Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : Oct 13, 2019 at 08:10:32 +00:00
Dependencies Scanned : 204 (170 unique)
Vulnerable Dependencies : 27
Vulnerabilities Found : 67
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 10/10/2019 09:15:36
NVD CVE 2003 : 11/10/2019 08:45:55
NVD CVE 2004 : 08/10/2019 13:32:07
NVD CVE 2005 : 11/10/2019 08:45:55
NVD CVE 2006 : 11/10/2019 08:45:55
NVD CVE 2007 : 10/10/2019 09:15:36
NVD CVE 2008 : 11/10/2019 08:45:55
NVD CVE 2009 : 11/10/2019 08:45:55
NVD CVE 2010 : 12/10/2019 08:45:35
NVD CVE 2011 : 10/10/2019 08:45:44
NVD CVE 2012 : 10/10/2019 08:45:45
NVD CVE 2013 : 11/10/2019 08:45:56
NVD CVE 2014 : 10/10/2019 08:45:45
NVD CVE 2015 : 12/10/2019 08:45:35
NVD CVE 2016 : 12/10/2019 08:15:30
NVD CVE 2017 : 12/10/2019 08:15:30
NVD CVE 2018 : 12/10/2019 07:45:35
NVD CVE 2019 : 12/10/2019 07:45:35
NVD CVE Checked : 13/10/2019 07:53:12
NVD CVE Modified : 13/10/2019 05:15:31
VersionCheckOn : 1570953192127
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
portlet-api-2.0.jar
Description: The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group.
File Path: /home/ciagent/.m2/repository/javax/portlet/portlet-api/2.0/portlet-api-2.0.jar
MD5: 0ec08593cda1df33985391919996c740
SHA1: 1cd72f2a37fcf8ab9893a9468d7ba71c85fe2653
Referenced In Project/Scope:
eXo PLF:: Commons - API:provided
Evidence
Type Source Name Value Confidence
Vendor pom groupid javax.portlet Highest
Vendor pom name Java Portlet Specification V2.0 High
Vendor Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Vendor pom artifactid portlet-api Low
Vendor file name portlet-api High
Vendor Manifest bundle-symbolicname javax.portlet Medium
Vendor pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Vendor central groupid javax.portlet Highest
Vendor pom url http://www.jcp.org/en/jsr/detail?id=286 Highest
Product pom name Java Portlet Specification V2.0 High
Product Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Product central artifactid portlet-api Highest
Product pom artifactid portlet-api Highest
Product file name portlet-api High
Product Manifest bundle-symbolicname javax.portlet Medium
Product pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Product Manifest Bundle-Name JSR 286 Medium
Product pom groupid javax.portlet Low
Product pom url http://www.jcp.org/en/jsr/detail?id=286 Medium
Version pom version 2.0 Highest
Version file version 2.0 Highest
Version central version 2.0 Highest
javax.websocket-api-1.0.jar
Description: JSR 356: Java API for WebSocket
License:
https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /home/ciagent/.m2/repository/javax/websocket/javax.websocket-api/1.0/javax.websocket-api-1.0.jar
MD5: 510563ac69503be2d6cbb6d492a8027b
SHA1: fc843b649d4a1dcb0497669d262befa3918c7ba8
Referenced In Project/Scope:
eXo PLF:: Commons - API:provided
Evidence
Type Source Name Value Confidence
Vendor pom name WebSocket server API High
Vendor pom url http://websocket-spec.java.net Highest
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor pom description JSR 356: Java API for WebSocket Medium
Vendor Manifest extension-name javax.websocket Medium
Vendor central groupid javax.websocket Highest
Vendor pom groupid javax.websocket Highest
Vendor pom artifactid javax.websocket-api Low
Vendor Manifest bundle-symbolicname javax.websocket-api Medium
Vendor pom parent-artifactid javax.websocket-all Low
Vendor file name javax.websocket-api High
Vendor manifest Bundle-Description JSR 356: Java API for WebSocket Medium
Product pom name WebSocket server API High
Product pom parent-artifactid javax.websocket-all Medium
Product central artifactid javax.websocket-api Highest
Product pom artifactid javax.websocket-api Highest
Product pom url http://websocket-spec.java.net Medium
Product Manifest bundle-docurl http://www.oracle.com Low
Product pom description JSR 356: Java API for WebSocket Medium
Product Manifest extension-name javax.websocket Medium
Product Manifest Bundle-Name WebSocket server API Medium
Product Manifest bundle-symbolicname javax.websocket-api Medium
Product pom groupid javax.websocket Low
Product file name javax.websocket-api High
Product manifest Bundle-Description JSR 356: Java API for WebSocket Medium
Version central version 1.0 Highest
Version file version 1.0 Highest
Version pom version 1.0 Highest
Version Manifest Implementation-Version 1.0 High
commons-lang-2.6.jar
Description:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor file name commons-lang High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor central groupid commons-lang High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium
Vendor pom artifactid commons-lang Low
Vendor pom url http://commons.apache.org/lang/ Highest
Vendor central groupid org.netbeans.external High
Vendor pom groupid commons-lang Highest
Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low
Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor pom name Commons Lang High
Product file name commons-lang High
Product central artifactid org-apache-commons-lang High
Product Manifest specification-title Commons Lang Medium
Product Manifest Implementation-Title Commons Lang High
Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest Bundle-Name Commons Lang Medium
Product pom artifactid commons-lang Highest
Product central artifactid commons-lang High
Product Manifest bundle-symbolicname org.apache.commons.lang Medium
Product pom url http://commons.apache.org/lang/ Medium
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/lang/ Low
Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product pom groupid commons-lang Low
Product pom name Commons Lang High
Version Manifest Implementation-Version 2.6 High
Version file version 2.6 Highest
jcr-1.0.1.jar
Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.
License:
Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Day Software Management AG High
Vendor pom groupid javax.jcr Highest
Vendor pom organization url http://www.day.com/ Medium
Vendor Manifest specification-vendor Day Software Management AG Low
Vendor pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Vendor file name jcr High
Vendor pom url http://www.jcp.org/en/jsr/detail?id=170 Highest
Vendor pom artifactid jcr Low
Vendor pom name Content Repository for Java Technology API High
Vendor Manifest extension-name jcr Medium
Vendor pom organization name Day Software Management AG High
Product pom url http://www.jcp.org/en/jsr/detail?id=170 Medium
Product Manifest specification-title Content Repository for Java Technology API Medium
Product pom organization url http://www.day.com/ Low
Product pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Product pom artifactid jcr Highest
Product file name jcr High
Product pom groupid javax.jcr Low
Product Manifest Implementation-Title javax.jcr High
Product pom organization name Day Software Management AG Low
Product pom name Content Repository for Java Technology API High
Product Manifest extension-name jcr Medium
Version pom version 1.0.1 Highest
Version file version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
cpe: cpe:/a:content_project:content:1.0.1
Confidence :Low
suppress
maven: javax.jcr:jcr:1.0.1
Confidence :High
Published Vulnerabilities
CVE-2017-16111 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Vulnerable Software & Versions:
jtidy-r938.jar
Description:
JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be
used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the
document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML.
