Highest
Vendor pom artifactid groovy Low
Vendor pom organization url http://groovy-lang.org Medium
Vendor pom groupid org.codehaus.groovy Highest
Vendor pom organization name Apache Software Foundation High
Vendor pom description Groovy: A powerful, dynamic language for the JVM Medium
Vendor pom groupid codehaus.groovy Highest
Vendor file name groovy High
Vendor Manifest originally-created-by 1.8.0_131-b11 (Oracle Corporation) Low
Product Manifest extension-name groovy Medium
Product pom organization url http://groovy-lang.org Low
Product pom artifactid groovy Highest
Product Manifest bundle-symbolicname groovy Medium
Product Manifest Implementation-Title Groovy: a powerful, dynamic language for the JVM High
Product central artifactid groovy Highest
Product manifest Bundle-Description Groovy Runtime Medium
Product pom name Apache Groovy High
Product pom groupid codehaus.groovy Low
Product Manifest specification-title Groovy: a powerful, dynamic language for the JVM Medium
Product Manifest Bundle-Name Groovy Runtime Medium
Product pom description Groovy: A powerful, dynamic language for the JVM Medium
Product pom url http://groovy-lang.org Medium
Product pom organization name Apache Software Foundation Low
Product file name groovy High
Product Manifest originally-created-by 1.8.0_131-b11 (Oracle Corporation) Low
Version pom version 2.4.12 Highest
Version central version 2.4.12 Highest
Version Manifest Implementation-Version 2.4.12 High
Version file version 2.4.12 Highest
thymeleaf-layout-dialect-1.4.0.jar
Description: A dialect for Thymeleaf that allows you to use layout/decorator templates to style your content.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/nz/net/ultraq/thymeleaf/thymeleaf-layout-dialect/1.4.0/thymeleaf-layout-dialect-1.4.0.jar
MD5: c7f68cea0796caf11585998f3bbe858f
SHA1: 08d7810c069ed1534b9631fb1e85c35973546086
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:compile
spring-i18n-support-samples-starter:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid nz.net.ultraq.thymeleaf Highest
Vendor file name thymeleaf-layout-dialect High
Vendor pom name Thymeleaf Layout Dialect High
Vendor pom description A dialect for Thymeleaf that allows you to use layout/decorator templates to style your content. Medium
Vendor pom artifactid thymeleaf-layout-dialect Low
Vendor jar package name ultraq Low
Vendor central groupid nz.net.ultraq.thymeleaf Highest
Vendor jar package name net Low
Vendor jar package name nz Low
Vendor pom url http://www.ultraq.net.nz/programming/thymeleaf-layout-dialect/ Highest
Product file name thymeleaf-layout-dialect High
Product pom name Thymeleaf Layout Dialect High
Product pom url http://www.ultraq.net.nz/programming/thymeleaf-layout-dialect/ Medium
Product jar package name thymeleaf Low
Product pom description A dialect for Thymeleaf that allows you to use layout/decorator templates to style your content. Medium
Product jar package name ultraq Low
Product jar package name net Low
Product pom artifactid thymeleaf-layout-dialect Highest
Product pom groupid nz.net.ultraq.thymeleaf Low
Product central artifactid thymeleaf-layout-dialect Highest
Version pom version 1.4.0 Highest
Version central version 1.4.0 Highest
Version file version 1.4.0 Highest
h2-1.4.192.jar
Description: H2 Database Engine
License:
MPL 2.0 or EPL 1.0: http://h2database.com/html/license.html
File Path: /home/travis/.m2/repository/com/h2database/h2/1.4.192/h2-1.4.192.jar
MD5: 8e161053d21949a13e0918550cd5d2ca
SHA1: 1106492605db135523d2817881cdf029d9292afa
Referenced In Projects/Scopes:
spring-i18n-support-samples-xml:runtime
spring-i18n-support-samples-starter:runtime
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.h2database.com Highest
Vendor Manifest bundle-symbolicname org.h2 Medium
Vendor pom groupid h2database Highest
Vendor pom name H2 Database Engine High
Vendor pom groupid com.h2database Highest
Vendor Manifest implementation-url http://www.h2database.com Low
Vendor pom artifactid h2 Low
Vendor file name h2 High
Vendor pom description H2 Database Engine Medium
Vendor central groupid com.h2database Highest
Product central artifactid h2 Highest
Product Manifest bundle-symbolicname org.h2 Medium
Product pom name H2 Database Engine High
Product Manifest Bundle-Name H2 Database Engine Medium
Product Manifest implementation-url http://www.h2database.com Low
Product pom url http://www.h2database.com Medium
Product pom artifactid h2 Highest
Product Manifest Implementation-Title H2 Database Engine High
Product file name h2 High
Product pom description H2 Database Engine Medium
Product pom groupid h2database Low
Version file version 1.4.192 Highest
Version Manifest Implementation-Version 1.4.192 High
Version central version 1.4.192 Highest
Version pom version 1.4.192 Highest
android-json-0.0.20131108.vaadin1.jar
Description:
JSON (JavaScript Object Notation) is a lightweight data-interchange format.
