Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : Oct 13, 2019 at 08:35:53 +00:00
Dependencies Scanned : 236 (197 unique)
Vulnerable Dependencies : 29
Vulnerabilities Found : 72
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 10/10/2019 09:15:36
NVD CVE 2003 : 11/10/2019 08:45:55
NVD CVE 2004 : 08/10/2019 13:32:07
NVD CVE 2005 : 11/10/2019 08:45:55
NVD CVE 2006 : 11/10/2019 08:45:55
NVD CVE 2007 : 10/10/2019 09:15:36
NVD CVE 2008 : 11/10/2019 08:45:55
NVD CVE 2009 : 11/10/2019 08:45:55
NVD CVE 2010 : 12/10/2019 08:45:35
NVD CVE 2011 : 10/10/2019 08:45:44
NVD CVE 2012 : 10/10/2019 08:45:45
NVD CVE 2013 : 11/10/2019 08:45:56
NVD CVE 2014 : 10/10/2019 08:45:45
NVD CVE 2015 : 12/10/2019 08:45:35
NVD CVE 2016 : 12/10/2019 08:15:30
NVD CVE 2017 : 12/10/2019 08:15:30
NVD CVE 2018 : 12/10/2019 07:45:35
NVD CVE 2019 : 12/10/2019 07:45:35
NVD CVE Checked : 13/10/2019 07:53:12
NVD CVE Modified : 13/10/2019 05:15:31
VersionCheckOn : 1570953192127
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
commons-lang-2.6.jar
Description:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name commons-lang High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor central groupid commons-lang High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium
Vendor pom artifactid commons-lang Low
Vendor pom url http://commons.apache.org/lang/ Highest
Vendor central groupid org.netbeans.external High
Vendor pom groupid commons-lang Highest
Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low
Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor pom name Commons Lang High
Product file name commons-lang High
Product central artifactid org-apache-commons-lang High
Product Manifest specification-title Commons Lang Medium
Product Manifest Implementation-Title Commons Lang High
Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest Bundle-Name Commons Lang Medium
Product pom artifactid commons-lang Highest
Product central artifactid commons-lang High
Product Manifest bundle-symbolicname org.apache.commons.lang Medium
Product pom url http://commons.apache.org/lang/ Medium
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/lang/ Low
Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product pom groupid commons-lang Low
Product pom name Commons Lang High
Version Manifest Implementation-Version 2.6 High
Version file version 2.6 Highest
jsr250-api-1.0.jar
Description: JSR-250 Reference Implementation by Glassfish
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/annotation/jsr250-api/1.0/jsr250-api-1.0.jar
MD5: 4cd56b2e4977e541186de69f5126b4a6
SHA1: 5025422767732a1ab45d93abfea846513d742dcf
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name jsr250-api High
Vendor pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Highest
Vendor pom artifactid jsr250-api Low
Vendor pom name JSR-250 Common Annotations for the JavaTM Platform High
Vendor central groupid javax.annotation Highest
Vendor pom groupid javax.annotation Highest
Vendor jar package name javax Low
Vendor pom description JSR-250 Reference Implementation by Glassfish Medium
Vendor jar package name annotation Low
Product pom artifactid jsr250-api Highest
Product file name jsr250-api High
Product pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Medium
Product pom name JSR-250 Common Annotations for the JavaTM Platform High
Product pom groupid javax.annotation Low
Product central artifactid jsr250-api Highest
Product pom description JSR-250 Reference Implementation by Glassfish Medium
Product jar package name annotation Low
Version central version 1.0 Highest
Version file version 1.0 Highest
Version pom version 1.0 Highest
jcr-1.0.1.jar
Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.
License:
Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Day Software Management AG High
Vendor pom groupid javax.jcr Highest
Vendor pom organization url http://www.day.com/ Medium
Vendor Manifest specification-vendor Day Software Management AG Low
Vendor pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Vendor file name jcr High
Vendor pom url http://www.jcp.org/en/jsr/detail?id=170 Highest
Vendor pom artifactid jcr Low
Vendor pom name Content Repository for Java Technology API High
Vendor Manifest extension-name jcr Medium
Vendor pom organization name Day Software Management AG High
Product pom url http://www.jcp.org/en/jsr/detail?id=170 Medium
Product Manifest specification-title Content Repository for Java Technology API Medium
Product pom organization url http://www.day.com/ Low
Product pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Product pom artifactid jcr Highest
Product file name jcr High
Product pom groupid javax.jcr Low
Product Manifest Implementation-Title javax.jcr High
Product pom organization name Day Software Management AG Low
Product pom name Content Repository for Java Technology API High
Product Manifest extension-name jcr Medium
Version pom version 1.0.1 Highest
Version file version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
cpe: cpe:/a:content_project:content:1.0.1
Confidence :Low
suppress
maven: javax.jcr:jcr:1.0.1
Confidence :High
Published Vulnerabilities
CVE-2017-16111 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Vulnerable Software & Versions:
jsr311-api-1.1.1.jar
License:
CDDL License
: http://www.opensource.org/licenses/cddl1.php
File Path: /home/ciagent/.m2/repository/javax/ws/rs/jsr311-api/1.1.1/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.sun.com/ Low
Vendor pom artifactid jsr311-api Low
Vendor Manifest extension-name javax.ws.rs Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom organization url http://www.sun.com/ Medium
Vendor file name jsr311-api High
Vendor pom url https://jsr311.dev.java.net Highest
Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Vendor pom name jsr311-api High
Vendor pom groupid javax.ws.rs Highest
Vendor pom organization name Sun Microsystems, Inc High
Vendor central groupid javax.ws.rs Highest
Product Manifest Bundle-Name jsr311-api Medium
Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium
Product pom artifactid jsr311-api Highest
Product Manifest bundle-docurl http://www.sun.com/ Low
Product Manifest extension-name javax.ws.rs Medium
Product pom url https://jsr311.dev.java.net Medium
Product file name jsr311-api High
Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Product pom name jsr311-api High
Product pom organization url http://www.sun.com/ Low
Product central artifactid jsr311-api Highest
Product pom groupid javax.ws.rs Low
Product pom organization name Sun Microsystems, Inc Low
Version central version 1.1.1 Highest
Version file version 1.1.1 Highest
Version pom version 1.1.1 Highest
chromattic.api-1.3.0.jar
Description: Chromattic Framework API
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.api/1.3.0/chromattic.api-1.3.0.jar
MD5: 11f2df6e3a3b4451719710c0f4c08103
SHA1: 4f60a9585bd6e68833eaaea1f1a615c682adbe27
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name chromattic.api High
Vendor pom parent-groupid org.chromattic Medium
Vendor jar package name api Low
Vendor pom parent-artifactid chromattic.parent Low
Vendor pom groupid chromattic Highest
Vendor pom name Chromattic Framework API High
Vendor pom description Chromattic Framework API Medium
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor pom groupid org.chromattic Highest
Vendor pom artifactid chromattic.api Low
Product pom artifactid chromattic.api Highest
Product file name chromattic.api High
Product jar package name api Low
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework API High
Product pom description Chromattic Framework API Medium
Product pom parent-artifactid chromattic.parent Medium
Product central artifactid chromattic.api Highest
Product pom groupid chromattic Low
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
javaparser-1.0.8.jar
Description: A Java 1.5 Parser with AST generation and visitor support. The AST records the source code structure, javadoc and comments. It is also possible to change the AST nodes or create new ones to modify the source code.
