Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.1.2
Report Generated On : May 26, 2019 at 07:26:57 +00:00
Dependencies Scanned : 400 (293 unique)
Vulnerable Dependencies : 42
Vulnerabilities Found : 147
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 16/05/2019 09:15:31
NVD CVE 2003 : 24/05/2019 08:15:38
NVD CVE 2004 : 16/05/2019 09:15:31
NVD CVE 2005 : 24/05/2019 08:15:38
NVD CVE 2006 : 23/05/2019 08:15:43
NVD CVE 2007 : 25/05/2019 08:15:38
NVD CVE 2008 : 25/05/2019 08:15:38
NVD CVE 2009 : 24/05/2019 08:15:38
NVD CVE 2010 : 24/05/2019 08:15:38
NVD CVE 2011 : 23/05/2019 08:15:44
NVD CVE 2012 : 25/05/2019 08:15:39
NVD CVE 2013 : 25/05/2019 08:15:39
NVD CVE 2014 : 25/05/2019 08:15:39
NVD CVE 2015 : 25/05/2019 07:45:46
NVD CVE 2016 : 25/05/2019 07:45:46
NVD CVE 2017 : 25/05/2019 07:45:47
NVD CVE 2018 : 25/05/2019 07:45:47
NVD CVE 2019 : 25/05/2019 07:15:28
NVD CVE Checked : 26/05/2019 07:26:05
NVD CVE Modified : 26/05/2019 05:15:29
VersionCheckOn : 1557645553942
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
platform-ui-skin-5.3.x-SNAPSHOT.war
File Path: /home/ciagent/.m2/repository/org/exoplatform/platform-ui/platform-ui-skin/5.3.x-SNAPSHOT/platform-ui-skin-5.3.x-SNAPSHOT.war
MD5: 27ec72c7e2b3d00395a6ffd4cee60748
SHA1: 995106fdac815a895ae87f40050a61e4cbb8d3fa
Referenced In Project/Scope:
eXo PLF:: Wiki Webapp:provided
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.platform-ui Highest
Vendor file name platform-ui-skin High
Vendor pom artifactid platform-ui-skin Low
Vendor Manifest date 2019-05-24T09:49:10Z Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor Manifest implementation-url https://projects.exoplatform.org/platform-ui/platform-ui-skin Low
Vendor pom parent-artifactid platform-ui Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.platform-ui Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.platform-ui Medium
Vendor pom groupid exoplatform.platform-ui Highest
Vendor pom name eXo PLF:: Platform UI - Skin High
Product Manifest Implementation-Title eXo PLF:: Platform UI - Skin High
Product file name platform-ui-skin High
Product Manifest date 2019-05-24T09:49:10Z Low
Product Manifest specification-title eXo PLF:: Platform UI - Skin Medium
Product pom parent-artifactid platform-ui Medium
Product pom artifactid platform-ui-skin Highest
Product pom groupid exoplatform.platform-ui Low
Product pom parent-groupid org.exoplatform.platform-ui Low
Product Manifest implementation-url https://projects.exoplatform.org/platform-ui/platform-ui-skin Low
Product pom name eXo PLF:: Platform UI - Skin High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.platform-ui:platform-ui-skin:5.3.x-SNAPSHOT
Confidence :High
gwt-servlet-2.6.1.jar
Description:
Protocol Buffers are a way of encoding structured data in an efficient yet
extensible format.
License:
New BSD license: http://www.opensource.org/licenses/bsd-license.php
File Path: /home/ciagent/.m2/repository/com/google/gwt/gwt-servlet/2.6.1/gwt-servlet-2.6.1.jar
MD5: 46fa19a4859520cdf86c083e4c4519a4
SHA1: 983e26ec957ee3463f8554f4f03a58e16129e8f2
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Protocol Buffer Java API High
Vendor pom parent-artifactid google Low
Vendor jar package name google Low
Vendor jar package name gwt Low
Vendor pom groupid com.google.gwt Highest
Vendor central groupid com.google.gwt Highest
Vendor pom artifactid protobuf-java Low
Vendor pom url http://code.google.com/p/protobuf Highest
Vendor pom description Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Vendor pom parent-groupid com.google Medium
Vendor file name gwt-servlet High
Vendor pom groupid google.protobuf Highest
Product pom name Protocol Buffer Java API High
Product pom parent-artifactid google Medium
Product pom url http://code.google.com/p/protobuf Medium
Product pom artifactid gwt-servlet Highest
Product pom description Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Product central artifactid gwt-servlet Highest
Product file name gwt-servlet High
Product pom groupid google.protobuf Low
Product pom parent-groupid com.google Low
Product jar package name gwt Low
Product pom artifactid protobuf-java Highest
Version pom version 2.5.0 Highest
Version central version 2.6.1 Highest
Version file version 2.6.1 Highest
Version pom version 2.6.1 Highest
Published Vulnerabilities
CVE-2015-5237 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
Vulnerable Software & Versions: (show all )
smartgwt-lgpl-6.0-p20170514.jar
File Path: /home/ciagent/.m2/repository/com/isomorphic/smartgwt/lgpl/smartgwt-lgpl/6.0-p20170514/smartgwt-lgpl-6.0-p20170514.jar
MD5: feef4d7601d4e2ca9cfdaa5315eb17c6
SHA1: b27485a980eca557785290c25f15349075e077b7
Referenced In Project/Scope:
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid smartgwt-lgpl Low
Vendor jar package name widgets Low
Vendor pom groupid isomorphic.smartgwt.lgpl Highest
Vendor jar package name client Low
Vendor pom groupid com.isomorphic.smartgwt.lgpl Highest
Vendor jar package name smartgwt Low
Vendor file name smartgwt-lgpl High
Product pom groupid isomorphic.smartgwt.lgpl Low
Product jar package name widgets Low
Product pom artifactid smartgwt-lgpl Highest
Product jar package name client Low
Product file name smartgwt-lgpl High
Version pom version 6.0-p20170514 Highest
Version file version 6.0.p20170514 Highest
Published Vulnerabilities
CVE-2015-6737 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in the Widgets extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors involving base64 encoded content.
Vulnerable Software & Versions:
xwiki-platform-gwt-dom-6.0.jar
Description: An extension of the GWT DOM API, providing W3C Range and Selection support, depth-first pre-order iterator and lots of DOM utility methods
License:
http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/xwiki/platform/xwiki-platform-gwt-dom/6.0/xwiki-platform-gwt-dom-6.0.jar
MD5: a032bb06ae3b65d4eb77611b87c9870c
SHA1: 06b7a3ce91be3c3ae2878c1ee4811f74a7d50df0
Referenced In Project/Scope:
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom name XWiki Platform - GWT - DOM API High
Vendor pom description An extension of the GWT DOM API, providing W3C Range and Selection support, depth-first pre-order iterator and lots of DOM utility methods Low
Vendor Manifest bundle-docurl http://xwiki.org/ Low
Vendor pom groupid org.xwiki.platform Highest
Vendor pom parent-artifactid xwiki-platform-gwt Low
Vendor manifest Bundle-Description An extension of the GWT DOM API, providing W3C Range and Selection support, depth-first pre-order iterator and lots of DOM utility methods Low
Vendor pom groupid xwiki.platform Highest
Vendor file name xwiki-platform-gwt-dom High
Vendor pom parent-groupid org.xwiki.platform Medium
Vendor pom artifactid xwiki-platform-gwt-dom Low
Vendor Manifest xwiki-extension-id org.xwiki.platform:xwiki-platform-gwt-dom Low
Vendor Manifest bundle-symbolicname org.xwiki.platform.xwiki-platform-gwt-dom Medium
Product pom name XWiki Platform - GWT - DOM API High
Product pom description An extension of the GWT DOM API, providing W3C Range and Selection support, depth-first pre-order iterator and lots of DOM utility methods Low
Product Manifest bundle-docurl http://xwiki.org/ Low
Product Manifest Bundle-Name XWiki Platform - GWT - DOM API Medium
Product manifest Bundle-Description An extension of the GWT DOM API, providing W3C Range and Selection support, depth-first pre-order iterator and lots of DOM utility methods Low
Product pom artifactid xwiki-platform-gwt-dom Highest
Product pom parent-groupid org.xwiki.platform Low
Product pom parent-artifactid xwiki-platform-gwt Medium
Product pom groupid xwiki.platform Low
Product file name xwiki-platform-gwt-dom High
Product Manifest xwiki-extension-id org.xwiki.platform:xwiki-platform-gwt-dom Low
Product Manifest bundle-symbolicname org.xwiki.platform.xwiki-platform-gwt-dom Medium
Version file version 6.0 Highest
Version pom version 6.0 Highest
Related Dependencies
xwiki-platform-wysiwyg-client-6.0.jar
File Path: /home/ciagent/.m2/repository/org/xwiki/platform/xwiki-platform-wysiwyg-client/6.0/xwiki-platform-wysiwyg-client-6.0.jar
SHA1: f02c454a697e75f0b6de88115550d2cca40c0e1c
MD5: eb12e1be531e918d93c41b582fbf00d2
xwiki-platform-gwt-user-6.0.jar
File Path: /home/ciagent/.m2/repository/org/xwiki/platform/xwiki-platform-gwt-user/6.0/xwiki-platform-gwt-user-6.0.jar
SHA1: f3b7238adabafddea4d56dc7dd747458a87402e8
MD5: 5c1cefee278ba00dcc6d3459917b6c34
xwiki-platform-wysiwyg-plugin-api-6.0.jar
File Path: /home/ciagent/.m2/repository/org/xwiki/platform/xwiki-platform-wysiwyg-plugin-api/6.0/xwiki-platform-wysiwyg-plugin-api-6.0.jar
SHA1: fd3188b8ec923b14b83fdd4215d3a15234e2174a
MD5: cba6f3dd0dd57547cfe4eae23a9496da
cpe: cpe:/a:xwiki:xwiki:6.0
Confidence :Low
suppress
maven: org.xwiki.platform:xwiki-platform-gwt-dom:6.0
Confidence :High
Published Vulnerabilities
CVE-2018-16277 suppress
Severity:
Low
CVSS Score: 3.5
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The Image Import function in XWiki through 10.7 has XSS.