This is the org.json compatible Android implementation extracted from the Android SDK
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/travis/.m2/repository/com/vaadin/external/google/android-json/0.0.20131108.vaadin1/android-json-0.0.20131108.vaadin1.jar
MD5: 10612241a9cc269501a7a2b8a984b949
SHA1: fa26d351fe62a6a17f5cda1287c1c6110dec413f
Referenced In Project/Scope:
spring-i18n-support-starter:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.json Medium
Vendor central groupid com.vaadin.external.google Highest
Vendor pom name JSON library from Android SDK High
Vendor pom groupid vaadin.external.google Highest
Vendor pom artifactid android-json Low
Vendor pom url http://developer.android.com/sdk Highest
Vendor Manifest Implementation-Vendor Google High
Vendor pom description JSON (JavaScript Object Notation) is a lightweight data-interchange format. This is the org.json compatible Android implementation extracted from the Android SDK Low
Vendor pom groupid com.vaadin.external.google Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest implementation-url http://developer.android.com/sdk Low
Vendor file name android-json High
Product Manifest Bundle-Name json-android Medium
Product Manifest bundle-symbolicname org.json Medium
Product pom name JSON library from Android SDK High
Product pom description JSON (JavaScript Object Notation) is a lightweight data-interchange format. This is the org.json compatible Android implementation extracted from the Android SDK Low
Product pom url http://developer.android.com/sdk Medium
Product central artifactid android-json Highest
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product pom artifactid android-json Highest
Product Manifest implementation-url http://developer.android.com/sdk Low
Product file name android-json High
Product pom groupid vaadin.external.google Low
Version central version 0.0.20131108.vaadin1 Highest
Version Manifest Implementation-Version 0.0.20131108.vaadin1 High
Version pom version 0.0.20131108.vaadin1 Highest
spring-data-commons-1.13.8.RELEASE.jar
File Path: /home/travis/.m2/repository/org/springframework/data/spring-data-commons/1.13.8.RELEASE/spring-data-commons-1.13.8.RELEASE.jar
MD5: 41b6ce6edafc9db13a523c78b3c4e19a
SHA1: 2853e3c38e02d42529f6c8b247d7bace40c25642
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid spring-data-commons Low
Vendor pom name Spring Data Core High
Vendor pom parent-groupid org.springframework.data.build Medium
Vendor central groupid org.springframework.data Highest
Vendor file name spring-data-commons High
Vendor pom groupid org.springframework.data Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor pom parent-artifactid spring-data-parent Low
Vendor Manifest bundle-symbolicname org.springframework.data.core Medium
Vendor pom groupid springframework.data Highest
Product pom name Spring Data Core High
Product file name spring-data-commons High
Product pom artifactid spring-data-commons Highest
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest Bundle-Name spring-data-commons Medium
Product pom groupid springframework.data Low
Product pom parent-groupid org.springframework.data.build Low
Product pom parent-artifactid spring-data-parent Medium
Product Manifest bundle-symbolicname org.springframework.data.core Medium
Product central artifactid spring-data-commons Highest
Version central version 1.13.8.RELEASE Highest
Version Manifest Bundle-Version 1.13.8.RELEASE High
Version file version 1.13.8 Highest
