Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : Sep 8, 2019 at 07:42:01 +00:00
Dependencies Scanned : 289 (240 unique)
Vulnerable Dependencies : 33
Vulnerabilities Found : 124
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 27/08/2019 03:15:28
NVD CVE 2003 : 27/08/2019 02:45:38
NVD CVE 2004 : 27/08/2019 02:45:38
NVD CVE 2005 : 27/08/2019 02:45:38
NVD CVE 2006 : 29/08/2019 08:45:47
NVD CVE 2007 : 27/08/2019 02:15:31
NVD CVE 2008 : 27/08/2019 01:45:43
NVD CVE 2009 : 06/09/2019 08:15:30
NVD CVE 2010 : 27/08/2019 01:15:32
NVD CVE 2011 : 31/08/2019 08:45:45
NVD CVE 2012 : 04/09/2019 08:45:34
NVD CVE 2013 : 31/08/2019 08:45:45
NVD CVE 2014 : 31/08/2019 08:45:45
NVD CVE 2015 : 05/09/2019 08:45:28
NVD CVE 2016 : 07/09/2019 08:15:30
NVD CVE 2017 : 07/09/2019 08:15:30
NVD CVE 2018 : 07/09/2019 07:45:37
NVD CVE 2019 : 07/09/2019 07:15:29
NVD CVE Checked : 08/09/2019 07:41:22
NVD CVE Modified : 08/09/2019 05:15:29
VersionCheckOn : 1567322986466
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
xmlpull-1.1.3.1.jar
License:
Public Domain: http://www.xmlpull.org/v1/download/unpacked/LICENSE.txt
File Path: /home/ciagent/.m2/repository/xmlpull/xmlpull/1.1.3.1/xmlpull-1.1.3.1.jar
MD5: cc57dacc720eca721a50e78934b822d2
SHA1: 2b8e230d2ab644e4ecaa94db7cdedbc40c805dfa
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name v1 Low
Vendor pom name XML Pull Parsing API High
Vendor pom url http://www.xmlpull.org Highest
Vendor central groupid xmlpull Highest
Vendor jar package name xmlpull Low
Vendor file name xmlpull High
Vendor pom groupid xmlpull Highest
Vendor pom artifactid xmlpull Low
Product pom artifactid xmlpull Highest
Product pom groupid xmlpull Low
Product jar package name v1 Low
Product pom name XML Pull Parsing API High
Product pom url http://www.xmlpull.org Medium
Product file name xmlpull High
Product central artifactid xmlpull Highest
Version file version 1.1.3.1 Highest
Version central version 1.1.3.1 Highest
Version pom version 1.1.3.1 Highest
xstream-1.4.10.jar
Description: XStream is a serialization library from Java objects to XML and back.
License:
http://x-stream.github.io/license.html
File Path: /home/ciagent/.m2/repository/com/thoughtworks/xstream/xstream/1.4.10/xstream-1.4.10.jar
MD5: d00eec778910f95b26201395ac64cca0
SHA1: dfecae23647abc9d9fd0416629a4213a3882b101
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest x-builder Maven 3.3.9 Low
Vendor central groupid com.thoughtworks.xstream Highest
Vendor pom artifactid xstream Low
Vendor pom groupid thoughtworks.xstream Highest
Vendor Manifest x-compile-target 1.5 Low
Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low
Vendor Manifest x-compile-source 1.5 Low
Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low
Vendor Manifest x-build-time 2017-05-23T14:28:02Z Low
Vendor pom groupid com.thoughtworks.xstream Highest
Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low
Vendor pom name XStream Core High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Vendor pom parent-artifactid xstream-parent Low
Vendor manifest Bundle-Description XStream is a serialization library from Java objects to XML and back. Medium
Vendor Manifest java_1_9_home /opt/oracle-jdk-bin-1.9.0.0_beta167 Low
Vendor Manifest specification-vendor XStream Low
Vendor Manifest Implementation-Vendor-Id com.thoughtworks.xstream Medium
Vendor Manifest bundle-docurl http://x-stream.github.io Low
Vendor file name xstream High
Vendor Manifest bundle-symbolicname xstream Medium
Vendor pom parent-groupid com.thoughtworks.xstream Medium
Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.131 Low
Vendor Manifest Implementation-Vendor XStream High
Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low
Product Manifest x-builder Maven 3.3.9 Low
Product pom artifactid xstream Highest
Product central artifactid xstream Highest
Product Manifest x-compile-target 1.5 Low
Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low
Product Manifest x-compile-source 1.5 Low
Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low
Product Manifest specification-title XStream Core Medium
Product Manifest x-build-time 2017-05-23T14:28:02Z Low
Product Manifest Implementation-Title XStream Core High
Product Manifest Bundle-Name XStream Core Medium
Product pom groupid thoughtworks.xstream Low
Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low
Product pom parent-groupid com.thoughtworks.xstream Low
Product pom name XStream Core High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Product manifest Bundle-Description XStream is a serialization library from Java objects to XML and back. Medium
Product Manifest java_1_9_home /opt/oracle-jdk-bin-1.9.0.0_beta167 Low
Product Manifest bundle-docurl http://x-stream.github.io Low
Product file name xstream High
Product Manifest bundle-symbolicname xstream Medium
Product pom parent-artifactid xstream-parent Medium
Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.131 Low
Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low
Version pom version 1.4.10 Highest
Version Manifest Implementation-Version 1.4.10 High
Version file version 1.4.10 Highest
Version central version 1.4.10 Highest
Published Vulnerabilities
CVE-2013-7285 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Vulnerable Software & Versions: (show all )
CVE-2019-10173 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
Vulnerable Software & Versions:
commons-chain-1.2.jar
Description:
An implementation of the GoF Chain of Responsibility pattern
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-chain/commons-chain/1.2/commons-chain-1.2.jar
MD5: e18e2c87826644e4c8c08635572c154f
SHA1: 744a13e8766e338bd347b6fbc28c6db12979d0c6
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid commons-chain Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid commons-chain Highest
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-symbolicname org.apache.commons.chain Medium
Vendor pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Vendor Manifest bundle-docurl http://commons.apache.org/chain/ Low
Vendor manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Vendor pom groupid commons-chain Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom url http://commons.apache.org/chain/ Highest
Vendor pom name Commons Chain High
Vendor file name commons-chain High
Vendor pom parent-artifactid commons-parent Low
Product Manifest Bundle-Name Commons Chain Medium
Product Manifest bundle-symbolicname org.apache.commons.chain Medium
Product pom parent-artifactid commons-parent Medium
Product central artifactid commons-chain Highest
Product pom url http://commons.apache.org/chain/ Medium
Product Manifest specification-title Commons Chain Medium
Product pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Product pom artifactid commons-chain Highest
Product pom groupid commons-chain Low
Product Manifest bundle-docurl http://commons.apache.org/chain/ Low
Product manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Product Manifest Implementation-Title Commons Chain High
Product pom parent-groupid org.apache.commons Low
Product pom name Commons Chain High
Product file name commons-chain High
Version pom version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
Version central version 1.2 Highest
Version file version 1.2 Highest
commons-codec-1.10.jar
Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid commons-codec Highest
Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Vendor pom name Apache Commons Codec High
Vendor central groupid commons-codec Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor file name commons-codec High
Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-codec Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Vendor pom parent-artifactid commons-parent Low
Product Manifest bundle-symbolicname org.apache.commons.codec Medium
Product manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product pom groupid commons-codec Low
Product pom parent-artifactid commons-parent Medium
Product Manifest specification-title Apache Commons Codec Medium
Product Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Product pom name Apache Commons Codec High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product pom url http://commons.apache.org/proper/commons-codec/ Medium
Product Manifest Implementation-Title Apache Commons Codec High
Product central artifactid commons-codec Highest
Product pom parent-groupid org.apache.commons Low
Product pom artifactid commons-codec Highest
Product file name commons-codec High
Product Manifest Bundle-Name Apache Commons Codec Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Version Manifest Implementation-Version 1.10 High
Version central version 1.10 Highest
Version file version 1.10 Highest
Version pom version 1.10 Highest
commons-httpclient-3.1.jar
Description: The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily.