License:
Java HTML Tidy License: http://jtidy.svn.sourceforge.net/viewvc/jtidy/trunk/jtidy/LICENSE.txt?revision=95
File Path: /home/ciagent/.m2/repository/net/sf/jtidy/jtidy/r938/jtidy-r938.jar
MD5: 6a9121561b8f98c0a8fb9b6e57f50e6b
SHA1: ab08d87a225a715a69107732b67f21e1da930349
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom description JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML. Low
Vendor jar package name w3c Low
Vendor pom url http://jtidy.sourceforge.net Highest
Vendor central groupid net.sf.jtidy Highest
Vendor file name jtidy-r938 High
Vendor pom organization url http://sourceforge.net Medium
Vendor pom groupid net.sf.jtidy Highest
Vendor pom organization name sourceforge High
Vendor pom artifactid jtidy Low
Vendor pom name JTidy High
Vendor jar package name tidy Low
Product pom organization url http://sourceforge.net Low
Product pom description JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML. Low
Product central artifactid jtidy Highest
Product pom groupid net.sf.jtidy Low
Product pom url http://jtidy.sourceforge.net Medium
Product pom artifactid jtidy Highest
Product file name jtidy-r938 High
Product pom organization name sourceforge Low
Product pom name JTidy High
Product jar package name tidy Low
Version file name jtidy-r938 Medium
Version file version 938 Medium
Version pom version r938 Highest
Version central version r938 Highest
exo.core.component.xml-processing-6.0.x-SNAPSHOT.jar
Description: Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.xml-processing/6.0.x-SNAPSHOT/exo.core.component.xml-processing-6.0.x-SNAPSHOT.jar
MD5: b3b006595fbe303c9d739a79121f189e
SHA1: 1e6d90393499b0d884fe8c93a63074633f351f27
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.core.component.xml-processing High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom description Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor pom name eXo PLF Core :: Component :: XML Processing Service High
Vendor pom groupid org.exoplatform.core Highest
Vendor pom artifactid exo.core.component.xml-processing Low
Vendor pom parent-artifactid core-parent Low
Product pom artifactid exo.core.component.xml-processing Highest
Product file name exo.core.component.xml-processing High
Product Manifest specification-title exo-core Medium
Product pom description Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest Implementation-Title eXo PLF Core :: Component :: XML Processing Service High
Product pom parent-artifactid core-parent Medium
Product pom groupid exoplatform.core Low
Product pom parent-groupid org.exoplatform.core Low
Product pom name eXo PLF Core :: Component :: XML Processing Service High
Version pom version 6.0.x-20191006.143856-7 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.xml-processing:6.0.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:processing:processing:6.0.20191006
Confidence :Low
suppress
exo.core.component.script.groovy-6.0.x-SNAPSHOT.jar
Description: Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.script.groovy/6.0.x-SNAPSHOT/exo.core.component.script.groovy-6.0.x-SNAPSHOT.jar
MD5: 5c6d0169bbc28be47a74ccee4b9ddb74
SHA1: 0385aa69f19847a08969929d085c48850a498ff9
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom description Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project. Medium
Vendor file name exo.core.component.script.groovy High
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom artifactid exo.core.component.script.groovy Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor pom groupid org.exoplatform.core Highest
Vendor pom name eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Vendor pom parent-artifactid core-parent Low
Product pom artifactid exo.core.component.script.groovy Highest
Product Manifest specification-title exo-core Medium
Product pom description Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project. Medium
Product file name exo.core.component.script.groovy High
Product Manifest Implementation-Title eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Product pom parent-artifactid core-parent Medium
Product pom groupid exoplatform.core Low
Product pom parent-groupid org.exoplatform.core Low
Product pom name eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.script.groovy:6.0.x-SNAPSHOT
Confidence :High
jsr311-api-1.1.1.jar
License:
CDDL License
: http://www.opensource.org/licenses/cddl1.php
File Path: /home/ciagent/.m2/repository/javax/ws/rs/jsr311-api/1.1.1/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.sun.com/ Low
Vendor pom artifactid jsr311-api Low
Vendor Manifest extension-name javax.ws.rs Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom organization url http://www.sun.com/ Medium
Vendor file name jsr311-api High
Vendor pom url https://jsr311.dev.java.net Highest
Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Vendor pom name jsr311-api High
Vendor pom groupid javax.ws.rs Highest
Vendor pom organization name Sun Microsystems, Inc High
Vendor central groupid javax.ws.rs Highest
Product Manifest Bundle-Name jsr311-api Medium
Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium
Product pom artifactid jsr311-api Highest
Product Manifest bundle-docurl http://www.sun.com/ Low
Product Manifest extension-name javax.ws.rs Medium
Product pom url https://jsr311.dev.java.net Medium
Product file name jsr311-api High
Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Product pom name jsr311-api High
Product pom organization url http://www.sun.com/ Low
Product central artifactid jsr311-api Highest
Product pom groupid javax.ws.rs Low
Product pom organization name Sun Microsystems, Inc Low
Version central version 1.1.1 Highest
Version file version 1.1.1 Highest
Version pom version 1.1.1 Highest
commons-fileupload-1.3.3.jar
Description:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-fileupload/commons-fileupload/1.3.3/commons-fileupload-1.3.3.jar
MD5: dd77e787b7b5dc56f6a1cb658716d55d
SHA1: 04ff14d809195b711fd6bcc87e6777f886730ca1
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid commons-fileupload Highest
Vendor manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor pom name Apache Commons FileUpload High
Vendor Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid commons-fileupload Highest
Vendor Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Vendor pom parent-artifactid commons-parent Low
Vendor file name commons-fileupload High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest
Vendor pom artifactid commons-fileupload Low
Product pom artifactid commons-fileupload Highest
Product Manifest specification-title Apache Commons FileUpload Medium
Product manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom name Apache Commons FileUpload High
Product Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Product Manifest Implementation-Title Apache Commons FileUpload High
Product Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Product file name commons-fileupload High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Product pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom groupid commons-fileupload Low
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium
Product central artifactid commons-fileupload Highest
Product Manifest Bundle-Name Apache Commons FileUpload Medium
Version Manifest Implementation-Version 1.3.3 High
Version central version 1.3.3 Highest
Version file version 1.3.3 Highest
Version pom version 1.3.3 Highest
exo.ws.rest.core-6.0.x-SNAPSHOT.jar
Description: Implementation of REST Core for Exoplatform SAS 'Web Services' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.core/6.0.x-SNAPSHOT/exo.ws.rest.core-6.0.x-SNAPSHOT.jar
MD5: 2e5bcea622faca44fa175918d5cc256b
SHA1: 486f797c093590f2fc415145bfddaa43fd5db6bf
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.ws Medium
Vendor pom parent-groupid org.exoplatform.ws Medium
Vendor pom artifactid exo.ws.rest.core Low
Vendor pom groupid exoplatform.ws Highest
Vendor pom name eXo PLF:: WS :: REST :: Core High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid ws-parent Low
Vendor pom groupid org.exoplatform.ws Highest
Vendor file name exo.ws.rest.core High
Vendor pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Product pom groupid exoplatform.ws Low
Product pom parent-artifactid ws-parent Medium
Product Manifest specification-title exo-ws Medium
Product pom name eXo PLF:: WS :: REST :: Core High
Product pom artifactid exo.ws.rest.core Highest
Product file name exo.ws.rest.core High
Product Manifest Implementation-Title eXo PLF:: WS :: REST :: Core High
Product pom parent-groupid org.exoplatform.ws Low
Product pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Version pom version 6.0.x-20191006.150752-8 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
Related Dependencies