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ciagent/.m2/repository/com/google/code/javaparser/javaparser/1.0.8/javaparser-1.0.8.jar
MD5: 32228e53ef6cc2ebe515bc40d7c9a4f9
SHA1: 9ca2f8ef2233babc53a8c2b6bb21869d94f5fcc1
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid google.code.javaparser Highest
Vendor jar package name parser Low
Vendor file name javaparser High
Vendor pom groupid com.google.code.javaparser Highest
Vendor pom url http://code.google.com/p/javaparser/ Highest
Vendor jar package name ast Low
Vendor pom name Java 1.5 Parser and AST High
Vendor jar package name japa Low
Vendor pom artifactid javaparser Low
Vendor pom description A Java 1.5 Parser with AST generation and visitor support. The AST records the source code structure, javadoc and comments. It is also possible to change the AST nodes or create new ones to modify the source code. Low
Product jar package name parser Low
Product pom artifactid javaparser Highest
Product file name javaparser High
Product pom url http://code.google.com/p/javaparser/ Medium
Product jar package name ast Low
Product pom name Java 1.5 Parser and AST High
Product pom groupid google.code.javaparser Low
Product pom description A Java 1.5 Parser with AST generation and visitor support. The AST records the source code structure, javadoc and comments. It is also possible to change the AST nodes or create new ones to modify the source code. Low
Version file version 1.0.8 Highest
Version pom version 1.0.8 Highest
maven: com.google.code.javaparser:javaparser:1.0.8
Confidence :High
chromattic.testgenerator-1.3.0.jar
Description: Chromattic Framework generator
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.testgenerator/1.3.0/chromattic.testgenerator-1.3.0.jar
MD5: 971802dfdfdc6500f1ff0e583a7659a1
SHA1: e725269db29a0fc8c982df481e5ce09b84e5d6a8
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.chromattic Medium
Vendor pom parent-artifactid chromattic.parent Low
Vendor pom groupid chromattic Highest
Vendor pom name Chromattic Framework Test generator High
Vendor pom description Chromattic Framework generator Medium
Vendor file name chromattic.testgenerator High
Vendor jar package name testgenerator Low
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor pom groupid org.chromattic Highest
Vendor pom artifactid chromattic.testgenerator Low
Product pom artifactid chromattic.testgenerator Highest
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework Test generator High
Product pom description Chromattic Framework generator Medium
Product file name chromattic.testgenerator High
Product pom parent-artifactid chromattic.parent Medium
Product jar package name testgenerator Low
Product central artifactid chromattic.testgenerator Highest
Product pom groupid chromattic Low
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
chromattic.metamodel-1.3.0.jar
Description: Chromattic Framework Metamodel
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.metamodel/1.3.0/chromattic.metamodel-1.3.0.jar
MD5: 0d534975c688ebabbc232601c6bc13da
SHA1: fbaa10037faf34a2d4d8eeb4e6b5ce28c95a9455
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.chromattic Medium
Vendor pom parent-artifactid chromattic.parent Low
Vendor pom groupid chromattic Highest
Vendor file name chromattic.metamodel High
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor pom name Chromattic Framework Metamodel High
Vendor pom description Chromattic Framework Metamodel Medium
Vendor pom groupid org.chromattic Highest
Vendor jar package name metamodel Low
Vendor pom artifactid chromattic.metamodel Low
Product pom artifactid chromattic.metamodel Highest
Product pom parent-groupid org.chromattic Low
Product file name chromattic.metamodel High
Product pom parent-artifactid chromattic.parent Medium
Product pom name Chromattic Framework Metamodel High
Product pom description Chromattic Framework Metamodel Medium
Product jar package name metamodel Low
Product pom groupid chromattic Low
Product central artifactid chromattic.metamodel Highest
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
chromattic.spi-1.3.0.jar
Description: Chromattic Framework SPI
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.spi/1.3.0/chromattic.spi-1.3.0.jar
MD5: e440e3f5a8e5ad38720975546ab7f06d
SHA1: 64c36f826b832acab48fea793b7c70b019a46181
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom artifactid chromattic.spi Low
Vendor jar package name chromattic Low
Vendor pom description Chromattic Framework SPI Medium
Vendor pom parent-groupid org.chromattic Medium
Vendor pom parent-artifactid chromattic.parent Low
Vendor pom name Chromattic Framework SPI High
Vendor file name chromattic.spi High
Vendor pom groupid chromattic Highest
Vendor central groupid org.chromattic Highest
Vendor pom groupid org.chromattic Highest
Vendor jar package name spi Low
Vendor jar package name type Low
Product pom name Chromattic Framework SPI High
Product file name chromattic.spi High
Product pom parent-groupid org.chromattic Low
Product central artifactid chromattic.spi Highest
Product pom parent-artifactid chromattic.parent Medium
Product pom artifactid chromattic.spi Highest
Product pom description Chromattic Framework SPI Medium
Product jar package name spi Low
Product jar package name type Low
Product pom groupid chromattic Low
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
reflext.api-1.1.0.jar
Description: The Reflext Framework API
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.api/1.1.0/reflext.api-1.1.0.jar
MD5: fe732172fa2fb5ae4b63866ef15da41f
SHA1: 28374c509099736aeedc52fef3d7b8e78238c2a0
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid reflext Highest
Vendor jar package name api Low
Vendor pom groupid org.reflext Highest
Vendor pom artifactid reflext.api Low
Vendor jar package name reflext Low
Vendor pom name Reflext Framework API High
Vendor file name reflext.api High
Vendor pom description The Reflext Framework API Medium
Vendor central groupid org.reflext Highest
Vendor pom parent-groupid org.reflext Medium
Vendor pom parent-artifactid reflext.parent Low
Product pom parent-artifactid reflext.parent Medium
Product jar package name api Low
Product pom groupid reflext Low
Product central artifactid reflext.api Highest
Product pom parent-groupid org.reflext Low
Product pom name Reflext Framework API High
Product file name reflext.api High
Product pom description The Reflext Framework API Medium
Product pom artifactid reflext.api Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
Version pom version 1.1.0 Highest
reflext.core-1.1.0.jar
Description: The Reflect Framework Core
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.core/1.1.0/reflext.core-1.1.0.jar
MD5: cc65231f60a70dec43a57ccba5adce81
SHA1: 56316a714b99d7ac85d23d0f1a4680149c3273d6
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid reflext Highest
Vendor pom description The Reflect Framework Core Medium
Vendor pom groupid org.reflext Highest
Vendor jar package name reflext Low
Vendor pom name Reflext Framework Core High
Vendor jar package name core Low
Vendor file name reflext.core High
Vendor central groupid org.reflext Highest
Vendor pom parent-groupid org.reflext Medium
Vendor pom artifactid reflext.core Low
Vendor pom parent-artifactid reflext.parent Low
Product pom parent-artifactid reflext.parent Medium
Product pom groupid reflext Low
Product pom description The Reflect Framework Core Medium
Product pom artifactid reflext.core Highest
Product pom name Reflext Framework Core High
Product pom parent-groupid org.reflext Low
Product jar package name core Low
Product file name reflext.core High
Product central artifactid reflext.core Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
Version pom version 1.1.0 Highest
reflext.spi-1.1.0.jar
Description: The Reflext Framework SPI
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.spi/1.1.0/reflext.spi-1.1.0.jar
MD5: 2c967ae0c3078d23b615f8825377f304
SHA1: 4df0428c39922079c53955602bce66735f9d20a8
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom name Reflext Framework SPI High
Vendor file name reflext.spi High
Vendor pom description The Reflext Framework SPI Medium
Vendor central groupid org.reflext Highest
Vendor pom parent-groupid org.reflext Medium
Vendor pom groupid reflext Highest
Vendor pom groupid org.reflext Highest
Vendor jar package name reflext Low
Vendor jar package name model Low
Vendor jar package name spi Low
Vendor pom parent-artifactid reflext.parent Low
Vendor pom artifactid reflext.spi Low
Product pom name Reflext Framework SPI High
Product pom parent-artifactid reflext.parent Medium
Product pom groupid reflext Low
Product pom artifactid reflext.spi Highest
Product file name reflext.spi High
Product pom parent-groupid org.reflext Low
Product pom description The Reflext Framework SPI Medium
Product jar package name model Low
Product jar package name spi Low
Product central artifactid reflext.spi Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
Version pom version 1.1.0 Highest
reflext.apt-1.1.0.jar
Description: The Reflext Framework Annotation Processing Tool Plugin
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.apt/1.1.0/reflext.apt-1.1.0.jar
MD5: e6bb0195d6cdd15b618939c78999ea4e
SHA1: 093ab21e03197c1c7a2d2d20da4d3dd34a60ac24
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid reflext Highest
Vendor jar package name apt Low
Vendor pom artifactid reflext.apt Low
Vendor pom groupid org.reflext Highest
Vendor jar package name reflext Low
Vendor pom description The Reflext Framework Annotation Processing Tool Plugin Medium
Vendor pom name Reflext Framework Annotation Processing Tool Plugin High
Vendor central groupid org.reflext Highest
Vendor file name reflext.apt High
Vendor pom parent-groupid org.reflext Medium
Vendor pom parent-artifactid reflext.parent Low
Product jar package name apt Low
Product pom parent-artifactid reflext.parent Medium
Product pom groupid reflext Low
Product central artifactid reflext.apt Highest
Product pom description The Reflext Framework Annotation Processing Tool Plugin Medium
Product pom parent-groupid org.reflext Low
Product pom name Reflext Framework Annotation Processing Tool Plugin High
Product pom artifactid reflext.apt Highest
Product file name reflext.apt High
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
Version pom version 1.1.0 Highest
Published Vulnerabilities
CVE-2018-1000840 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrate their contents via HTTP requests. This attack appear to be exploitable via The victim must use Processing to parse a crafted XML document.