Version file name spring-data-commons Medium
Version pom version 1.13.8.RELEASE Highest
Version pom parent-version 1.13.8.RELEASE Low
aspectjrt-1.8.11.jar
Description: The runtime needed to execute a program using AspectJ
License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/travis/.m2/repository/org/aspectj/aspectjrt/1.8.11/aspectjrt-1.8.11.jar
MD5: 166f90f29e3500174638bada09d75178
SHA1: 8810071477b9700a180350b331a8f3a8707b2f16
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid aspectjrt Low
Vendor central groupid org.aspectj Highest
Vendor pom description The runtime needed to execute a program using AspectJ Medium
Vendor file name aspectjrt High
Vendor manifest: org/aspectj/lang/ Implementation-Vendor aspectj.org Medium
Vendor pom groupid aspectj Highest
Vendor pom groupid org.aspectj Highest
Vendor pom url http://www.aspectj.org Highest
Vendor pom name AspectJ runtime High
Product pom groupid aspectj Low
Product manifest: org/aspectj/lang/ Specification-Title AspectJ Runtime Classes Medium
Product pom description The runtime needed to execute a program using AspectJ Medium
Product file name aspectjrt High
Product pom url http://www.aspectj.org Medium
Product manifest: org/aspectj/lang/ Implementation-Title org.aspectj.tools Medium
Product central artifactid aspectjrt Highest
Product pom artifactid aspectjrt Highest
Product pom name AspectJ runtime High
Version pom version 1.8.11 Highest
Version file version 1.8.11 Highest
Version central version 1.8.11 Highest
spring-data-jpa-1.11.8.RELEASE.jar
Description: Spring Data module for JPA repositories.
File Path: /home/travis/.m2/repository/org/springframework/data/spring-data-jpa/1.11.8.RELEASE/spring-data-jpa-1.11.8.RELEASE.jar
MD5: edace70f681e79388d3376995f5ca123
SHA1: d674b8407de3d2998c106557fd6a6665de2bc217
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor file name spring-data-jpa High
Vendor pom parent-groupid org.springframework.data.build Medium
Vendor pom artifactid spring-data-jpa Low
Vendor pom name Spring Data JPA High
Vendor Manifest bundle-symbolicname org.springframework.data.jpa Medium
Vendor pom url http://projects.spring.io/spring-data-jpa Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor central groupid org.springframework.data Highest
Vendor pom description Spring Data module for JPA repositories. Medium
Vendor pom groupid org.springframework.data Highest
Vendor pom parent-artifactid spring-data-parent Low
Vendor pom groupid springframework.data Highest
Product file name spring-data-jpa High
Product pom artifactid spring-data-jpa Highest
Product pom url http://projects.spring.io/spring-data-jpa Medium
Product pom groupid springframework.data Low
Product pom parent-groupid org.springframework.data.build Low
Product pom name Spring Data JPA High
Product Manifest bundle-symbolicname org.springframework.data.jpa Medium
Product central artifactid spring-data-jpa Highest
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom description Spring Data module for JPA repositories. Medium
Product Manifest Bundle-Name spring-data-jpa Medium
Product pom parent-artifactid spring-data-parent Medium
Version central version 1.11.8.RELEASE Highest
Version Manifest Bundle-Version 1.11.8.RELEASE High
Version pom parent-version 1.11.8.RELEASE Low
Version pom version 1.11.8.RELEASE Highest
Version file name spring-data-jpa Medium
Version file version 1.11.8 Highest
ehcache-core-2.6.11.jar
Description: This is the ehcache core module. Pair it with other modules for added functionality.