exo.ws.frameworks.json-6.0.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.frameworks.json/6.0.x-SNAPSHOT/exo.ws.frameworks.json-6.0.x-SNAPSHOT.jar
SHA1: f913e841d6cfe481e1c84a6e06bf6123c3b1340d
MD5: 346a577c1e9d5c14a5f9f1519dbf6aa1
exo.ws.commons-6.0.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.commons/6.0.x-SNAPSHOT/exo.ws.commons-6.0.x-SNAPSHOT.jar
SHA1: abc7cac84f235b75f1df0aeaca136259aa27b099
MD5: a452c3d0a0e39fafbc3fde51e49f16fa
exo.ws.rest.ext-6.0.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.ext/6.0.x-SNAPSHOT/exo.ws.rest.ext-6.0.x-SNAPSHOT.jar
SHA1: 92225310ca34078ddd248be19b0588a015e099f0
MD5: 2398fb4beeecf30c45522184b5ca02f0
cpe: cpe:/a:ws_project:ws:6.0.20191006
Confidence :Low
suppress
maven: org.exoplatform.ws:exo.ws.rest.core:6.0.x-SNAPSHOT
Confidence :High
jsr250-api-1.0.jar
Description: JSR-250 Reference Implementation by Glassfish
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/annotation/jsr250-api/1.0/jsr250-api-1.0.jar
MD5: 4cd56b2e4977e541186de69f5126b4a6
SHA1: 5025422767732a1ab45d93abfea846513d742dcf
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor file name jsr250-api High
Vendor pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Highest
Vendor pom artifactid jsr250-api Low
Vendor pom name JSR-250 Common Annotations for the JavaTM Platform High
Vendor central groupid javax.annotation Highest
Vendor pom groupid javax.annotation Highest
Vendor jar package name javax Low
Vendor pom description JSR-250 Reference Implementation by Glassfish Medium
Vendor jar package name annotation Low
Product pom artifactid jsr250-api Highest
Product file name jsr250-api High
Product pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Medium
Product pom name JSR-250 Common Annotations for the JavaTM Platform High
Product pom groupid javax.annotation Low
Product central artifactid jsr250-api Highest
Product pom description JSR-250 Reference Implementation by Glassfish Medium
Product jar package name annotation Low
Version central version 1.0 Highest
Version file version 1.0 Highest
Version pom version 1.0 Highest
exo.jcr.component.ext-6.0.x-SNAPSHOT.jar
Description: Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/jcr/exo.jcr.component.ext/6.0.x-SNAPSHOT/exo.jcr.component.ext-6.0.x-SNAPSHOT.jar
MD5: d7555e7a04b45fcef490c3658f111ec9
SHA1: 2d17b07d4fc4f5f655b07a2103fdb18796674ebb
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom name eXo PLF:: JCR :: Component :: Extension Service High
Vendor file name exo.jcr.component.ext High
Vendor pom parent-groupid org.exoplatform.jcr Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom artifactid exo.jcr.component.ext Low
Vendor pom parent-artifactid jcr-parent Low
Vendor pom groupid exoplatform.jcr Highest
Vendor pom description Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project. Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.jcr Medium
Vendor pom groupid org.exoplatform.jcr Highest
Product pom parent-artifactid jcr-parent Medium
Product Manifest specification-title exo-jcr Medium
Product pom name eXo PLF:: JCR :: Component :: Extension Service High
Product pom artifactid exo.jcr.component.ext Highest
Product file name exo.jcr.component.ext High
Product pom groupid exoplatform.jcr Low
Product Manifest Implementation-Title eXo PLF:: JCR :: Component :: Extension Service High
Product pom description Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project. Medium
Product pom parent-groupid org.exoplatform.jcr Low
Version pom version 6.0.x-20191006.160139-8 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.jcr:exo.jcr.component.ext:6.0.x-SNAPSHOT
Confidence :High
mime-util-2.1.3.jar
Description: mime-util is a simple to use, small, light weight and fast open source java utility library that can detect
MIME types from files, input streams, URL's and byte arrays.
Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/eu/medsea/mimeutil/mime-util/2.1.3/mime-util-2.1.3.jar
MD5: 3d4f3e1a96eb79683197f1c8b182f4a6
SHA1: 0c9cfae15c74f62491d4f28def0dff1dabe52a47
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization url http://www.medsea.eu Medium
Vendor Manifest url http://www.medsea.eu/mime-util/ Low
Vendor pom name Mime Detection Utility High
Vendor manifest Bundle-Description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Vendor pom artifactid mime-util Low
Vendor pom organization name Medsea Business Solutions S.L. High
Vendor pom description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Vendor central groupid eu.medsea.mimeutil Highest
Vendor pom url http://www.medsea.eu/mime-util/ Highest
Vendor Manifest bundle-symbolicname eu.medsea.mimeutil.mime-util Medium
Vendor pom groupid eu.medsea.mimeutil Highest
Vendor Manifest bundle-docurl http://www.medsea.eu Low
Vendor file name mime-util High
Product Manifest url http://www.medsea.eu/mime-util/ Low
Product pom name Mime Detection Utility High
Product Manifest Bundle-Name Mime Detection Utility Medium
Product manifest Bundle-Description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Product pom organization name Medsea Business Solutions S.L. Low
Product pom artifactid mime-util Highest
Product pom groupid eu.medsea.mimeutil Low
Product pom description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Product central artifactid mime-util Highest
Product Manifest bundle-symbolicname eu.medsea.mimeutil.mime-util Medium
Product pom organization url http://www.medsea.eu Low
Product Manifest bundle-docurl http://www.medsea.eu Low
Product pom url http://www.medsea.eu/mime-util/ Medium
Product file name mime-util High
Version pom version 2.1.3 Highest
Version central version 2.1.3 Highest
Version file version 2.1.3 Highest
jakarta-regexp-1.4.jar
File Path: /home/ciagent/.m2/repository/jakarta-regexp/jakarta-regexp/1.4/jakarta-regexp-1.4.jar
MD5: 5d8b8c601c21b37aa6142d38f45c0297
SHA1: 0ea514a179ac1dd7e81c7e6594468b9b9910d298
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name regexp Low
Vendor file name jakarta-regexp High
Vendor pom artifactid jakarta-regexp Low
Vendor central groupid jakarta-regexp Highest
Vendor jar package name apache Low
Vendor pom groupid jakarta-regexp Highest
Product jar package name regexp Low
Product file name jakarta-regexp High
Product pom artifactid jakarta-regexp Highest
Product pom groupid jakarta-regexp Low
Product central artifactid jakarta-regexp Highest
Version central version 1.4 Highest
Version file version 1.4 Highest
Version pom version 1.4 Highest
xpp3-1.1.6.jar
Description: XML Pull parser library developed by Extreme Computing Lab, Indiana University
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/ogce/xpp3/1.1.6/xpp3-1.1.6.jar
MD5: 626a429318310e92e3466151e050bdc5
SHA1: dc87e00ddb69341b46a3eb1c331c6fcebf6c8546
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor file name xpp3 High
Vendor jar package name v1 Low
Vendor pom url http://www.extreme.indiana.edu/xpp/ Highest
Vendor pom artifactid xpp3 Low
Vendor pom name XPP3 High
Vendor pom groupid ogce Highest
Vendor central groupid org.ogce Highest
Vendor jar package name xmlpull Low
Vendor jar package name builder Low
Vendor pom groupid org.ogce Highest
Vendor pom description XML Pull parser library developed by Extreme Computing Lab, Indiana University Medium
Product file name xpp3 High
Product pom artifactid xpp3 Highest
Product jar package name v1 Low
Product pom name XPP3 High
Product jar package name xpath Low
Product central artifactid xpp3 Highest
Product pom url http://www.extreme.indiana.edu/xpp/ Medium
Product pom groupid ogce Low
Product jar package name builder Low
Product pom description XML Pull parser library developed by Extreme Computing Lab, Indiana University Medium
Version file version 1.1.6 Highest
Version central version 1.1.6 Highest
Version pom version 1.1.6 Highest
jcl-over-slf4j-1.7.18.jar
Description: JCL 1.1.1 implemented over SLF4J
File Path: /home/ciagent/.m2/repository/org/slf4j/jcl-over-slf4j/1.7.18/jcl-over-slf4j-1.7.18.jar
MD5: 86c8f80da62e4640564effb9dff7e003
SHA1: eca71be00af2579564e9f3a23ce0b245ca79ee5d
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JCL 1.1.1 implemented over SLF4J High
Vendor pom url http://www.slf4j.org Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom parent-groupid org.slf4j Medium
Vendor manifest Bundle-Description JCL 1.1.1 implemented over SLF4J Medium
Vendor central groupid org.slf4j Highest
Vendor pom artifactid jcl-over-slf4j Low
Vendor file name jcl-over-slf4j High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom groupid org.slf4j Highest
Vendor pom groupid slf4j Highest
Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium
Vendor pom description JCL 1.1.1 implemented over SLF4J Medium
Product pom name JCL 1.1.1 implemented over SLF4J High
Product Manifest Implementation-Title jcl-over-slf4j High