License:
Apache License: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/commons-httpclient/commons-httpclient/3.1/commons-httpclient-3.1.jar
MD5: 8ad8c9229ef2d59ab9f59f7050e846a5
SHA1: 964cd74171f427720480efdec40a7c7f6e58426a
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid commons-httpclient Low
Vendor pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Highest
Vendor pom name HttpClient High
Vendor file name commons-httpclient High
Vendor pom organization name Apache Software Foundation High
Vendor pom description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. Low
Vendor pom groupid commons-httpclient Highest
Vendor manifest: org/apache/commons/httpclient Implementation-Vendor Apache Software Foundation Medium
Vendor pom organization url http://jakarta.apache.org/ Medium
Vendor central groupid commons-httpclient Highest
Product pom organization url http://jakarta.apache.org/ Low
Product pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Medium
Product pom organization name Apache Software Foundation Low
Product pom artifactid commons-httpclient Highest
Product manifest: org/apache/commons/httpclient Specification-Title Jakarta Commons HttpClient Medium
Product pom groupid commons-httpclient Low
Product pom name HttpClient High
Product file name commons-httpclient High
Product pom description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. Low
Product central artifactid commons-httpclient Highest
Product manifest: org/apache/commons/httpclient Implementation-Title org.apache.commons.httpclient Medium
Version file version 3.1 Highest
Version central version 3.1 Highest
Version pom version 3.1 Highest
commons-lang-2.6.jar
Description:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid commons-lang High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom name Commons Lang High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor file name commons-lang High
Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low
Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor pom url http://commons.apache.org/lang/ Highest
Vendor pom groupid commons-lang Highest
Vendor central groupid org.netbeans.external High
Vendor pom artifactid commons-lang Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium
Vendor pom parent-artifactid commons-parent Low
Product pom name Commons Lang High
Product central artifactid org-apache-commons-lang High
Product file name commons-lang High
Product pom parent-artifactid commons-parent Medium
Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest bundle-docurl http://commons.apache.org/lang/ Low
Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest Bundle-Name Commons Lang Medium
Product pom groupid commons-lang Low
Product pom artifactid commons-lang Highest
Product Manifest Implementation-Title Commons Lang High
Product Manifest specification-title Commons Lang Medium
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-lang High
Product pom url http://commons.apache.org/lang/ Medium
Product Manifest bundle-symbolicname org.apache.commons.lang Medium
Version Manifest Implementation-Version 2.6 High
Version file version 2.6 Highest
ical4j-1.0-beta5.jar
Description:
A Java library for reading and writing iCalendar (*.ics) files
License:
iCal4j - License: LICENSE
File Path: /home/ciagent/.m2/repository/ical4j/ical4j/1.0-beta5/ical4j-1.0-beta5.jar
MD5: 6da73e184e456aebd7bd81923c8cccce
SHA1: 6c19c4eec102ae28871c8765fc8d60dc60df93ec
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom name iCal4j High
Vendor jar package name ical4j Low
Vendor jar package name fortuna Low
Vendor file name ical4j High
Vendor pom description
A Java library for reading and writing iCalendar (*.ics) files
Medium
Vendor pom url http://ical4j.sourceforge.net Highest
Vendor jar package name net Low
Vendor pom groupid ical4j Highest
Vendor pom artifactid ical4j Low
Product pom name iCal4j High
Product jar package name ical4j Low
Product pom groupid ical4j Low
Product jar package name fortuna Low
Product pom artifactid ical4j Highest
Product file name ical4j High
Product pom description
A Java library for reading and writing iCalendar (*.ics) files
Medium
Product jar package name model Low
Product pom url http://ical4j.sourceforge.net Medium
Version pom version 1.0-beta5 Highest
Version file version 1.0.beta Highest
Version file name ical4j Medium
maven: ical4j:ical4j:1.0-beta5
Confidence :High
jcr-1.0.1.jar
Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.
License:
Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest extension-name jcr Medium
Vendor pom groupid javax.jcr Highest
Vendor pom organization name Day Software Management AG High
Vendor pom name Content Repository for Java Technology API High
Vendor file name jcr High
Vendor Manifest specification-vendor Day Software Management AG Low
Vendor pom organization url http://www.day.com/ Medium
Vendor pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Vendor pom artifactid jcr Low
Vendor pom url http://www.jcp.org/en/jsr/detail?id=170 Highest
Vendor Manifest Implementation-Vendor Day Software Management AG High
Product Manifest specification-title Content Repository for Java Technology API Medium
Product Manifest extension-name jcr Medium
Product pom organization url http://www.day.com/ Low
Product pom name Content Repository for Java Technology API High
Product pom url http://www.jcp.org/en/jsr/detail?id=170 Medium
Product file name jcr High
Product Manifest Implementation-Title javax.jcr High
Product pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Product pom groupid javax.jcr Low
Product pom artifactid jcr Highest
Product pom organization name Day Software Management AG Low
Version Manifest Implementation-Version 1.0.1 High
Version file version 1.0.1 Highest
Version pom version 1.0.1 Highest
cpe: cpe:/a:content_project:content:1.0.1
Confidence :Low
suppress
maven: javax.jcr:jcr:1.0.1
Confidence :High
Published Vulnerabilities
CVE-2017-16111 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Vulnerable Software & Versions:
slf4j-api-1.7.18.jar
Description: The slf4j API
File Path: /home/ciagent/.m2/repository/org/slf4j/slf4j-api/1.7.18/slf4j-api-1.7.18.jar
MD5: 1b1d1af21206ac5ae44cd79a6c04dd92
SHA1: b631d286463ced7cc42ee2171fe3beaed2836823
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor central groupid org.slf4j Highest
Vendor pom description The slf4j API Medium
Vendor pom groupid org.slf4j Highest
Vendor pom groupid slf4j Highest
Vendor pom parent-groupid org.slf4j Medium
Vendor pom artifactid slf4j-api Low
Vendor manifest Bundle-Description The slf4j API Medium
Vendor pom parent-artifactid slf4j-parent Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom name SLF4J API Module High
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product Manifest bundle-symbolicname slf4j.api Medium
Product pom description The slf4j API Medium
Product Manifest Bundle-Name slf4j-api Medium
Product pom parent-groupid org.slf4j Low
Product central artifactid slf4j-api Highest
Product pom url http://www.slf4j.org Medium
Product pom groupid slf4j Low
Product manifest Bundle-Description The slf4j API Medium
Product Manifest Implementation-Title slf4j-api High
Product pom artifactid slf4j-api Highest
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Version pom version 1.7.18 Highest
Version file version 1.7.18 Highest
Version central version 1.7.18 Highest
Version Manifest Implementation-Version 1.7.18 High
jackrabbit-webdav-1.6.5.jar
Description: WebDAV library used by the Jackrabbit WebDAV support
File Path: /home/ciagent/.m2/repository/org/apache/jackrabbit/jackrabbit-webdav/1.6.5/jackrabbit-webdav-1.6.5.jar
MD5: 1d573cf67bcff173d91dd1d194334b66
SHA1: 5afbee7ce7bcf1c47d7e54e24afcd533cb6776ae
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jackrabbit-webdav Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid apache.jackrabbit Highest
Vendor Manifest Implementation-Vendor-Id org.apache.jackrabbit Medium
Vendor pom name Jackrabbit WebDAV Library High
Vendor central groupid org.apache.jackrabbit Highest
Vendor pom description WebDAV library used by the Jackrabbit WebDAV support Medium
Vendor file name jackrabbit-webdav High
Vendor pom groupid org.apache.jackrabbit Highest
Vendor pom parent-artifactid jackrabbit-parent Low
Vendor pom parent-groupid org.apache.jackrabbit Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Product pom parent-artifactid jackrabbit-parent Medium
Product Manifest Implementation-Title Jackrabbit WebDAV Library High