Vulnerable Software & Versions:
chromattic.apt-1.3.0.jar
Description: Chromattic Framework APT Plugin
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.apt/1.3.0/chromattic.apt-1.3.0.jar
MD5: 5f51682435a2e2014a9bd9c5936a5cc5
SHA1: f2e219c2b8e13983a26b4c3f4e8eb54d71730b4d
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor jar package name apt Low
Vendor pom parent-groupid org.chromattic Medium
Vendor pom parent-artifactid chromattic.parent Low
Vendor file name chromattic.apt High
Vendor pom groupid chromattic Highest
Vendor pom name Chromattic Framework APT Plugin High
Vendor pom description Chromattic Framework APT Plugin Medium
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor pom groupid org.chromattic Highest
Vendor pom artifactid chromattic.apt Low
Product jar package name apt Low
Product pom artifactid chromattic.apt Highest
Product file name chromattic.apt High
Product pom name Chromattic Framework APT Plugin High
Product pom description Chromattic Framework APT Plugin Medium
Product pom parent-groupid org.chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Product central artifactid chromattic.apt Highest
Product pom groupid chromattic Low
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
chromattic.common-1.3.0.jar
Description: Chromattic Framework Common
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.common/1.3.0/chromattic.common-1.3.0.jar
MD5: 15bfb4cc0312aefffb25952cdf18b2cd
SHA1: 55470175c1ba46a917504acf97018e6ef2932659
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor jar package name chromattic Low
Vendor file name chromattic.common High
Vendor jar package name common Low
Vendor pom name Chromattic Framework Common High
Vendor pom description Chromattic Framework Common Medium
Vendor jar package name collection Low
Vendor pom parent-groupid org.chromattic Medium
Vendor pom parent-artifactid chromattic.parent Low
Vendor pom groupid chromattic Highest
Vendor pom artifactid chromattic.common Low
Vendor central groupid org.chromattic Highest
Vendor pom groupid org.chromattic Highest
Product central artifactid chromattic.common Highest
Product pom parent-groupid org.chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Product pom artifactid chromattic.common Highest
Product file name chromattic.common High
Product jar package name common Low
Product pom name Chromattic Framework Common High
Product pom groupid chromattic Low
Product pom description Chromattic Framework Common Medium
Product jar package name collection Low
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
reflext.jlr-1.1.0.jar
Description: The Reflext Framework Java Lang Reflect Plugin
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.jlr/1.1.0/reflext.jlr-1.1.0.jar
MD5: 1103f3b1ed3762e0bd100cbee6e7f345
SHA1: 79ad1a5053213cbb350d37ff12d5f767243c8c46
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid reflext Highest
Vendor pom description The Reflext Framework Java Lang Reflect Plugin Medium
Vendor pom groupid org.reflext Highest
Vendor file name reflext.jlr High
Vendor jar package name reflext Low
Vendor pom name Reflext Framework Java Lang Reflect Plugin High
Vendor jar package name jlr Low
Vendor pom artifactid reflext.jlr Low
Vendor central groupid org.reflext Highest
Vendor pom parent-groupid org.reflext Medium
Vendor pom parent-artifactid reflext.parent Low
Product pom description The Reflext Framework Java Lang Reflect Plugin Medium
Product pom parent-artifactid reflext.parent Medium
Product pom artifactid reflext.jlr Highest
Product pom groupid reflext Low
Product central artifactid reflext.jlr Highest
Product file name reflext.jlr High
Product pom name Reflext Framework Java Lang Reflect Plugin High
Product jar package name jlr Low
Product pom parent-groupid org.reflext Low
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
Version pom version 1.1.0 Highest
chromattic.core-1.3.0.jar
Description: Chromattic Framework Core
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.core/1.3.0/chromattic.core-1.3.0.jar
MD5: 9ece56be0e1e1b3289bbe177e8e1b4ab
SHA1: 1bc4ebc89d7b47af394b920f44a0b51409343034
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.chromattic Medium
Vendor pom parent-artifactid chromattic.parent Low
Vendor file name chromattic.core High
Vendor pom groupid chromattic Highest
Vendor pom artifactid chromattic.core Low
Vendor pom name Chromattic Framework Core High
Vendor jar package name core Low
Vendor pom description Chromattic Framework Core Medium
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor pom groupid org.chromattic Highest
Product pom artifactid chromattic.core Highest
Product file name chromattic.core High
Product central artifactid chromattic.core Highest
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework Core High
Product jar package name core Low
Product pom parent-artifactid chromattic.parent Medium
Product pom description Chromattic Framework Core Medium
Product pom groupid chromattic Low
Version file version 1.3.0 Highest
Version pom version 1.3.0 Highest
Version central version 1.3.0 Highest
portlet-api-2.0.jar
Description: The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group.
File Path: /home/ciagent/.m2/repository/javax/portlet/portlet-api/2.0/portlet-api-2.0.jar
MD5: 0ec08593cda1df33985391919996c740
SHA1: 1cd72f2a37fcf8ab9893a9468d7ba71c85fe2653
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid javax.portlet Highest
Vendor pom name Java Portlet Specification V2.0 High
Vendor Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Vendor pom artifactid portlet-api Low
Vendor file name portlet-api High
Vendor Manifest bundle-symbolicname javax.portlet Medium
Vendor pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Vendor central groupid javax.portlet Highest
Vendor pom url http://www.jcp.org/en/jsr/detail?id=286 Highest
Product pom name Java Portlet Specification V2.0 High
Product Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Product central artifactid portlet-api Highest
Product pom artifactid portlet-api Highest
Product file name portlet-api High
Product Manifest bundle-symbolicname javax.portlet Medium
Product pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Product Manifest Bundle-Name JSR 286 Medium
Product pom groupid javax.portlet Low
Product pom url http://www.jcp.org/en/jsr/detail?id=286 Medium
Version pom version 2.0 Highest
Version file version 2.0 Highest
Version central version 2.0 Highest
common-logging-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-logging/2.2.2.Final/common-logging-2.2.2.Final.jar
MD5: 28b7108ee63899bca08636d360e7df11
SHA1: aee18008518671fb10982c0fe5f7383e98f71c47
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid gatein.common Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor file name common-logging High
Vendor pom name GateIn - Common component (logging) High
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Vendor pom parent-groupid org.gatein.common Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest implementation-url www.gatein.org/common-parent/common-logging/ Low
Vendor pom artifactid common-logging Low
Vendor pom groupid org.gatein.common Highest
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest os-name Linux Medium
Vendor central groupid org.gatein.common Highest
Vendor pom parent-artifactid common-parent Low
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Product file name common-logging High
Product pom name GateIn - Common component (logging) High
Product pom groupid gatein.common Low
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product Manifest specification-title GateIn - Common component (logging) Medium
Product Manifest Implementation-Title GateIn - Common component (logging) High
Product Manifest implementation-url www.gatein.org/common-parent/common-logging/ Low
Product central artifactid common-logging Highest
Product pom parent-artifactid common-parent Medium
Product pom artifactid common-logging Highest
Product Manifest os-name Linux Medium
Product pom parent-groupid org.gatein.common Low
Version central version 2.2.2.Final Highest
Version pom version 2.2.2.Final Highest
Version Manifest Implementation-Version 2.2.2.Final High
Version file version 2.2.2 Highest
common-common-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-common/2.2.2.Final/common-common-2.2.2.Final.jar
MD5: 8ce16b5e3991285cd27e553740d09d1f
SHA1: 44522d899e31a5a10dbd70f7b0ca2fe5a614f740
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid gatein.common Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Vendor pom parent-groupid org.gatein.common Medium
Vendor pom artifactid common-common Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Vendor pom groupid org.gatein.common Highest
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom name GateIn - Common component (common) High
Vendor Manifest os-name Linux Medium
Vendor central groupid org.gatein.common Highest
Vendor pom parent-artifactid common-parent Low
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Vendor file name common-common High
Product central artifactid common-common Highest
Product Manifest Implementation-Title GateIn - Common component (common) High
Product pom groupid gatein.common Low
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product Manifest specification-title GateIn - Common component (common) Medium
Product Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Product pom artifactid common-common Highest
Product pom parent-artifactid common-parent Medium
Product pom name GateIn - Common component (common) High
Product Manifest os-name Linux Medium
Product file name common-common High
Product pom parent-groupid org.gatein.common Low