Product pom parent-groupid org.slf4j Low
Product Manifest Bundle-Name jcl-over-slf4j Medium
Product pom artifactid jcl-over-slf4j Highest
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product manifest Bundle-Description JCL 1.1.1 implemented over SLF4J Medium
Product pom url http://www.slf4j.org Medium
Product central artifactid jcl-over-slf4j Highest
Product file name jcl-over-slf4j High
Product pom groupid slf4j Low
Product Manifest bundle-symbolicname jcl.over.slf4j Medium
Product pom parent-artifactid slf4j-parent Medium
Product pom description JCL 1.1.1 implemented over SLF4J Medium
Version pom version 1.7.18 Highest
Version central version 1.7.18 Highest
Version file version 1.7.18 Highest
Version Manifest Implementation-Version 1.7.18 High
exo.kernel.commons-6.0.x-SNAPSHOT.jar
Description: Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.commons/6.0.x-SNAPSHOT/exo.kernel.commons-6.0.x-SNAPSHOT.jar
MD5: 5c3577b09853d32650dda0412414cb4f
SHA1: 54663dc1cf7b231bc574a3388a1f817875dec4e0
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom description Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor file name exo.kernel.commons High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF:: Kernel :: Commons Utils High
Vendor pom artifactid exo.kernel.commons Low
Vendor pom parent-artifactid kernel-parent Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom groupid exoplatform.kernel Highest
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product pom description Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project. Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Commons Utils High
Product pom artifactid exo.kernel.commons Highest
Product file name exo.kernel.commons High
Product Manifest specification-title exo-kernel Medium
Product pom name eXo PLF:: Kernel :: Commons Utils High
Product pom parent-groupid org.exoplatform.kernel Low
Version pom version 6.0.x-20191006.134932-7 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.commons:6.0.x-SNAPSHOT
Confidence :High
javax.servlet-api-3.0.1.jar
Description: Java.net - The Source for Java Technology Collaboration
License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/ciagent/.m2/repository/javax/servlet/javax.servlet-api/3.0.1/javax.servlet-api-3.0.1.jar
MD5: 3ef236ac4c24850cd54abff60be25f35
SHA1: 6bf0ebb7efd993e222fc1112377b5e92a13b38dd
Referenced In Project/Scope:
eXo PLF:: Commons - API:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium
Vendor pom parent-groupid net.java Medium
Vendor pom organization name GlassFish Community High
Vendor pom artifactid javax.servlet-api Low
Vendor pom url http://servlet-spec.java.net Highest
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest bundle-symbolicname javax.servlet-api Medium
Vendor Manifest specification-vendor Oracle Low
Vendor pom organization url https://glassfish.dev.java.net Medium
Vendor pom groupid javax.servlet Highest
Vendor central groupid javax.servlet Highest
Vendor Manifest (hint) specification-vendor sun Low
Vendor Manifest extension-name javax.servlet Medium
Vendor pom name Java Servlet API High
Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low
Vendor file name javax.servlet-api High
Vendor pom parent-artifactid jvnet-parent Low
Product Manifest Bundle-Name Java Servlet API Medium
Product manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium
Product Manifest specification-title Java(TM) Servlet API Design Specification Medium
Product pom artifactid javax.servlet-api Highest
Product Manifest bundle-symbolicname javax.servlet-api Medium
Product pom groupid javax.servlet Low
Product central artifactid javax.servlet-api Highest
Product pom organization name GlassFish Community Low
Product pom url http://servlet-spec.java.net Medium
Product Manifest extension-name javax.servlet Medium
Product pom parent-artifactid jvnet-parent Medium
Product pom name Java Servlet API High
Product pom organization url https://glassfish.dev.java.net Low
Product pom parent-groupid net.java Low
Product Manifest bundle-docurl https://glassfish.dev.java.net Low
Product file name javax.servlet-api High
Version central version 3.0.1 Highest
Version file version 3.0.1 Highest
Version pom version 3.0.1 Highest
Version Manifest Implementation-Version 3.0.1 High
commons-beanutils-1.8.3.jar
Description: BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-beanutils/commons-beanutils/1.8.3/commons-beanutils-1.8.3.jar
MD5: b45be74134796c89db7126083129532f
SHA1: 686ef3410bcf4ab8ce7fd0b899e832aaba5facf7
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest bundle-docurl http://commons.apache.org/beanutils/ Low
Vendor pom name Commons BeanUtils High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-symbolicname org.apache.commons.beanutils Medium
Vendor central groupid commons-beanutils Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-beanutils Highest
Vendor pom artifactid commons-beanutils Low
Vendor file name commons-beanutils High
Vendor pom url http://commons.apache.org/beanutils/ Highest
Vendor manifest Bundle-Description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Product Manifest Implementation-Title Commons BeanUtils High
Product Manifest bundle-docurl http://commons.apache.org/beanutils/ Low
Product pom url http://commons.apache.org/beanutils/ Medium
Product central artifactid commons-beanutils Highest
Product Manifest Bundle-Name Commons BeanUtils Medium
Product pom name Commons BeanUtils High
Product pom artifactid commons-beanutils Highest
Product Manifest specification-title Commons BeanUtils Medium
Product pom groupid commons-beanutils Low
Product Manifest bundle-symbolicname org.apache.commons.beanutils Medium
Product pom description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product file name commons-beanutils High
Product manifest Bundle-Description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Version central version 1.8.3 Highest
Version file version 1.8.3 Highest
Version Manifest Implementation-Version 1.8.3 High
Version pom version 1.8.3 Highest
Published Vulnerabilities
CVE-2014-0114 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
Vulnerable Software & Versions: (show all )
CVE-2019-10086 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
Vulnerable Software & Versions:
common-common-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-common/2.2.2.Final/common-common-2.2.2.Final.jar
MD5: 8ce16b5e3991285cd27e553740d09d1f
SHA1: 44522d899e31a5a10dbd70f7b0ca2fe5a614f740
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid gatein.common Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Vendor pom parent-groupid org.gatein.common Medium
Vendor pom artifactid common-common Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Vendor pom groupid org.gatein.common Highest
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom name GateIn - Common component (common) High
Vendor Manifest os-name Linux Medium
Vendor central groupid org.gatein.common Highest
Vendor pom parent-artifactid common-parent Low
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Vendor file name common-common High
Product central artifactid common-common Highest
Product Manifest Implementation-Title GateIn - Common component (common) High
Product pom groupid gatein.common Low
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product Manifest specification-title GateIn - Common component (common) Medium
Product Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Product pom artifactid common-common Highest
Product pom parent-artifactid common-parent Medium
Product pom name GateIn - Common component (common) High
Product Manifest os-name Linux Medium
Product file name common-common High
Product pom parent-groupid org.gatein.common Low
Version central version 2.2.2.Final Highest
Version pom version 2.2.2.Final Highest
Version Manifest Implementation-Version 2.2.2.Final High
Version file version 2.2.2 Highest
wci-wci-6.0.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/wci/wci-wci/6.0.x-SNAPSHOT/wci-wci-6.0.x-SNAPSHOT.jar
MD5: 07e6bc22ee34629793d7f236bc178790
SHA1: ba1b3c6ef37118a93dd9c81a92029cc0c9aea0a9
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom name GateIn - Web Container Integration component (wci) High
Vendor file name wci-wci High
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom groupid org.exoplatform.gatein.wci Highest
Vendor Manifest implementation-url www.gatein.org/wci-parent/wci-wci/ Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom parent-artifactid wci-parent Low
Vendor Manifest build-timestamp Sun, 6 Oct 2019 12:45:07 +0000 Low
Vendor Manifest os-name Linux Medium
Vendor pom parent-groupid org.exoplatform.gatein.wci Medium
Vendor pom artifactid wci-wci Low