Product pom description WebDAV library used by the Jackrabbit WebDAV support Medium
Product central artifactid jackrabbit-webdav Highest
Product file name jackrabbit-webdav High
Product pom parent-groupid org.apache.jackrabbit Low
Product pom artifactid jackrabbit-webdav Highest
Product pom groupid apache.jackrabbit Low
Product pom name Jackrabbit WebDAV Library High
Product Manifest specification-title Jackrabbit WebDAV Library Medium
Version pom version 1.6.5 Highest
Version central version 1.6.5 Highest
Version file version 1.6.5 Highest
Version Manifest Implementation-Version 1.6.5 High
Related Dependencies
jackrabbit-jcr-commons-1.6.5.jar
File Path: /home/ciagent/.m2/repository/org/apache/jackrabbit/jackrabbit-jcr-commons/1.6.5/jackrabbit-jcr-commons-1.6.5.jar
SHA1: 0c65d825fd75f1ca3db19d553d9f453a13307175
MD5: d4a3a9629f22a0a987853419eeb9eb1d
maven: org.apache.jackrabbit:jackrabbit-jcr-commons:1.6.5 ✓
Published Vulnerabilities
CVE-2015-1833 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
CWE: CWE-20 Improper Input Validation
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.1, and 2.10.x before 2.10.1 allows remote attackers to read arbitrary files and send requests to intranet servers via a crafted WebDAV request.
Vulnerable Software & Versions: (show all )
exo.portal.webui.core-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.core/5.3.x-SNAPSHOT/exo.portal.webui.core-5.3.x-SNAPSHOT.jar
MD5: 2bdcd7617bc620aaf68b861a6239f6de
SHA1: b03f0171db0eb08d1919d2f22268f6f6f359d9f3
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.portal.webui.core Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.portal Medium
Vendor Manifest os-name Linux Medium
Vendor pom groupid exoplatform.gatein.portal Highest
Vendor pom name GateIn Portal WebUI Core High
Vendor pom parent-groupid org.exoplatform.gatein.portal Medium
Vendor file name exo.portal.webui.core High
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom groupid org.exoplatform.gatein.portal Highest
Vendor Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.webui/exo.portal.webui.core/ Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest build-timestamp Fri, 6 Sep 2019 07:08:20 +0000 Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom parent-artifactid exo.portal.webui Low
Product file name exo.portal.webui.core High
Product Manifest Implementation-Title GateIn Portal WebUI Core High
Product Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.webui/exo.portal.webui.core/ Low
Product pom parent-groupid org.exoplatform.gatein.portal Low
Product pom parent-artifactid exo.portal.webui Medium
Product Manifest specification-title GateIn Portal WebUI Core Medium
Product pom artifactid exo.portal.webui.core Highest
Product Manifest os-name Linux Medium
Product Manifest build-timestamp Fri, 6 Sep 2019 07:08:20 +0000 Low
Product pom name GateIn Portal WebUI Core High
Product pom groupid exoplatform.gatein.portal Low
Version pom version 5.3.x-20190906.072147-61 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Version file version 5.3 Highest
Related Dependencies
exo.portal.component.api-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.api/5.3.x-SNAPSHOT/exo.portal.component.api-5.3.x-SNAPSHOT.jar
SHA1: f30f7b9ea6a5576bf3478feedb6530d516822520
MD5: 420fb78d4153824e4ce3958a5ebaa3c1
exo.portal.gadgets-core-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.gadgets-core/5.3.x-SNAPSHOT/exo.portal.gadgets-core-5.3.x-SNAPSHOT.jar
SHA1: 4f49138ff8869e5f9228dc5da89d40bf0945358c
MD5: 00df8b09acf4d9258d4ee8a69055cc87
exo.portal.webui.portal-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.portal/5.3.x-SNAPSHOT/exo.portal.webui.portal-5.3.x-SNAPSHOT.jar
SHA1: b6a319e05049cb024c2960b06182384fd335c004
MD5: 3f6d0e5a66ecdecdef91447d9ac17d10
exo.portal.component.resources-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.resources/5.3.x-SNAPSHOT/exo.portal.component.resources-5.3.x-SNAPSHOT.jar
SHA1: 41f64e65226f0cf47623feac632683102b1b48a6
MD5: dd5bd9cf6282477aff32b388752cbb90
exo.portal.component.identity-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.identity/5.3.x-SNAPSHOT/exo.portal.component.identity-5.3.x-SNAPSHOT.jar
SHA1: 717a6b109585f5ab18a58ab5db841601500c77ea
MD5: 2d159c780025fb6fec498714a2d21008
maven: org.exoplatform.gatein.portal:exo.portal.webui.core:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:in-portal:in-portal:5.3.20190906
Confidence :Low
suppress
commons-webui-component-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-webui-component/5.3.x-SNAPSHOT/commons-webui-component-5.3.x-SNAPSHOT.jar
MD5: 1261e31f530995df71f81d4e6928b886
SHA1: 2de3d868c0965ede195d38c77274df295b68a36c
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid commons-webui-component Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.commons Highest
Vendor pom name eXo PLF:: Commons - Commons WebUI High
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-09-06T11:21:29Z Low
Vendor pom parent-artifactid commons Low
Vendor file name commons-webui-component High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-component Low
Product file name commons-webui-component High
Product pom parent-artifactid commons Medium
Product Manifest Implementation-Title eXo PLF:: Commons - Commons WebUI High
Product Manifest specification-title eXo PLF:: Commons - Commons WebUI Medium
Product pom name eXo PLF:: Commons - Commons WebUI High
Product pom artifactid commons-webui-component Highest
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest date 2019-09-06T11:21:29Z Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-component Low
Product pom groupid exoplatform.commons Low
Version pom version 5.3.x-20190906.113205-141 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Version file version 5.3 Highest
maven: org.exoplatform.commons:commons-webui-component:5.3.x-SNAPSHOT
Confidence :High
commons-api-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-api/5.3.x-SNAPSHOT/commons-api-5.3.x-SNAPSHOT.jar
MD5: dfebac856f07ea647810535fe98cb194
SHA1: 13b6568e624628a21f3505419d50e373465b3bac
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name commons-api High
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF:: Commons - API High
Vendor pom groupid exoplatform.commons Highest
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-api Low
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-09-06T11:21:29Z Low
Vendor pom parent-artifactid commons Low
Vendor pom artifactid commons-api Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Product Manifest Implementation-Title eXo PLF:: Commons - API High
Product file name commons-api High
Product pom parent-artifactid commons Medium
Product pom artifactid commons-api Highest
Product pom name eXo PLF:: Commons - API High
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-api Low
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest date 2019-09-06T11:21:29Z Low
Product pom groupid exoplatform.commons Low
Product Manifest specification-title eXo PLF:: Commons - API Medium
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Version file version 5.3 Highest
maven: org.exoplatform.commons:commons-api:5.3.x-SNAPSHOT
Confidence :High
jsr311-api-1.1.1.jar
License:
CDDL License
: http://www.opensource.org/licenses/cddl1.php
File Path: /home/ciagent/.m2/repository/javax/ws/rs/jsr311-api/1.1.1/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jsr311-api Low
Vendor Manifest bundle-docurl http://www.sun.com/ Low
Vendor pom organization name Sun Microsystems, Inc High
Vendor Manifest extension-name javax.ws.rs Medium
Vendor central groupid javax.ws.rs Highest
Vendor pom organization url http://www.sun.com/ Medium
Vendor file name jsr311-api High
Vendor pom url https://jsr311.dev.java.net Highest
Vendor pom name jsr311-api High
Vendor pom groupid javax.ws.rs Highest
Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Product Manifest bundle-docurl http://www.sun.com/ Low
Product pom organization name Sun Microsystems, Inc Low
Product central artifactid jsr311-api Highest
Product pom artifactid jsr311-api Highest
Product Manifest extension-name javax.ws.rs Medium
Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium
Product pom url https://jsr311.dev.java.net Medium
Product pom groupid javax.ws.rs Low
Product file name jsr311-api High
Product Manifest Bundle-Name jsr311-api Medium
Product pom organization url http://www.sun.com/ Low
Product pom name jsr311-api High
Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Version file version 1.1.1 Highest
