Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: google group | github issues

Project: eXo PLF:: Commons

org.exoplatform.commons:commons:6.0.x-SNAPSHOT

Scan Information (show all):

Display: Showing Vulnerable Dependencies (click to show all)

Dependency CPE Coordinates Highest Severity CVE Count CPE Confidence Evidence Count
jcr-1.0.1.jar cpe:/a:content_project:content:1.0.1 javax.jcr:jcr:1.0.1 Medium 1 Low 25
commons-chain-1.2.jar commons-chain:commons-chain:1.2    0 34
commons-digester-2.1.jar commons-digester:commons-digester:2.1    0 34
exo.kernel.component.command-6.0.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.component.command:6.0.x-SNAPSHOT   0 24
mail-1.4.7.jar cpe:/a:sun:javamail:1.4.7 javax.mail:mail:1.4.7    0 Low 38
commons-dbcp-1.4.jar commons-dbcp:commons-dbcp:1.4    0 34
commons-pool-1.6.jar commons-pool:commons-pool:1.6    0 36
exo.kernel.component.common-6.0.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.component.common:6.0.x-SNAPSHOT   0 22
exo.kernel.component.cache-6.0.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.component.cache:6.0.x-SNAPSHOT   0 24
exo.core.component.security.core-6.0.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.security.core:6.0.x-SNAPSHOT   0 22
antlr-2.7.7.jar antlr:antlr:2.7.7    0 18
dom4j-1.6.1.jar cpe:/a:dom4j_project:dom4j:1.6.1 dom4j:dom4j:1.6.1  Medium 1 Highest 28
hibernate-jpa-2.0-api-1.0.1.Final.jar org.hibernate.javax.persistence:hibernate-jpa-2.0-api:1.0.1.Final    0 26
jboss-logging-annotations-1.2.0.Beta1.jar org.jboss.logging:jboss-logging-annotations:1.2.0.Beta1    0 30
hibernate-commons-annotations-4.0.5.Final.jar org.hibernate.common:hibernate-commons-annotations:4.0.5.Final    0 30
hibernate-core-4.2.21.Final.jar org.hibernate:hibernate-core:4.2.21.Final    0 32
exo.core.component.organization.api-6.0.x-SNAPSHOT.jar cpe:/a:api-platform:core:6.0 org.exoplatform.core:exo.core.component.organization.api:6.0.x-SNAPSHOT   0 Low 22
commons-io-2.4.jar commons-io:commons-io:2.4    0 36
fontbox-1.8.14.jar cpe:/a:apache:pdfbox:1.8.14 org.apache.pdfbox:fontbox:1.8.14  Medium 2 Highest 37
jempbox-1.8.14.jar cpe:/a:apache:pdfbox:1.8.14 org.apache.pdfbox:jempbox:1.8.14  Medium 2 Highest 35
pdfbox-1.8.14.jar cpe:/a:apache:pdfbox:1.8.14 org.apache.pdfbox:pdfbox:1.8.14  Medium 2 Highest 35
htmllexer-2.1.jar org.htmlparser:htmllexer:2.1    0 23
htmlparser-2.1.jar org.htmlparser:htmlparser:2.1    0 23
poi-3.13.jar cpe:/a:apache:poi:3.13 org.apache.poi:poi:3.13  High 2 Highest 28
tika-core-1.5.jar cpe:/a:apache:tika:1.5 org.apache.tika:tika-core:1.5  High 8 Highest 33
vorbis-java-core-0.1-tests.jar org.gagravarr:vorbis-java-core:0.1    0 23
vorbis-java-tika-0.1.jar cpe:/a:apache:tika:0.1 org.gagravarr:vorbis-java-tika:0.1  High 6 Highest 23
netcdf-4.2-min.jar edu.ucar:netcdf:4.2-min    0 21
apache-mime4j-core-0.7.2.jar cpe:/a:apache:james:0.7.2 org.apache.james:apache-mime4j-core:0.7.2    0 Low 33
xz-1.2.jar cpe:/a:tukaani:xz:1.2 org.tukaani:xz:1.2  Medium 1 Low 27
commons-compress-1.5.jar cpe:/a:apache:commons_compress:1.5
cpe:/a:apache:commons-compress:1.5
org.apache.commons:commons-compress:1.5    0 Low 39
bcmail-jdk15-1.45.jar cpe:/a:no-cms_project:no-cms:1.45
cpe:/a:mime_project:mime:1.45
org.bouncycastle:bcmail-jdk15:1.45    0 Low 24
bcprov-jdk15-1.45.jar cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.45
cpe:/a:bouncycastle:bouncy_castle_crypto_package:1.45
org.bouncycastle:bcprov-jdk15:1.45  Medium 1 Low 24
tagsoup-1.2.1.jar org.ccil.cowan.tagsoup:tagsoup:1.2.1    0 18
asm-debug-all-4.1.jar cpe:/a:debug_project:debug:4.1 org.ow2.asm:asm-debug-all:4.1    0 Low 28
isoparser-1.0-RC-1.jar cpe:/a:boxes_project:boxes:7.x-1.0 com.googlecode.mp4parser:isoparser:1.0-RC-1  Low 1 Highest 24
xmpcore-5.1.2.jar com.adobe.xmp:xmpcore:5.1.2    0 30