License:
The Apache Software License, Version 2.0: src/assemble/EHCACHE-CORE-LICENSE.txt
File Path: /home/travis/.m2/repository/net/sf/ehcache/ehcache-core/2.6.11/ehcache-core-2.6.11.jar
MD5: 81840aace00ec514154d6dac91ba43e5
SHA1: fae7f84a5ffabe1b814e40190650c0ad5aeda5b1
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid ehcache-parent Low
Vendor file name ehcache-core High
Vendor central groupid net.sf.ehcache Highest
Vendor pom artifactid ehcache-core Low
Vendor pom url http://ehcache.org Highest
Vendor pom name Ehcache Core High
Vendor pom groupid net.sf.ehcache Highest
Vendor pom description This is the ehcache core module. Pair it with other modules for added functionality. Medium
Product file name ehcache-core High
Product pom url http://ehcache.org Medium
Product pom groupid net.sf.ehcache Low
Product pom parent-artifactid ehcache-parent Medium
Product pom name Ehcache Core High
Product pom artifactid ehcache-core Highest
Product pom description This is the ehcache core module. Pair it with other modules for added functionality. Medium
Product central artifactid ehcache-core Highest
Version file version 2.6.11 Highest
Version central version 2.6.11 Highest
Version pom version 2.6.11 Highest
hibernate-jpa-2.1-api-1.0.0.Final.jar
Description: Clean-room definition of JPA APIs intended for use in developing Hibernate JPA implementation. See README.md for details
License:
Eclipse Public License (EPL), Version 1.0: http://www.eclipse.org/legal/epl-v10.html
Eclipse Distribution License (EDL), Version 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /home/travis/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.1-api/1.0.0.Final/hibernate-jpa-2.1-api-1.0.0.Final.jar
MD5: 01b091825023c97fdfd6d2bceebe03ff
SHA1: 5e731d961297e5a07290bfaf3db1fbc8bbbf405a
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor hibernate.org High
Vendor pom url http://hibernate.org Highest
Vendor file name hibernate-jpa-2.1-api-1.0.0.Final High
Vendor Manifest bundle-symbolicname org.hibernate.javax.persistence.hibernate-jpa-2.1-api Medium
Vendor pom description Clean-room definition of JPA APIs intended for use in developing Hibernate JPA implementation. See README.md for details Low
Vendor pom groupid hibernate.javax.persistence Highest
Vendor central groupid org.hibernate.javax.persistence Highest
Vendor pom name Java Persistence API, Version 2.1 High
Vendor pom groupid org.hibernate.javax.persistence Highest
Vendor pom artifactid hibernate-jpa-2.1-api Low
Product Manifest specification-title Java Persistence API, Version 2.1 Medium
Product Manifest Implementation-Title Java Persistence API High
Product pom artifactid hibernate-jpa-2.1-api Highest
Product file name hibernate-jpa-2.1-api-1.0.0.Final High
Product Manifest bundle-symbolicname org.hibernate.javax.persistence.hibernate-jpa-2.1-api Medium
Product pom description Clean-room definition of JPA APIs intended for use in developing Hibernate JPA implementation. See README.md for details Low
Product Manifest Bundle-Name hibernate-jpa-2.1-api Medium
Product pom name Java Persistence API, Version 2.1 High
Product central artifactid hibernate-jpa-2.1-api Highest
Product pom groupid hibernate.javax.persistence Low
Product pom url http://hibernate.org Medium
Version central version 1.0.0.Final Highest
Version pom version 1.0.0.Final Highest
Version Manifest Implementation-Version 1.0.0.Final High
antlr-2.7.7.jar
Description:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html
File Path: /home/travis/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.antlr.org/ Highest
Vendor pom name AntLR Parser Generator High
Vendor pom groupid antlr Highest
Vendor pom artifactid antlr Low
Vendor jar package name antlr Low
Vendor central groupid antlr Highest
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Vendor file name antlr High
Product pom groupid antlr Low
Product pom name AntLR Parser Generator High
Product central artifactid antlr Highest
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom url http://www.antlr.org/ Medium
Product file name antlr High
Product pom artifactid antlr Highest
Version pom version 2.7.7 Highest
Version file version 2.7.7 Highest
Version central version 2.7.7 Highest