Version central version 1.1.1 Highest
Version pom version 1.1.1 Highest
commons-fileupload-1.3.3.jar
Description:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-fileupload/commons-fileupload/1.3.3/commons-fileupload-1.3.3.jar
MD5: dd77e787b7b5dc56f6a1cb658716d55d
SHA1: 04ff14d809195b711fd6bcc87e6777f886730ca1
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom name Apache Commons FileUpload High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor central groupid commons-fileupload Highest
Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest
Vendor pom artifactid commons-fileupload Low
Vendor Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor file name commons-fileupload High
Vendor pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor pom groupid commons-fileupload Highest
Vendor Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Vendor pom parent-artifactid commons-parent Low
Product pom name Apache Commons FileUpload High
Product manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom parent-artifactid commons-parent Medium
Product pom artifactid commons-fileupload Highest
Product central artifactid commons-fileupload Highest
Product Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Product Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product file name commons-fileupload High
Product Manifest specification-title Apache Commons FileUpload Medium
Product pom parent-groupid org.apache.commons Low
Product pom groupid commons-fileupload Low
Product pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium
Product Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Product Manifest Implementation-Title Apache Commons FileUpload High
Product Manifest Bundle-Name Apache Commons FileUpload Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Version Manifest Implementation-Version 1.3.3 High
Version central version 1.3.3 Highest
Version file version 1.3.3 Highest
Version pom version 1.3.3 Highest
exo.ws.rest.core-5.3.x-SNAPSHOT.jar
Description: Implementation of REST Core for Exoplatform SAS 'Web Services' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.core/5.3.x-SNAPSHOT/exo.ws.rest.core-5.3.x-SNAPSHOT.jar
MD5: 86342561ef49a5cb293729a73cc4112f
SHA1: 416f7877e8ddc88b5cdfcf21f68b86abeaed70c0
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.ws Medium
Vendor pom artifactid exo.ws.rest.core Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid exoplatform.ws Highest
Vendor file name exo.ws.rest.core High
Vendor pom groupid org.exoplatform.ws Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid ws-parent Low
Vendor pom name eXo PLF:: WS :: REST :: Core High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.ws Medium
Vendor pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Product pom parent-artifactid ws-parent Medium
Product pom groupid exoplatform.ws Low
Product Manifest specification-title exo-ws Medium
Product Manifest Implementation-Title eXo PLF:: WS :: REST :: Core High
Product file name exo.ws.rest.core High
Product pom artifactid exo.ws.rest.core Highest
Product pom parent-groupid org.exoplatform.ws Low
Product pom name eXo PLF:: WS :: REST :: Core High
Product pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Version file version 5.3 Highest
Related Dependencies
exo.ws.commons-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.commons/5.3.x-SNAPSHOT/exo.ws.commons-5.3.x-SNAPSHOT.jar
SHA1: 319bfcfe62376085ca825da6a9b2654e9ffd6e75
MD5: c96ef81571e487407442682f86324e73
exo.ws.rest.ext-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.ext/5.3.x-SNAPSHOT/exo.ws.rest.ext-5.3.x-SNAPSHOT.jar
SHA1: 06eecbb170a9ae580f3432833d42d1f341c01d82
MD5: 53862a7799f6f95196ed4cd1fc096174
exo.ws.frameworks.json-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.frameworks.json/5.3.x-SNAPSHOT/exo.ws.frameworks.json-5.3.x-SNAPSHOT.jar
SHA1: 82734275f0a85d68e3c8ffa170212505f74045b7
MD5: 7847a8c462e0419afcdb0c28503ab692
maven: org.exoplatform.ws:exo.ws.rest.core:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:ws_project:ws:5.3
Confidence :Low
suppress
bayeux-api-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/bayeux-api/3.0.8/bayeux-api-3.0.8.jar
MD5: a09842b7f274cefffa408299b5fc8dd0
SHA1: d5aceb0e7fef4a140f7e95be48338b97723d3163
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname bayeux-api Medium
Vendor pom name CometD :: Bayeux API High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor file name bayeux-api High
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/bayeux-api Low
Vendor pom groupid cometd.java Highest
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom artifactid bayeux-api Low
Product Manifest bundle-symbolicname bayeux-api Medium
Product pom name CometD :: Bayeux API High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest Bundle-Name CometD :: Bayeux API Medium
Product file name bayeux-api High
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product central artifactid bayeux-api Highest
Product pom parent-artifactid cometd-java Medium
Product pom artifactid bayeux-api Highest
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/bayeux-api Low
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-common-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-common/3.0.8/cometd-java-common-3.0.8.jar
MD5: 70c7cc13ecc20634a6b357e33134d551
SHA1: 5e2134a1b3bc6e03b7e1666a74e9993d0bb52a7d
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name cometd-java-common High
Vendor Manifest bundle-symbolicname cometd-java-common Medium
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-common Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom artifactid cometd-java-common Low
Vendor pom name CometD :: Java :: Bayeux Common High
Product file name cometd-java-common High
Product Manifest bundle-symbolicname cometd-java-common Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-common Low
Product Manifest Bundle-Name CometD :: Java :: Bayeux Common Medium
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java Medium
Product pom artifactid cometd-java-common Highest
Product central artifactid cometd-java-common Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom name CometD :: Java :: Bayeux Common High
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-websocket-javax-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-javax-server/3.0.8/cometd-java-websocket-javax-server-3.0.8.jar
MD5: afa5e80138d48292a6f93b708257d2fc
SHA1: 353860f809886a58c181dd9e273ee7b79e133277
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-server Low
Vendor Manifest bundle-symbolicname cometd-java-websocket-javax-server Medium
Vendor pom name CometD :: Java :: WebSocket :: JSR 356 Server High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor file name cometd-java-websocket-javax-server High
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom artifactid cometd-java-websocket-javax-server Low
Vendor pom groupid cometd.java Highest
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: JSR 356 Server Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-server Low
Product central artifactid cometd-java-websocket-javax-server Highest
Product Manifest bundle-symbolicname cometd-java-websocket-javax-server Medium
Product pom name CometD :: Java :: WebSocket :: JSR 356 Server High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product file name cometd-java-websocket-javax-server High
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom artifactid cometd-java-websocket-javax-server Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-websocket-common-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-common-server/3.0.8/cometd-java-websocket-common-server-3.0.8.jar
MD5: 5772b2360cec4ff610e62151fb4deb62
SHA1: 61538a1231b700bf045fa197514f63509960985e
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom name CometD :: Java :: WebSocket :: Common Server High
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-server Low
Vendor file name cometd-java-websocket-common-server High
Vendor pom artifactid cometd-java-websocket-common-server Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor Manifest bundle-symbolicname cometd-java-websocket-common-server Medium
Vendor pom groupid cometd.java Highest
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom name CometD :: Java :: WebSocket :: Common Server High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-server Low
Product central artifactid cometd-java-websocket-common-server Highest