xercesImpl-2.9.1.jar cpe:/a:apache:xerces2_java:2.9.1 xerces:xercesImpl:2.9.1  High 1 Low 50
metadata-extractor-2.6.2.jar com.drewnoakes:metadata-extractor:2.6.2    0 21
rome-1.0.jar rome:rome:1.0    0 32
vorbis-java-core-0.1.jar org.gagravarr:vorbis-java-core:0.1    0 21
juniversalchardet-1.0.3.jar org.zenframework.z8.dependencies.commons:juniversalchardet-1.0.3:2.0    0 26
jhighlight-1.0.jar com.uwyn:jhighlight:1.0    0 25
xmlbeans-2.6.0.jar org.apache.xmlbeans:xmlbeans:2.6.0    0 24
exo.core.component.document-6.0.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.document:6.0.x-SNAPSHOT   0 24
exo.core.component.database-6.0.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.database:6.0.x-SNAPSHOT   0 24
lucene-core-3.6.2.jar org.apache.lucene:lucene-core:3.6.2    0 26
lucene-analyzers-3.6.2.jar org.apache.lucene:lucene-analyzers:3.6.2    0 26
lucene-spellchecker-3.6.2.jar org.apache.lucene:lucene-spellchecker:3.6.2    0 26
jta-1.1.jar javax.transaction:transaction-api:1.1    0 22
concurrent-1.3.4.jar concurrent:concurrent:1.3.4    0 23
commons-collections-3.2.2.jar cpe:/a:apache:commons_collections:3.2.2 commons-collections:commons-collections:3.2.2    0 Low 40
jgroups-3.6.13.Final.jar org.jgroups:jgroups:3.6.13.Final    0 32
jbossjta-4.16.6.Final.jar org.jboss.jbossts:jbossjta:4.16.6.Final    0 22
ws-commons-util-1.0.1.jar cpe:/a:ws_project:ws:1.0.1 ws-commons-util:ws-commons-util:1.0.1  Medium 1 Low 30
jboss-common-core-2.2.22.GA.jar org.jboss:jboss-common-core:2.2.22.GA    0 30
stringtemplate-3.2.1.jar cpe:/a:string_project:string:3.2.1::~~~node.js~~ org.antlr:stringtemplate:3.2.1  Medium 1 Highest 23
antlr-runtime-3.5.jar org.antlr:antlr-runtime:3.5    0 26
exo.kernel.component.ext.cache.impl.infinispan.v8-6.0.x-SNAPSHOT.jar cpe:/a:infinispan:infinispan:6.0.0 org.exoplatform.kernel:exo.kernel.component.ext.cache.impl.infinispan.v8:6.0.x-SNAPSHOT Medium 3 Highest 24
jboss-marshalling-osgi-2.0.0.Beta3.jar org.jboss.marshalling:jboss-marshalling-osgi:2.0.0.Beta3    0 29
infinispan-core-8.2.6.Final.jar cpe:/a:infinispan:infinispan:8.2.6 org.infinispan:infinispan-core:8.2.6.Final  Medium 3 Highest 35
exo.jcr.component.core-6.0.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.component.core:6.0.x-SNAPSHOT   0 24
jtidy-r938.jar cpe:/a:html-tidy:tidy:- net.sf.jtidy:jtidy:r938    0 Low 25
exo.core.component.xml-processing-6.0.x-SNAPSHOT.jar cpe:/a:processing:processing:6.0.20191006 org.exoplatform.core:exo.core.component.xml-processing:6.0.x-SNAPSHOT   0 Low 24
groovy-all-2.4.12.jar cpe:/a:apache:groovy:2.4.12 org.codehaus.groovy:groovy-all:2.4.12    0 Low 36
exo.core.component.script.groovy-6.0.x-SNAPSHOT.jar org.exoplatform.core:exo.core.component.script.groovy:6.0.x-SNAPSHOT   0 22
exo.jcr.component.ext-6.0.x-SNAPSHOT.jar org.exoplatform.jcr:exo.jcr.component.ext:6.0.x-SNAPSHOT   0 24
mime-util-2.1.3.jar cpe:/a:mime_project:mime:2.1.3 eu.medsea.mimeutil:mime-util:2.1.3    0 Low 30
jakarta-regexp-1.4.jar jakarta-regexp:jakarta-regexp:1.4    0 14
xpp3-1.1.6.jar org.ogce:xpp3:1.1.6    0 24
slf4j-api-1.7.18.jar org.slf4j:slf4j-api:1.7.18    0 31
exo.kernel.commons-6.0.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.commons:6.0.x-SNAPSHOT   0 24
commons-beanutils-1.8.3.jar cpe:/a:apache:commons_beanutils:1.8.3 commons-beanutils:commons-beanutils:1.8.3  High 2 Low 34
common-common-2.2.2.Final.jar org.gatein.common:common-common:2.2.2.Final    0 31
wci-wci-6.0.x-SNAPSHOT.jar org.exoplatform.gatein.wci:wci-wci:6.0.x-SNAPSHOT   0 29
jibx-run-1.2.6.jar org.jibx:jibx-run:1.2.6    0 29
javax.inject-1.jar javax.inject:javax.inject:1    0 20
cdi-api-1.0-SP4.jar javax.enterprise:cdi-api:1.0-SP4    0 31
exo.kernel.container-6.0.x-SNAPSHOT.jar org.exoplatform.kernel:exo.kernel.container:6.0.x-SNAPSHOT   0 24
xpp3-1.1.4c.jar xpp3:xpp3:1.1.4c    0 26