jboss-transaction-api_1.2_spec-1.0.1.Final.jar
Description: The Java Transaction 1.2 API classes
License:
Common Development and Distribution License: http://repository.jboss.org/licenses/cddl.txt
GNU General Public License, Version 2 with the Classpath Exception: http://repository.jboss.org/licenses/gpl-2.0-ce.txt
File Path: /home/travis/.m2/repository/org/jboss/spec/javax/transaction/jboss-transaction-api_1.2_spec/1.0.1.Final/jboss-transaction-api_1.2_spec-1.0.1.Final.jar
MD5: 4d3a6329aa429d92e7bf0c2d34302660
SHA1: 4441f144a2a1f46ed48fcc6b476a4b6295e6d524
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Windows 10 Medium
Vendor pom groupid jboss.spec.javax.transaction Highest
Vendor pom name Java Transaction API High
Vendor pom parent-artifactid jboss-parent Low
Vendor pom parent-groupid org.jboss Medium
Vendor manifest Bundle-Description The Java Transaction 1.2 API classes Medium
Vendor pom groupid org.jboss.spec.javax.transaction Highest
Vendor Manifest Implementation-Vendor-Id org.jboss.spec.javax.transaction Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid jboss-transaction-api_1.2_spec Low
Vendor central groupid org.jboss.spec.javax.transaction Highest
Vendor Manifest bundle-symbolicname org.jboss.spec.javax.transaction.jboss-transaction-api_1.2_spec Medium
Vendor file name jboss-transaction-api_1.2_spec-1.0.1.Final High
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor Manifest implementation-url http://www.jboss.org/jboss-transaction-api_1.2_spec Low
Vendor pom description The Java Transaction 1.2 API classes Medium
Product Manifest os-name Windows 10 Medium
Product pom name Java Transaction API High
Product pom artifactid jboss-transaction-api_1.2_spec Highest
Product Manifest Bundle-Name Java Transaction API Medium
Product Manifest specification-title JSR 907: Java Transaction API (JTA) Medium
Product manifest Bundle-Description The Java Transaction 1.2 API classes Medium
Product pom groupid jboss.spec.javax.transaction Low
Product central artifactid jboss-transaction-api_1.2_spec Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Low
Product Manifest bundle-symbolicname org.jboss.spec.javax.transaction.jboss-transaction-api_1.2_spec Medium
Product file name jboss-transaction-api_1.2_spec-1.0.1.Final High
Product Manifest bundle-docurl http://www.jboss.org Low
Product Manifest implementation-url http://www.jboss.org/jboss-transaction-api_1.2_spec Low
Product Manifest Implementation-Title Java Transaction API High
Product pom description The Java Transaction 1.2 API classes Medium
Version Manifest Implementation-Version 1.0.1.Final High
Version central version 1.0.1.Final Highest
Version pom version 1.0.1.Final Highest
jandex-2.0.3.Final.jar
Description: Parent POM for JBoss projects. Provides default project build configuration.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/travis/.m2/repository/org/jboss/jandex/2.0.3.Final/jandex-2.0.3.Final.jar
MD5: 77db6e55da888349f5466d2dcf150b14
SHA1: bfc4d6257dbff7a33a357f0de116be6ff951d849
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom artifactid jandex Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom parent-artifactid jboss-parent Low
Vendor file name jandex High
Vendor Manifest build-timestamp Tue, 2 Aug 2016 13:41:44 -0500 Low
Vendor pom groupid org.jboss Highest
Vendor manifest Bundle-Description Parent POM for JBoss projects. Provides default project build configuration. Medium
Vendor pom parent-groupid org.jboss Medium
Vendor Manifest bundle-symbolicname org.jboss.jandex Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.jboss Medium
Vendor pom groupid jboss Highest
Vendor pom name Java Annotation Indexer High
Vendor central groupid org.jboss Highest
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor Manifest os-name Mac OS X Medium
Vendor Manifest implementation-url http://www.jboss.org/jandex Low
Product pom groupid jboss Low
Product file name jandex High
Product Manifest build-timestamp Tue, 2 Aug 2016 13:41:44 -0500 Low
Product manifest Bundle-Description Parent POM for JBoss projects. Provides default project build configuration. Medium
Product Manifest bundle-symbolicname org.jboss.jandex Medium
Product pom artifactid jandex Highest