Vulnerable Software & Versions:
slf4j-api-1.7.18.jar
Description: The slf4j API
File Path: /home/ciagent/.m2/repository/org/slf4j/slf4j-api/1.7.18/slf4j-api-1.7.18.jar
MD5: 1b1d1af21206ac5ae44cd79a6c04dd92
SHA1: b631d286463ced7cc42ee2171fe3beaed2836823
Referenced In Projects/Scopes:
eXo PLF:: Wiki Macros Iframe:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom name SLF4J API Module High
Vendor pom parent-groupid org.slf4j Medium
Vendor pom url http://www.slf4j.org Highest
Vendor file name slf4j-api High
Vendor pom groupid slf4j Highest
Vendor manifest Bundle-Description The slf4j API Medium
Vendor pom parent-artifactid slf4j-parent Low
Vendor central groupid org.slf4j Highest
Vendor pom artifactid slf4j-api Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom groupid org.slf4j Highest
Vendor pom description The slf4j API Medium
Product pom name SLF4J API Module High
Product pom groupid slf4j Low
Product pom url http://www.slf4j.org Medium
Product file name slf4j-api High
Product central artifactid slf4j-api Highest
Product pom artifactid slf4j-api Highest
Product manifest Bundle-Description The slf4j API Medium
Product pom parent-artifactid slf4j-parent Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest Bundle-Name slf4j-api Medium
Product pom parent-groupid org.slf4j Low
Product pom description The slf4j API Medium
Version central version 1.7.18 Highest
Version pom version 1.7.18 Highest
Version Manifest Implementation-Version 1.7.18 High
Version file version 1.7.18 Highest
javax.inject-1.jar
Description: The javax.inject API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
Referenced In Projects/Scopes:
eXo PLF:: Wiki Macros Iframe:compile
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid javax.inject Low
Vendor pom groupid javax.inject Highest
Vendor pom name javax.inject High
Vendor central groupid javax.inject Highest
Vendor jar package name javax Low
Vendor file name javax.inject-1 High
Vendor pom url http://code.google.com/p/atinject/ Highest
Vendor pom description The javax.inject API Medium
Vendor jar package name inject Low
Product central artifactid javax.inject Highest
Product pom artifactid javax.inject Highest
Product pom name javax.inject High
Product pom groupid javax.inject Low
Product file name javax.inject-1 High
Product pom description The javax.inject API Medium
Product pom url http://code.google.com/p/atinject/ Medium
Product jar package name inject Low
Version file version 1 Medium
Version pom version 1 Highest
Version central version 1 Highest
commons-io-2.4.jar
Description:
The Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-io/commons-io/2.4/commons-io-2.4.jar
MD5: 7f97854dc04c119d461fed14f5d8bb96
SHA1: b1b6ea3b7e4aa4f492509a4952029cd8e48019ad
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom artifactid commons-io Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low
Vendor central groupid commons-io Highest
Vendor pom name Commons IO High
Vendor pom groupid commons-io Highest
Vendor pom url http://commons.apache.org/io/ Highest
Vendor Manifest bundle-symbolicname org.apache.commons.io Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor file name commons-io High
Vendor pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor Manifest bundle-docurl http://commons.apache.org/io/ Low
Product pom parent-artifactid commons-parent Medium
Product pom url http://commons.apache.org/io/ Medium
Product pom groupid commons-io Low
Product Manifest implementation-build tags/2.4-RC2@r1349569; 2012-06-12 18:18:20-0400 Low
Product Manifest Bundle-Name Commons IO Medium
Product pom name Commons IO High
Product Manifest bundle-symbolicname org.apache.commons.io Medium
Product central artifactid commons-io Highest
Product manifest Bundle-Description The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product file name commons-io High
Product pom parent-groupid org.apache.commons Low
Product pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product pom artifactid commons-io Highest
Product Manifest specification-title Commons IO Medium
Product Manifest bundle-docurl http://commons.apache.org/io/ Low
Product Manifest Implementation-Title Commons IO High
Version file version 2.4 Highest
Version central version 2.4 Highest
Version pom version 2.4 Highest
Version Manifest Implementation-Version 2.4 High
jcommon-1.0.17.jar
Description:
JCommon is a free general purpose Java class library that is used in
several projects at www.jfree.org, including JFreeChart and
JFreeReport.
License:
GNU Lesser General Public Licence: http://www.gnu.org/licenses/lgpl.txt
File Path: /home/ciagent/.m2/repository/org/jfree/jcommon/1.0.17/jcommon-1.0.17.jar
MD5: d123cd511e2ebc4542e8b424cd20bbde
SHA1: 7bcb68fde08258e59fe7bcc758c08af830fb2c1d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JCommon High
Vendor pom artifactid jcommon Low
Vendor jar package name jfree Low
Vendor pom organization url http://www.jfree.org/ Medium
Vendor central groupid org.jfree Highest
Vendor file name jcommon High
Vendor pom organization name JFree.org High
Vendor pom url http://www.jfree.org/jcommon/ Highest
Vendor pom groupid jfree Highest
Vendor pom description JCommon is a free general purpose Java class library that is used in several projects at www.jfree.org, including JFreeChart and JFreeReport. Low
Vendor pom groupid org.jfree Highest
Product pom name JCommon High
Product pom artifactid jcommon Highest
Product central artifactid jcommon Highest
Product pom organization name JFree.org Low
Product pom url http://www.jfree.org/jcommon/ Medium
Product file name jcommon High
Product pom groupid jfree Low
Product pom description JCommon is a free general purpose Java class library that is used in several projects at www.jfree.org, including JFreeChart and JFreeReport. Low
Product pom organization url http://www.jfree.org/ Low
Version pom version 1.0.17 Highest
Version file version 1.0.17 Highest
Version central version 1.0.17 Highest
jfreechart-1.0.14.jar
Description:
JFreeChart is a class library, written in Java, for generating charts.
Utilising the Java2D APIs, it currently supports bar charts, pie charts,
line charts, XY-plots and time series plots.
License:
GNU Lesser General Public Licence: http://www.gnu.org/licenses/lgpl.txt
File Path: /home/ciagent/.m2/repository/org/jfree/jfreechart/1.0.14/jfreechart-1.0.14.jar
MD5: e0ac6e8ecb858f946200b326209fe639
SHA1: fa67c798b0ae80b84f3854d69e341abacd3867c5
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JFreeChart High
Vendor pom description JFreeChart is a class library, written in Java, for generating charts. Utilising the Java2D APIs, it currently supports bar charts, pie charts, line charts, XY-plots and time series plots. Low
Vendor jar package name chart Low
Vendor pom artifactid jfreechart Low
Vendor jar package name jfree Low
Vendor file name jfreechart High
Vendor central groupid org.jfree Highest
Vendor pom groupid jfree Highest
Vendor pom url http://www.jfree.org/jfreechart/ Highest
Vendor pom organization url http://www.jfree.org/ Medium
Vendor pom organization name JFree.org High
Vendor pom groupid org.jfree Highest
Product pom name JFreeChart High
Product pom description JFreeChart is a class library, written in Java, for generating charts. Utilising the Java2D APIs, it currently supports bar charts, pie charts, line charts, XY-plots and time series plots. Low
Product jar package name chart Low
Product pom artifactid jfreechart Highest
Product pom organization name JFree.org Low
Product file name jfreechart High
Product pom groupid jfree Low
Product pom url http://www.jfree.org/jfreechart/ Medium
Product central artifactid jfreechart Highest
Product pom organization url http://www.jfree.org/ Low
Version central version 1.0.14 Highest
Version file version 1.0.14 Highest
Version pom version 1.0.14 Highest
velocity-1.7.jar
Description: Apache Velocity is a general purpose template engine.
File Path: /home/ciagent/.m2/repository/org/apache/velocity/velocity/1.7/velocity-1.7.jar
MD5: 3692dd72f8367cb35fb6280dc2916725
SHA1: 2ceb567b8f3f21118ecdec129fe1271dbc09aa7a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor central groupid org.apache.velocity Highest
Vendor pom parent-artifactid apache Low
Vendor pom url http://velocity.apache.org/engine/devel/ Highest
Vendor pom groupid org.apache.velocity Highest
Vendor pom artifactid velocity Low
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor pom groupid apache.velocity Highest
Vendor file name velocity High
Vendor Manifest extension-name velocity Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest bundle-symbolicname org.apache.velocity Medium
Vendor pom name Apache Velocity High
Vendor pom description Apache Velocity is a general purpose template engine. Medium
Vendor pom parent-groupid org.apache Medium
Product central artifactid velocity Highest
Product pom artifactid velocity Highest
Product pom groupid apache.velocity Low
Product pom parent-groupid org.apache Low
Product pom url http://velocity.apache.org/engine/devel/ Medium
Product Manifest Implementation-Title org.apache.velocity High
Product Manifest Bundle-Name Apache Velocity Medium
Product file name velocity High
Product Manifest extension-name velocity Medium
Product pom parent-artifactid apache Medium
Product Manifest bundle-symbolicname org.apache.velocity Medium
Product pom name Apache Velocity High
Product pom description Apache Velocity is a general purpose template engine. Medium
Product Manifest specification-title Velocity is a Java-based template engine Medium
Version pom version 1.7 Highest
Version central version 1.7 Highest
Version file version 1.7 Highest
Version Manifest Implementation-Version 1.7 High
velocity-tools-1.4.jar
File Path: /home/ciagent/.m2/repository/velocity-tools/velocity-tools/1.4/velocity-tools-1.4.jar
MD5: 2ef7ed8b728186558b5d587c38900b84
SHA1: 4e1f4d507030a00959f4c0c7fcc60b3565617d08
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid velocity-tools Highest
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor pom groupid velocity-tools Highest
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid velocity-tools Low
Vendor file name velocity-tools High
Vendor Manifest extension-name velocity-tools Medium
Product pom groupid velocity-tools Low
Product Manifest Implementation-Title org.apache.velocity High
Product Manifest specification-title VelocityTools is a set of utilities for use with the Velocity template engine and Struts web framework Medium
Product central artifactid velocity-tools Highest
Product file name velocity-tools High
Product Manifest extension-name velocity-tools Medium
Product pom artifactid velocity-tools Highest
Version Manifest Implementation-Version 1.4 High
Version pom version 1.4 Highest
Version file version 1.4 Highest
Version central version 1.4 Highest
commons-codec-1.10.jar
Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.apache.commons.codec Medium
Vendor manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor central groupid commons-codec Highest
Vendor file name commons-codec High
Vendor pom groupid commons-codec Highest
Vendor pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom artifactid commons-codec Low
Vendor pom name Apache Commons Codec High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Vendor pom url http://commons.apache.org/proper/commons-codec/ Highest
Product pom groupid commons-codec Low
Product Manifest bundle-symbolicname org.apache.commons.codec Medium
Product manifest Bundle-Description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product pom parent-artifactid commons-parent Medium
Product central artifactid commons-codec Highest
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-codec/ Low
Product Manifest Bundle-Name Apache Commons Codec Medium
Product Manifest Implementation-Title Apache Commons Codec High
Product Manifest specification-title Apache Commons Codec Medium
Product file name commons-codec High
Product pom description The Apache Commons Codec package contains simple encoder and decoders for various formats such as Base64 and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom name Apache Commons Codec High
Product pom artifactid commons-codec Highest
Product pom parent-groupid org.apache.commons Low
Product Manifest implementation-build trunk@r1637108; 2014-11-06 14:14:12+0000 Low
Product pom url http://commons.apache.org/proper/commons-codec/ Medium
Version pom version 1.10 Highest
Version central version 1.10 Highest
Version Manifest Implementation-Version 1.10 High
Version file version 1.10 Highest
jackson-core-2.3.1.jar
Description: Core Jackson abstractions, basic JSON streaming API implementation
License:
http://www.apache.org/licenses/LICENSE-2.0.txt, http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.3.1/jackson-core-2.3.1.jar
MD5: aa2152b5f610a2dee75bb81bcab66c36
SHA1: f9f7185c92ca5fefe2fb3efdeb477a67c96ea2d0
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Low
Vendor pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium
Vendor pom name Jackson-core High
Vendor Manifest implementation-build-date 2013-12-27 17:00:34-0800 Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Vendor pom parent-groupid com.fasterxml Medium
Vendor pom parent-artifactid oss-parent Low
Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest
Vendor file name jackson-core High
Product pom url http://wiki.fasterxml.com/JacksonHome Medium
Product Manifest Bundle-Name Jackson-core Medium
Product pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium
Product pom name Jackson-core High
Product Manifest implementation-build-date 2013-12-27 17:00:34-0800 Low
Product pom parent-artifactid oss-parent Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest specification-title Jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium
Product central artifactid jackson-core Highest
Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Product pom parent-groupid com.fasterxml Low
Product pom artifactid jackson-core Highest
Product pom groupid fasterxml.jackson.core Low
Product file name jackson-core High
Version central version 2.3.1 Highest
Version pom version 2.3.1 Highest
Version file version 2.3.1 Highest
Version Manifest Implementation-Version 2.3.1 High
jackson-annotations-2.3.0.jar
Description: Core annotations used for value types, used by Jackson data binding package.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt, http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.3.0/jackson-annotations-2.3.0.jar
MD5: c954fbca7d677f323d810d0fa8baead2
SHA1: f5e853a20b60758922453d56f9ae1e64af5cb3da
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor pom description Core annotations used for value types, used by Jackson data binding package.
Medium
Vendor Manifest implementation-build-date 2013-11-13 20:56:27-0800 Low
Vendor pom artifactid jackson-annotations Low
Vendor file name jackson-annotations High
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Vendor pom parent-groupid com.fasterxml Medium
Vendor manifest Bundle-Description Core annotations used for value types, used by Jackson data binding package. Medium
Vendor pom parent-artifactid oss-parent Low
Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest
Product pom url http://wiki.fasterxml.com/JacksonHome Medium
Product pom artifactid jackson-annotations Highest
Product pom description Core annotations used for value types, used by Jackson data binding package.