picocontainer-1.1.jar picocontainer:picocontainer:1.1    0 28
xmlpull-1.1.3.1.jar xmlpull:xmlpull:1.1.3.1    0 18
xpp3_min-1.1.4c.jar xpp3:xpp3_min:1.1.4c    0 24
xstream-1.4.10.jar cpe:/a:xstream_project:xstream:1.4.10 com.thoughtworks.xstream:xstream:1.4.10  High 2 Highest 53
chromattic.api-1.3.0.jar org.chromattic:chromattic.api:1.3.0    0 23
chromattic.spi-1.3.0.jar org.chromattic:chromattic.spi:1.3.0    0 25
staxnav.core-0.9.8.jar org.staxnav:staxnav.core:0.9.8    0 19
javassist-3.20.0-GA.jar org.javassist:javassist:3.20.0-GA    0 27
hibernate-entitymanager-4.2.21.Final.jar org.hibernate:hibernate-entitymanager:4.2.21.Final    0 32
liquibase-core-3.4.2.jar org.liquibase:liquibase-core:3.4.2    0 19
pc-api-6.0.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-api:6.0.x-SNAPSHOT   0 27
pc-portlet-6.0.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-portlet:6.0.x-SNAPSHOT   0 29
pc-federation-6.0.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-federation:6.0.x-SNAPSHOT   0 29
pc-bridge-6.0.x-SNAPSHOT.jar org.exoplatform.gatein.pc:pc-bridge:6.0.x-SNAPSHOT   0 27
log4j-1.2.17.jar cpe:/a:apache:log4j:2.0:alpha1 log4j:log4j:1.2.17  High 1 High 33
stax-api-1.0-2.jar javax.xml.stream:stax-api:1.0-2    0 20
activation-1.1.1.jar javax.activation:activation:1.1.1    0 24
jaxb-api-2.1.jar javax.xml.bind:jaxb-api:2.1    0 15
jaxb-impl-2.1.8.jar com.sun.xml.bind:jaxb-impl:2.1.8    0 20
picketlink-idm-core-1.4.6.Final.jar cpe:/a:picketlink:picketlink:1.4.6 org.picketlink.idm:picketlink-idm-core:1.4.6.Final  Medium 3 Low 37
common-logging-2.2.2.Final.jar org.gatein.common:common-logging:2.2.2.Final    0 31
mop-api-1.3.2.Final.jar org.gatein.mop:mop-api:1.3.2.Final   0 30
mop-spi-1.3.2.Final.jar org.gatein.mop:mop-spi:1.3.2.Final   0 30
chromattic.ext-1.3.0.jar org.chromattic:chromattic.ext:1.3.0    0 25
chromattic.common-1.3.0.jar org.chromattic:chromattic.common:1.3.0    0 25
mop-core-1.3.2.Final.jar org.gatein.mop:mop-core:1.3.2.Final   0 30
gatein-management-api-2.1.0.Final.jar org.gatein.management:gatein-management-api:2.1.0.Final   0 28
gatein-management-spi-2.1.0.Final.jar org.gatein.management:gatein-management-spi:2.1.0.Final   0 28
commons-lang3-3.3.2.jar org.apache.commons:commons-lang3:3.3.2    0 37
json-20070829.jar org.json:json:20070829    0 23
exo.portal.webui.core-6.0.x-SNAPSHOT.jar cpe:/a:in-portal:in-portal:6.0.20191006 org.exoplatform.gatein.portal:exo.portal.webui.core:6.0.x-SNAPSHOT   0 Low 29
closure-compiler-externs-v20170910.jar com.google.javascript:closure-compiler-externs:v20170910    0 19
args4j-2.33.jar args4j:args4j:2.33    0 24
error_prone_annotations-2.0.18.jar com.google.errorprone:error_prone_annotations:2.0.18    0 23
gson-2.7.jar com.google.code.gson:gson:2.7    0 34
jsinterop-annotations-1.0.0.jar com.google.jsinterop:jsinterop-annotations:1.0.0    0 19
closure-compiler-v20170910.jar com.google.javascript:closure-compiler:v20170910    0 13
commons-webui-component-6.0.x-SNAPSHOT.jar org.exoplatform.commons:commons-webui-component:6.0.x-SNAPSHOT   0 24
commons-api-6.0.x-SNAPSHOT.jar org.exoplatform.commons:commons-api:6.0.x-SNAPSHOT   0 24
commons-lang-2.6.jar org.netbeans.external:org-apache-commons-lang:RELEASE90    0 34
jsr250-api-1.0.jar javax.annotation:jsr250-api:1.0    0 20
jsr311-api-1.1.1.jar javax.ws.rs:jsr311-api:1.1.1    0 28
javaparser-1.0.8.jar com.google.code.javaparser:javaparser:1.0.8   0 20
chromattic.testgenerator-1.3.0.jar org.chromattic:chromattic.testgenerator:1.3.0    0 23
chromattic.metamodel-1.3.0.jar org.chromattic:chromattic.metamodel:1.3.0    0 23
reflext.api-1.1.0.jar org.reflext:reflext.api:1.1.0    0 23
reflext.core-1.1.0.jar org.reflext:reflext.core:1.1.0    0 23
reflext.spi-1.1.0.jar org.reflext:reflext.spi:1.1.0    0 25
reflext.apt-1.1.0.jar cpe:/a:processing:processing:1.1.0 org.reflext:reflext.apt:1.1.0  Medium 1 Low 23