Vendor pom groupid exoplatform.gatein.wci Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.wci Medium
Product Manifest specification-title GateIn - Web Container Integration component (wci) Medium
Product Manifest build-timestamp Sun, 6 Oct 2019 12:45:07 +0000 Low
Product Manifest os-name Linux Medium
Product pom name GateIn - Web Container Integration component (wci) High
Product pom artifactid wci-wci Highest
Product file name wci-wci High
Product pom groupid exoplatform.gatein.wci Low
Product pom parent-artifactid wci-parent Medium
Product Manifest Implementation-Title GateIn - Web Container Integration component (wci) High
Product Manifest implementation-url www.gatein.org/wci-parent/wci-wci/ Low
Product pom parent-groupid org.exoplatform.gatein.wci Low
Version pom version 6.0.x-20191006.124516-5 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.gatein.wci:wci-wci:6.0.x-SNAPSHOT
Confidence :High
jibx-run-1.2.6.jar
Description: JiBX runtime code
License:
http://jibx.sourceforge.net/jibx-license.html
File Path: /home/ciagent/.m2/repository/org/jibx/jibx-run/1.2.6/jibx-run-1.2.6.jar
MD5: 4ef53e4279c8440aff2d16c0af024231
SHA1: 544f3ac7887d7eed20ca0420ee1963df6c7ecebb
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.jibx.org Low
Vendor pom parent-artifactid main-reactor Low
Vendor manifest Bundle-Description JiBX runtime code Medium
Vendor pom groupid org.jibx Highest
Vendor pom artifactid jibx-run Low
Vendor Manifest bundle-symbolicname jibx-run Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom parent-groupid org.jibx.config Medium
Vendor central groupid org.jibx Highest
Vendor pom groupid jibx Highest
Vendor pom name jibx-run - JiBX runtime High
Vendor pom description JiBX runtime code Medium
Vendor file name jibx-run High
Product Manifest bundle-docurl http://www.jibx.org Low
Product central artifactid jibx-run Highest
Product manifest Bundle-Description JiBX runtime code Medium
Product pom parent-artifactid main-reactor Medium
Product pom artifactid jibx-run Highest
Product Manifest bundle-symbolicname jibx-run Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom groupid jibx Low
Product pom name jibx-run - JiBX runtime High
Product pom description JiBX runtime code Medium
Product file name jibx-run High
Product Manifest Bundle-Name jibx-run - JiBX runtime Medium
Product pom parent-groupid org.jibx.config Low
Version file version 1.2.6 Highest
Version central version 1.2.6 Highest
Version pom version 1.2.6 Highest
javax.inject-1.jar
Description: The javax.inject API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor file name javax.inject-1 High
Vendor pom url http://code.google.com/p/atinject/ Highest
Vendor jar package name inject Low
Vendor central groupid javax.inject Highest
Vendor pom groupid javax.inject Highest
Vendor pom name javax.inject High
Vendor pom artifactid javax.inject Low
Vendor jar package name javax Low
Vendor pom description The javax.inject API Medium
Product file name javax.inject-1 High
Product pom groupid javax.inject Low
Product pom artifactid javax.inject Highest
Product pom url http://code.google.com/p/atinject/ Medium
Product jar package name inject Low
Product pom name javax.inject High
Product central artifactid javax.inject Highest
Product pom description The javax.inject API Medium
Version file version 1 Medium
Version central version 1 Highest
Version pom version 1 Highest
cdi-api-1.0-SP4.jar
Description: APIs for JSR-299: Contexts and Dependency Injection for Java EE
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/javax/enterprise/cdi-api/1.0-SP4/cdi-api-1.0-SP4.jar
MD5: 6c1e2b4036d64b6ba1a1136a00c7cdaa
SHA1: 6e38490033eb8b36c4cf1f7605163424a574dcf0
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid cdi-api Low
Vendor pom name CDI APIs High
Vendor pom groupid javax.enterprise Highest
Vendor Manifest Implementation-Vendor Seam Framework High
Vendor pom organization name Seam Framework High
Vendor file name cdi-api High
Vendor Manifest specification-vendor Seam Framework Low
Vendor pom description APIs for JSR-299: Contexts and Dependency Injection for Java EE Medium
Vendor pom parent-artifactid weld-parent Low
Vendor pom url http://www.seamframework.org/Weld Highest
Vendor pom parent-groupid org.jboss.weld Medium
Vendor pom organization url http://seamframework.org Medium
Vendor central groupid javax.enterprise Highest
Vendor Manifest implementation-url http://www.seamframework.org/Weld Low
Product pom parent-groupid org.jboss.weld Low
Product pom artifactid cdi-api Highest
Product pom organization url http://seamframework.org Low
Product central artifactid cdi-api Highest
Product Manifest specification-title CDI APIs Medium
Product pom url http://www.seamframework.org/Weld Medium
Product pom name CDI APIs High
Product pom organization name Seam Framework Low
Product pom parent-artifactid weld-parent Medium
Product Manifest Implementation-Title CDI APIs High
Product file name cdi-api High
Product pom description APIs for JSR-299: Contexts and Dependency Injection for Java EE Medium
Product pom groupid javax.enterprise Low
Product Manifest implementation-url http://www.seamframework.org/Weld Low
Version pom version 1.0-SP4 Highest
Version file version 1.0.sp4 Highest
Version central version 1.0-SP4 Highest
exo.kernel.container-6.0.x-SNAPSHOT.jar
Description: Implementation of Container for Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.container/6.0.x-SNAPSHOT/exo.kernel.container-6.0.x-SNAPSHOT.jar
MD5: 5ccfd8aac148ce1e486a3b2e11e44a0c
SHA1: 6c40e6b14e5a8acc22c1626be5b236bd61359eb2
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom name eXo PLF:: Kernel :: Container High
Vendor pom groupid org.exoplatform.kernel Highest
Vendor file name exo.kernel.container High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom description Implementation of Container for Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid kernel-parent Low
Vendor pom artifactid exo.kernel.container Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom groupid exoplatform.kernel Highest
Product pom groupid exoplatform.kernel Low
Product pom name eXo PLF:: Kernel :: Container High
Product file name exo.kernel.container High
Product pom parent-artifactid kernel-parent Medium
Product pom description Implementation of Container for Exoplatform SAS 'eXo Kernel' project. Medium
Product pom artifactid exo.kernel.container Highest
Product Manifest Implementation-Title eXo PLF:: Kernel :: Container High
Product Manifest specification-title exo-kernel Medium
Product pom parent-groupid org.exoplatform.kernel Low
Version pom version 6.0.x-20191006.135022-6 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.container:6.0.x-SNAPSHOT
Confidence :High
log4j-1.2.17.jar
Description: Apache Log4j 1.2
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/log4j/log4j/1.2.17/log4j-1.2.17.jar
MD5: 04a41f0a068986f0f73485cf507c0f40
SHA1: 5af35056b4d257e4b64b9e8069c0746e8b08629f
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid log4j Highest
Vendor pom organization name Apache Software Foundation High
Vendor central groupid log4j High
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor pom artifactid log4j Low
Vendor pom description Apache Log4j 1.2 Medium
Vendor pom url http://logging.apache.org/log4j/1.2/ Highest
Vendor Manifest bundle-symbolicname log4j Medium
Vendor Manifest bundle-docurl http://logging.apache.org/log4j/1.2 Low
Vendor pom organization url http://www.apache.org Medium
Vendor file name log4j High
Vendor manifest Bundle-Description Apache Log4j 1.2 Medium
Vendor manifest: org.apache.log4j Implementation-Vendor "Apache Software Foundation" Medium
Vendor pom name Apache Log4j High
Product Manifest Bundle-Name Apache Log4j Medium
Product pom url http://logging.apache.org/log4j/1.2/ Medium
Product central artifactid log4j-1.2.17 High
Product pom description Apache Log4j 1.2 Medium
Product Manifest bundle-symbolicname log4j Medium
Product pom organization url http://www.apache.org Low
Product Manifest bundle-docurl http://logging.apache.org/log4j/1.2 Low
Product pom artifactid log4j Highest
Product pom groupid log4j Low
Product manifest: org.apache.log4j Implementation-Title log4j Medium
Product central artifactid log4j High
Product file name log4j High
Product manifest Bundle-Description Apache Log4j 1.2 Medium
Product pom organization name Apache Software Foundation Low
Product pom name Apache Log4j High
Version central version 1.2.17 High
Version central version 2.0 High
Version pom version 1.2.17 Highest
Version file version 1.2.17 Highest
Published Vulnerabilities
CVE-2017-5645 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Vulnerable Software & Versions: (show all )
stax-api-1.0-2.jar
Description:
StAX is a standard XML processing API that allows you to stream XML data from and to your application.