Product file name cometd-java-websocket-common-server High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java-websocket Medium
Product Manifest bundle-symbolicname cometd-java-websocket-common-server Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: Common Server Medium
Product pom artifactid cometd-java-websocket-common-server Highest
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-annotations-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-annotations/3.0.8/cometd-java-annotations-3.0.8.jar
MD5: 98b60697675562cf957655c3239a1ad3
SHA1: 5b56875b2ac024b5666633596abb90702ec35e81
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname cometd-java-annotations Medium
Vendor pom name CometD :: Java :: Annotations High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor file name cometd-java-annotations High
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom artifactid cometd-java-annotations Low
Vendor pom groupid cometd.java Highest
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-annotations Low
Product central artifactid cometd-java-annotations Highest
Product Manifest bundle-symbolicname cometd-java-annotations Medium
Product pom name CometD :: Java :: Annotations High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product file name cometd-java-annotations High
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java Medium
Product pom artifactid cometd-java-annotations Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-annotations Low
Product Manifest Bundle-Name CometD :: Java :: Annotations Medium
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
jetty-io-9.2.14.v20151106.jar
Description: Administrative parent pom for Jetty modules
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-io/9.2.14.v20151106/jetty-io-9.2.14.v20151106.jar
MD5: 94d0e857144c7615b6fd65019cd32b59
SHA1: dfa4137371a3f08769820138ca1a2184dacda267
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid eclipse.jetty Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor file name jetty-io High
Vendor Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Vendor pom url http://www.eclipse.org/jetty Highest
Vendor pom groupid org.eclipse.jetty Highest
Vendor manifest Bundle-Description Administrative parent pom for Jetty modules Medium
Vendor pom artifactid jetty-io Low
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Vendor pom parent-groupid org.eclipse.jetty Medium
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor pom name Jetty :: IO Utility High
Vendor central groupid org.eclipse.jetty Highest
Vendor pom parent-artifactid jetty-project Low
Vendor Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product pom groupid eclipse.jetty Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product file name jetty-io High
Product Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Product manifest Bundle-Description Administrative parent pom for Jetty modules Medium
Product pom url http://www.eclipse.org/jetty Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Product pom artifactid jetty-io Highest
Product Manifest Bundle-Name Jetty :: IO Utility Medium
Product Manifest url http://www.eclipse.org/jetty Low
Product pom name Jetty :: IO Utility High
Product central artifactid jetty-io Highest
Product pom parent-groupid org.eclipse.jetty Low
Product pom parent-artifactid jetty-project Medium
Product Manifest bundle-docurl http://www.eclipse.org/jetty Low
Version pom version 9.2.14.v20151106 Highest
Version file version 9.2.14.v20151106 Highest
Version Manifest Implementation-Version 9.2.14.v20151106 High
Version central version 9.2.14.v20151106 Highest
cometd-java-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-client/3.0.8/cometd-java-client-3.0.8.jar
MD5: 24f1367fb4d96fe70a3f07a1f48e447e
SHA1: 826d4ae9402e7c48cc98fe287389788134e4986f
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom name CometD :: Java :: Bayeux Client High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom artifactid cometd-java-client Low
Vendor file name cometd-java-client High
Vendor Manifest bundle-symbolicname cometd-java-client Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-client Low
Product pom artifactid cometd-java-client Highest
Product pom name CometD :: Java :: Bayeux Client High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product central artifactid cometd-java-client Highest
Product file name cometd-java-client High
Product Manifest bundle-symbolicname cometd-java-client Medium
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java Medium
Product Manifest Bundle-Name CometD :: Java :: Bayeux Client Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-client Low
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-websocket-common-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-common-client/3.0.8/cometd-java-websocket-common-client-3.0.8.jar
MD5: c17616c290c54ffc4a70dda2b901919a
SHA1: 8b75f11de5bba306d0bcb20a6c1bed89675579cd
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name cometd-java-websocket-common-client High
Vendor Manifest bundle-symbolicname cometd-java-websocket-common-client Medium
Vendor pom name CometD :: Java :: WebSocket :: Common Client High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid cometd-java-websocket-common-client Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom groupid cometd.java Highest
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-client Low
Product file name cometd-java-websocket-common-client High
Product Manifest bundle-symbolicname cometd-java-websocket-common-client Medium
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: Common Client Medium
Product central artifactid cometd-java-websocket-common-client Highest
Product pom name CometD :: Java :: WebSocket :: Common Client High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom artifactid cometd-java-websocket-common-client Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-client Low
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-websocket-javax-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-javax-client/3.0.8/cometd-java-websocket-javax-client-3.0.8.jar
MD5: 433dd449f689697bbe1a75b0ed2788f8
SHA1: b44bcf098667f0112301d75f73adb5ba3295699d
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name cometd-java-websocket-javax-client High
Vendor pom artifactid cometd-java-websocket-javax-client Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-client Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom name CometD :: Java :: WebSocket :: JSR 356 Client High
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor Manifest bundle-symbolicname cometd-java-websocket-javax-client Medium
Vendor pom groupid cometd.java Highest
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product file name cometd-java-websocket-javax-client High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-client Low
Product pom name CometD :: Java :: WebSocket :: JSR 356 Client High
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom artifactid cometd-java-websocket-javax-client Highest
Product pom parent-artifactid cometd-java-websocket Medium
Product central artifactid cometd-java-websocket-javax-client Highest
Product Manifest bundle-symbolicname cometd-java-websocket-javax-client Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: JSR 356 Client Medium
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
cometd-java-oort-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-oort/3.0.8/cometd-java-oort-3.0.8.jar
MD5: 62dbbecedab27927495fc9c9e0b70505
SHA1: a72695546e010c250ba65519fc91867b208fc8f9
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-oort Low
Vendor pom name CometD :: Java :: Oort High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid cometd-java-oort Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor file name cometd-java-oort High
Vendor Manifest bundle-symbolicname cometd-java-oort Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-oort Low
Product pom name CometD :: Java :: Oort High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product central artifactid cometd-java-oort Highest
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom artifactid cometd-java-oort Highest
Product pom parent-artifactid cometd-java Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest Bundle-Name CometD :: Java :: Oort Medium
Product file name cometd-java-oort High
Product Manifest bundle-symbolicname cometd-java-oort Medium
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
jetty-jmx-9.2.14.v20151106.jar
Description: JMX management artifact for jetty.