Product Manifest specification-title Java Annotation Indexer Medium
Product Manifest Bundle-Name Java Annotation Indexer Medium
Product pom parent-artifactid jboss-parent Medium
Product pom parent-groupid org.jboss Low
Product pom name Java Annotation Indexer High
Product central artifactid jandex Highest
Product Manifest bundle-docurl http://www.jboss.org Low
Product Manifest os-name Mac OS X Medium
Product Manifest Implementation-Title Java Annotation Indexer High
Product Manifest implementation-url http://www.jboss.org/jandex Low
Version pom version 2.0.3.Final Highest
Version file version 2.0.3 Highest
Version Manifest Implementation-Version 2.0.3.Final High
Version central version 2.0.3.Final Highest
dom4j-1.6.1.jar
Description: dom4j: the flexible XML framework for Java
File Path: /home/travis/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar
MD5: 4d8f51d3fe3900efc6e395be48030d6d
SHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor file name dom4j High
Vendor Manifest specification-vendor MetaStuff Ltd. Low
Vendor pom organization url http://sourceforge.net/projects/dom4j Medium
Vendor pom description dom4j: the flexible XML framework for Java Medium
Vendor pom name dom4j High
Vendor pom artifactid dom4j Low
Vendor central groupid dom4j High
Vendor Manifest Implementation-Vendor MetaStuff Ltd. High
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor Manifest extension-name dom4j Medium
Vendor pom url http://dom4j.org Highest
Vendor pom groupid dom4j Highest
Vendor pom organization name MetaStuff Ltd. High
Product file name dom4j High
Product Manifest Implementation-Title org.dom4j High
Product pom artifactid dom4j Highest
Product pom description dom4j: the flexible XML framework for Java Medium
Product central artifactid dom4j-1.6.1 High
Product pom groupid dom4j Low
Product pom name dom4j High
Product pom organization url http://sourceforge.net/projects/dom4j Low
Product pom url http://dom4j.org Medium
Product Manifest specification-title dom4j : XML framework for Java Medium
Product Manifest extension-name dom4j Medium
Product central artifactid dom4j High
Product pom organization name MetaStuff Ltd. Low
Version file version 1.6.1 Highest
Version Manifest Implementation-Version 1.6.1 High
Version central version 2.0 High
Version pom version 1.6.1 Highest
Version central version 1.6.1 High
Published Vulnerabilities
CVE-2018-1000632 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-91 XML Injection (aka Blind XPath Injection)
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Vulnerable Software & Versions: (show all )
hibernate-commons-annotations-5.0.1.Final.jar
Description: Common reflection code used in support of annotation processing
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/travis/.m2/repository/org/hibernate/common/hibernate-commons-annotations/5.0.1.Final/hibernate-commons-annotations-5.0.1.Final.jar
MD5: 2a9d6f5a4ece96557bc4300ecc4486fb
SHA1: 71e1cff3fcb20d3b3af4f3363c3ddb24d33c6879
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Hibernate Commons Annotations High
Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Vendor central groupid org.hibernate.common Highest
Vendor file name hibernate-commons-annotations High
Vendor pom groupid org.hibernate.common Highest
Vendor pom artifactid hibernate-commons-annotations Low
Vendor pom groupid hibernate.common Highest
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom url http://hibernate.org Highest
Vendor pom description Common reflection code used in support of annotation processing Medium
Vendor pom organization name Hibernate.org High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Product Manifest Bundle-Name hibernate-commons-annotations Medium
Product pom groupid hibernate.common Low
Product pom organization url http://hibernate.org Low
Product pom name Hibernate Commons Annotations High
Product pom artifactid hibernate-commons-annotations Highest
Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Product file name hibernate-commons-annotations High
Product central artifactid hibernate-commons-annotations Highest
Product pom organization name Hibernate.org Low