Medium
Product Manifest Bundle-Name Jackson-annotations Medium
Product pom parent-artifactid oss-parent Medium
Product Manifest implementation-build-date 2013-11-13 20:56:27-0800 Low
Product file name jackson-annotations High
Product pom name Jackson-annotations High
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product central artifactid jackson-annotations Highest
Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Product pom parent-groupid com.fasterxml Low
Product Manifest Implementation-Title Jackson-annotations High
Product pom groupid fasterxml.jackson.core Low
Product manifest Bundle-Description Core annotations used for value types, used by Jackson data binding package. Medium
Product Manifest specification-title Jackson-annotations Medium
Version file version 2.3.0 Highest
Version Manifest Implementation-Version 2.3.0 High
Version central version 2.3.0 Highest
Version pom version 2.3.0 Highest
jackson-databind-2.3.1.jar
Description: General data-binding functionality for Jackson: works on core streaming API
License:
http://www.apache.org/licenses/LICENSE-2.0.txt, http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.3.1/jackson-databind-2.3.1.jar
MD5: 4de637793707fdecb1b7a90f677103ec
SHA1: c4096a8323bbbcbeda072e3def123a9b66783361
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor file name jackson-databind High
Vendor pom artifactid jackson-databind Low
Vendor Manifest implementation-build-date 2013-12-27 18:28:29-0800 Low
Vendor manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Vendor pom name jackson-databind High
Vendor pom parent-groupid com.fasterxml Medium
Vendor pom parent-artifactid oss-parent Low
Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest
Vendor pom description General data-binding functionality for Jackson: works on core streaming API Medium
Product pom url http://wiki.fasterxml.com/JacksonHome Medium
Product file name jackson-databind High
Product pom parent-artifactid oss-parent Medium
Product pom artifactid jackson-databind Highest
Product Manifest implementation-build-date 2013-12-27 18:28:29-0800 Low
Product manifest Bundle-Description General data-binding functionality for Jackson: works on core streaming API Medium
Product Manifest Implementation-Title jackson-databind High
Product central artifactid jackson-databind Highest
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium
Product Manifest specification-title jackson-databind Medium
Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Product pom parent-groupid com.fasterxml Low
Product pom name jackson-databind High
Product pom groupid fasterxml.jackson.core Low
Product Manifest Bundle-Name jackson-databind Medium
Product pom description General data-binding functionality for Jackson: works on core streaming API Medium
Version central version 2.3.1 Highest
Version pom version 2.3.1 Highest
Version file version 2.3.1 Highest
Version Manifest Implementation-Version 2.3.1 High
Published Vulnerabilities
CVE-2017-15095 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
Vulnerable Software & Versions: (show all )
CVE-2017-17485 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
Vulnerable Software & Versions: (show all )
CVE-2017-7525 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
BID - 99623
CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1462702
CONFIRM - https://cwiki.apache.org/confluence/display/WW/S2-055
CONFIRM - https://github.com/FasterXML/jackson-databind/issues/1599
CONFIRM - https://github.com/FasterXML/jackson-databind/issues/1723
CONFIRM - https://security.netapp.com/advisory/ntap-20171214-0002/
CONFIRM - https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
CONFIRM - https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
DEBIAN - DSA-4004
MISC - https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
MLIST - [lucene-dev] 20190325 [jira] [Assigned] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Closed] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Resolved] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
REDHAT - RHSA-2017:1834
REDHAT - RHSA-2017:1835
REDHAT - RHSA-2017:1836
REDHAT - RHSA-2017:1837
REDHAT - RHSA-2017:1839
REDHAT - RHSA-2017:1840
REDHAT - RHSA-2017:2477
REDHAT - RHSA-2017:2546
REDHAT - RHSA-2017:2547
REDHAT - RHSA-2017:2633
REDHAT - RHSA-2017:2635
REDHAT - RHSA-2017:2636
REDHAT - RHSA-2017:2637
REDHAT - RHSA-2017:2638
REDHAT - RHSA-2017:3141
REDHAT - RHSA-2017:3454
REDHAT - RHSA-2017:3455
REDHAT - RHSA-2017:3456
REDHAT - RHSA-2017:3458
REDHAT - RHSA-2018:0294
REDHAT - RHSA-2018:0342
REDHAT - RHSA-2018:1449
REDHAT - RHSA-2018:1450
REDHAT - RHSA-2019:0910
SECTRACK - 1039744
SECTRACK - 1039947
SECTRACK - 1040360
Vulnerable Software & Versions: (show all )
CVE-2018-1000873 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.
Vulnerable Software & Versions: (show all )
CVE-2018-14719 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-14720 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-14721 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-918 Server-Side Request Forgery (SSRF)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-19360 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-19361 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-19362 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-5968 suppress
Severity:
Medium
CVSS Score: 5.1
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-184 Incomplete Blacklist
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
Vulnerable Software & Versions: (show all )
CVE-2018-7489 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-184 Incomplete Blacklist
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.
Vulnerable Software & Versions: (show all )
CVE-2019-12086 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.
Vulnerable Software & Versions: (show all )
ezmorph-1.0.6.jar
Description:
Simple java library for transforming an Object to another Object.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/net/sf/ezmorph/ezmorph/1.0.6/ezmorph-1.0.6.jar
MD5: 1fa113c6aacf3a01af1449df77acd474
SHA1: 01e55d2a0253ea37745d33062852fd2c90027432
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor central groupid net.sf.ezmorph Highest
Vendor pom url http://ezmorph.sourceforge.net Highest
Vendor pom description
Simple java library for transforming an Object to another Object.
Medium
Vendor jar package name sf Low
Vendor pom artifactid ezmorph Low
Vendor jar package name ezmorph Low
Vendor file name ezmorph High
Vendor pom groupid net.sf.ezmorph Highest
Vendor pom name ezmorph High
Product pom url http://ezmorph.sourceforge.net Medium
Product pom artifactid ezmorph Highest
Product pom groupid net.sf.ezmorph Low
Product pom description
Simple java library for transforming an Object to another Object.
Medium
Product jar package name sf Low
Product jar package name ezmorph Low
Product file name ezmorph High
Product central artifactid ezmorph Highest
Product pom name ezmorph High
Version pom version 1.0.6 Highest
Version central version 1.0.6 Highest
Version file version 1.0.6 Highest
json-lib-2.4-jdk15.jar
File Path: /home/ciagent/.m2/repository/net/sf/json-lib/json-lib/2.4/json-lib-2.4-jdk15.jar
MD5: f5db294d05b3d5a5bfb873455b0a8626
SHA1: 136743e0d12df4e785e62b48618cee169b2ae546
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor jar package name sf Low
Vendor central groupid net.sf.json-lib High
Vendor file name json-lib High
Vendor central groupid com.hynnet High
Vendor jar package name json Low
Vendor pom groupid net.sf.json-lib Highest
Product jar package name sf Low
Product pom artifactid json-lib Highest
Product file name json-lib High
Product central artifactid json-lib High
Product jar package name json Low
Version central version 2.4 High
Version file version 2.4 Highest
Version pom version 2.4 Highest
commons-configuration-1.10.jar
Description: Tools to assist in the reading of configuration/preferences files in various formats.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-configuration/commons-configuration/1.10/commons-configuration-1.10.jar
MD5: b16511ce540fefd53981245f5f21c5f8
SHA1: 2b36e4adfb66d966c5aef2d73deb6be716389dc9
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom url http://commons.apache.org/configuration/ Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom description Tools to assist in the reading of configuration/preferences files in various formats. Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom artifactid commons-configuration Low
Vendor central groupid commons-configuration Highest
Vendor pom name Apache Commons Configuration High
Vendor pom groupid commons-configuration Highest
Vendor Manifest bundle-docurl http://commons.apache.org/configuration/ Low
Vendor file name commons-configuration High
Vendor manifest Bundle-Description Tools to assist in the reading of configuration/preferences files in various formats. Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest bundle-symbolicname org.apache.commons.configuration Medium
Vendor Manifest implementation-build tags/CONFIGURATION_1_10RC2@r1535308; 2013-10-24 01:20:22-0700 Low
Product pom groupid commons-configuration Low
Product Manifest specification-title Apache Commons Configuration Medium
Product pom parent-artifactid commons-parent Medium
Product pom description Tools to assist in the reading of configuration/preferences files in various formats. Medium
Product Manifest Bundle-Name Apache Commons Configuration Medium
Product Manifest Implementation-Title Apache Commons Configuration High
Product pom name Apache Commons Configuration High
Product Manifest bundle-docurl http://commons.apache.org/configuration/ Low
Product file name commons-configuration High
Product manifest Bundle-Description Tools to assist in the reading of configuration/preferences files in various formats. Medium
Product central artifactid commons-configuration Highest
Product pom artifactid commons-configuration Highest
Product pom parent-groupid org.apache.commons Low
Product Manifest bundle-symbolicname org.apache.commons.configuration Medium
Product pom url http://commons.apache.org/configuration/ Medium
Product Manifest implementation-build tags/CONFIGURATION_1_10RC2@r1535308; 2013-10-24 01:20:22-0700 Low
Version pom version 1.10 Highest
Version central version 1.10 Highest
Version Manifest Implementation-Version 1.10 High
Version file version 1.10 Highest
commons-collections-3.2.2.jar
Description: Types that extend and augment the Java Collections Framework.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Vendor pom name Apache Commons Collections High
Vendor pom url http://commons.apache.org/collections/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-collections Low
Vendor pom parent-artifactid commons-parent Low
Vendor file name commons-collections High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-collections Highest
Vendor Manifest implementation-url http://commons.apache.org/collections/ Low
Vendor Manifest bundle-docurl http://commons.apache.org/collections/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.collections Medium
Vendor pom description Types that extend and augment the Java Collections Framework. Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor central groupid commons-collections Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low
Vendor manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium
Product Manifest implementation-build tags/COLLECTIONS_3_2_2_RC3@r1714131; 2015-11-13 00:09:45+0100 Low
Product pom name Apache Commons Collections High
Product pom parent-artifactid commons-parent Medium
Product file name commons-collections High
Product Manifest Implementation-Title Apache Commons Collections High
Product Manifest Bundle-Name Apache Commons Collections Medium
Product pom groupid commons-collections Low
Product Manifest implementation-url http://commons.apache.org/collections/ Low
Product Manifest bundle-docurl http://commons.apache.org/collections/ Low
Product Manifest bundle-symbolicname org.apache.commons.collections Medium
Product pom description Types that extend and augment the Java Collections Framework. Medium
Product Manifest specification-title Apache Commons Collections Medium
Product pom artifactid commons-collections Highest
Product pom url http://commons.apache.org/collections/ Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.3))" Low
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-collections Highest
Product manifest Bundle-Description Types that extend and augment the Java Collections Framework. Medium
Version pom version 3.2.2 Highest
Version Manifest Implementation-Version 3.2.2 High
Version file version 3.2.2 Highest
Version central version 3.2.2 Highest
commons-lang3-3.2.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-lang3/3.2/commons-lang3-3.2.jar
MD5: 9f2013bc16457ff8dfbfbf3357060192
SHA1: 4ff27bd725ae39f616e4ecdd08c27978cef749ec
Referenced In Projects/Scopes:
eXo PLF:: Wiki Macros Iframe:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.apache.commons Highest
Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest implementation-build tags/LANG_3_2_RC2@r1553875; 2013-12-28 18:05:45+0100 Low
Vendor pom groupid apache.commons Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low
Vendor central groupid org.apache.commons Highest
Vendor pom artifactid commons-lang3 Low
Vendor manifest Bundle-Description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom name Apache Commons Lang High
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor file name commons-lang3 High
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Product Manifest implementation-build tags/LANG_3_2_RC2@r1553875; 2013-12-28 18:05:45+0100 Low
Product pom parent-artifactid commons-parent Medium
Product pom description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low
Product Manifest specification-title Apache Commons Lang Medium
Product manifest Bundle-Description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest Implementation-Title Apache Commons Lang High
Product pom name Apache Commons Lang High
Product pom groupid apache.commons Low
Product pom url http://commons.apache.org/proper/commons-lang/ Medium
Product central artifactid commons-lang3 Highest
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product pom parent-groupid org.apache.commons Low
Product file name commons-lang3 High
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Product pom artifactid commons-lang3 Highest
Version pom version 3.2 Highest
Version central version 3.2 Highest
Version Manifest Implementation-Version 3.2 High
Version file version 3.2 Highest
rome-1.0.jar
Description: All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it
easy to work in Java with most syndication formats. Today it accepts all flavors of RSS
(0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes
a set of parsers and generators for the various flavors of feeds, as well as converters
to convert from one format to another. The parsers can give you back Java objects that
are either specific for the format you want to work with, or a generic normalized
SyndFeed object that lets you work on with the data without bothering about the
underlying format.