chromattic.apt-1.3.0.jar org.chromattic:chromattic.apt:1.3.0    0 23
reflext.jlr-1.1.0.jar org.reflext:reflext.jlr:1.1.0    0 23
chromattic.core-1.3.0.jar org.chromattic:chromattic.core:1.3.0    0 23
bayeux-api-3.0.8.jar org.cometd.java:bayeux-api:3.0.8    0 29
cometd-java-common-3.0.8.jar org.cometd.java:cometd-java-common:3.0.8    0 29
cometd-java-websocket-javax-server-3.0.8.jar org.cometd.java:cometd-java-websocket-javax-server:3.0.8    0 29
cometd-java-websocket-common-server-3.0.8.jar org.cometd.java:cometd-java-websocket-common-server:3.0.8    0 29
cometd-java-annotations-3.0.8.jar org.cometd.java:cometd-java-annotations:3.0.8    0 29
jetty-io-9.2.14.v20151106.jar org.eclipse.jetty:jetty-io:9.2.14.v20151106    0 35
cometd-java-client-3.0.8.jar org.cometd.java:cometd-java-client:3.0.8    0 29
cometd-java-websocket-common-client-3.0.8.jar org.cometd.java:cometd-java-websocket-common-client:3.0.8    0 29
cometd-java-websocket-javax-client-3.0.8.jar org.cometd.java:cometd-java-websocket-javax-client:3.0.8    0 29
cometd-java-oort-3.0.8.jar org.cometd.java:cometd-java-oort:3.0.8    0 29
jetty-jmx-9.2.14.v20151106.jar cpe:/a:jetty:jetty:9.2.14.v20151106
cpe:/a:eclipse:jetty:9.2.14.v20151106
org.eclipse.jetty:jetty-jmx:9.2.14.v20151106  High 4 Low 37
cometd-java-server-3.0.8.jar org.cometd.java:cometd-java-server:3.0.8    0 29
commons-comet-service-6.0.x-SNAPSHOT.jar org.exoplatform.commons:commons-comet-service:6.0.x-SNAPSHOT   0 24
commons-fileupload-1.3.3.jar cpe:/a:apache:commons_fileupload:1.3.3 commons-fileupload:commons-fileupload:1.3.3    0 Low 40
exo.ws.rest.core-6.0.x-SNAPSHOT.jar cpe:/a:ws_project:ws:6.0.20191006 org.exoplatform.ws:exo.ws.rest.core:6.0.x-SNAPSHOT   0 Low 24
twitter4j-core-3.0.5.jar cpe:/a:twitter_project:twitter:3.0.5
cpe:/a:twitter:twitter:3.0.5
org.twitter4j:twitter4j-core:3.0.5    0 Low 22
scribe-1.3.5.jar cpe:/a:scribe:scribe:1.3.5 org.scribe:scribe:1.3.5    0 Low 23
httpcore-4.3.3.jar org.apache.httpcomponents:httpcore:4.3.3    0 32
commons-logging-1.1.3.jar commons-logging:commons-logging:1.1.3    0 36
httpclient-4.3.6.jar cpe:/a:apache:httpclient:4.3.6 org.apache.httpcomponents:httpclient:4.3.6    0 Low 32
google-http-client-1.14.1-beta.jar cpe:/a:google_forms_project:google_forms:1.14.1.beta com.google.http-client:google-http-client:1.14.1-beta    0 Low 24
jsr305-1.3.9.jar com.google.code.findbugs:jsr305:1.3.9    0 21
google-api-client-1.14.1-beta.jar com.google.api-client:google-api-client:1.14.1-beta    0 22
jackson-core-asl-1.9.11.jar cpe:/a:fasterxml:jackson:1.9.11 org.codehaus.jackson:jackson-core-asl:1.9.11    0 Low 32
google-http-client-jackson-1.14.1-beta.jar com.google.http-client:google-http-client-jackson:1.14.1-beta    0 22
google-api-services-plus-v1-rev69-1.14.2-beta.jar com.google.apis:google-api-services-plus:v1-rev69-1.14.2-beta    0 26
google-api-services-oauth2-v2-rev36-1.14.2-beta.jar com.google.apis:google-api-services-oauth2:v2-rev36-1.14.2-beta    0 26
filters-2.0.235.jar cpe:/a:image_processing_software:image_processing_software:2.0.235 com.jhlabs:filters:2.0.235  Low 1 Low 22
simplecaptcha-1.1.1.Final-gatein-4.jar org.gatein.captcha:simplecaptcha:1.1.1.Final-gatein-4   0 27
gatein-api-1.0.1.Final.jar org.gatein.api:gatein-api:1.0.1.Final    0 29
icu4j-56.1.jar cpe:/a:icu-project:international_components_for_unicode:56.1::~~~c%2fc%2b%2b~~ com.ibm.icu:icu4j:56.1  High 8 Highest 33
aspectjrt-1.8.8.jar org.aspectj:aspectjrt:1.8.8    0 21
c3p0-0.9.1.1.jar cpe:/a:mchange:c3p0:0.9.1.1 c3p0:c3p0:0.9.1.1  Medium 1 Highest 23
quartz-2.2.2.jar org.quartz-scheduler:quartz:2.2.2    0 43
guava-20.0.jar cpe:/a:google:guava:20.0 com.google.guava:guava:20.0  Medium 1 Highest 29
commons-codec-1.10.jar commons-codec:commons-codec:1.10    0 38