Version central version 2.2.2.Final Highest
Version pom version 2.2.2.Final Highest
Version Manifest Implementation-Version 2.2.2.Final High
Version file version 2.2.2 Highest
jboss-logging-3.3.0.Final.jar
Description: The JBoss Logging Framework
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging/3.3.0.Final/jboss-logging-3.3.0.Final.jar
MD5: bc11af4b8ce7138cdc79b7ba8561638c
SHA1: 3616bb87707910296e2c195dc016287080bba5af
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-logging Low
Vendor Manifest build-timestamp Thu, 28 May 2015 09:49:28 -0700 Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom description The JBoss Logging Framework Medium
Vendor Manifest implementation-url http://www.jboss.org Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom parent-groupid org.jboss Medium
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor pom name JBoss Logging 3 High
Vendor manifest Bundle-Description The JBoss Logging Framework Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Vendor central groupid org.jboss.logging Highest
Vendor Manifest os-name Linux Medium
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor pom parent-artifactid jboss-parent Low
Vendor pom groupid jboss.logging Highest
Vendor pom groupid org.jboss.logging Highest
Vendor file name jboss-logging High
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom url http://www.jboss.org Highest
Product Manifest specification-title JBoss Logging 3 Medium
Product Manifest build-timestamp Thu, 28 May 2015 09:49:28 -0700 Low
Product pom description The JBoss Logging Framework Medium
Product Manifest Implementation-Title JBoss Logging 3 High
Product Manifest implementation-url http://www.jboss.org Low
Product central artifactid jboss-logging Highest
Product Manifest Bundle-Name JBoss Logging 3 Medium
Product pom name JBoss Logging 3 High
Product pom parent-groupid org.jboss Low
Product pom artifactid jboss-logging Highest
Product manifest Bundle-Description The JBoss Logging Framework Medium
Product pom parent-artifactid jboss-parent Medium
Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Product Manifest os-name Linux Medium
Product Manifest bundle-docurl http://www.jboss.org Low
Product pom url http://www.jboss.org Medium
Product pom groupid jboss.logging Low
Product file name jboss-logging High
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Version central version 3.3.0.Final Highest
Version pom version 3.3.0.Final Highest
Version Manifest Implementation-Version 3.3.0.Final High
Version file version 3.3.0 Highest
exo.kernel.component.ext.cache.impl.infinispan.v8-6.0.x-SNAPSHOT.jar
Description: Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.ext.cache.impl.infinispan.v8/6.0.x-SNAPSHOT/exo.kernel.component.ext.cache.impl.infinispan.v8-6.0.x-SNAPSHOT.jar
MD5: e6f5afb88163e7a90e2e9d051f873051
SHA1: 02154b5970536c8129f7391e8e895957d57e7ce5
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.kernel.component.ext.cache.impl.infinispan.v8 Low
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor file name exo.kernel.component.ext.cache.impl.infinispan.v8 High
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid kernel-parent Low
Vendor pom name eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Vendor pom description Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom groupid exoplatform.kernel Highest
Product pom groupid exoplatform.kernel Low
Product pom parent-artifactid kernel-parent Medium
Product file name exo.kernel.component.ext.cache.impl.infinispan.v8 High
Product Manifest specification-title exo-kernel Medium
Product pom name eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Product pom parent-groupid org.exoplatform.kernel Low
Product pom artifactid exo.kernel.component.ext.cache.impl.infinispan.v8 Highest
Product Manifest Implementation-Title eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Product pom description Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project. Medium
Version pom version 6.0.x-20191006.135433-6 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.ext.cache.impl.infinispan.v8:6.0.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:infinispan:infinispan:6.0.0
Confidence :Highest
suppress
Published Vulnerabilities
CVE-2016-0750 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-15089 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-2638 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
CWE: CWE-287 Improper Authentication
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Vulnerable Software & Versions: (show all )
exo.core.component.database-6.0.x-SNAPSHOT.jar
Description: Implementation of Database Service of Exoplatform SAS eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.database/6.0.x-SNAPSHOT/exo.core.component.database-6.0.x-SNAPSHOT.jar
MD5: 14870e78a5eac97df541022f4cfe8eef
SHA1: 31ecd2bcaa90ee0ef4313a44cfb606c860e264a5
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor file name exo.core.component.database High
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom name eXo PLF Core :: Component :: Database Service High
Vendor pom description Implementation of Database Service of Exoplatform SAS eXo Core' project. Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor pom groupid org.exoplatform.core Highest
Vendor pom artifactid exo.core.component.database Low
Vendor pom parent-artifactid core-parent Low
Product Manifest specification-title exo-core Medium
Product file name exo.core.component.database High
Product pom artifactid exo.core.component.database Highest
Product pom name eXo PLF Core :: Component :: Database Service High
Product pom parent-artifactid core-parent Medium
Product pom description Implementation of Database Service of Exoplatform SAS eXo Core' project. Medium
Product pom groupid exoplatform.core Low
Product pom parent-groupid org.exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: Database Service High
Version pom version 6.0.x-20191006.143710-7 Highest
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.database:6.0.x-SNAPSHOT
Confidence :High
staxnav.core-0.9.8.jar
File Path: /home/ciagent/.m2/repository/org/staxnav/staxnav.core/0.9.8/staxnav.core-0.9.8.jar
MD5: 0f786e5be21df9fbe8753175564564c7
SHA1: 27bd12d4d74b0851e38de79f8299462d93ba3d7f
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom name Staxnav - Core High
Vendor jar package name staxnav Low
Vendor pom parent-artifactid staxnav.parent Low
Vendor pom parent-groupid org.staxnav Medium
Vendor file name staxnav.core High
Vendor central groupid org.staxnav Highest
Vendor pom artifactid staxnav.core Low
Vendor pom groupid org.staxnav Highest
Vendor pom groupid staxnav Highest
Product pom name Staxnav - Core High
Product pom artifactid staxnav.core Highest
Product pom groupid staxnav Low
Product file name staxnav.core High
Product central artifactid staxnav.core Highest
Product pom parent-artifactid staxnav.parent Medium
Product pom parent-groupid org.staxnav Low
Version file version 0.9.8 Highest
Version central version 0.9.8 Highest
Version pom version 0.9.8 Highest
commons-lang3-3.3.2.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-lang3/3.3.2/commons-lang3-3.3.2.jar
MD5: 3128bf75a2549ebe38663401191bacab
SHA1: 90a3822c38ec8c996e84c16a3477ef632cbc87a3
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid org.apache.commons Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Vendor pom name Apache Commons Lang High
Vendor manifest Bundle-Description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-lang3 Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom groupid org.apache.commons Highest
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest implementation-build tags/LANG_3_3_2_RC1@r1585295; 2014-04-06 14:18:52+0200 Low
Vendor pom groupid apache.commons Highest
Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest
Vendor file name commons-lang3 High
Product pom artifactid commons-lang3 Highest
Product Manifest specification-title Apache Commons Lang Medium
Product pom url http://commons.apache.org/proper/commons-lang/ Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Product pom name Apache Commons Lang High
Product manifest Bundle-Description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product central artifactid commons-lang3 Highest
Product pom description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest implementation-build tags/LANG_3_3_2_RC1@r1585295; 2014-04-06 14:18:52+0200 Low
Product Manifest Implementation-Title Apache Commons Lang High
Product pom groupid apache.commons Low
Product file name commons-lang3 High
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Version file version 3.3.2 Highest
Version central version 3.3.2 Highest
Version pom version 3.3.2 Highest
Version Manifest Implementation-Version 3.3.2 High
dom4j-1.6.1.jar
Description: dom4j: the flexible XML framework for Java
File Path: /home/ciagent/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar
MD5: 4d8f51d3fe3900efc6e395be48030d6d
SHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor MetaStuff Ltd. High
Vendor pom artifactid dom4j Low
Vendor pom description dom4j: the flexible XML framework for Java Medium
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor Manifest specification-vendor MetaStuff Ltd. Low
Vendor pom groupid dom4j Highest
Vendor pom organization name MetaStuff Ltd. High
Vendor pom organization url http://sourceforge.net/projects/dom4j Medium
Vendor pom url http://dom4j.org Highest
Vendor file name dom4j High
Vendor central groupid dom4j High
Vendor pom name dom4j High
Vendor Manifest extension-name dom4j Medium
Product pom organization name MetaStuff Ltd. Low
Product pom artifactid dom4j Highest