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-jmx/9.2.14.v20151106/jetty-jmx-9.2.14.v20151106.jar
MD5: 5eccc25d22921cb4787812d0687a2978
SHA1: 617edc5e966b4149737811ef8b289cd94b831bab
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name jetty-jmx High
Vendor pom groupid eclipse.jetty Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor pom description JMX management artifact for jetty. Medium
Vendor Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Vendor pom url http://www.eclipse.org/jetty Highest
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom name Jetty :: JMX Management High
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor pom parent-groupid org.eclipse.jetty Medium
Vendor manifest Bundle-Description JMX management artifact for jetty. Medium
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor central groupid org.eclipse.jetty Highest
Vendor pom parent-artifactid jetty-project Low
Vendor pom artifactid jetty-jmx Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Vendor Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product file name jetty-jmx High
Product pom groupid eclipse.jetty Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product pom description JMX management artifact for jetty. Medium
Product Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Product pom url http://www.eclipse.org/jetty Medium
Product pom name Jetty :: JMX Management High
Product Manifest Bundle-Name Jetty :: JMX Management Medium
Product manifest Bundle-Description JMX management artifact for jetty. Medium
Product Manifest url http://www.eclipse.org/jetty Low
Product central artifactid jetty-jmx Highest
Product Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Product pom parent-groupid org.eclipse.jetty Low
Product pom parent-artifactid jetty-project Medium
Product Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product pom artifactid jetty-jmx Highest
Version pom version 9.2.14.v20151106 Highest
Version file version 9.2.14.v20151106 Highest
Version Manifest Implementation-Version 9.2.14.v20151106 High
Version central version 9.2.14.v20151106 Highest
Related Dependencies
jetty-util-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-util/9.2.14.v20151106/jetty-util-9.2.14.v20151106.jar
SHA1: 0057e00b912ae0c35859ac81594a996007706a0b
MD5: 15eae2dc1689fa8c72652b156d2619d3
maven: org.eclipse.jetty:jetty-util:9.2.14.v20151106 ✓
jetty-http-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-http/9.2.14.v20151106/jetty-http-9.2.14.v20151106.jar
SHA1: 699ad1f2fa6fb0717e1b308a8c9e1b8c69d81ef6
MD5: 2e42ff59b2a5e8525f0fa1b55351d161
maven: org.eclipse.jetty:jetty-http:9.2.14.v20151106 ✓
jetty-util-ajax-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-util-ajax/9.2.14.v20151106/jetty-util-ajax-9.2.14.v20151106.jar
SHA1: 13470555681de54a10cfed3ab15b1554765d1171
MD5: 1623fc2d77b1bd864a2416e2da15cd9b
maven: org.eclipse.jetty:jetty-util-ajax:9.2.14.v20151106 ✓
jetty-client-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-client/9.2.14.v20151106/jetty-client-9.2.14.v20151106.jar
SHA1: d02985c3a5bd974dacbb4c3d7cf71169135a8e7a
MD5: c400f74ab61fc17fafd19144b548bede
maven: org.eclipse.jetty:jetty-client:9.2.14.v20151106 ✓
Published Vulnerabilities
CVE-2017-7656 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-284 Improper Access Control
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.
Vulnerable Software & Versions: (show all )
CVE-2017-7657 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-190 Integer Overflow or Wraparound
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.