Product pom description Common reflection code used in support of annotation processing Medium
Product Manifest implementation-url http://hibernate.org Low
Product pom url http://hibernate.org Medium
Version file version 5.0.1 Highest
Version pom version 5.0.1.Final Highest
Version central version 5.0.1.Final Highest
Version Manifest Implementation-Version 5.0.1.Final High
hibernate-core-5.2.11.Final.jar
Description: The core O/RM functionality as provided by Hibernate
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/travis/.m2/repository/org/hibernate/hibernate-core/5.2.11.Final/hibernate-core-5.2.11.Final.jar
MD5: e3f79bc4af31070146442d0649598a9e
SHA1: c7bc35a9caccb66f6b7209849c5feab8241abb76
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.hibernate Highest
Vendor pom description The core O/RM functionality as provided by Hibernate Medium
Vendor Manifest bundle-symbolicname org.hibernate.core Medium
Vendor manifest Bundle-Description A module of the Hibernate O/RM project Medium
Vendor pom groupid org.hibernate Highest
Vendor Manifest specification-vendor Hibernate.org Low
Vendor pom artifactid hibernate-core Low
Vendor file name hibernate-core High
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom url http://hibernate.org Highest
Vendor pom organization name Hibernate.org High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom organization url http://hibernate.org Medium
Vendor pom groupid hibernate Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Vendor pom name Core Hibernate O/RM functionality High
Product pom organization url http://hibernate.org Low
Product pom description The core O/RM functionality as provided by Hibernate Medium
Product Manifest Implementation-Title hibernate-core High
Product pom artifactid hibernate-core Highest
Product Manifest bundle-symbolicname org.hibernate.core Medium
Product manifest Bundle-Description A module of the Hibernate O/RM project Medium
Product central artifactid hibernate-core Highest
Product pom groupid hibernate Low
Product file name hibernate-core High
Product pom organization name Hibernate.org Low
Product Manifest specification-title hibernate-core Medium
Product Manifest implementation-url http://hibernate.org Low
Product Manifest Bundle-Name hibernate-core Medium
Product pom url http://hibernate.org Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Product pom name Core Hibernate O/RM functionality High
Version file version 5.2.11 Highest
Version central version 5.2.11.Final Highest
Version Manifest Implementation-Version 5.2.11.Final High
Version pom version 5.2.11.Final Highest
ehcache-core-2.6.11.jar: sizeof-agent.jar
File Path: /home/travis/.m2/repository/net/sf/ehcache/ehcache-core/2.6.11/ehcache-core-2.6.11.jar/net/sf/ehcache/pool/sizeof/sizeof-agent.jar
MD5: 5ad919b3ac0516897bdca079c9a222a8
SHA1: e86399a80ae6a6c7a563717eaa0ce9ba4708571c
Referenced In Project/Scope:
spring-i18n-support:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid ehcache-parent Low
Vendor pom url http://www.ehcache.org Highest
Vendor Manifest hudson-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Vendor pom name Ehcache Size-Of Agent High
Vendor file name sizeof-agent High
Vendor Manifest hudson-build-number 6 Low
Vendor Manifest jenkins-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Vendor pom groupid net.sf.ehcache Highest
Vendor Manifest jenkins-build-number 6 Low
Vendor pom artifactid sizeof-agent Low
Product Manifest hudson-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Product pom name Ehcache Size-Of Agent High
Product file name sizeof-agent High
Product pom groupid net.sf.ehcache Low
Product pom parent-artifactid ehcache-parent Medium
Product pom url http://www.ehcache.org Medium
Product Manifest hudson-build-number 6 Low
Product pom artifactid sizeof-agent Highest
Product Manifest jenkins-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Product Manifest jenkins-build-number 6 Low
Version pom parent-version 1.0.1 Low
Version Manifest hudson-version 1.449 Medium
Version pom version 1.0.1 Highest
Version Manifest hudson-build-number 6 Low
Version Manifest jenkins-build-number 6 Low
Version Manifest jenkins-version 1.449 Medium
maven: net.sf.ehcache:sizeof-agent:1.0.1
Confidence :High