owasp-java-html-sanitizer-20160413.1.jar cpe:/a:owasp-java-html-sanitizer_project:owasp-java-html-sanitizer:20160413.1 com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer:20160413.1    0 Low 21
jrcs.diff-0.4.2.jar org.jvnet.hudson:org.suigeneris.jrcs.diff:0.4.2    0 17
ecs-1.4.2.jar ecs:ecs:1.4.2    0 14
json-simple-1.1.1.jar com.googlecode.json-simple:json-simple:1.1.1    0 23
jackson-core-2.9.8.jar cpe:/a:fasterxml:jackson:2.9.8 com.fasterxml.jackson.core:jackson-core:2.9.8    0 Low 41
jackson-databind-2.9.8.jar cpe:/a:fasterxml:jackson:2.9.8
cpe:/a:fasterxml:jackson-databind:2.9.8
com.fasterxml.jackson.core:jackson-databind:2.9.8  High 10 Highest 41
snakeyaml-1.23.jar org.yaml:snakeyaml:1.23    0 25
jackson-dataformat-yaml-2.9.8.jar cpe:/a:fasterxml:jackson:2.9.8
cpe:/a:fasterxml:jackson-dataformat-xml:2.9.8
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.9.8    0 Low 41
swagger-annotations-1.5.22.jar io.swagger:swagger-annotations:1.5.22    0 24
swagger-models-1.5.22.jar io.swagger:swagger-models:1.5.22    0 24
validation-api-1.1.0.Final.jar javax.validation:validation-api:1.1.0.Final    0 22
swagger-core-1.5.22.jar io.swagger:swagger-core:1.5.22    0 24
reflections-0.9.11.jar org.reflections:reflections:0.9.11    0 25
swagger-jaxrs-1.5.22.jar io.swagger:swagger-jaxrs:1.5.22    0 24
commons-component-common-6.0.x-SNAPSHOT.jar org.exoplatform.commons:commons-component-common:6.0.x-SNAPSHOT   0 24
portlet-api-2.0.jar javax.portlet:portlet-api:2.0    0 22
jboss-logging-3.3.0.Final.jar org.jboss.logging:jboss-logging:3.3.0.Final    0 44
jcl-over-slf4j-1.7.18.jar org.slf4j:jcl-over-slf4j:1.7.18    0 31
javax.servlet-api-3.0.1.jar javax.servlet:javax.servlet-api:3.0.1    0 38
hamcrest-core-1.3.jar org.hamcrest:hamcrest-core:1.3    0 25
junit-4.12.jar junit:junit:4.12    0 25
jmock-1.0.1.jar jmock:jmock:1.0.1    0 14
platform-ui-skin-6.0.x-SNAPSHOT.war org.exoplatform.platform-ui:platform-ui-skin:6.0.x-SNAPSHOT   0 26
commons-httpclient-3.1.jar cpe:/a:apache:httpclient:3.1
cpe:/a:apache:commons-httpclient:3.1
commons-httpclient:commons-httpclient:3.1    0 Low 24
javax.websocket-api-1.0.jar javax.websocket:javax.websocket-api:1.0    0 29
cometd-javascript-jquery-3.0.8.war cpe:/a:jquery:jquery:3.0.8 org.cometd.javascript:cometd-javascript-jquery:3.0.8 Medium 1 Low 24
commons-component-product-6.0.x-SNAPSHOT.jar org.exoplatform.commons:commons-component-product:6.0.x-SNAPSHOT   0 26
jsf-api-1.2_13.jar cpe:/a:sun:jsf:1.2.13 javax.faces:jsf-api:1.2_13    0 Low 38
exo.tool.framework.junit-1.2.4-GA.jar org.exoplatform.tool:exo.tool.framework.junit:1.2.4-GA   0 25
jcip-annotations-1.0.jar net.jcip:jcip-annotations:1.0    0 20
exo.portal.component.test.core-6.0.x-SNAPSHOT.jar cpe:/a:in-portal:in-portal:6.0 org.exoplatform.gatein.portal:exo.portal.component.test.core:6.0.x-SNAPSHOT   0 Low 27
mockito-all-1.10.19.jar org.mockito:mockito-all:1.10.19    0 21
juzu-core-1.2.x-SNAPSHOT.jar org.juzu:juzu-core:1.2.x-SNAPSHOT   0 22
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling/pom.xml org.jboss.marshalling:jboss-marshalling:2.0.0.Beta3   0 13
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-river/pom.xml org.jboss.marshalling:jboss-marshalling-river:2.0.0.Beta3   0 13
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-serial/pom.xml org.jboss.marshalling:jboss-marshalling-serial:2.0.0.Beta3   0 13
closure-compiler-v20170910.jar/META-INF/maven/com.google.javascript/closure-compiler/pom.xml cpe:/a:google:gmail:- com.google.javascript:closure-compiler:v20170910 Medium 1 Low 15
closure-compiler-v20170910.jar/META-INF/maven/com.google.protobuf/protobuf-java/pom.xml cpe:/a:google:protobuf:3.0.2 com.google.protobuf:protobuf-java:3.0.2 Medium 1 Highest 13
closure-compiler-v20170910.jar/META-INF/maven/com.google.code.findbugs/jsr305/pom.xml com.google.code.findbugs:jsr305:3.0.1   0 11