File Path: /home/ciagent/.m2/repository/rome/rome/1.0/rome-1.0.jar
MD5: 53d38c030287b939f4e6d745ba1269a7
SHA1: 022b33347f315833e9348cec2751af1a5d5656e4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest embed-directory META-INF/lib Low
Vendor pom organization url http://java.sun.com/ Medium
Vendor pom description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Vendor pom organization name Sun Microsystems High
Vendor central groupid rome Highest
Vendor Manifest bundle-docurl http://java.sun.com/ Low
Vendor pom name ROME, RSS and atOM utilitiEs for Java High
Vendor pom url https://rome.dev.java.net/ Highest
Vendor Manifest bundle-symbolicname rome.rome Medium
Vendor pom artifactid rome Low
Vendor pom groupid rome Highest
Vendor manifest Bundle-Description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Vendor file name rome High
Vendor Manifest originally-created-by 1.6.0_10 (Sun Microsystems Inc.) Low
Product Manifest embed-directory META-INF/lib Low
Product pom groupid rome Low
Product pom organization url http://java.sun.com/ Low
Product pom organization name Sun Microsystems Low
Product pom description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Product central artifactid rome Highest
Product pom url https://rome.dev.java.net/ Medium
Product Manifest bundle-docurl http://java.sun.com/ Low
Product Manifest Bundle-Name ROME, RSS and atOM utilitiEs for Java Medium
Product pom name ROME, RSS and atOM utilitiEs for Java High
Product Manifest bundle-symbolicname rome.rome Medium
Product pom artifactid rome Highest
Product manifest Bundle-Description All Roads Lead to ROME. ROME is a set of Atom/RSS Java utilities that make it easy to work in Java with most syndication formats. Today it accepts all flavors of RSS (0.90, 0.91, 0.92, 0.93, 0.94, 1.0 and 2.0), Atom 0.3 and Atom 1.0 feeds. Rome includes a set of parsers and generators for the various flavors of feeds, as well as converters to convert from one format to another. The parsers can give you back Java objects that are either specific for the format you want to work with, or a generic normalized SyndFeed object that lets you work on with the data without bothering about the underlying format. Low
Product file name rome High
Product Manifest originally-created-by 1.6.0_10 (Sun Microsystems Inc.) Low
Version file version 1.0 Highest
Version central version 1.0 Highest
Version pom version 1.0 Highest
jdom-1.1.3.jar
Description:
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
License:
Similar to Apache License but with the acknowledgment clause removed: https://raw.github.com/hunterhacker/jdom/master/LICENSE.txt
File Path: /home/ciagent/.m2/repository/org/jdom/jdom/1.1.3/jdom-1.1.3.jar
MD5: 140bfed13341fe2039eee0f26a16d705
SHA1: 8bdfeb39fa929c35f5e4f0b02d34350db39a1efc
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.jdom Highest
Vendor manifest: org/jdom/output/ Implementation-Vendor jdom.org Medium
Vendor manifest: org/jdom/xpath/ Implementation-Vendor jdom.org Medium
Vendor pom organization url http://www.jdom.org Medium
Vendor manifest: org/jdom/adapters/ Implementation-Vendor jdom.org Medium
Vendor manifest: org/jdom/transform/ Implementation-Vendor jdom.org Medium
Vendor manifest: org/jdom/filter/ Implementation-Vendor jdom.org Medium
Vendor pom groupid jdom Highest
Vendor pom url http://www.jdom.org Highest
Vendor pom artifactid jdom Low
Vendor pom name JDOM High
Vendor file name jdom High
Vendor central groupid org.jdom High
Vendor manifest: org/jdom/input/ Implementation-Vendor jdom.org Medium
Vendor pom organization name JDOM High
Vendor manifest: org/jdom/ Implementation-Vendor jdom.org Medium
Vendor pom description
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
Medium
Product manifest: org/jdom/ Specification-Title JDOM Classes Medium
Product manifest: org/jdom/output/ Specification-Title JDOM Output Classes Medium
Product manifest: org/jdom/adapters/ Specification-Title JDOM Adapter Classes Medium
Product manifest: org/jdom/ Implementation-Title org.jdom Medium
Product manifest: org/jdom/input/ Specification-Title JDOM Input Classes Medium
Product manifest: org/jdom/adapters/ Implementation-Title org.jdom.adapters Medium
Product pom name JDOM High
Product manifest: org/jdom/xpath/ Implementation-Title org.jdom.xpath Medium
Product file name jdom High
Product manifest: org/jdom/filter/ Specification-Title JDOM Filter Classes Medium
Product pom description
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
Medium
Product central artifactid jdom-legacy High
Product pom url http://www.jdom.org Medium
Product pom artifactid jdom Highest
Product manifest: org/jdom/transform/ Specification-Title JDOM Transformation Classes Medium
Product central artifactid jdom High
Product manifest: org/jdom/input/ Implementation-Title org.jdom.input Medium
Product manifest: org/jdom/transform/ Implementation-Title org.jdom.transform Medium
Product pom groupid jdom Low
Product manifest: org/jdom/filter/ Implementation-Title org.jdom.filter Medium
Product manifest: org/jdom/output/ Implementation-Title org.jdom.output Medium
Product pom organization url http://www.jdom.org Low
Product manifest: org/jdom/xpath/ Specification-Title JDOM XPath Classes Medium
Product pom organization name JDOM Low
Version file version 1.1.3 Highest
Version pom version 1.1.3 Highest
Version central version 1.1.3 High
commons-httpclient-3.1.jar
Description: The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily.
License:
Apache License: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/commons-httpclient/commons-httpclient/3.1/commons-httpclient-3.1.jar
MD5: 8ad8c9229ef2d59ab9f59f7050e846a5
SHA1: 964cd74171f427720480efdec40a7c7f6e58426a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor manifest: org/apache/commons/httpclient Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid commons-httpclient Low
Vendor pom organization name Apache Software Foundation High
Vendor pom organization url http://jakarta.apache.org/ Medium
Vendor pom name HttpClient High
Vendor file name commons-httpclient High
Vendor central groupid commons-httpclient Highest
Vendor pom groupid commons-httpclient Highest
Vendor pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Highest
Vendor pom description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. Low
Product manifest: org/apache/commons/httpclient Implementation-Title org.apache.commons.httpclient Medium
Product pom artifactid commons-httpclient Highest
Product manifest: org/apache/commons/httpclient Specification-Title Jakarta Commons HttpClient Medium
Product pom name HttpClient High
Product pom groupid commons-httpclient Low
Product file name commons-httpclient High
Product pom organization name Apache Software Foundation Low
Product pom organization url http://jakarta.apache.org/ Low
Product pom url http://jakarta.apache.org/httpcomponents/httpclient-3.x/ Medium
Product central artifactid commons-httpclient Highest
Product pom description The HttpClient component supports the client-side of RFC 1945 (HTTP/1.0) and RFC 2616 (HTTP/1.1) , several related specifications (RFC 2109 (Cookies) , RFC 2617 (HTTP Authentication) , etc.), and provides a framework by which new request types (methods) or HTTP extensions can be created easily. Low
Version pom version 3.1 Highest
Version file version 3.1 Highest
Version central version 3.1 Highest
snuggletex-core-1.1.0.jar
File Path: /home/ciagent/.m2/repository/uk/ac/ed/ph/snuggletex/snuggletex-core/1.1.0/snuggletex-core-1.1.0.jar
MD5: 1ea61a45bcb155a830d6a149f9f3f845
SHA1: 668865eca57ae9765b042558bc95522763333b70
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor file name snuggletex-core High
Vendor pom parent-artifactid snuggletex Low
Vendor jar package name ac Low
Vendor pom name SnuggleTeX Core High
Vendor jar package name uk Low
Vendor pom artifactid snuggletex-core Low
Vendor jar package name ed Low
Vendor pom groupid uk.ac.ed.ph.snuggletex Highest
Product file name snuggletex-core High
Product jar package name ph Low
Product pom groupid uk.ac.ed.ph.snuggletex Low
Product jar package name ac Low
Product pom artifactid snuggletex-core Highest
Product pom name SnuggleTeX Core High
Product jar package name ed Low
Product pom parent-artifactid snuggletex Medium
Version pom version 1.1.0 Highest
Version file version 1.1.0 Highest
maven: uk.ac.ed.ph.snuggletex:snuggletex-core:1.1.0
Confidence :High
batik-css-1.7.jar
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-css/1.7/batik-css-1.7.jar
MD5: b0203e64b3c06729baa0ef84743ab119
SHA1: e6bb5c85753331534593f33fb9236acb41a0ab79
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor The Apache Software Foundation (http://xmlgraphics.apache.org/batik/) High
Vendor pom name Batik CSS engine High
Vendor pom organization name Apache Software Foundation High
Vendor pom groupid apache.xmlgraphics Highest
Vendor pom artifactid batik-css Low
Vendor pom groupid org.apache.xmlgraphics Highest
Vendor pom organization url http://www.apache.org/ Medium
Vendor central groupid org.apache.xmlgraphics Highest
Vendor file name batik-css High
Vendor pom url http://xmlgraphics.apache.org/batik/ Highest
Product pom name Batik CSS engine High
Product Manifest Implementation-Title Batik CSS engine High
Product central artifactid batik-css Highest
Product pom organization url http://www.apache.org/ Low
Product pom artifactid batik-css Highest
Product pom groupid apache.xmlgraphics Low
Product pom organization name Apache Software Foundation Low
Product pom url http://xmlgraphics.apache.org/batik/ Medium
Product file name batik-css High
Version pom version 1.7 Highest
Version central version 1.7 Highest
Version file version 1.7 Highest
Related Dependencies
batik-parser-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-parser/1.7/batik-parser-1.7.jar
SHA1: 5d756cc4f6bf891793e6c7590773859c33a8609f
MD5: 7811e15f14917248b380e162d1512df9
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-parser:1.7 ✓
batik-awt-util-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-awt-util/1.7/batik-awt-util-1.7.jar
SHA1: 67605a29d49bf33f3c1d7832f490b0a007e7a6e2
MD5: b23ca091c9b4cf04b00a32dc9fdc29a3
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-awt-util:1.7 ✓
batik-svg-dom-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-svg-dom/1.7/batik-svg-dom-1.7.jar
SHA1: 5b3b1fea480fabbd3e0c44540af25b9fda0587ae
MD5: 8bb7fd15419c08f37d479a5a0fcff5b8
maven: org.apache.xmlgraphics:batik-svg-dom:1.7 ✓
cpe: cpe:/a:apache:batik:1.7
batik-anim-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-anim/1.7/batik-anim-1.7.jar
SHA1: a45dd2ff8e4ecd56a4fc64dc668b53bee90bf601
MD5: 2f25bf3516af864292f0bbdc19a49967
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-anim:1.7 ✓
batik-util-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-util/1.7/batik-util-1.7.jar
SHA1: 5c4dd0dd9a86a2fba2c6ea26fb62b32b21b2a61e
MD5: 99f99684b6df6200e529575dccce9970
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-util:1.7 ✓
batik-xml-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-xml/1.7/batik-xml-1.7.jar
SHA1: 17e3da8bd9d4a131350a7835f5cc0d93ba199c89
MD5: 72a36789b023019af66cd4120446033b
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-xml:1.7 ✓
batik-ext-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-ext/1.7/batik-ext-1.7.jar
SHA1: 4784302b44a0336166fef6153a5e3d73e861aecc
MD5: 080f3a49c658693dfbb4e48b0bfc8f07
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-ext:1.7 ✓
batik-dom-1.7.jar
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/batik-dom/1.7/batik-dom-1.7.jar
SHA1: 710d559bd1df52581b57b75a99ed5fd2e2918bb7
MD5: 664b4f1510ba700909c9034ac7f2b264
cpe: cpe:/a:apache:batik:1.7
maven: org.apache.xmlgraphics:batik-dom:1.7 ✓
Published Vulnerabilities
CVE-2015-0250 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:N/A:P)
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.