License:
GNU General Public Library: http://www.gnu.org/licenses/gpl.txt
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: http://www.sun.com/cddl/cddl.html
File Path: /home/ciagent/.m2/repository/javax/xml/stream/stax-api/1.0-2/stax-api-1.0-2.jar
MD5: 7d18b63063580284c3f5734081fdc99f
SHA1: d6337b0de8b25e53e81b922352fbea9f9f57ba0b
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name stream Low
Vendor pom artifactid stax-api Low
Vendor pom description StAX is a standard XML processing API that allows you to stream XML data from and to your application. Low
Vendor file name stax-api High
Vendor jar package name xml Low
Vendor central groupid javax.xml.stream Highest
Vendor jar package name javax Low
Vendor pom groupid javax.xml.stream Highest
Vendor pom name Streaming API for XML High
Product jar package name stream Low
Product pom description StAX is a standard XML processing API that allows you to stream XML data from and to your application. Low
Product pom groupid javax.xml.stream Low
Product pom artifactid stax-api Highest
Product file name stax-api High
Product jar package name xml Low
Product central artifactid stax-api Highest
Product pom name Streaming API for XML High
Version file version 1.0.2 Highest
Version central version 1.0-2 Highest
Version pom version 1.0-2 Highest
activation-1.1.1.jar
Description: The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/activation/activation/1.1.1/activation-1.1.1.jar
MD5: 46a37512971d8eca81c3fcf245bf07d2
SHA1: 485de3a253e23f645037828c07f1d7f1af40763a
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest extension-name javax.activation Medium
Vendor pom name JavaBeans(TM) Activation Framework High
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor pom description The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data Medium
Vendor pom groupid javax.activation Highest
Vendor pom artifactid activation Low
Vendor file name activation High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Highest
Vendor central groupid javax.activation Highest
Product Manifest extension-name javax.activation Medium
Product pom name JavaBeans(TM) Activation Framework High
Product pom artifactid activation Highest
Product pom description The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data Medium
Product file name activation High
Product pom groupid javax.activation Low
Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium
Product pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Medium
Product central artifactid activation Highest
Version central version 1.1.1 Highest
Version file version 1.1.1 Highest
Version pom version 1.1.1 Highest
Version Manifest Implementation-Version 1.1.1 High
jaxb-api-2.1.jar
File Path: /home/ciagent/.m2/repository/javax/xml/bind/jaxb-api/2.1/jaxb-api-2.1.jar
MD5: 9534ce6506dc96bac3944423d804be30
SHA1: d68570e722cffe2000358ce9c661a0b0bf1ebe11
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid javax.xml.bind Highest
Vendor Manifest extension-name javax.xml.bind Medium
Vendor pom artifactid jaxb-api Low
Vendor file name jaxb-api High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor central groupid javax.xml.bind Highest
Product Manifest extension-name javax.xml.bind Medium
Product file name jaxb-api High
Product Manifest specification-title Java Architecture for XML Binding Medium
Product central artifactid jaxb-api Highest
Product pom artifactid jaxb-api Highest
Product pom groupid javax.xml.bind Low
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version central version 2.1 Highest
jaxb-impl-2.1.8.jar
File Path: /home/ciagent/.m2/repository/com/sun/xml/bind/jaxb-impl/2.1.8/jaxb-impl-2.1.8.jar
MD5: 1340264c75ea00b3d4d83e1ba57b606a
SHA1: 41b915446cb6962f9b403d1a5da3817a95ee579e
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.sun.xml.bind Highest
Vendor pom groupid sun.xml.bind Highest
Vendor Manifest extension-name com.sun.xml.bind Medium
Vendor pom artifactid jaxb-impl Low
Vendor central groupid com.sun.xml.bind Highest
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor file name jaxb-impl High
Product pom groupid sun.xml.bind Low
Product pom artifactid jaxb-impl Highest
Product Manifest extension-name com.sun.xml.bind Medium
Product Manifest specification-title Java Architecture for XML Binding Medium
Product central artifactid jaxb-impl Highest
Product Manifest Implementation-Title JAXB Reference Implementation High
Product file name jaxb-impl High
Version pom version 2.1.8 Highest
Version Manifest Implementation-Version 2.1.8 High
Version central version 2.1.8 Highest
Version file version 2.1.8 Highest
picketlink-idm-core-1.4.6.Final.jar
Description: PicketLink IDM IMPL contains the implementation of the API and the Identity Model.