Product central artifactid dom4j High
Product pom description dom4j: the flexible XML framework for Java Medium
Product pom groupid dom4j Low
Product pom url http://dom4j.org Medium
Product file name dom4j High
Product pom organization url http://sourceforge.net/projects/dom4j Low
Product Manifest specification-title dom4j : XML framework for Java Medium
Product pom name dom4j High
Product Manifest extension-name dom4j Medium
Product central artifactid dom4j-1.6.1 High
Product Manifest Implementation-Title org.dom4j High
Version Manifest Implementation-Version 1.6.1 High
Version file version 1.6.1 Highest
Published Vulnerabilities
CVE-2018-1000632 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-91 XML Injection (aka Blind XPath Injection)
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Vulnerable Software & Versions: (show all )
javassist-3.20.0-GA.jar
Description:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/
File Path: /home/ciagent/.m2/repository/org/javassist/javassist/3.20.0-GA/javassist-3.20.0-GA.jar
MD5: a89dd7907d76e061ec2c07e762a74256
SHA1: a9cbcdfb7e9f86fbc74d3afae65f2248bfbf82a0
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Vendor manifest Bundle-Description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Vendor file name javassist High
Vendor pom groupid javassist Highest
Vendor pom name Javassist High
Vendor pom url http://www.javassist.org/ Highest
Vendor central groupid org.javassist Highest
Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low
Vendor pom groupid org.javassist Highest
Vendor pom artifactid javassist Low
Vendor Manifest bundle-symbolicname javassist Medium
Vendor pom organization name Shigeru Chiba, www.javassist.org High
Product pom organization name Shigeru Chiba, www.javassist.org Low
Product pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Product manifest Bundle-Description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Product Manifest Bundle-Name Javassist Medium
Product pom url http://www.javassist.org/ Medium
Product pom artifactid javassist Highest
Product pom groupid javassist Low
Product file name javassist High
Product pom name Javassist High
Product Manifest specification-title Javassist Medium
Product Manifest bundle-symbolicname javassist Medium
Product central artifactid javassist Highest
Version file version 3.20.0 Highest
Version central version 3.20.0-GA Highest
Version pom version 3.20.0-GA Highest
hibernate-jpa-2.0-api-1.0.1.Final.jar
Description:
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
License:
license.txt
File Path: /home/ciagent/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.0-api/1.0.1.Final/hibernate-jpa-2.0-api-1.0.1.Final.jar
MD5: d7e7d8f60fc44a127ba702d43e71abec
SHA1: 3306a165afa81938fc3d8a0948e891de9f6b192b
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name hibernate-jpa-2.0-api-1.0.1.Final High
Vendor pom groupid hibernate.javax.persistence Highest
Vendor pom organization name Hibernate.org High
Vendor pom artifactid hibernate-jpa-2.0-api Low
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor Manifest Implementation-Vendor hibernate.org High
Vendor central groupid org.hibernate.javax.persistence Highest
Vendor pom name JPA 2.0 API High
Vendor pom url http://hibernate.org Highest
Vendor pom groupid org.hibernate.javax.persistence Highest
Vendor pom organization url http://hibernate.org Medium
Vendor pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Product file name hibernate-jpa-2.0-api-1.0.1.Final High
Product Manifest specification-title Java Persistence API, Version 2.0 Medium
Product pom name JPA 2.0 API High
Product pom groupid hibernate.javax.persistence Low
Product central artifactid hibernate-jpa-2.0-api Highest
Product pom url http://hibernate.org Medium
Product pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Product pom artifactid hibernate-jpa-2.0-api Highest
Product pom organization name Hibernate.org Low
Product Manifest Implementation-Title JPA API High
Product pom organization url http://hibernate.org Low
Version central version 1.0.1.Final Highest
Version pom version 1.0.1.Final Highest
Version Manifest Implementation-Version 1.0.1.Final High
jboss-logging-annotations-1.2.0.Beta1.jar
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging-annotations/1.2.0.Beta1/jboss-logging-annotations-1.2.0.Beta1.jar
MD5: 938e552e319015a8863dd91284aada54
SHA1: 2f437f37bb265d9f8f1392823dbca12d2bec06d6
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom artifactid jboss-logging-annotations Low
Vendor pom parent-artifactid jboss-logging-tools-parent Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor pom name JBoss Logging I18n Annotations High
Vendor Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Vendor file name jboss-logging-annotations High
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor central groupid org.jboss.logging Highest
Vendor Manifest os-name Linux Medium
Vendor pom parent-groupid org.jboss.logging Medium
Vendor pom groupid jboss.logging Highest
Vendor Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Vendor pom groupid org.jboss.logging Highest
Product pom artifactid jboss-logging-annotations Highest
Product central artifactid jboss-logging-annotations Highest
Product pom name JBoss Logging I18n Annotations High
Product Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Product pom parent-groupid org.jboss.logging Low
Product file name jboss-logging-annotations High
Product Manifest specification-title JBoss Logging I18n Annotations Medium
Product Manifest Implementation-Title JBoss Logging I18n Annotations High
Product Manifest os-name Linux Medium
Product pom groupid jboss.logging Low
Product Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Product pom parent-artifactid jboss-logging-tools-parent Medium
Version pom version 1.2.0.Beta1 Highest
Version Manifest Implementation-Version 1.2.0.Beta1 High
Version central version 1.2.0.Beta1 Highest
hibernate-commons-annotations-4.0.5.Final.jar
Description: Common reflection code used in support of annotation processing
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/common/hibernate-commons-annotations/4.0.5.Final/hibernate-commons-annotations-4.0.5.Final.jar
MD5: 5dadbafd7c7bc1168c10a2ba87e927a2
SHA1: 2a581b9edb8168e45060d8bad8b7f46712d2c52c
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid hibernate.common Highest
Vendor pom organization name Hibernate.org High
Vendor central groupid org.hibernate.common Highest
Vendor pom groupid org.hibernate.common Highest
Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Vendor pom artifactid hibernate-commons-annotations Low
Vendor pom name Hibernate Commons Annotations High
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom description Common reflection code used in support of annotation processing Medium
Vendor pom url http://hibernate.org Highest
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Vendor file name hibernate-commons-annotations High
Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Product pom artifactid hibernate-commons-annotations Highest
Product pom name Hibernate Commons Annotations High
Product pom organization name Hibernate.org Low
Product pom organization url http://hibernate.org Low
Product Manifest implementation-url http://hibernate.org Low
Product pom description Common reflection code used in support of annotation processing Medium
Product central artifactid hibernate-commons-annotations Highest
Product pom url http://hibernate.org Medium
Product file name hibernate-commons-annotations High
Product Manifest Bundle-Name hibernate-commons-annotations Medium
Product pom groupid hibernate.common Low
Version file version 4.0.5 Highest
Version central version 4.0.5.Final Highest
Version Manifest Implementation-Version 4.0.5.Final High
Version pom version 4.0.5.Final Highest
hibernate-entitymanager-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-entitymanager/4.2.21.Final/hibernate-entitymanager-4.2.21.Final.jar
MD5: 2c1a3f1c7bb83b730ab3db1fe588904e
SHA1: a6675070b4c7bb843d74d6ab3bc9440fd315dbb3
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description Hibernate ORM JPA Entity Manager Medium
Vendor pom organization name Hibernate.org High
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor pom groupid org.hibernate Highest
Vendor pom name A Hibernate O/RM Module High
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom artifactid hibernate-entitymanager Low
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom groupid hibernate Highest
Vendor pom url http://hibernate.org Highest
Vendor file name hibernate-entitymanager High
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest bundle-symbolicname org.hibernate.entitymanager Medium
Vendor central groupid org.hibernate Highest
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Product manifest Bundle-Description Hibernate ORM JPA Entity Manager Medium
Product pom description A module of the Hibernate O/RM project Medium
Product Manifest Bundle-Name hibernate-entitymanager Medium
Product pom artifactid hibernate-entitymanager Highest
Product pom name A Hibernate O/RM Module High
Product central artifactid hibernate-entitymanager Highest
Product pom organization name Hibernate.org Low
Product pom organization url http://hibernate.org Low
Product Manifest implementation-url http://hibernate.org Low
Product pom groupid hibernate Low
Product file name hibernate-entitymanager High
Product Manifest bundle-symbolicname org.hibernate.entitymanager Medium
Product pom url http://hibernate.org Medium
Version file version 4.2.21 Highest
Version Manifest Implementation-Version 4.2.21.Final High
Version pom version 4.2.21.Final Highest