Vulnerable Software & Versions: (show all )
CVE-2017-7658 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-19 Data Handling
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
Vulnerable Software & Versions: (show all )
CVE-2017-9735 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Vulnerable Software & Versions:
cometd-java-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-server/3.0.8/cometd-java-server-3.0.8.jar
MD5: c55eb617762fad72683da9de856e008c
SHA1: 11d535c657bdb491abc2ccd820118f9d6a8f44e0
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-server Low
Vendor Manifest bundle-symbolicname cometd-java-server Medium
Vendor file name cometd-java-server High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid cometd-java-server Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom name CometD :: Java :: Bayeux Server High
Vendor pom groupid org.cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-server Low
Product Manifest bundle-symbolicname cometd-java-server Medium
Product file name cometd-java-server High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom name CometD :: Java :: Bayeux Server High
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom parent-artifactid cometd-java Medium
Product pom artifactid cometd-java-server Highest
Product central artifactid cometd-java-server Highest
Product Manifest Bundle-Name CometD :: Java :: Bayeux Server Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Version pom version 3.0.8 Highest
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
commons-comet-service-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-comet-service/5.3.x-SNAPSHOT/commons-comet-service-5.3.x-SNAPSHOT.jar
MD5: dfdf9fc213432e3ef2cfbfd5fcad1cbd
SHA1: 8c3a6ef247f7e569b39246bf6aad05f29e2d4b44
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name commons-comet-service High
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.commons Highest
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-09-06T11:21:29Z Low
Vendor pom parent-artifactid commons Low
Vendor pom artifactid commons-comet-service Low
Vendor pom name eXo PLF:: Commons - Comet Services High
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-comet-service Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Product Manifest specification-title eXo PLF:: Commons - Comet Services Medium
Product pom name eXo PLF:: Commons - Comet Services High
Product file name commons-comet-service High
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-comet-service Low
Product pom parent-artifactid commons Medium
Product pom artifactid commons-comet-service Highest
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest date 2019-09-06T11:21:29Z Low
Product pom groupid exoplatform.commons Low
Product Manifest Implementation-Title eXo PLF:: Commons - Comet Services High
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Version file version 5.3 Highest
maven: org.exoplatform.commons:commons-comet-service:5.3.x-SNAPSHOT
Confidence :High
jsr250-api-1.0.jar
Description: JSR-250 Reference Implementation by Glassfish
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/annotation/jsr250-api/1.0/jsr250-api-1.0.jar
MD5: 4cd56b2e4977e541186de69f5126b4a6
SHA1: 5025422767732a1ab45d93abfea846513d742dcf
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
eXo PLF:: Calendar Common Statistics:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Highest
Vendor central groupid javax.annotation Highest
Vendor jar package name javax Low
Vendor pom artifactid jsr250-api Low
Vendor pom name JSR-250 Common Annotations for the JavaTM Platform High
Vendor pom groupid javax.annotation Highest
Vendor pom description JSR-250 Reference Implementation by Glassfish Medium
Vendor file name jsr250-api High
Vendor jar package name annotation Low
Product pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Medium
Product pom artifactid jsr250-api Highest
Product pom name JSR-250 Common Annotations for the JavaTM Platform High
Product pom groupid javax.annotation Low
Product pom description JSR-250 Reference Implementation by Glassfish Medium
Product central artifactid jsr250-api Highest
Product file name jsr250-api High
Product jar package name annotation Low
Version pom version 1.0 Highest
Version file version 1.0 Highest
Version central version 1.0 Highest
staxnav.core-0.9.8.jar
File Path: /home/ciagent/.m2/repository/org/staxnav/staxnav.core/0.9.8/staxnav.core-0.9.8.jar
MD5: 0f786e5be21df9fbe8753175564564c7
SHA1: 27bd12d4d74b0851e38de79f8299462d93ba3d7f
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name staxnav Low
Vendor file name staxnav.core High
Vendor pom parent-groupid org.staxnav Medium
Vendor pom parent-artifactid staxnav.parent Low
Vendor pom name Staxnav - Core High
Vendor central groupid org.staxnav Highest
Vendor pom groupid org.staxnav Highest
Vendor pom artifactid staxnav.core Low
Vendor pom groupid staxnav Highest
Product pom artifactid staxnav.core Highest
Product pom parent-artifactid staxnav.parent Medium
Product file name staxnav.core High
Product pom name Staxnav - Core High
Product pom groupid staxnav Low
Product central artifactid staxnav.core Highest
Product pom parent-groupid org.staxnav Low
Version central version 0.9.8 Highest
Version file version 0.9.8 Highest
Version pom version 0.9.8 Highest
hibernate-entitymanager-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-entitymanager/4.2.21.Final/hibernate-entitymanager-4.2.21.Final.jar
MD5: 2c1a3f1c7bb83b730ab3db1fe588904e
SHA1: a6675070b4c7bb843d74d6ab3bc9440fd315dbb3
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom groupid org.hibernate Highest
Vendor pom organization url http://hibernate.org Medium
Vendor pom organization name Hibernate.org High
Vendor central groupid org.hibernate Highest
Vendor file name hibernate-entitymanager High
Vendor manifest Bundle-Description Hibernate ORM JPA Entity Manager Medium
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom groupid hibernate Highest
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor pom url http://hibernate.org Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor Manifest bundle-symbolicname org.hibernate.entitymanager Medium
Vendor pom artifactid hibernate-entitymanager Low
Vendor pom name A Hibernate O/RM Module High
Product pom artifactid hibernate-entitymanager Highest
Product file name hibernate-entitymanager High
Product manifest Bundle-Description Hibernate ORM JPA Entity Manager Medium
Product Manifest implementation-url http://hibernate.org Low
Product pom groupid hibernate Low
Product pom description A module of the Hibernate O/RM project Medium
Product Manifest Bundle-Name hibernate-entitymanager Medium
Product pom url http://hibernate.org Medium
Product Manifest bundle-symbolicname org.hibernate.entitymanager Medium
Product pom organization url http://hibernate.org Low
Product pom organization name Hibernate.org Low
Product central artifactid hibernate-entitymanager Highest
Product pom name A Hibernate O/RM Module High
Version Manifest Implementation-Version 4.2.21.Final High
Version file version 4.2.21 Highest
Version pom version 4.2.21.Final Highest
Version central version 4.2.21.Final Highest
liquibase-core-3.4.2.jar
File Path: /home/ciagent/.m2/repository/org/liquibase/liquibase-core/3.4.2/liquibase-core-3.4.2.jar
MD5: d4ad6d5f7958b69b8fbd01a5564ae45b
SHA1: c91ccf342466857251cf6795b0cecc42509206f2
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Applications commons:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.liquibase Highest
Vendor pom name Liquibase Core High
Vendor pom artifactid liquibase-core Low
Vendor file name liquibase-core High
Vendor central groupid org.liquibase Highest
Vendor pom parent-groupid org.liquibase Medium
Vendor pom parent-artifactid liquibase-parent Low
Vendor jar package name liquibase Low
Vendor pom groupid liquibase Highest
Product pom parent-groupid org.liquibase Low
Product pom parent-artifactid liquibase-parent Medium
Product pom name Liquibase Core High
Product file name liquibase-core High
Product pom groupid liquibase Low
Product central artifactid liquibase-core Highest
Product pom artifactid liquibase-core Highest
Version file version 3.4.2 Highest
Version pom version 3.4.2 Highest
Version central version 3.4.2 Highest
twitter4j-core-3.0.5.jar
Description: A Java library for the Twitter API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/org/twitter4j/twitter4j-core/3.0.5/twitter4j-core-3.0.5.jar
MD5: e6c8d2b10c621b2bbd7809bad9cedca3
SHA1: c38ad47bc8ba5991886ce2c0e0acd76d0fdd6e6d
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.twitter4j Highest
Vendor pom groupid twitter4j Highest
Vendor Manifest Implementation-Vendor-Id org.twitter4j Medium
Vendor pom description A Java library for the Twitter API Medium
Vendor pom url http://twitter4j.org/ Highest
Vendor pom name twitter4j-core High
Vendor pom artifactid twitter4j-core Low
Vendor file name twitter4j-core High
Vendor central groupid org.twitter4j Highest
Product Manifest specification-title twitter4j-core Medium
Product pom artifactid twitter4j-core Highest
Product central artifactid twitter4j-core Highest
Product pom description A Java library for the Twitter API Medium
Product pom groupid twitter4j Low
Product pom name twitter4j-core High
Product pom url http://twitter4j.org/ Medium
Product file name twitter4j-core High
Product Manifest Implementation-Title twitter4j-core High
Version file version 3.0.5 Highest
Version Manifest Implementation-Version 3.0.5 High
Version central version 3.0.5 Highest
Version pom version 3.0.5 Highest
cpe: cpe:/a:twitter_project:twitter:3.0.5
Confidence :Low
suppress
maven: org.twitter4j:twitter4j-core:3.0.5 ✓
Confidence :Highest
cpe: cpe:/a:twitter:twitter:3.0.5
Confidence :Low
suppress
scribe-1.3.5.jar
Description: The best OAuth library out there
License:
MIT: http://github.com/fernandezpablo85/scribe-java/blob/master/LICENSE.txt
File Path: /home/ciagent/.m2/repository/org/scribe/scribe/1.3.5/scribe-1.3.5.jar
MD5: 0abb910da19741cd84aabf5520385bc2
SHA1: a3b3deded9d241d9f2c8aa9c9bcd90ad29e2581e
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.scribe Highest
Vendor pom name Scribe OAuth Library High
Vendor file name scribe High
Vendor jar package name scribe Low
Vendor pom description The best OAuth library out there Medium
Vendor pom url http://github.com/fernandezpablo85/scribe-java Highest
Vendor jar package name api Low
Vendor jar package name builder Low
Vendor central groupid org.scribe Highest
Vendor pom groupid scribe Highest
Vendor pom artifactid scribe Low
Product pom name Scribe OAuth Library High
Product file name scribe High
Product pom description The best OAuth library out there Medium
Product pom url http://github.com/fernandezpablo85/scribe-java Medium
Product jar package name api Low
Product pom artifactid scribe Highest
Product pom groupid scribe Low
Product central artifactid scribe Highest
Product jar package name builder Low
Version file version 1.3.5 Highest
Version central version 1.3.5 Highest
Version pom version 1.3.5 Highest
google-http-client-1.14.1-beta.jar
Description:
Google HTTP Client Library for Java. Functionality that works on all supported Java platforms,
including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine.