Dependencies

jcr-1.0.1.jar

Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.

License:

Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

  • cpe: cpe:/a:content_project:content:1.0.1   Confidence:Low   
  • maven: javax.jcr:jcr:1.0.1   Confidence:High

CVE-2017-16111  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

Vulnerable Software & Versions:

commons-chain-1.2.jar

Description:  An implementation of the GoF Chain of Responsibility pattern

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-chain/commons-chain/1.2/commons-chain-1.2.jar
MD5: e18e2c87826644e4c8c08635572c154f
SHA1: 744a13e8766e338bd347b6fbc28c6db12979d0c6
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

commons-digester-2.1.jar

Description:  The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-digester/commons-digester/2.1/commons-digester-2.1.jar
MD5: 528445033f22da28f5047b6abcd1c7c9
SHA1: 73a8001e7a54a255eef0f03521ec1805dc738ca0
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

exo.kernel.component.command-6.0.x-SNAPSHOT.jar

Description: Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project.

File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.command/6.0.x-SNAPSHOT/exo.kernel.component.command-6.0.x-SNAPSHOT.jar
MD5: 6cd704efa2fd1fb9be83bdb727c5815d
SHA1: 7eec89696a2fa5e0eaf724e1b2468594e26f6bcf
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

  • maven: org.exoplatform.kernel:exo.kernel.component.command:6.0.x-SNAPSHOT   Confidence:High

mail-1.4.7.jar

Description: JavaMail API (compat)

License:

http://www.sun.com/cddl, https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /home/ciagent/.m2/repository/javax/mail/mail/1.4.7/mail-1.4.7.jar
MD5: 77f53ff0c78ba43c4812ecc9f53e20f8
SHA1: 9add058589d5d85adeb625859bf2c5eeaaedf12d
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

commons-dbcp-1.4.jar

Description: Commons Database Connection Pooling

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:runtime
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - Juzu Bridge for Platform:runtime
  • eXo PLF:: Commons - Commons WebUI:runtime
  • eXo PLF:: Commons - WebUI Extension:runtime
  • eXo PLF:: Commons - Product Informations:runtime
  • eXo PLF:: Commons - Comet Services:runtime
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:runtime
  • eXo PLF:: Commons - Comet Ext Service (test only):runtime
  • eXo PLF:: Commons - Common Services:runtime

Identifiers

commons-pool-1.6.jar

Description: Commons Object Pooling Library

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:runtime
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - Juzu Bridge for Platform:runtime
  • eXo PLF:: Commons - Commons WebUI:runtime
  • eXo PLF:: Commons - WebUI Extension:runtime
  • eXo PLF:: Commons - Product Informations:runtime
  • eXo PLF:: Commons - Comet Services:runtime
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:runtime
  • eXo PLF:: Commons - Comet Ext Service (test only):runtime
  • eXo PLF:: Commons - Common Services:runtime

Identifiers

exo.kernel.component.common-6.0.x-SNAPSHOT.jar

Description: Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project.

File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.common/6.0.x-SNAPSHOT/exo.kernel.component.common-6.0.x-SNAPSHOT.jar
MD5: 7d56b2a5181e482b340b4f0e9ee5e017
SHA1: bb1382baadbd0dd13685e7cc493f37dcf551896d
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

  • maven: org.exoplatform.kernel:exo.kernel.component.common:6.0.x-SNAPSHOT   Confidence:High

exo.kernel.component.cache-6.0.x-SNAPSHOT.jar

Description: Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project.

File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.cache/6.0.x-SNAPSHOT/exo.kernel.component.cache-6.0.x-SNAPSHOT.jar
MD5: 8b0d5bca7bccac22c8b49202e3af31d4
SHA1: fc7fd420984fb3a4f426029ce1353149fab42d35
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

  • maven: org.exoplatform.kernel:exo.kernel.component.cache:6.0.x-SNAPSHOT   Confidence:High

exo.core.component.security.core-6.0.x-SNAPSHOT.jar

Description: Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project.

File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.security.core/6.0.x-SNAPSHOT/exo.core.component.security.core-6.0.x-SNAPSHOT.jar
MD5: ed9e42743794ca109fb30bfe6543b076
SHA1: 1a774aae09ac563ecf77c7c78153a60c9c8e6bd0
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

  • maven: org.exoplatform.core:exo.core.component.security.core:6.0.x-SNAPSHOT   Confidence:High

antlr-2.7.7.jar

Description:  A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions.

License:

BSD License: http://www.antlr.org/license.html
File Path: /home/ciagent/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

dom4j-1.6.1.jar

Description: dom4j: the flexible XML framework for Java

File Path: /home/ciagent/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar
MD5: 4d8f51d3fe3900efc6e395be48030d6d
SHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

CVE-2018-1000632  

Severity: Medium
CVSS Score: 6.4 (AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-91 XML Injection (aka Blind XPath Injection)

dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.

Vulnerable Software & Versions: (show all)

hibernate-jpa-2.0-api-1.0.1.Final.jar

Description:  Hibernate definition of the Java Persistence 2.0 (JSR 317) API.