Vulnerable Software & Versions: (show all )
CVE-2017-5662 suppress
Severity:
High
CVSS Score: 7.9
(AV:N/AC:M/Au:S/C:C/I:N/A:C)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Vulnerable Software & Versions:
CVE-2018-8013 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Vulnerable Software & Versions: (show all )
xmlgraphics-commons-1.3.1.jar
Description:
Apache XML Graphics Commons is a library that consists of several reusable
components used by Apache Batik and Apache FOP. Many of these components
can easily be used separately outside the domains of SVG and XSL-FO.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/xmlgraphics/xmlgraphics-commons/1.3.1/xmlgraphics-commons-1.3.1.jar
MD5: e63589601d939739349a50a029dab120
SHA1: f7d0fa54e2750acd82b1a241c043be6fce1bf0dc
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Apache XML Graphics Commons High
Vendor pom description Apache XML Graphics Commons is a library that consists of several reusable components used by Apache Batik and Apache FOP. Many of these components can easily be used separately outside the domains of SVG and XSL-FO. Low
Vendor file name xmlgraphics-commons High
Vendor pom organization name Apache Software Foundation High
Vendor pom groupid apache.xmlgraphics Highest
Vendor pom url http://xmlgraphics.apache.org/commons/ Highest
Vendor pom groupid org.apache.xmlgraphics Highest
Vendor pom organization url http://www.apache.org/ Medium
Vendor central groupid org.apache.xmlgraphics Highest
Vendor pom artifactid xmlgraphics-commons Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation (http://xmlgraphics.apache.org/) High
Product pom name Apache XML Graphics Commons High
Product pom description Apache XML Graphics Commons is a library that consists of several reusable components used by Apache Batik and Apache FOP. Many of these components can easily be used separately outside the domains of SVG and XSL-FO. Low
Product file name xmlgraphics-commons High
Product pom artifactid xmlgraphics-commons Highest
Product pom organization url http://www.apache.org/ Low
Product Manifest Implementation-Title Apache XML Graphics Commons High
Product pom groupid apache.xmlgraphics Low
Product pom organization name Apache Software Foundation Low
Product pom url http://xmlgraphics.apache.org/commons/ Medium
Product central artifactid xmlgraphics-commons Highest
Version file version 1.3.1 Highest
Version Manifest Implementation-Version 1.3.1 High
Version central version 1.3.1 Highest
Version pom version 1.3.1 Highest
jeuclid-core-3.1.5.jar
Description: This is the core module containing the basic JEuclid rendering and document handling classes.
File Path: /home/ciagent/.m2/repository/net/sourceforge/jeuclid/jeuclid-core/3.1.5/jeuclid-core-3.1.5.jar
MD5: ef55609690f186df77611d25e79ae781
SHA1: e7b45abc13ba621b384b475ff6d10aa13e121b02
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor pom artifactid jeuclid-core Low
Vendor pom name JEuclid Core Module High
Vendor pom groupid net.sourceforge.jeuclid Highest
Vendor jar package name jeuclid Low
Vendor pom parent-artifactid jeuclid-parent Low
Vendor pom description This is the core module containing the basic JEuclid rendering and document handling classes. Medium
Vendor file name jeuclid-core High
Vendor jar package name sourceforge Low
Vendor central groupid net.sourceforge.jeuclid Highest
Product pom groupid net.sourceforge.jeuclid Low
Product central artifactid jeuclid-core Highest
Product pom artifactid jeuclid-core Highest
Product pom name JEuclid Core Module High
Product jar package name jeuclid Low
Product pom description This is the core module containing the basic JEuclid rendering and document handling classes. Medium
Product pom parent-artifactid jeuclid-parent Medium
Product file name jeuclid-core High
Product jar package name sourceforge Low
Version central version 3.1.5 Highest
Version pom version 3.1.5 Highest
Version file version 3.1.5 Highest
snuggletex-jeuclid-1.1.0.jar
File Path: /home/ciagent/.m2/repository/uk/ac/ed/ph/snuggletex/snuggletex-jeuclid/1.1.0/snuggletex-jeuclid-1.1.0.jar
MD5: 4b84195d37d3ad1ece60e9abb56e9bf7
SHA1: 14c790c08d2ca60b9067b5fd156ba01c83f25a3e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid snuggletex Low
Vendor jar package name ac Low
Vendor pom artifactid snuggletex-jeuclid Low
Vendor pom name SnuggleTeX JEuclid Extensions High
Vendor jar package name uk Low
Vendor file name snuggletex-jeuclid High
Vendor jar package name ed Low
Vendor pom groupid uk.ac.ed.ph.snuggletex Highest
Product jar package name ph Low
Product pom groupid uk.ac.ed.ph.snuggletex Low
Product jar package name ac Low
Product pom name SnuggleTeX JEuclid Extensions High
Product pom artifactid snuggletex-jeuclid Highest
Product file name snuggletex-jeuclid High
Product jar package name ed Low
Product pom parent-artifactid snuggletex Medium
Version pom version 1.1.0 Highest
Version file version 1.1.0 Highest
maven: uk.ac.ed.ph.snuggletex:snuggletex-jeuclid:1.1.0
Confidence :High
serializer-2.7.1.jar
Description:
Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input
SAX events.
File Path: /home/ciagent/.m2/repository/xalan/serializer/2.7.1/serializer-2.7.1.jar
MD5: a6b64dfe58229bdd810263fa0cc54cff
SHA1: 4b4b18df434451249bb65a63f2fb69e215a6a020
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Renderer:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom artifactid serializer Low
Vendor pom name Xalan Java Serializer High
Vendor manifest: org/apache/xml/serializer/utils/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom parent-artifactid apache Low
Vendor central groupid xalan Highest
Vendor pom url http://xml.apache.org/xalan-j/ Highest
Vendor file name serializer High
Vendor manifest: org/apache/xml/serializer/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom description Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input SAX events. Low
Vendor pom groupid xalan Highest
Vendor pom parent-groupid org.apache Medium
Product central artifactid serializer Highest
Product pom description Serializer to write out XML, HTML etc. as a stream of characters from an input DOM or from input SAX events. Low
Product pom parent-groupid org.apache Low
Product manifest: org/apache/xml/serializer/ Implementation-Title org.apache.xml.serializer Medium
Product pom name Xalan Java Serializer High
Product pom url http://xml.apache.org/xalan-j/ Medium
Product manifest: org/apache/xml/serializer/ Specification-Title XSL Transformations (XSLT), at http://www.w3.org/TR/xslt Medium
Product pom parent-artifactid apache Medium
Product manifest: org/apache/xml/serializer/utils/ Implementation-Title org.apache.xml.serializer.utils Medium
Product pom groupid xalan Low
Product file name serializer High
Product pom artifactid serializer Highest
Version file version 2.7.1 Highest
Version central version 2.7.1 Highest
Version pom version 2.7.1 Highest
Published Vulnerabilities
CVE-2014-0107 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
Vulnerable Software & Versions: (show all )
xalan-2.7.1.jar
Description:
Xalan-Java is an XSLT processor for transforming XML documents into HTML,
text, or other XML document types. It implements XSL Transformations (XSLT)
Version 1.0 and XML Path Language (XPath) Version 1.0 and can be used from
the command line, in an applet or a servlet, or as a module in other program.
File Path: /home/ciagent/.m2/repository/xalan/xalan/2.7.1/xalan-2.7.1.jar
MD5: d43aad24f2c143b675292ccfef487f9c
SHA1: 75f1d83ce27bab5f29fff034fc74aa9f7266f22a
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Renderer:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor manifest: org/apache/xalan/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/regexp/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom description Xalan-Java is an XSLT processor for transforming XML documents into HTML, text, or other XML document types. It implements XSL Transformations (XSLT) Version 1.0 and XML Path Language (XPath) Version 1.0 and can be used from the command line, in an applet or a servlet, or as a module in other program. Low
Vendor pom parent-artifactid apache Low
Vendor central groupid xalan Highest
Vendor manifest: java_cup/runtime/ Implementation-Vendor Princeton University Medium
Vendor manifest: org/apache/bcel/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid xalan Low
Vendor pom name Xalan Java High
Vendor manifest: org/apache/xml/ Implementation-Vendor Apache Software Foundation Medium
Vendor file name xalan High
Vendor manifest: org/apache/xalan/xsltc/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom url http://xml.apache.org/xalan-j/ Highest
Vendor pom groupid xalan Highest
Vendor manifest: org/apache/xpath/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom parent-groupid org.apache Medium
Product manifest: org/apache/xalan/xsltc/ Implementation-Title org.apache.xalan.xsltc Medium
Product pom description Xalan-Java is an XSLT processor for transforming XML documents into HTML, text, or other XML document types. It implements XSL Transformations (XSLT) Version 1.0 and XML Path Language (XPath) Version 1.0 and can be used from the command line, in an applet or a servlet, or as a module in other program. Low
Product pom artifactid xalan Highest
Product manifest: java_cup/runtime/ Implementation-Title runtime Medium
Product manifest: org/apache/xpath/ Implementation-Title org.apache.xpath Medium
Product manifest: org/apache/xalan/ Implementation-Title org.apache.xalan Medium
Product manifest: org/apache/bcel/ Implementation-Title org.apache.bcel Medium
Product central artifactid xalan Highest
Product manifest: org/apache/xml/ Implementation-Title org.apache.xml Medium
Product manifest: org/apache/xalan/ Specification-Title Java API for XML Processing Medium
Product pom parent-groupid org.apache Low
Product manifest: org/apache/regexp/ Specification-Title Java Regular Expression package Medium
Product manifest: java_cup/runtime/ Specification-Title Runtime component of JCup Medium
Product pom name Xalan Java High
Product pom url http://xml.apache.org/xalan-j/ Medium
Product file name xalan High
Product manifest: org/apache/xalan/xsltc/ Specification-Title Java API for XML Processing Medium
Product pom parent-artifactid apache Medium
Product pom groupid xalan Low
Product manifest: org/apache/regexp/ Implementation-Title org.apache.regexp Medium
Product manifest: org/apache/bcel/ Specification-Title Byte Code Engineering Library Medium
Version file version 2.7.1 Highest
Version central version 2.7.1 Highest
Version pom version 2.7.1 Highest
Published Vulnerabilities
CVE-2014-0107 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.
Vulnerable Software & Versions: (show all )
commons-lang-2.6.jar
Description:
Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
Referenced In Projects/Scopes:
eXo PLF:: Wiki Macros Iframe:compile
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor pom name Commons Lang High
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-lang Highest
Vendor pom url http://commons.apache.org/lang/ Highest
Vendor central groupid commons-lang High
Vendor pom artifactid commons-lang Low
Vendor Manifest bundle-docurl http://commons.apache.org/lang/ Low
Vendor file name commons-lang High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor central groupid org.netbeans.external High
Product pom artifactid commons-lang Highest
Product manifest Bundle-Description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest Bundle-Name Commons Lang Medium
Product pom parent-artifactid commons-parent Medium
Product pom description Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product pom name Commons Lang High
Product Manifest bundle-symbolicname org.apache.commons.lang Medium
Product central artifactid commons-lang High
Product pom groupid commons-lang Low
Product pom url http://commons.apache.org/lang/ Medium
Product Manifest bundle-docurl http://commons.apache.org/lang/ Low
Product file name commons-lang High
Product central artifactid org-apache-commons-lang High
Product pom parent-groupid org.apache.commons Low
Product Manifest Implementation-Title Commons Lang High
Product Manifest specification-title Commons Lang Medium
Version pom version 2.6 Highest
Version central version RELEASE110 High
Version file version 2.6 Highest
Version Manifest Implementation-Version 2.6 High
Version central version RELEASE90 High
Version central version RELEASE100 High
Version central version 2.6 High
portlet-api-2.0.jar
Description: The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group.