Version central version 4.2.21.Final Highest
liquibase-core-3.4.2.jar
File Path: /home/ciagent/.m2/repository/org/liquibase/liquibase-core/3.4.2/liquibase-core-3.4.2.jar
MD5: d4ad6d5f7958b69b8fbd01a5564ae45b
SHA1: c91ccf342466857251cf6795b0cecc42509206f2
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.liquibase Highest
Vendor file name liquibase-core High
Vendor pom groupid liquibase Highest
Vendor pom artifactid liquibase-core Low
Vendor jar package name liquibase Low
Vendor pom parent-groupid org.liquibase Medium
Vendor pom parent-artifactid liquibase-parent Low
Vendor pom name Liquibase Core High
Vendor central groupid org.liquibase Highest
Product pom artifactid liquibase-core Highest
Product file name liquibase-core High
Product pom parent-artifactid liquibase-parent Medium
Product pom parent-groupid org.liquibase Low
Product pom groupid liquibase Low
Product central artifactid liquibase-core Highest
Product pom name Liquibase Core High
Version pom version 3.4.2 Highest
Version file version 3.4.2 Highest
Version central version 3.4.2 Highest
closure-compiler-externs-v20170910.jar
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler-externs/v20170910/closure-compiler-externs-v20170910.jar
MD5: 573e49fb83760d25b675028eb612e2b2
SHA1: 036e801a929fcd121d212093923daf34986f5572
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid closure-compiler-parent Low
Vendor pom parent-groupid com.google.javascript Medium
Vendor central groupid com.google.javascript Highest
Vendor file name closure-compiler-externs-v20170910 High
Vendor pom artifactid closure-compiler-externs Low
Vendor pom name Closure Compiler Externs High
Vendor pom groupid google.javascript Highest
Vendor pom groupid com.google.javascript Highest
Product central artifactid closure-compiler-externs Highest
Product file name closure-compiler-externs-v20170910 High
Product pom groupid google.javascript Low
Product pom parent-artifactid closure-compiler-parent Medium
Product pom name Closure Compiler Externs High
Product pom artifactid closure-compiler-externs Highest
Product pom parent-groupid com.google.javascript Low
Version file version 20170910 Medium
Version file name closure-compiler-externs-v20170910 Medium
Version pom version v20170910 Highest
Version central version v20170910 Highest
args4j-2.33.jar
Description: args4j : Java command line arguments parser
License:
http://www.opensource.org/licenses/mit-license.php
File Path: /home/ciagent/.m2/repository/args4j/args4j/2.33/args4j-2.33.jar
MD5: 0a6d515f76b15d29e3cd529de9319739
SHA1: bd87a75374a6d6523de82fef51fc3cfe9baf9fc9
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor central groupid args4j Highest
Vendor Manifest bundle-symbolicname org.kohsuke.args4j Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom name args4j High
Vendor pom artifactid args4j Low
Vendor file name args4j High
Vendor pom parent-artifactid args4j-site Low
Vendor manifest Bundle-Description args4j : Java command line arguments parser Medium
Vendor pom groupid args4j Highest
Vendor Manifest bundle-docurl http://www.kohsuke.org/ Low
Product Manifest bundle-symbolicname org.kohsuke.args4j Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom parent-artifactid args4j-site Medium
Product pom name args4j High
Product Manifest Bundle-Name args4j Medium
Product pom artifactid args4j Highest
Product file name args4j High
Product pom groupid args4j Low
Product manifest Bundle-Description args4j : Java command line arguments parser Medium
Product central artifactid args4j Highest
Product Manifest bundle-docurl http://www.kohsuke.org/ Low
Version central version 2.33 Highest
Version file version 2.33 Highest
Version pom version 2.33 Highest
error_prone_annotations-2.0.18.jar
File Path: /home/ciagent/.m2/repository/com/google/errorprone/error_prone_annotations/2.0.18/error_prone_annotations-2.0.18.jar
MD5: 98051758c08c9b7111b3268655069432
SHA1: 5f65affce1684999e2f4024983835efc3504012e
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor central groupid com.google.errorprone Highest
Vendor pom groupid com.google.errorprone Highest
Vendor pom artifactid error_prone_annotations Low
Vendor pom name error-prone annotations High
Vendor pom groupid google.errorprone Highest
Vendor jar package name google Low
Vendor pom parent-artifactid error_prone_parent Low
Vendor jar package name errorprone Low
Vendor jar package name annotations Low
Vendor file name error_prone_annotations High
Vendor pom parent-groupid com.google.errorprone Medium
Product pom name error-prone annotations High
Product pom parent-groupid com.google.errorprone Low
Product pom groupid google.errorprone Low
Product pom artifactid error_prone_annotations Highest
Product jar package name errorprone Low
Product jar package name annotations Low
Product central artifactid error_prone_annotations Highest
Product file name error_prone_annotations High
Product pom parent-artifactid error_prone_parent Medium
Version pom version 2.0.18 Highest
Version file version 2.0.18 Highest
Version central version 2.0.18 Highest
gson-2.7.jar
Description: Gson JSON library
File Path: /home/ciagent/.m2/repository/com/google/code/gson/gson/2.7/gson-2.7.jar
MD5: 5134a2350f58890ffb9db0b40047195d
SHA1: 751f548c85fa49f330cecbb1875893f971b33c4e
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor central groupid com.google.code.gson High
Vendor pom name Gson High
Vendor file name gson High
Vendor pom parent-groupid com.google.code.gson Medium
Vendor pom parent-artifactid gson-parent Low
Vendor Manifest bundle-symbolicname com.google.gson Medium
Vendor pom groupid com.google.code.gson Highest
Vendor manifest Bundle-Description Gson JSON library Medium
Vendor pom artifactid gson Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low
Vendor Manifest bundle-contactaddress https://github.com/google/gson Low
Vendor central groupid org.netbeans.external High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom groupid google.code.gson Highest
Product pom name Gson High
Product file name gson High
Product pom parent-artifactid gson-parent Medium
Product pom groupid google.code.gson Low
Product central artifactid com-google-gson High
Product Manifest bundle-symbolicname com.google.gson Medium
Product manifest Bundle-Description Gson JSON library Medium
Product central artifactid gson High
Product pom artifactid gson Highest
Product Manifest Bundle-Name Gson Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low
Product Manifest bundle-contactaddress https://github.com/google/gson Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom parent-groupid com.google.code.gson Low
Version central version 2.7 High
Version central version RELEASE110 High
Version central version RELEASE111 High
Version central version RELEASE100 High
Version file version 2.7 Highest
Version pom version 2.7 Highest
jsinterop-annotations-1.0.0.jar
File Path: /home/ciagent/.m2/repository/com/google/jsinterop/jsinterop-annotations/1.0.0/jsinterop-annotations-1.0.0.jar
MD5: 93302e3d0cc146097ecd08039dc1de52
SHA1: 23c3a3c060ffe4817e67673cc8294e154b0a4a95
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jsinterop-annotations Low
Vendor pom parent-groupid com.google.jsinterop Medium
Vendor pom parent-artifactid jsinterop Low
Vendor central groupid com.google.jsinterop Highest
Vendor jar package name annotations Low
Vendor pom groupid com.google.jsinterop Highest
Vendor file name jsinterop-annotations High
Vendor pom groupid google.jsinterop Highest
Vendor jar package name jsinterop Low
Product central artifactid jsinterop-annotations Highest
Product pom groupid google.jsinterop Low
Product jar package name annotations Low
Product pom parent-groupid com.google.jsinterop Low
Product pom artifactid jsinterop-annotations Highest
Product file name jsinterop-annotations High
Product pom parent-artifactid jsinterop Medium
Version pom version 1.0.0 Highest
Version central version 1.0.0 Highest
Version file version 1.0.0 Highest
closure-compiler-v20170910.jar
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar
MD5: ca8e9f88ba9aad9c5e2c0f8f937fe869
SHA1: 3b87499e9ed3f068e69889182ab95cff92de0932
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name closure-compiler-v20170910 High
Vendor jar package name google Low
Vendor central groupid com.google.javascript Highest
Vendor jar package name javascript Low
Vendor pom groupid com.google.javascript Highest
Product file name closure-compiler-v20170910 High
Product central artifactid closure-compiler Highest
Product jar package name javascript Low
Product pom artifactid closure-compiler Highest
Version file version 20170910 Medium
Version file name closure-compiler-v20170910 Medium
Version pom version v20170910 Highest
Version central version v20170910 Highest
commons-webui-component-6.0.x-SNAPSHOT.jar
File Path: /srv/ciagent/workspace/PLF/commons-develop-site/sources/commons-webui-component/target/commons-webui-component-6.0.x-SNAPSHOT.jar
MD5: 9e0d0437a8acee56ed47ea2c9982feaf
SHA1: da7b7976a134da2c2edcac5edde9b71f0e1f2826
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid commons-webui-component Low
Vendor pom name eXo PLF:: Commons - Commons WebUI High
Vendor Manifest date 2019-10-13T07:16:26Z Low
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-component Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor file name commons-webui-component High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.commons Highest
Vendor pom groupid org.exoplatform.commons Highest
Vendor pom parent-artifactid commons Low
Product pom artifactid commons-webui-component Highest
Product Manifest Implementation-Title eXo PLF:: Commons - Commons WebUI High