File Path: /home/ciagent/.m2/repository/com/google/http-client/google-http-client/1.14.1-beta/google-http-client-1.14.1-beta.jar
MD5: 8a3711522ebceef2531d455e2f04a639
SHA1: cb503d4021739e6bac39442ac87b4e311ec77b5e
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.http-client Highest
Vendor pom groupid google.http-client Highest
Vendor central groupid com.google.http-client Highest
Vendor pom parent-groupid com.google.http-client Medium
Vendor Manifest Implementation-Vendor Google High
Vendor Manifest Implementation-Vendor-Id com.google.http-client Medium
Vendor file name google-http-client High
Vendor pom parent-artifactid google-http-client-parent Low
Vendor pom artifactid google-http-client Low
Vendor pom name Google HTTP Client Library for Java High
Vendor pom description Google HTTP Client Library for Java. Functionality that works on all supported Java platforms, including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine. Low
Product pom artifactid google-http-client Highest
Product pom groupid google.http-client Low
Product pom parent-groupid com.google.http-client Low
Product Manifest Implementation-Title Google HTTP Client Library for Java High
Product pom parent-artifactid google-http-client-parent Medium
Product file name google-http-client High
Product pom name Google HTTP Client Library for Java High
Product pom description Google HTTP Client Library for Java. Functionality that works on all supported Java platforms, including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine. Low
Product central artifactid google-http-client Highest
Version central version 1.14.1-beta Highest
Version file version 1.14.1.beta Highest
Version pom version 1.14.1-beta Highest
Version Manifest Implementation-Version 1.14.1-beta High
Related Dependencies
google-oauth-client-1.14.1-beta.jar
File Path: /home/ciagent/.m2/repository/com/google/oauth-client/google-oauth-client/1.14.1-beta/google-oauth-client-1.14.1-beta.jar
SHA1: 7260cd30808a6d1d4ddef6250e3d92d814aaa4cb
MD5: 71feea1d54eb7878c12855b7c47ef289
maven: com.google.oauth-client:google-oauth-client:1.14.1-beta ✓
google-api-client-1.14.1-beta.jar
File Path: /home/ciagent/.m2/repository/com/google/api-client/google-api-client/1.14.1-beta/google-api-client-1.14.1-beta.jar
MD5: 6832804471d4d635ed74ae1fbd5d9d86
SHA1: e95d3b6e36fc67bffd7e71ef60bc5af623e73843
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor file name google-api-client High
Vendor pom artifactid google-api-client Low
Vendor pom groupid google.api-client Highest
Vendor pom name Google APIs Client Library for Java High
Vendor central groupid com.google.api-client Highest
Vendor Manifest Implementation-Vendor-Id com.google.api-client Medium
Vendor pom parent-artifactid google-api-client-parent Low
Vendor Manifest Implementation-Vendor Google High
Vendor pom parent-groupid com.google.api-client Medium
Vendor pom groupid com.google.api-client Highest
Product file name google-api-client High
Product pom groupid google.api-client Low
Product pom artifactid google-api-client Highest
Product pom name Google APIs Client Library for Java High
Product pom parent-groupid com.google.api-client Low
Product Manifest Implementation-Title Google APIs Client Library for Java High
Product pom parent-artifactid google-api-client-parent Medium
Product central artifactid google-api-client Highest
Version central version 1.14.1-beta Highest
Version file version 1.14.1.beta Highest
Version pom version 1.14.1-beta Highest
Version Manifest Implementation-Version 1.14.1-beta High
jackson-core-asl-1.9.11.jar
Description: Jackson is a high-performance JSON processor (parser, generator)
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/codehaus/jackson/jackson-core-asl/1.9.11/jackson-core-asl-1.9.11.jar
MD5: 49801a6d43725d5c3a1a52ca021d7dc5
SHA1: e32303ef8bd18a5c9272780d49b81c95e05ddf43
Referenced In Projects/Scopes:
eXo PLF:: Calendar Service:compile
eXo PLF:: Calendar Application:compile
eXo PLF:: Calendar Webservice:compile
eXo PLF:: Calendar Create:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.codehaus.jackson Highest
Vendor pom groupid codehaus.jackson Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low
Vendor pom artifactid jackson-core-asl Low
Vendor pom url http://jackson.codehaus.org Highest
Vendor pom name Jackson High
Vendor pom organization url http://fasterxml.com Medium
Vendor Manifest specification-vendor http://www.ietf.org/rfc/rfc4627.txt Low
Vendor Manifest Implementation-Vendor http://fasterxml.com High
Vendor file name jackson-core-asl High
Vendor Manifest bundle-symbolicname jackson-core-asl Medium
Vendor pom groupid org.codehaus.jackson Highest
Vendor pom organization name FasterXML High
Vendor pom description Jackson is a high-performance JSON processor (parser, generator)
Medium
Product Manifest specification-title JSON - JavaScript Object Notation Medium
Product pom organization name FasterXML Low
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low
Product pom url http://jackson.codehaus.org Medium
Product pom name Jackson High
Product central artifactid jackson-core-asl Highest
Product Manifest Implementation-Title Jackson JSON processor High
Product pom artifactid jackson-core-asl Highest
Product Manifest Bundle-Name Jackson JSON processor Medium
Product file name jackson-core-asl High
Product Manifest bundle-symbolicname jackson-core-asl Medium
Product pom organization url http://fasterxml.com Low
Product pom groupid codehaus.jackson Low
Product pom description Jackson is a high-performance JSON processor (parser, generator)
Medium
Version file version 1.9.11 Highest
Version central version 1.9.11 Highest
Version pom version 1.9.11 Highest