File Path: /home/ciagent/.m2/repository/javax/portlet/portlet-api/2.0/portlet-api-2.0.jar
MD5: 0ec08593cda1df33985391919996c740
SHA1: 1cd72f2a37fcf8ab9893a9468d7ba71c85fe2653
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Vendor Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Vendor file name portlet-api High
Vendor pom name Java Portlet Specification V2.0 High
Vendor pom url http://www.jcp.org/en/jsr/detail?id=286 Highest
Vendor central groupid javax.portlet Highest
Vendor pom artifactid portlet-api Low
Vendor pom groupid javax.portlet Highest
Vendor Manifest bundle-symbolicname javax.portlet Medium
Product pom description The Java Portlet API version 2.0 developed by the Java Community Process JSR-286 Expert Group. Medium
Product pom groupid javax.portlet Low
Product Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=286 Low
Product pom artifactid portlet-api Highest
Product file name portlet-api High
Product pom name Java Portlet Specification V2.0 High
Product pom url http://www.jcp.org/en/jsr/detail?id=286 Medium
Product Manifest Bundle-Name JSR 286 Medium
Product Manifest bundle-symbolicname javax.portlet Medium
Product central artifactid portlet-api Highest
Version central version 2.0 Highest
Version file version 2.0 Highest
Version pom version 2.0 Highest
jcr-1.0.1.jar
Description: Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation.
License:
Day License: http://www.day.com/maven/jsr170/licenses/day-spec-license.htm
File Path: /home/ciagent/.m2/repository/javax/jcr/jcr/1.0.1/jcr-1.0.1.jar
MD5: 4639c7b994528948dab1a4feb1f68d6f
SHA1: 567ee103cf7592e3cf036e1bf4e2e06b9f08e1a1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name jcr High
Vendor Manifest extension-name jcr Medium
Vendor pom name Content Repository for Java Technology API High
Vendor pom url http://www.jcp.org/en/jsr/detail?id=170 Highest
Vendor Manifest Implementation-Vendor Day Software Management AG High
Vendor pom artifactid jcr Low
Vendor pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Vendor pom groupid javax.jcr Highest
Vendor pom organization name Day Software Management AG High
Vendor Manifest specification-vendor Day Software Management AG Low
Vendor pom organization url http://www.day.com/ Medium
Product file name jcr High
Product pom groupid javax.jcr Low
Product Manifest extension-name jcr Medium
Product pom name Content Repository for Java Technology API High
Product Manifest Implementation-Title javax.jcr High
Product pom organization url http://www.day.com/ Low
Product pom organization name Day Software Management AG Low
Product pom description Content Repository for Java technology API. Specifies a standard API to access content repositories in JavaTM 2 independently of implementation. Low
Product pom url http://www.jcp.org/en/jsr/detail?id=170 Medium
Product pom artifactid jcr Highest
Product Manifest specification-title Content Repository for Java Technology API Medium
Version pom version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
Version file version 1.0.1 Highest
cpe: cpe:/a:content_project:content:1.0.1
Confidence :Low
suppress
maven: javax.jcr:jcr:1.0.1
Confidence :High
Published Vulnerabilities
CVE-2017-16111 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.
Vulnerable Software & Versions:
fontbox-1.8.14.jar
Description:
The Apache FontBox library is an open source Java tool to obtain low level information
from font files. FontBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/fontbox/1.8.14/fontbox-1.8.14.jar
MD5: 901640f7e2bd12508ae4a7cccba3df79
SHA1: 9c7caec614a6a132bedc83f1d6d247bb96ca0df3
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Vendor pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid apache.pdfbox Highest
Vendor manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Vendor pom artifactid fontbox Low
Vendor Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Vendor pom url http://pdfbox.apache.org/ Highest
Vendor pom name Apache FontBox High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor file name fontbox High
Vendor pom parent-artifactid pdfbox-parent Low
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom parent-groupid org.apache.pdfbox Medium
Product Manifest specification-title Apache FontBox Medium
Product pom description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Product pom parent-artifactid pdfbox-parent Medium
Product manifest Bundle-Description The Apache FontBox library is an open source Java tool to obtain low level information from font files. FontBox is a subproject of Apache PDFBox. Low
Product pom parent-groupid org.apache.pdfbox Low
Product Manifest bundle-symbolicname org.apache.pdfbox.fontbox Medium
Product pom name Apache FontBox High
Product pom url http://pdfbox.apache.org/ Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom groupid apache.pdfbox Low
Product file name fontbox High
Product Manifest Implementation-Title Apache FontBox High
Product pom artifactid fontbox Highest
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product central artifactid fontbox Highest
Product Manifest Bundle-Name Apache FontBox Medium
Version pom version 1.8.14 Highest
Version Manifest Implementation-Version 1.8.14 High
Version central version 1.8.14 Highest
Version file version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
jempbox-1.8.14.jar
Description:
The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM)
specification. JempBox is a subproject of Apache PDFBox.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/jempbox/1.8.14/jempbox-1.8.14.jar
MD5: 393135759731daf4e301903b3de2fbbb
SHA1: 7f94c7cd4efc21e78729436cc4cf0c09eeea0f38
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid apache.pdfbox Highest
Vendor manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Vendor Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom artifactid jempbox Low
Vendor file name jempbox High
Vendor pom parent-artifactid pdfbox-parent Low
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom name Apache JempBox High
Vendor pom parent-groupid org.apache.pdfbox Medium
Product pom description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Product central artifactid jempbox Highest
Product pom artifactid jempbox Highest
Product pom parent-artifactid pdfbox-parent Medium
Product manifest Bundle-Description The Apache JempBox library is an open source Java tool that implements Adobe's XMP(TM) specification. JempBox is a subproject of Apache PDFBox. Low
Product pom parent-groupid org.apache.pdfbox Low
Product Manifest bundle-symbolicname org.apache.pdfbox.jempbox Medium
Product Manifest Implementation-Title Apache JempBox High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product file name jempbox High
Product pom groupid apache.pdfbox Low
Product Manifest specification-title Apache JempBox Medium
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Product pom name Apache JempBox High
Product Manifest Bundle-Name Apache JempBox Medium
Version pom version 1.8.14 Highest
Version Manifest Implementation-Version 1.8.14 High
Version central version 1.8.14 Highest
Version file version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
pdfbox-1.8.14.jar
Description:
The Apache PDFBox library is an open source Java tool for working with PDF documents.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/pdfbox/pdfbox/1.8.14/pdfbox-1.8.14.jar
MD5: c90740e185fc2f8013d1119f509ea4f3
SHA1: 7550298240c8540b721733ede6dc88fcf4fa2b0f
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Apache PDFBox High
Vendor pom groupid org.apache.pdfbox Highest
Vendor Manifest bundle-symbolicname org.apache.pdfbox Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor-Id org.apache.pdfbox Medium
Vendor central groupid org.apache.pdfbox Highest
Vendor pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid apache.pdfbox Highest
Vendor file name pdfbox High
Vendor manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium
Vendor pom artifactid pdfbox Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom parent-artifactid pdfbox-parent Low
Vendor Manifest bundle-docurl http://pdfbox.apache.org Low
Vendor pom parent-groupid org.apache.pdfbox Medium
Product pom name Apache PDFBox High
Product pom artifactid pdfbox Highest
Product Manifest bundle-symbolicname org.apache.pdfbox Medium
Product central artifactid pdfbox Highest
Product pom description
The Apache PDFBox library is an open source Java tool for working with PDF documents.
Medium
Product pom parent-artifactid pdfbox-parent Medium
Product file name pdfbox High
Product manifest Bundle-Description The Apache PDFBox library is an open source Java tool for working with PDF documents. Medium
Product Manifest Bundle-Name Apache PDFBox Medium
Product pom parent-groupid org.apache.pdfbox Low
Product Manifest specification-title Apache PDFBox Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom groupid apache.pdfbox Low
Product Manifest Implementation-Title Apache PDFBox High
Product Manifest bundle-docurl http://pdfbox.apache.org Low
Version pom version 1.8.14 Highest
Version Manifest Implementation-Version 1.8.14 High
Version central version 1.8.14 Highest
Version file version 1.8.14 Highest
Published Vulnerabilities
CVE-2018-11797 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
Vulnerable Software & Versions: (show all )
CVE-2018-8036 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
In Apache PDFBox 1.8.0 to 1.8.14 and 2.0.0RC1 to 2.0.10, a carefully crafted (or fuzzed) file can trigger an infinite loop which leads to an out of memory exception in Apache PDFBox's AFMParser.
Vulnerable Software & Versions: (show all )
htmllexer-2.1.jar
Description: HTML Lexer is the low level lexical analyzer.
File Path: /home/ciagent/.m2/repository/org/htmlparser/htmllexer/2.1/htmllexer-2.1.jar
MD5: 1cb7184766a0c52f4d98d671bb08be19
SHA1: 2ebf2c073e649b7e674cddd0558ff102a486402f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.htmlparser Medium
Vendor central groupid org.htmlparser Highest
Vendor pom parent-artifactid HTMLParserProject Low
Vendor pom description HTML Lexer is the low level lexical analyzer. Medium
Vendor pom groupid org.htmlparser Highest
Vendor file name htmllexer High
Vendor pom groupid htmlparser Highest
Vendor pom url http://htmlparser.org Highest
Vendor pom artifactid htmllexer Low
Vendor pom name HTML Lexer Jar High
Vendor jar package name htmlparser Low
Product pom parent-artifactid HTMLParserProject Medium
Product pom artifactid htmllexer Highest
Product pom description HTML Lexer is the low level lexical analyzer. Medium
Product pom url http://htmlparser.org Medium
Product file name htmllexer High
Product pom groupid htmlparser Low
Product pom name HTML Lexer Jar High
Product central artifactid htmllexer Highest
Product pom parent-groupid org.htmlparser Low
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version central version 2.1 Highest
htmlparser-2.1.jar
Description: HTML Parser is the high level syntactical analyzer.