License:

license.txt
File Path: /home/ciagent/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.0-api/1.0.1.Final/hibernate-jpa-2.0-api-1.0.1.Final.jar
MD5: d7e7d8f60fc44a127ba702d43e71abec
SHA1: 3306a165afa81938fc3d8a0948e891de9f6b192b
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

jboss-logging-annotations-1.2.0.Beta1.jar

File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging-annotations/1.2.0.Beta1/jboss-logging-annotations-1.2.0.Beta1.jar
MD5: 938e552e319015a8863dd91284aada54
SHA1: 2f437f37bb265d9f8f1392823dbca12d2bec06d6
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

hibernate-commons-annotations-4.0.5.Final.jar

Description: Common reflection code used in support of annotation processing

License:

GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/common/hibernate-commons-annotations/4.0.5.Final/hibernate-commons-annotations-4.0.5.Final.jar
MD5: 5dadbafd7c7bc1168c10a2ba87e927a2
SHA1: 2a581b9edb8168e45060d8bad8b7f46712d2c52c
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

hibernate-core-4.2.21.Final.jar

Description: A module of the Hibernate O/RM project

License:

GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-core/4.2.21.Final/hibernate-core-4.2.21.Final.jar
MD5: 492567c1f36fb3a5968ca2d3c452edaf
SHA1: bb587d00287c13d9e4324bc76c13abbd493efa81
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

exo.core.component.organization.api-6.0.x-SNAPSHOT.jar

Description: API of Organization Service of Exoplatform SAS 'eXo Core' project.

File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.organization.api/6.0.x-SNAPSHOT/exo.core.component.organization.api-6.0.x-SNAPSHOT.jar
MD5: a7eb0f78ea4e73e5c8560e0697866970
SHA1: b5c9fa30c3833c3e0769a7bcf761c5366805a732
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Commons Search:provided
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime

Identifiers

  • maven: org.exoplatform.core:exo.core.component.organization.api:6.0.x-SNAPSHOT   Confidence:High
  • cpe: cpe:/a:api-platform:core:6.0   Confidence:Low   

commons-io-2.4.jar

Description:  The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-io/commons-io/2.4/commons-io-2.4.jar
MD5: 7f97854dc04c119d461fed14f5d8bb96
SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

fontbox-1.8.14.jar

Description:  The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/fontbox/1.8.14/fontbox-1.8.14.jar
MD5: 901640f7e2bd12508ae4a7cccba3df79
SHA1: 9c7caec614a6a132bedc83f1d6d247bb96ca0df3
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

CVE-2018-11797  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Vulnerable Software & Versions: (show all)

CVE-2018-8036  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

Vulnerable Software & Versions: (show all)

jempbox-1.8.14.jar

Description:  The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/jempbox/1.8.14/jempbox-1.8.14.jar
MD5: 393135759731daf4e301903b3de2fbbb
SHA1: 7f94c7cd4efc21e78729436cc4cf0c09eeea0f38
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

CVE-2018-11797  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Vulnerable Software & Versions: (show all)

CVE-2018-8036  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

Vulnerable Software & Versions: (show all)

pdfbox-1.8.14.jar

Description:  The Apache PDFBox library is an open source Java tool for working with PDF documents.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/pdfbox/1.8.14/pdfbox-1.8.14.jar
MD5: c90740e185fc2f8013d1119f509ea4f3
SHA1: 7550298240c8540b721733ede6dc88fcf4fa2b0f
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

CVE-2018-11797  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation

In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.

Vulnerable Software & Versions: (show all)

CVE-2018-8036  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.

Vulnerable Software & Versions: (show all)

htmllexer-2.1.jar

Description: HTML Lexer is the low level lexical analyzer.

File Path: /home/ciagent/.m2/repository/org/htmlparser/htmllexer/2.1/htmllexer-2.1.jar
MD5: 1cb7184766a0c52f4d98d671bb08be19
SHA1: 2ebf2c073e649b7e674cddd0558ff102a486402f
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

htmlparser-2.1.jar

Description: HTML Parser is the high level syntactical analyzer.

File Path: /home/ciagent/.m2/repository/org/htmlparser/htmlparser/2.1/htmlparser-2.1.jar
MD5: aa05b921026c228f92ef8b4a13c26f8d
SHA1: c752e5984b7767533cbd3fdffa48cecb52fa226c
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

poi-3.13.jar

Description: Apache POI - Java API To Access Microsoft Format Files

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi/3.13/poi-3.13.jar
MD5: 1b43f32e2211546040597a9e2d07b869
SHA1: 0f59f504ba8c521e61e25f417ec652fd485010f3
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

CVE-2016-5000  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')

The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Vulnerable Software & Versions:

CVE-2017-5644  

Severity: High
CVSS Score: 7.1 (AV:N/AC:M/Au:N/C:N/I:N/A:C)
CWE: CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

Vulnerable Software & Versions:

tika-core-1.5.jar

Description: This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-core/1.5/tika-core-1.5.jar
MD5: e864bf637f51283dc525087b015d7b1a
SHA1: 194ca0fb3d73b07737524806fbc3bec89063c03a
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

CVE-2016-6809  

Severity: High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

Vulnerable Software & Versions:

CVE-2018-11761  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

Vulnerable Software & Versions: (show all)

CVE-2018-11762  

Severity: Medium
CVSS Score: 5.8 (AV:N/AC:M/Au:N/C:N/I:P/A:P)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.

Vulnerable Software & Versions: (show all)

CVE-2018-11796  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')

In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.

Vulnerable Software & Versions: (show all)

CVE-2018-1335  

Severity: High
CVSS Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Vulnerable Software & Versions: (show all)

CVE-2018-1338  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.

Vulnerable Software & Versions: (show all)

CVE-2018-1339  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

Vulnerable Software & Versions: (show all)

CVE-2018-8017  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.