License:
lgpl: http://repository.jboss.com/licenses/lgpl.txt
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-core/1.4.6.Final/picketlink-idm-core-1.4.6.Final.jar
MD5: a5c21c2186c186bc296d9909bcb11616
SHA1: 30d4385012393e4c50a82f8b84153eb6ee301a7d
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom name PicketLink IDM Implementation High
Vendor pom organization url http://www.jboss.org Medium
Vendor Manifest java-vendor Sun Microsystems Inc. Medium
Vendor pom parent-groupid org.picketlink.idm Medium
Vendor file name picketlink-idm-core High
Vendor pom description PicketLink IDM IMPL contains the implementation of the API and the Identity Model. Medium
Vendor Manifest Implementation-Vendor-Id org.picketlink.idm Medium
Vendor pom parent-artifactid picketlink-idm-parent Low
Vendor Manifest specification-vendor JBoss Inc. Low
Vendor Manifest Implementation-Vendor JBoss Inc. High
Vendor Manifest os-name Linux Medium
Vendor Manifest build-timestamp Fri, 27 Feb 2015 09:44:09 +0100 Low
Vendor central groupid org.picketlink.idm Highest
Vendor Manifest implementation-url http://www.jboss.org/picketlink-idm-parent/picketlink-idm-core Low
Vendor pom groupid picketlink.idm Highest
Vendor pom artifactid picketlink-idm-core Low
Vendor pom groupid org.picketlink.idm Highest
Vendor pom organization name JBoss Inc. High
Product pom name PicketLink IDM Implementation High
Product pom organization url http://www.jboss.org Low
Product Manifest Implementation-Title PicketLink IDM Implementation High
Product file name picketlink-idm-core High
Product pom description PicketLink IDM IMPL contains the implementation of the API and the Identity Model. Medium
Product pom parent-groupid org.picketlink.idm Low
Product pom parent-artifactid picketlink-idm-parent Medium
Product Manifest os-name Linux Medium
Product Manifest build-timestamp Fri, 27 Feb 2015 09:44:09 +0100 Low
Product pom artifactid picketlink-idm-core Highest
Product Manifest implementation-url http://www.jboss.org/picketlink-idm-parent/picketlink-idm-core Low
Product pom organization name JBoss Inc. Low
Product central artifactid picketlink-idm-core Highest
Product Manifest specification-title PicketLink IDM Implementation Medium
Product pom groupid picketlink.idm Low
Version central version 1.4.6.Final Highest
Version Manifest Implementation-Version 1.4.6.Final High
Version pom version 1.4.6.Final Highest
Version file version 1.4.6 Highest
Related Dependencies
picketlink-idm-ldap-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-ldap/1.4.6.Final/picketlink-idm-ldap-1.4.6.Final.jar
SHA1: b52fefb76b4f2d047422f4ff5caff9c7a18001f3
MD5: 7da4240664f237384cd33b35939ff153
maven: org.picketlink.idm:picketlink-idm-ldap:1.4.6.Final ✓
picketlink-idm-api-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-api/1.4.6.Final/picketlink-idm-api-1.4.6.Final.jar
SHA1: 6af0f6f08add632a442a6a415907460f9e8a9913
MD5: b85343ae7bcc7162b42ed3aaac08322a
maven: org.picketlink.idm:picketlink-idm-api:1.4.6.Final ✓
picketlink-idm-common-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-common/1.4.6.Final/picketlink-idm-common-1.4.6.Final.jar
SHA1: 37c1309fd376db4f4ff969fb0df4f8c388e2022c
MD5: 1ad4f8384e856abf4696895d7647dabf
maven: org.picketlink.idm:picketlink-idm-common:1.4.6.Final ✓
picketlink-idm-hibernate-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-hibernate/1.4.6.Final/picketlink-idm-hibernate-1.4.6.Final.jar
SHA1: 4cd6d4e7bc818d5d89e06d268302908903cd3447
MD5: 4e80873b893295bab629a5764c40b345
maven: org.picketlink.idm:picketlink-idm-hibernate:1.4.6.Final ✓
picketlink-idm-spi-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-spi/1.4.6.Final/picketlink-idm-spi-1.4.6.Final.jar
SHA1: 0804a3a34b7d031cc8daab4f4a8cbac1c00e98dd
MD5: 7289815e139890cb98b0f5a80e7b7a59
maven: org.picketlink.idm:picketlink-idm-spi:1.4.6.Final ✓
Published Vulnerabilities
CVE-2015-0277 suppress
Severity:
Medium
CVSS Score: 6.0
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users' accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.
Vulnerable Software & Versions:
CVE-2015-3158 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.
Vulnerable Software & Versions:
CVE-2015-6254 suppress
Severity:
Medium
CVSS Score: 6.0
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
CWE: CWE-17 Code
The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.
Vulnerable Software & Versions:
jackson-core-2.9.8.jar
Description: Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.9.8/jackson-core-2.9.8.jar
MD5: 65831e4f46f29db904708e4b9cc72843
SHA1: 0f5a654e4675769c716e5b387830d19b501ca191
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor Manifest Implementation-Vendor FasterXML High
Vendor pom groupid fasterxml.jackson.core Highest
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom name Jackson-core High
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor manifest Bundle-Description Core Jackson processing abstractions (aka Streaming API), implementation for JSON Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor Manifest implementation-build-date 2018-12-15 21:18:52+0000 Low
Vendor pom artifactid jackson-core Low
Vendor file name jackson-core High
Vendor Manifest automatic-module-name com.fasterxml.jackson.core Medium
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom parent-artifactid jackson-base Low
Vendor pom description Core Jackson processing abstractions (aka Streaming API), implementation for JSON Medium
Vendor pom url FasterXML/jackson-core Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest Implementation-Title Jackson-core High
Product pom groupid fasterxml.jackson.core Low
Product pom parent-groupid com.fasterxml.jackson Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product pom artifactid jackson-core Highest
Product pom url FasterXML/jackson-core High
Product Manifest Bundle-Name Jackson-core Medium
Product pom name Jackson-core High
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product manifest Bundle-Description Core Jackson processing abstractions (aka Streaming API), implementation for JSON Medium
Product Manifest implementation-build-date 2018-12-15 21:18:52+0000 Low
Product Manifest specification-title Jackson-core Medium
Product central artifactid jackson-core Highest
Product file name jackson-core High
Product Manifest automatic-module-name com.fasterxml.jackson.core Medium
Product pom description Core Jackson processing abstractions (aka Streaming API), implementation for JSON Medium
Product pom parent-artifactid jackson-base Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Version pom version 2.9.8 Highest
Version Manifest Implementation-Version 2.9.8 High
Version central version 2.9.8 Highest
Version file version 2.9.8 Highest
Related Dependencies
jackson-annotations-2.9.8.jar
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.9.8/jackson-annotations-2.9.8.jar
SHA1: ba7f0e6f8f1b28d251eeff2a5604bed34c53ff35
MD5: 25fed62a8553a51981b5225d703a23ef
maven: com.fasterxml.jackson.core:jackson-annotations:2.9.8 ✓
jackson-databind-2.9.8.jar
Description: General data-binding functionality for Jackson: works on core streaming API
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.9.8/jackson-databind-2.9.8.jar
MD5: 39271d9bb1cb7ec563925953b1fa9ff7
SHA1: 11283f21cc480aa86c4df7a0a3243ec508372ed2
Referenced In Project/Scope:
eXo PLF:: Commons - API:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor pom groupid fasterxml.jackson.core Highest
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom url http://github.com/FasterXML/jackson Highest
Vendor Manifest automatic-module-name com.fasterxml.jackson.databind Medium
Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low
Vendor pom description General data-binding functionality for Jackson: works on core streaming API Medium
Vendor Manifest implementation-build-date 2018-12-15 21:58:52+0000 Low
Vendor file name jackson-databind High
Vendor pom artifactid jackson-databind Low
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom parent-artifactid jackson-base Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom name jackson-databind High
Product Manifest specification-title jackson-databind Medium
Product central artifactid jackson-databind Highest
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product pom groupid fasterxml.jackson.core Low
Product pom parent-groupid com.fasterxml.jackson Low
Product Manifest Implementation-Title jackson-databind High
Product pom artifactid jackson-databind Highest
Product manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium
Product Manifest automatic-module-name com.fasterxml.jackson.databind Medium
Product pom url http://github.com/FasterXML/jackson Medium
Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low
Product pom description General data-binding functionality for Jackson: works on core streaming API Medium
Product Manifest implementation-build-date 2018-12-15 21:58:52+0000 Low
Product file name jackson-databind High
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid jackson-base Medium
Product pom name jackson-databind High
Version pom version 2.9.8 Highest
Version Manifest Implementation-Version 2.9.8 High
Version central version 2.9.8 Highest
Version file version 2.9.8 Highest
Published Vulnerabilities
CVE-2019-12086 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.
Vulnerable Software & Versions: (show all )
CVE-2019-12384 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.