File Path: /home/ciagent/.m2/repository/org/htmlparser/htmlparser/2.1/htmlparser-2.1.jar
MD5: aa05b921026c228f92ef8b4a13c26f8d
SHA1: c752e5984b7767533cbd3fdffa48cecb52fa226c
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.htmlparser Medium
Vendor pom artifactid htmlparser Low
Vendor central groupid org.htmlparser Highest
Vendor pom parent-artifactid HTMLParserProject Low
Vendor pom groupid org.htmlparser Highest
Vendor pom groupid htmlparser Highest
Vendor pom name HTML Parser Jar High
Vendor pom url http://htmlparser.org Highest
Vendor pom description HTML Parser is the high level syntactical analyzer. Medium
Vendor jar package name htmlparser Low
Vendor file name htmlparser High
Product pom parent-artifactid HTMLParserProject Medium
Product pom artifactid htmlparser Highest
Product central artifactid htmlparser Highest
Product pom url http://htmlparser.org Medium
Product pom name HTML Parser Jar High
Product pom groupid htmlparser Low
Product pom description HTML Parser is the high level syntactical analyzer. Medium
Product file name htmlparser High
Product pom parent-groupid org.htmlparser Low
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version central version 2.1 Highest
poi-3.13.jar
Description: Apache POI - Java API To Access Microsoft Format Files
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi/3.13/poi-3.13.jar
MD5: 1b43f32e2211546040597a9e2d07b869
SHA1: 0f59f504ba8c521e61e25f417ec652fd485010f3
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.poi Highest
Vendor Manifest Implementation-Vendor-Id org.apache.poi Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid poi Low
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom name Apache POI High
Vendor file name poi High
Vendor pom description Apache POI - Java API To Access Microsoft Format Files Medium
Vendor pom organization name Apache Software Foundation High
Vendor central groupid org.apache.poi Highest
Vendor pom groupid org.apache.poi Highest
Vendor pom url http://poi.apache.org/ Highest
Product pom description Apache POI - Java API To Access Microsoft Format Files Medium
Product pom artifactid poi Highest
Product Manifest specification-title Apache POI Medium
Product pom groupid apache.poi Low
Product central artifactid poi Highest
Product pom organization url http://www.apache.org/ Low
Product pom organization name Apache Software Foundation Low
Product pom name Apache POI High
Product file name poi High
Product Manifest Implementation-Title Apache POI High
Product pom url http://poi.apache.org/ Medium
Version file version 3.13 Highest
Version Manifest Implementation-Version 3.13 High
Version central version 3.13 Highest
Version pom version 3.13 Highest
Related Dependencies
poi-ooxml-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-ooxml/3.13/poi-ooxml-3.13.jar
SHA1: c364a8f5422d613e3a56db3b4b889f2989d7ee73
MD5: 38bb36c35a16030d4bc0ac14421430d7
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-ooxml:3.13 ✓
poi-ooxml-schemas-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-ooxml-schemas/3.13/poi-ooxml-schemas-3.13.jar
SHA1: 56fb0b9f3ffc3d7f7fc9b59e17b5fa2c3ab921e7
MD5: ca12e13961e9df83ddd5471733d73d91
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-ooxml-schemas:3.13 ✓
poi-scratchpad-3.13.jar
File Path: /home/ciagent/.m2/repository/org/apache/poi/poi-scratchpad/3.13/poi-scratchpad-3.13.jar
SHA1: 09d763275e6c7fa05d47e2581606748669e88c55
MD5: d8dbe05b289da779874e4783881e1b57
cpe: cpe:/a:apache:poi:3.13
maven: org.apache.poi:poi-scratchpad:3.13 ✓
Published Vulnerabilities
CVE-2016-5000 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Vulnerable Software & Versions:
CVE-2017-5644 suppress
Severity:
High
CVSS Score: 7.1
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
CWE: CWE-399 Resource Management Errors
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
Vulnerable Software & Versions:
tika-core-1.5.jar
Description: This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-core/1.5/tika-core-1.5.jar
MD5: e864bf637f51283dc525087b015d7b1a
SHA1: 194ca0fb3d73b07737524806fbc3bec89063c03a
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://tika.apache.org/ Highest
Vendor pom artifactid tika-core Low
Vendor pom groupid apache.tika Highest
Vendor manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Vendor Manifest bundle-symbolicname org.apache.tika.core Medium
Vendor file name tika-core High
Vendor pom organization name The Apache Software Foundation High
Vendor pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Vendor pom parent-artifactid tika-parent Low
Vendor pom parent-groupid org.apache.tika Medium
Vendor pom name Apache Tika core High
Vendor central groupid org.apache.tika Highest
Vendor pom groupid org.apache.tika Highest
Vendor pom organization url http://www.apache.org Medium
Vendor Manifest bundle-docurl http://tika.apache.org/ Low
Product Manifest Bundle-Name Apache Tika core Medium
Product pom organization url http://www.apache.org Low
Product manifest Bundle-Description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Product Manifest bundle-symbolicname org.apache.tika.core Medium
Product pom organization name The Apache Software Foundation Low
Product pom artifactid tika-core Highest
Product file name tika-core High
Product pom groupid apache.tika Low
Product pom description This is the core Apache Tika™ toolkit library from which all other modules inherit functionality. It also includes the core facades for the Tika API. Low
Product central artifactid tika-core Highest
Product pom url http://tika.apache.org/ Medium
Product pom name Apache Tika core High
Product pom parent-groupid org.apache.tika Low
Product pom parent-artifactid tika-parent Medium
Product Manifest bundle-docurl http://tika.apache.org/ Low
Version file version 1.5 Highest
Version central version 1.5 Highest
Version pom version 1.5 Highest
Related Dependencies
tika-parsers-1.5.jar
File Path: /home/ciagent/.m2/repository/org/apache/tika/tika-parsers/1.5/tika-parsers-1.5.jar
SHA1: 9b895231b7a0dae7349dfb42cb1b926c345b5281
MD5: f1056da5d1021ad1bbac7dab01b335d1
cpe: cpe:/a:apache:tika:1.5
maven: org.apache.tika:tika-parsers:1.5 ✓
Published Vulnerabilities
CVE-2016-6809 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Vulnerable Software & Versions:
CVE-2018-11761 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11762 suppress
Severity:
Medium
CVSS Score: 5.8
(AV:N/AC:M/Au:N/C:N/I:P/A:P)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
Vulnerable Software & Versions: (show all )
CVE-2018-11796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Vulnerable Software & Versions: (show all )
CVE-2018-1335 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1338 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-8017 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
In Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an infinite loop in the IptcAnpaParser.
Vulnerable Software & Versions: (show all )
vorbis-java-core-0.1-tests.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-core/0.1/vorbis-java-core-0.1-tests.jar
MD5: d58f076c08a917277d03f3417aa867a6
SHA1: c849979e199d8a7c3da1a00799c623c00f94efac
Referenced In Projects/Scopes:
eXo PLF:: Wiki Service:test,provided
eXo PLF:: Wiki Webui:test,provided
eXo PLF:: Wiki Renderer:test,provided
eXo Wiki JPA Migration Service:test,provided
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Upgrade Plugins:test,provided
Evidence
Type Source Name Value Confidence
Vendor file name vorbis-java-core High
Vendor pom parent-groupid org.gagravarr Medium
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor pom groupid org.gagravarr Highest
Vendor pom groupid gagravarr Highest
Vendor jar package name gagravarr Low
Vendor jar package name ogg Low
Vendor pom artifactid vorbis-java-core Low
Vendor pom url Gagravarr/VorbisJava Highest
Vendor pom name Ogg and Vorbis for Java, Core High
Vendor central groupid org.gagravarr Highest
Product file name vorbis-java-core High
Product pom parent-groupid org.gagravarr Low
Product central artifactid vorbis-java-core Highest
Product pom groupid gagravarr Low
Product pom url Gagravarr/VorbisJava High
Product pom artifactid vorbis-java-core Highest
Product jar package name ogg Low
Product pom parent-artifactid vorbis-java-parent Medium
Product pom name Ogg and Vorbis for Java, Core High
Version central version 0.1 Highest
Version file version 0.1 Highest
Version pom version 0.1 Highest
vorbis-java-tika-0.1.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-tika/0.1/vorbis-java-tika-0.1.jar
MD5: 1fccc6796a0924ba4f32eb1d44b8616b
SHA1: 6966c8663a7f689021accb13cceaa6101f53ea3d
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.gagravarr Medium
Vendor pom artifactid vorbis-java-tika Low
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor jar package name tika Low
Vendor pom groupid org.gagravarr Highest
Vendor pom groupid gagravarr Highest
Vendor pom name Apache Tika plugin for Ogg, Vorbis and FLAC High
Vendor jar package name gagravarr Low
Vendor file name vorbis-java-tika High
Vendor pom url Gagravarr/VorbisJava Highest
Vendor central groupid org.gagravarr Highest
Product pom parent-groupid org.gagravarr Low
Product pom groupid gagravarr Low
Product pom url Gagravarr/VorbisJava High
Product jar package name tika Low
Product central artifactid vorbis-java-tika Highest
Product pom name Apache Tika plugin for Ogg, Vorbis and FLAC High
Product pom artifactid vorbis-java-tika Highest
Product file name vorbis-java-tika High
Product pom parent-artifactid vorbis-java-parent Medium
Version central version 0.1 Highest
Version file version 0.1 Highest
Version pom version 0.1 Highest
Published Vulnerabilities
CVE-2016-6809 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.
Vulnerable Software & Versions:
CVE-2018-11761 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
Vulnerable Software & Versions: (show all )
CVE-2018-11796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.
Vulnerable Software & Versions: (show all )
CVE-2018-1335 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on a server that is open to untrusted clients. The mitigation is to upgrade to Tika 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1338 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's BPGParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
CVE-2018-1339 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
A carefully crafted (or fuzzed) file can trigger an infinite loop in Apache Tika's ChmParser in versions of Apache Tika before 1.18.
Vulnerable Software & Versions: (show all )
netcdf-4.2-min.jar
Description: The NetCDF-Java Library is a Java interface to NetCDF files,
as well as to many other types of scientific data formats.
License:
(MIT-style) netCDF C library license.: http://www.unidata.ucar.edu/software/netcdf/copyright.html
File Path: /home/ciagent/.m2/repository/edu/ucar/netcdf/4.2-min/netcdf-4.2-min.jar
MD5: eb00b40b0511f0fc1dfcfc9cb89e3c53
SHA1: 0f3c3f3db4c54483aa1fbc4497e300879ce24da1
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid edu.ucar Highest
Vendor file name netcdf High
Vendor Manifest Implementation-Vendor UCAR/Unidata High
Vendor central groupid edu.ucar Highest
Vendor pom name The NetCDF-Java Library High
Vendor pom artifactid netcdf Low
Vendor pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low
Vendor Manifest built-on 2010-11-24 05:51:29 Low
Vendor pom url http://www.unidata.ucar.edu/software/netcdf-java/ Highest
Product pom url http://www.unidata.ucar.edu/software/netcdf-java/ Medium
Product central artifactid netcdf Highest
Product file name netcdf High
Product pom groupid edu.ucar Low
Product Manifest Implementation-Title NetCDF-Java-Library High
Product pom name The NetCDF-Java Library High
Product pom artifactid netcdf Highest
Product pom description The NetCDF-Java Library is a Java interface to NetCDF files, as well as to many other types of scientific data formats. Low
Product Manifest built-on 2010-11-24 05:51:29 Low
Version file version 4.2 Highest
Version central version 4.2-min Highest
Version pom version 4.2-min Highest
apache-mime4j-core-0.7.2.jar
Description: Java stream based MIME message parser
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-core/0.7.2/apache-mime4j-core-0.7.2.jar
MD5: 88f799546eca803c53eee01a4ce5edcd
SHA1: a81264fe0265ebe8fd1d8128aad06dc320de6eef
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid apache.james Highest
Vendor manifest Bundle-Description Java stream based MIME message parser Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid apache-mime4j-core Low
Vendor central groupid org.apache.james Highest
Vendor file name apache-mime4j-core High
Vendor Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid org.apache.james Highest
Vendor pom parent-artifactid apache-mime4j-project Low
Vendor pom name Apache JAMES Mime4j (Core) High
Vendor pom parent-groupid org.apache.james Medium
Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest bundle-docurl http://www.apache.org/ Low
Product Manifest Implementation-Title Apache Mime4j High
Product manifest Bundle-Description Java stream based MIME message parser Medium
Product Manifest specification-title Apache Mime4j Medium
Product file name apache-mime4j-core High
Product Manifest url http://james.apache.org/mime4j/apache-mime4j-core Low
Product central artifactid apache-mime4j-core Highest
Product pom groupid apache.james Low
Product pom artifactid apache-mime4j-core Highest
Product pom parent-groupid org.apache.james Low
Product pom name Apache JAMES Mime4j (Core) High
Product pom parent-artifactid apache-mime4j-project Medium
Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium
Product Manifest Bundle-Name Apache JAMES Mime4j (Core) Medium
Product Manifest bundle-docurl http://www.apache.org/ Low
Version file version 0.7.2 Highest
Version central version 0.7.2 Highest
Version Manifest Implementation-Version 0.7.2 High
Version pom version 0.7.2 Highest
Related Dependencies
apache-mime4j-dom-0.7.2.jar
File Path: /home/ciagent/.m2/repository/org/apache/james/apache-mime4j-dom/0.7.2/apache-mime4j-dom-0.7.2.jar
SHA1: 1c289aa264548a0a1f1b43685a9cb2ab23f67287
MD5: dedc747b5c367fbd7f8a7235d1d7cbee
maven: org.apache.james:apache-mime4j-dom:0.7.2 ✓
xz-1.2.jar
Description: XZ data compression
License:
Public Domain
File Path: /home/ciagent/.m2/repository/org/tukaani/xz/1.2/xz-1.2.jar
MD5: 04bd31459826c30c2a3c304e3b225ad4
SHA1: bfc66dda280a18ab341b5023248925265c00394c
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.tukaani Highest
Vendor file name xz High
Vendor pom url http://tukaani.org/xz/java.html Highest
Vendor pom name XZ for Java High
Vendor Manifest implementation-url http://tukaani.org/xz/java.html Low
Vendor pom description XZ data compression Medium
Vendor Manifest bundle-symbolicname org.tukaani.xz Medium
Vendor pom groupid tukaani Highest
Vendor Manifest bundle-docurl http://tukaani.org/xz/java.html Low
Vendor pom artifactid xz Low
Vendor central groupid org.tukaani Highest
Product Manifest Bundle-Name XZ data compression Medium
Product pom name XZ for Java High
Product pom groupid tukaani Low
Product pom description XZ data compression Medium
Product Manifest bundle-symbolicname org.tukaani.xz Medium
Product file name xz High
Product Manifest Implementation-Title XZ data compression High
Product pom url http://tukaani.org/xz/java.html Medium
Product Manifest implementation-url http://tukaani.org/xz/java.html Low
Product pom artifactid xz Highest
Product Manifest bundle-docurl http://tukaani.org/xz/java.html Low
Product central artifactid xz Highest
Version pom version 1.2 Highest
Version file version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
Version central version 1.2 Highest
maven: org.tukaani:xz:1.2 ✓
Confidence :Highest
cpe: cpe:/a:tukaani:xz:1.2
Confidence :Low
suppress
Published Vulnerabilities
CVE-2015-4035 suppress
Severity:
Medium
CVSS Score: 4.6
(AV:L/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attackers to execute arbitrary code by having a user run xzgrep on a crafted file name.