Vulnerable Software & Versions: (show all)

vorbis-java-core-0.1-tests.jar

File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-core/0.1/vorbis-java-core-0.1-tests.jar
MD5: d58f076c08a917277d03f3417aa867a6
SHA1: c849979e199d8a7c3da1a00799c623c00f94efac
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - WebUI Extension:test,provided
  • eXo PLF:: Commons - Commons WebUI:test,provided
  • eXo PLF:: Commons - Testing:test,provided
  • eXo PLF:: Commons - Comet Services:test,provided
  • eXo PLF:: Commons - Transparent Upgrade Framework:test,provided
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:test,provided
  • eXo PLF:: Commons - Product Informations:test,provided
  • eXo PLF:: Commons - Juzu Bridge for Platform:test,provided
  • eXo PLF:: Commons - Comet Ext Service (test only):test,provided
  • eXo PLF:: Commons - Common Services:test,provided

Identifiers

vorbis-java-tika-0.1.jar

File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-tika/0.1/vorbis-java-tika-0.1.jar
MD5: 1fccc6796a0924ba4f32eb1d44b8616b
SHA1: 6966c8663a7f689021accb13cceaa6101f53ea3d
Referenced In Projects/Scopes:

  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

CVE-2016-6809  

Severity: High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

Vulnerable Software & Versions:

CVE-2018-11761  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.

Vulnerable Software & Versions: (show all)

CVE-2018-11796  

Severity: Medium
CVSS Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')

In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.

Vulnerable Software & Versions: (show all)

CVE-2018-1335  

Severity: High
CVSS Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)

From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.

Vulnerable Software & Versions: (show all)

CVE-2018-1338  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.

Vulnerable Software & Versions: (show all)

CVE-2018-1339  

Severity: Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.

Vulnerable Software & Versions: (show all)

netcdf-4.2-min.jar

Description: The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats.

License:

(MIT-style) netCDF C library license.: http://www.unidata.ucar.edu/software/netcdf/copyright.html
File Path: /home/ciagent/.m2/repository/edu/ucar/netcdf/4.2-min/netcdf-4.2-min.jar
MD5: eb00b40b0511f0fc1dfcfc9cb89e3c53
SHA1: 0f3c3f3db4c54483aa1fbc4497e300879ce24da1
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

apache-mime4j-core-0.7.2.jar

Description: Java stream based MIME message parser

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-core/0.7.2/apache-mime4j-core-0.7.2.jar
MD5: 88f799546eca803c53eee01a4ce5edcd
SHA1: a81264fe0265ebe8fd1d8128aad06dc320de6eef
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

xz-1.2.jar

Description: XZ data compression

License:

Public Domain
File Path: /home/ciagent/.m2/repository/org/tukaani/xz/1.2/xz-1.2.jar
MD5: 04bd31459826c30c2a3c304e3b225ad4
SHA1: bfc66dda280a18ab341b5023248925265c00394c
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

  • maven: org.tukaani:xz:1.2    Confidence:Highest
  • cpe: cpe:/a:tukaani:xz:1.2   Confidence:Low   

CVE-2015-4035  

Severity: Medium
CVSS Score: 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.

Vulnerable Software & Versions:

commons-compress-1.5.jar

Description:  Apache Commons Compress software defines an API for working with compression and archive formats. These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-compress/1.5/commons-compress-1.5.jar
MD5: 5e18cfcf472548c2e0b90a4ea1cedf42
SHA1: d2bd2c0bd328f1dabdf33e10b6d223ebcbe93343
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

  • cpe: cpe:/a:apache:commons_compress:1.5   Confidence:Low   
  • maven: org.apache.commons:commons-compress:1.5    Confidence:Highest
  • cpe: cpe:/a:apache:commons-compress:1.5   Confidence:Low   

bcmail-jdk15-1.45.jar

Description: The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. If the S/MIME API is used, the JavaMail API and the Java activation framework will also be needed.

License:

Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcmail-jdk15/1.45/bcmail-jdk15-1.45.jar
MD5: 13321fc7eff7bcada7b4fedfb592025c
SHA1: 3aed7e642dd8d39dc14ed1dec3ff79e084637148
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

  • cpe: cpe:/a:no-cms_project:no-cms:1.45   Confidence:Low   
  • cpe: cpe:/a:mime_project:mime:1.45   Confidence:Low   
  • maven: org.bouncycastle:bcmail-jdk15:1.45    Confidence:Highest

bcprov-jdk15-1.45.jar

Description: The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5.

License:

Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcprov-jdk15/1.45/bcprov-jdk15-1.45.jar
MD5: 2062f8e3d15748443ea60a94b266371c
SHA1: 7741883cb07b4634e8b5fd3337113b6ea770a9bb
Referenced In Projects/Scopes:
  • eXo PLF:: Commons - Comet Services:compile
  • eXo PLF:: Commons - Testing:compile
  • eXo PLF:: Commons - WebUI Extension:compile
  • eXo PLF:: Commons - Transparent Upgrade Framework:compile
  • eXo PLF:: Commons - Product Informations:compile
  • eXo PLF:: Commons - Comet Ext Service (test only):compile
  • eXo PLF:: Commons - Juzu Bridge for Platform:compile
  • eXo PLF:: Commons - Commons WebUI:compile
  • eXo PLF:: Commons - Commons Extension Webapp:runtime
  • eXo PLF:: Commons - API:compile
  • eXo PLF:: Commons - Common Services:compile

Identifiers

  • cpe: cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.45   Confidence:Low