BUGTRAQ - 20191007 [SECURITY] [DSA 4542-1] jackson-databind security update
CONFIRM - https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html
CONFIRM - https://security.netapp.com/advisory/ntap-20190703-0002/
DEBIAN - DSA-4542
FEDORA - FEDORA-2019-99ff6aa32c
FEDORA - FEDORA-2019-ae6a703b8f
FEDORA - FEDORA-2019-fb23eccc03
MISC - https://blog.doyensec.com/2019/07/22/jackson-gadgets.html
MISC - https://doyensec.com/research.html
MISC - https://github.com/FasterXML/jackson-databind/compare/74b90a4...a977aad
MLIST - [cassandra-commits] 20190919 [jira] [Created] (CASSANDRA-15328) Bump jackson version to >= 2.9.9.3 to address security vulnerabilities
MLIST - [geode-notifications] 20191007 [GitHub] [geode] jmelchio commented on issue #4102: Fix for GEODE-7255: Pickup Jackson CVE fix
MLIST - [struts-dev] 20190908 Build failed in Jenkins: Struts-master-JDK8-dependency-check #204
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] robert-schaft-hon commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190906 [GitHub] [tomee] rzo1 commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
REDHAT - RHSA-2019:1820
REDHAT - RHSA-2019:2720
REDHAT - RHSA-2019:2858
REDHAT - RHSA-2019:2935
REDHAT - RHSA-2019:2936
REDHAT - RHSA-2019:2937
REDHAT - RHSA-2019:2938
REDHAT - RHSA-2019:2998
Vulnerable Software & Versions: (show all )
CVE-2019-12814 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.
CONFIRM - https://github.com/FasterXML/jackson-databind/issues/2341
CONFIRM - https://security.netapp.com/advisory/ntap-20190625-0006/
FEDORA - FEDORA-2019-99ff6aa32c
FEDORA - FEDORA-2019-ae6a703b8f
FEDORA - FEDORA-2019-fb23eccc03
MISC - https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
MLIST - [accumulo-commits] 20190723 [accumulo] branch 2.0 updated: Fix CVE-2019-12814 Use jackson-databind 2.9.9.1
MLIST - [cassandra-commits] 20190919 [jira] [Created] (CASSANDRA-15328) Bump jackson version to >= 2.9.9.3 to address security vulnerabilities
MLIST - [debian-lts-announce] 20190621 [SECURITY] [DLA 1831-1] jackson-databind security update
MLIST - [geode-notifications] 20191007 [GitHub] [geode] jmelchio commented on issue #4102: Fix for GEODE-7255: Pickup Jackson CVE fix
MLIST - [struts-dev] 20190908 Build failed in Jenkins: Struts-master-JDK8-dependency-check #204
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] robert-schaft-hon commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190906 [GitHub] [tomee] rzo1 commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [zookeeper-dev] 20190623 [jira] [Created] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190623 [jira] [Created] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190623 [jira] [Updated] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190708 [jira] [Commented] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190712 [jira] [Assigned] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190712 [jira] [Commented] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190712 [jira] [Resolved] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-issues] 20190713 [jira] [Updated] (ZOOKEEPER-3441) OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-notifications] 20190623 [GitHub] [zookeeper] eolivelli opened a new pull request #1001: ZOOKEEPER-3441 OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-notifications] 20190624 [GitHub] [zookeeper] eolivelli closed pull request #1001: ZOOKEEPER-3441 OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-notifications] 20190624 [GitHub] [zookeeper] eolivelli commented on issue #1001: ZOOKEEPER-3441 OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-notifications] 20190624 [GitHub] [zookeeper] phunt commented on a change in pull request #1001: ZOOKEEPER-3441 OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-notifications] 20190710 [GitHub] [zookeeper] phunt closed pull request #1013: ZOOKEEPER-3441: OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
MLIST - [zookeeper-notifications] 20190710 [GitHub] [zookeeper] phunt opened a new pull request #1013: ZOOKEEPER-3441: OWASP is flagging jackson-databind-2.9.9.jar for CVE-2019-12814
REDHAT - RHSA-2019:2858
REDHAT - RHSA-2019:2935
REDHAT - RHSA-2019:2936
REDHAT - RHSA-2019:2937
REDHAT - RHSA-2019:2938
Vulnerable Software & Versions: (show all )
CVE-2019-14379 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
CONFIRM - https://security.netapp.com/advisory/ntap-20190814-0001/
FEDORA - FEDORA-2019-99ff6aa32c
FEDORA - FEDORA-2019-ae6a703b8f
FEDORA - FEDORA-2019-fb23eccc03
MISC - https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2
MISC - https://github.com/FasterXML/jackson-databind/issues/2387
MLIST - [ambari-commits] 20190813 [ambari] branch branch-2.7 updated: AMBARI-25352 : Upgrade fasterxml jackson dependency due to CVE-2019-14379 (#3066)
MLIST - [ambari-commits] 20190813 [ambari] branch trunk updated: AMBARI-25352 : Upgrade fasterxml jackson dependency due to CVE-2019-14379(trunk) (#3067)
MLIST - [debian-lts-announce] 20190812 [SECURITY] [DLA 1879-1] jackson-databind security update
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] mccheah commented on issue #535: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] mccheah opened a new pull request #535: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] rdblue closed pull request #533: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] rdblue commented on issue #533: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] rdblue commented on issue #535: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] rdblue merged pull request #535: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [iceberg-issues] 20191010 [GitHub] [incubator-iceberg] rdblue opened a new pull request #533: Update Jackson to 2.9.10 for CVE-2019-14379
MLIST - [pulsar-commits] 20190822 [GitHub] [pulsar] massakam opened a new pull request #5011: [security] Upgrade jackson-databind
MLIST - [struts-dev] 20190908 Build failed in Jenkins: Struts-master-JDK8-dependency-check #204
MLIST - [tinkerpop-commits] 20190924 [GitHub] [tinkerpop] justinchuch opened a new pull request #1200: Upgrade jackson due to CVE issues
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] robert-schaft-hon commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190906 [GitHub] [tomee] rzo1 commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
REDHAT - RHBA-2019:2824
REDHAT - RHSA-2019:2743
REDHAT - RHSA-2019:2858
REDHAT - RHSA-2019:2935
REDHAT - RHSA-2019:2936
REDHAT - RHSA-2019:2937
REDHAT - RHSA-2019:2938
REDHAT - RHSA-2019:2998
Vulnerable Software & Versions: (show all )
CVE-2019-14439 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.
BUGTRAQ - 20191007 [SECURITY] [DSA 4542-1] jackson-databind security update
CONFIRM - https://security.netapp.com/advisory/ntap-20190814-0001/
DEBIAN - DSA-4542
FEDORA - FEDORA-2019-ae6a703b8f
FEDORA - FEDORA-2019-fb23eccc03
MISC - https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b
MISC - https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2
MISC - https://github.com/FasterXML/jackson-databind/issues/2389
MLIST - [cassandra-commits] 20190919 [jira] [Created] (CASSANDRA-15328) Bump jackson version to >= 2.9.9.3 to address security vulnerabilities
MLIST - [debian-lts-announce] 20190812 [SECURITY] [DLA 1879-1] jackson-databind security update
MLIST - [struts-dev] 20190908 Build failed in Jenkins: Struts-master-JDK8-dependency-check #204
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] asf-ci commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] robert-schaft-hon commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190905 [GitHub] [tomee] rzo1 opened a new pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190906 [GitHub] [tomee] rzo1 commented on issue #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #548: [TOMEE-2655] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
MLIST - [tomee-dev] 20190909 [GitHub] [tomee] jgallimore merged pull request #549: [TOMEE-2655] [7.1.x] Updates jackson-databind to 2.9.9.3 to mitigate CVE-2019-12384, CVE-2019-12814, CVE-2019-14379 and CVE-2019-14439
Vulnerable Software & Versions: (show all )
CVE-2019-14540 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig.
Vulnerable Software & Versions: (show all )
CVE-2019-16335 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.
Vulnerable Software & Versions: (show all )