Product pom name eXo PLF:: Commons - Commons WebUI High
Product file name commons-webui-component High
Product Manifest date 2019-10-13T07:16:26Z Low
Product pom parent-artifactid commons Medium
Product Manifest specification-title eXo PLF:: Commons - Commons WebUI Medium
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-component Low
Product pom groupid exoplatform.commons Low
Product pom parent-groupid org.exoplatform.commons Low
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-webui-component:6.0.x-SNAPSHOT
Confidence :High
commons-api-6.0.x-SNAPSHOT.jar
File Path: /srv/ciagent/workspace/PLF/commons-develop-site/sources/commons-api/target/commons-api-6.0.x-SNAPSHOT.jar
MD5: 332b87dddaf0be269662405ecc51a34d
SHA1: a549807a3bf40b0c82c8fd19d03c14a76dab3dd4
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor file name commons-api High
Vendor Manifest date 2019-10-13T07:16:26Z Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.commons Highest
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-api Low
Vendor pom name eXo PLF:: Commons - API High
Vendor pom artifactid commons-api Low
Vendor pom parent-artifactid commons Low
Product pom artifactid commons-api Highest
Product file name commons-api High
Product Manifest date 2019-10-13T07:16:26Z Low
Product Manifest Implementation-Title eXo PLF:: Commons - API High
Product pom parent-artifactid commons Medium
Product Manifest specification-title eXo PLF:: Commons - API Medium
Product pom groupid exoplatform.commons Low
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-api Low
Product pom name eXo PLF:: Commons - API High
Version pom version 6.0.x-SNAPSHOT Highest
Version file version 6.0 Highest
Version Manifest Implementation-Version 6.0.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-api:6.0.x-SNAPSHOT
Confidence :High
bayeux-api-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/bayeux-api/3.0.8/bayeux-api-3.0.8.jar
MD5: a09842b7f274cefffa408299b5fc8dd0
SHA1: d5aceb0e7fef4a140f7e95be48338b97723d3163
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom artifactid bayeux-api Low
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-symbolicname bayeux-api Medium
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/bayeux-api Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor file name bayeux-api High
Vendor pom name CometD :: Bayeux API High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid cometd-java Medium
Product Manifest Bundle-Name CometD :: Bayeux API Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom artifactid bayeux-api Highest
Product Manifest bundle-symbolicname bayeux-api Medium
Product pom parent-groupid org.cometd.java Low
Product central artifactid bayeux-api Highest
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/bayeux-api Low
Product pom groupid cometd.java Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product file name bayeux-api High
Product pom name CometD :: Bayeux API High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-common-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-common/3.0.8/cometd-java-common-3.0.8.jar
MD5: 70c7cc13ecc20634a6b357e33134d551
SHA1: 5e2134a1b3bc6e03b7e1666a74e9993d0bb52a7d
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-common Low
Vendor file name cometd-java-common High
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom parent-artifactid cometd-java Low
Vendor pom name CometD :: Java :: Bayeux Common High
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-symbolicname cometd-java-common Medium
Vendor pom artifactid cometd-java-common Low
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid cometd-java Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-common Low
Product file name cometd-java-common High
Product pom name CometD :: Java :: Bayeux Common High
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product central artifactid cometd-java-common Highest
Product Manifest bundle-symbolicname cometd-java-common Medium
Product pom parent-groupid org.cometd.java Low
Product pom artifactid cometd-java-common Highest
Product Manifest Bundle-Name CometD :: Java :: Bayeux Common Medium
Product pom groupid cometd.java Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-websocket-javax-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-javax-server/3.0.8/cometd-java-websocket-javax-server-3.0.8.jar
MD5: afa5e80138d48292a6f93b708257d2fc
SHA1: 353860f809886a58c181dd9e273ee7b79e133277
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-server Low
Vendor pom name CometD :: Java :: WebSocket :: JSR 356 Server High
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor Manifest bundle-symbolicname cometd-java-websocket-javax-server Medium
Vendor pom groupid cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor pom artifactid cometd-java-websocket-javax-server Low
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor file name cometd-java-websocket-javax-server High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-server Low
Product pom name CometD :: Java :: WebSocket :: JSR 356 Server High
Product central artifactid cometd-java-websocket-javax-server Highest
Product pom artifactid cometd-java-websocket-javax-server Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-symbolicname cometd-java-websocket-javax-server Medium
Product pom parent-artifactid cometd-java-websocket Medium
Product pom parent-groupid org.cometd.java Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: JSR 356 Server Medium
Product pom groupid cometd.java Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product file name cometd-java-websocket-javax-server High
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-websocket-common-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-common-server/3.0.8/cometd-java-websocket-common-server-3.0.8.jar
MD5: 5772b2360cec4ff610e62151fb4deb62
SHA1: 61538a1231b700bf045fa197514f63509960985e
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname cometd-java-websocket-common-server Medium
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-server Low
Vendor pom name CometD :: Java :: WebSocket :: Common Server High
Vendor pom artifactid cometd-java-websocket-common-server Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor file name cometd-java-websocket-common-server High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest bundle-symbolicname cometd-java-websocket-common-server Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-server Low
Product pom name CometD :: Java :: WebSocket :: Common Server High
Product central artifactid cometd-java-websocket-common-server Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom artifactid cometd-java-websocket-common-server Highest
Product pom parent-groupid org.cometd.java Low
Product pom groupid cometd.java Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: Common Server Medium
Product Manifest bundle-docurl http://docs.cometd.org Low
Product file name cometd-java-websocket-common-server High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-annotations-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-annotations/3.0.8/cometd-java-annotations-3.0.8.jar
MD5: 98b60697675562cf957655c3239a1ad3
SHA1: 5b56875b2ac024b5666633596abb90702ec35e81
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom parent-artifactid cometd-java Low
Vendor pom name CometD :: Java :: Annotations High
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor Manifest bundle-symbolicname cometd-java-annotations Medium
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-annotations Low
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor pom artifactid cometd-java-annotations Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor file name cometd-java-annotations High
Product pom parent-artifactid cometd-java Medium
Product central artifactid cometd-java-annotations Highest
Product pom name CometD :: Java :: Annotations High
Product pom artifactid cometd-java-annotations Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-symbolicname cometd-java-annotations Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-annotations Low
Product pom parent-groupid org.cometd.java Low
Product pom groupid cometd.java Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest Bundle-Name CometD :: Java :: Annotations Medium
Product file name cometd-java-annotations High
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
jetty-io-9.2.14.v20151106.jar
Description: Administrative parent pom for Jetty modules
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-io/9.2.14.v20151106/jetty-io-9.2.14.v20151106.jar
MD5: 94d0e857144c7615b6fd65019cd32b59
SHA1: dfa4137371a3f08769820138ca1a2184dacda267
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.eclipse.jetty Medium
Vendor file name jetty-io High
Vendor pom groupid eclipse.jetty Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Vendor pom url http://www.eclipse.org/jetty Highest
Vendor manifest Bundle-Description Administrative parent pom for Jetty modules Medium
Vendor Manifest bundle-docurl http://www.eclipse.org/jetty Low
Vendor pom name Jetty :: IO Utility High
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor pom artifactid jetty-io Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom parent-artifactid jetty-project Low
Vendor central groupid org.eclipse.jetty Highest
Product pom groupid eclipse.jetty Low
Product file name jetty-io High
Product Manifest Bundle-Name Jetty :: IO Utility Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Product pom url http://www.eclipse.org/jetty Medium
Product pom parent-groupid org.eclipse.jetty Low
Product manifest Bundle-Description Administrative parent pom for Jetty modules Medium
Product pom artifactid jetty-io Highest
Product Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product pom name Jetty :: IO Utility High
Product Manifest url http://www.eclipse.org/jetty Low
Product pom parent-artifactid jetty-project Medium
Product Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Product central artifactid jetty-io Highest
Version pom version 9.2.14.v20151106 Highest
Version Manifest Implementation-Version 9.2.14.v20151106 High
Version file version 9.2.14.v20151106 Highest
Version central version 9.2.14.v20151106 Highest
cometd-java-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-client/3.0.8/cometd-java-client-3.0.8.jar
MD5: 24f1367fb4d96fe70a3f07a1f48e447e
SHA1: 826d4ae9402e7c48cc98fe287389788134e4986f
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom artifactid cometd-java-client Low
Vendor Manifest bundle-symbolicname cometd-java-client Medium
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-client Low
Vendor pom groupid cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor file name cometd-java-client High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom name CometD :: Java :: Bayeux Client High
Product pom parent-artifactid cometd-java Medium
Product Manifest bundle-symbolicname cometd-java-client Medium
Product Manifest Bundle-Name CometD :: Java :: Bayeux Client Medium
Product pom artifactid cometd-java-client Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-client Low
Product pom parent-groupid org.cometd.java Low
Product file name cometd-java-client High
Product pom groupid cometd.java Low
Product central artifactid cometd-java-client Highest
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom name CometD :: Java :: Bayeux Client High
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-websocket-common-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-common-client/3.0.8/cometd-java-websocket-common-client-3.0.8.jar
MD5: c17616c290c54ffc4a70dda2b901919a
SHA1: 8b75f11de5bba306d0bcb20a6c1bed89675579cd
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name cometd-java-websocket-common-client High
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-client Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-symbolicname cometd-java-websocket-common-client Medium
Vendor pom artifactid cometd-java-websocket-common-client Low
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom name CometD :: Java :: WebSocket :: Common Client High
Product file name cometd-java-websocket-common-client High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-client Low
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom parent-artifactid cometd-java-websocket Medium
Product Manifest bundle-symbolicname cometd-java-websocket-common-client Medium
Product pom parent-groupid org.cometd.java Low
Product pom artifactid cometd-java-websocket-common-client Highest
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: Common Client Medium
Product pom groupid cometd.java Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product central artifactid cometd-java-websocket-common-client Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom name CometD :: Java :: WebSocket :: Common Client High
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-websocket-javax-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-javax-client/3.0.8/cometd-java-websocket-javax-client-3.0.8.jar
MD5: 433dd449f689697bbe1a75b0ed2788f8
SHA1: b44bcf098667f0112301d75f73adb5ba3295699d
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom name CometD :: Java :: WebSocket :: JSR 356 Client High
Vendor Manifest bundle-symbolicname cometd-java-websocket-javax-client Medium
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor pom artifactid cometd-java-websocket-javax-client Low
Vendor file name cometd-java-websocket-javax-client High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-client Low
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom artifactid cometd-java-websocket-javax-client Highest
Product pom parent-groupid org.cometd.java Low
Product central artifactid cometd-java-websocket-javax-client Highest
Product pom name CometD :: Java :: WebSocket :: JSR 356 Client High
Product pom groupid cometd.java Low
Product Manifest bundle-symbolicname cometd-java-websocket-javax-client Medium
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: JSR 356 Client Medium
Product file name cometd-java-websocket-javax-client High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-client Low
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
cometd-java-oort-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-oort/3.0.8/cometd-java-oort-3.0.8.jar
MD5: 62dbbecedab27927495fc9c9e0b70505
SHA1: a72695546e010c250ba65519fc91867b208fc8f9
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-oort Low
Vendor file name cometd-java-oort High
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom parent-artifactid cometd-java Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid cometd.java Highest
Vendor central groupid org.cometd.java Highest
Vendor pom groupid org.cometd.java Highest
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor pom name CometD :: Java :: Oort High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid cometd-java-oort Low
Vendor Manifest bundle-symbolicname cometd-java-oort Medium
Product pom parent-artifactid cometd-java Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-oort Low
Product file name cometd-java-oort High
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom artifactid cometd-java-oort Highest
Product pom parent-groupid org.cometd.java Low
Product pom groupid cometd.java Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product pom name CometD :: Java :: Oort High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest Bundle-Name CometD :: Java :: Oort Medium
Product central artifactid cometd-java-oort Highest
Product Manifest bundle-symbolicname cometd-java-oort Medium
Version pom version 3.0.8 Highest
Version central version 3.0.8 Highest
Version file version 3.0.8 Highest
jetty-jmx-9.2.14.v20151106.jar
Description: JMX management artifact for jetty.
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-jmx/9.2.14.v20151106/jetty-jmx-9.2.14.v20151106.jar
MD5: 5eccc25d22921cb4787812d0687a2978
SHA1: 617edc5e966b4149737811ef8b289cd94b831bab
Referenced In Project/Scope:
eXo PLF:: Commons - Commons Extension Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name jetty-jmx High
Vendor pom parent-groupid org.eclipse.jetty Medium
Vendor manifest Bundle-Description JMX management artifact for jetty. Medium
Vendor pom groupid eclipse.jetty Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Vendor pom url http://www.eclipse.org/jetty Highest
Vendor Manifest bundle-docurl http://www.eclipse.org/jetty Low
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor pom description JMX management artifact for jetty. Medium
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor pom artifactid jetty-jmx Low
Vendor pom name Jetty :: JMX Management High
Vendor pom groupid org.eclipse.jetty Highest
Vendor pom parent-artifactid jetty-project Low
Vendor Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Vendor central groupid org.eclipse.jetty Highest
Product file name jetty-jmx High
Product pom groupid eclipse.jetty Low
Product manifest Bundle-Description JMX management artifact for jetty. Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest Bundle-Name Jetty :: JMX Management Medium
Product Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Product pom url http://www.eclipse.org/jetty Medium
Product pom parent-groupid org.eclipse.jetty Low
Product Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product pom artifactid jetty-jmx Highest
Product Manifest url http://www.eclipse.org/jetty Low
Product pom parent-artifactid jetty-project Medium
Product pom description JMX management artifact for jetty. Medium
Product central artifactid jetty-jmx Highest
Product pom name Jetty :: JMX Management High
Product Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Version pom version 9.2.14.v20151106 Highest
Version Manifest Implementation-Version 9.2.14.v20151106 High
Version file version 9.2.14.v20151106 Highest
Version central version 9.2.14.v20151106 Highest
Related Dependencies
jetty-util-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-util/9.2.14.v20151106/jetty-util-9.2.14.v20151106.jar
SHA1: 0057e00b912ae0c35859ac81594a996007706a0b
MD5: 15eae2dc1689fa8c72652b156d2619d3
maven: org.eclipse.jetty:jetty-util:9.2.14.v20151106 ✓
jetty-client-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-client/9.2.14.v20151106/jetty-client-9.2.14.v20151106.jar
SHA1: d02985c3a5bd974dacbb4c3d7cf71169135a8e7a
MD5: c400f74ab61fc17fafd19144b548bede
maven: org.eclipse.jetty:jetty-client:9.2.14.v20151106 ✓
jetty-http-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-http/9.2.14.v20151106/jetty-http-9.2.14.v20151106.jar
SHA1: 699ad1f2fa6fb0717e1b308a8c9e1b8c69d81ef6
MD5: 2e42ff59b2a5e8525f0fa1b55351d161
maven: org.eclipse.jetty:jetty-http:9.2.14.v20151106 ✓
jetty-util-ajax-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-util-ajax/9.2.14.v20151106/jetty-util-ajax-9.2.14.v20151106.jar
SHA1: 13470555681de54a10cfed3ab15b1554765d1171
MD5: 1623fc2d77b1bd864a2416e2da15cd9b
maven: org.eclipse.jetty:jetty-util-ajax:9.2.14.v20151106 ✓
Published Vulnerabilities
CVE-2017-7656 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.
Vulnerable Software & Versions: (show all )
CVE-2017-7657 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-190 Integer Overflow or Wraparound
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.
Vulnerable Software & Versions: (show all )