Vulnerable Software & Versions:
commons-compress-1.5.jar
Description:
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-compress/1.5/commons-compress-1.5.jar
MD5: 5e18cfcf472548c2e0b90a4ea1cedf42
SHA1: d2bd2c0bd328f1dabdf33e10b6d223ebcbe93343
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.apache.commons Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.commons Highest
Vendor file name commons-compress High
Vendor pom name Commons Compress High
Vendor pom parent-artifactid commons-parent Low
Vendor central groupid org.apache.commons Highest
Vendor Manifest extension-name org.apache.commons.compress Medium
Vendor Manifest bundle-docurl http://commons.apache.org/compress/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-symbolicname org.apache.commons.compress Medium
Vendor pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest implementation-build tags/COMPRESS-1.5_RC1@r1455005; 2013-03-11 07:12:20+0100 Low
Vendor pom url http://commons.apache.org/compress/ Highest
Vendor manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Vendor pom artifactid commons-compress Low
Product pom parent-artifactid commons-parent Medium
Product pom artifactid commons-compress Highest
Product file name commons-compress High
Product pom name Commons Compress High
Product Manifest extension-name org.apache.commons.compress Medium
Product Manifest bundle-docurl http://commons.apache.org/compress/ Low
Product central artifactid commons-compress Highest
Product Manifest specification-title Commons Compress Medium
Product Manifest Implementation-Title Commons Compress High
Product Manifest bundle-symbolicname org.apache.commons.compress Medium
Product pom groupid apache.commons Low
Product Manifest Bundle-Name Commons Compress Medium
Product pom description
Apache Commons Compress software defines an API for working with compression and archive formats.
These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Product Manifest implementation-build tags/COMPRESS-1.5_RC1@r1455005; 2013-03-11 07:12:20+0100 Low
Product pom parent-groupid org.apache.commons Low
Product manifest Bundle-Description Apache Commons Compress software defines an API for working with compression and archive formats.These include: bzip2, gzip, pack200, xz and ar, cpio, jar, tar, zip, dump. Low
Product pom url http://commons.apache.org/compress/ Medium
Version Manifest Implementation-Version 1.5 High
Version file version 1.5 Highest
Version central version 1.5 Highest
Version pom version 1.5 Highest
tagsoup-1.2.1.jar
Description: TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML.
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/ccil/cowan/tagsoup/tagsoup/1.2.1/tagsoup-1.2.1.jar
MD5: ae73a52cdcbec10cd61d9ef22fab5936
SHA1: 5584627487e984c03456266d3f8802eb85a9ce97
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.ccil.cowan.tagsoup Highest
Vendor pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low
Vendor pom groupid ccil.cowan.tagsoup Highest
Vendor file name tagsoup High
Vendor pom url http://home.ccil.org/~cowan/XML/tagsoup/ Highest
Vendor pom artifactid tagsoup Low
Vendor pom groupid org.ccil.cowan.tagsoup Highest
Vendor pom name TagSoup High
Product pom groupid ccil.cowan.tagsoup Low
Product pom description TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. Low
Product pom artifactid tagsoup Highest
Product file name tagsoup High
Product central artifactid tagsoup Highest
Product pom name TagSoup High
Product pom url http://home.ccil.org/~cowan/XML/tagsoup/ Medium
Version file version 1.2.1 Highest
Version central version 1.2.1 Highest
Version pom version 1.2.1 Highest
asm-debug-all-4.1.jar
File Path: /home/ciagent/.m2/repository/org/ow2/asm/asm-debug-all/4.1/asm-debug-all-4.1.jar
MD5: 6c3a8842f484dd3d620002b361e3610e
SHA1: dd6ba5c392d4102458494e29f54f70ac534ec2a2
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor France Telecom R&D High
Vendor pom name ASM Debug All High
Vendor pom parent-groupid org.ow2.asm Medium
Vendor pom artifactid asm-debug-all Low
Vendor pom groupid ow2.asm Highest
Vendor pom parent-artifactid asm-parent Low
Vendor pom groupid org.ow2.asm Highest
Vendor Manifest bundle-symbolicname org.objectweb.asm.all.debug Medium
Vendor central groupid org.ow2.asm Highest
Vendor Manifest bundle-docurl http://asm.objectweb.org Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor file name asm-debug-all High
Product pom name ASM Debug All High
Product pom groupid ow2.asm Low
Product Manifest Bundle-Name ASM all classes with debug info Medium
Product Manifest Implementation-Title ASM all classes with debug info High
Product pom parent-groupid org.ow2.asm Low
Product Manifest bundle-symbolicname org.objectweb.asm.all.debug Medium
Product central artifactid asm-debug-all Highest
Product Manifest bundle-docurl http://asm.objectweb.org Low
Product pom parent-artifactid asm-parent Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom artifactid asm-debug-all Highest
Product file name asm-debug-all High
Version pom version 4.1 Highest
Version central version 4.1 Highest
Version file version 4.1 Highest
Version Manifest Implementation-Version 4.1 High
isoparser-1.0-RC-1.jar
Description: A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/googlecode/mp4parser/isoparser/1.0-RC-1/isoparser-1.0-RC-1.jar
MD5: b0444fde2290319c9028564c3c3ff1ab
SHA1: 4a5768b1070b9488a433362d736720fd7a7b264f
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid googlecode.mp4parser Highest
Vendor pom url http://code.google.com/p/mp4parser/ Highest
Vendor jar package name coremedia Low
Vendor central groupid com.googlecode.mp4parser Highest
Vendor file name isoparser High
Vendor jar package name iso Low
Vendor jar package name boxes Low
Vendor pom description A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
Medium
Vendor pom artifactid isoparser Low
Vendor pom name ISO Parser High
Vendor pom groupid com.googlecode.mp4parser Highest
Product pom artifactid isoparser Highest
Product file name isoparser High
Product jar package name iso Low
Product pom url http://code.google.com/p/mp4parser/ Medium
Product jar package name boxes Low
Product pom groupid googlecode.mp4parser Low
Product pom description A generic parser and writer for all ISO 14496 based files (MP4, Quicktime, DCF, PDCF, ...)
Medium
Product pom name ISO Parser High
Product central artifactid isoparser Highest
Version file version 1.0 Highest
Version central version 1.0-RC-1 Highest
Version file name isoparser Medium
Version pom version 1.0-RC-1 Highest
Published Vulnerabilities
CVE-2013-0259 suppress
Severity:
Low
CVSS Score: 2.1
(AV:N/AC:H/Au:S/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.
Vulnerable Software & Versions: (show all )
xmpcore-5.1.2.jar
Description:
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
License:
The BSD License: http://www.adobe.com/devnet/xmp/library/eula-xmp-library-java.html
File Path: /home/ciagent/.m2/repository/com/adobe/xmp/xmpcore/5.1.2/xmpcore-5.1.2.jar
MD5: 0b2cf2a09d32abdedd17de864e93ad25
SHA1: 55615fa2582424e38705487d1d3969af8554f637
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest builddate 2012 Jul 03 11:48:46-CEST Low
Vendor pom groupid adobe.xmp Highest
Vendor file name xmpcore High
Vendor Manifest implementation-minor 1 Low
Vendor Manifest implementation-major 5 Low
Vendor Manifest Implementation-Vendor Copyright 2006-2009 Adobe Systems Incorporated. All rights reserved High
Vendor pom url http://www.adobe.com/devnet/xmp.html Highest
Vendor central groupid com.adobe.xmp Highest
Vendor pom groupid com.adobe.xmp Highest
Vendor Manifest implementation-micro 1 Low
Vendor pom name XMP Library for Java High
Vendor pom description
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
Medium
Vendor Manifest implementation-engbuild 003 Low
Vendor pom artifactid xmpcore Low
Product pom groupid adobe.xmp Low
Product pom url http://www.adobe.com/devnet/xmp.html Medium
Product Manifest builddate 2012 Jul 03 11:48:46-CEST Low
Product central artifactid xmpcore Highest
Product file name xmpcore High
Product Manifest implementation-minor 1 Low
Product Manifest implementation-major 5 Low
Product pom artifactid xmpcore Highest
Product Manifest implementation-micro 1 Low
Product Manifest Implementation-Title Adobe XMP Core High
Product pom name XMP Library for Java High
Product pom description
The XMP Library for Java is based on the C++ XMPCore library
and the API is similar.
Medium
Product Manifest implementation-engbuild 003 Low
Version pom version 5.1.2 Highest
Version central version 5.1.2 Highest
Version file version 5.1.2 Highest
metadata-extractor-2.6.2.jar
Description: Java library for reading metadata from image files.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/drewnoakes/metadata-extractor/2.6.2/metadata-extractor-2.6.2.jar
MD5: 8f3acbee87dbd5b0cdfacee3bb3aff8b
SHA1: 13930ff22d3f152bd969a63e88537d2f2adc2cd5
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Java library for reading metadata from image files. Medium
Vendor jar package name metadata Low
Vendor pom groupid drewnoakes Highest
Vendor pom name metadata-extractor High
Vendor pom url http://code.google.com/p/metadata-extractor/ Highest
Vendor jar package name drew Low
Vendor file name metadata-extractor High
Vendor central groupid com.drewnoakes Highest
Vendor pom groupid com.drewnoakes Highest
Vendor pom artifactid metadata-extractor Low
Product pom description Java library for reading metadata from image files. Medium
Product pom url http://code.google.com/p/metadata-extractor/ Medium
Product jar package name metadata Low
Product pom name metadata-extractor High
Product pom artifactid metadata-extractor Highest
Product file name metadata-extractor High
Product pom groupid drewnoakes Low
Product central artifactid metadata-extractor Highest
Version file version 2.6.2 Highest
Version pom version 2.6.2 Highest
Version central version 2.6.2 Highest
vorbis-java-core-0.1.jar
File Path: /home/ciagent/.m2/repository/org/gagravarr/vorbis-java-core/0.1/vorbis-java-core-0.1.jar
MD5: b88115be2754cb6883e652ba68ca46c8
SHA1: 662a02b94701947e6e66e7793d996043f05fad4a
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name vorbis-java-core High
Vendor pom parent-groupid org.gagravarr Medium
Vendor pom parent-artifactid vorbis-java-parent Low
Vendor pom groupid org.gagravarr Highest
Vendor pom groupid gagravarr Highest
Vendor jar package name gagravarr Low
Vendor pom artifactid vorbis-java-core Low
Vendor pom url Gagravarr/VorbisJava Highest
Vendor pom name Ogg and Vorbis for Java, Core High
Vendor central groupid org.gagravarr Highest
Product file name vorbis-java-core High
Product pom parent-groupid org.gagravarr Low
Product central artifactid vorbis-java-core Highest
Product pom groupid gagravarr Low
Product pom url Gagravarr/VorbisJava High
Product pom artifactid vorbis-java-core Highest
Product pom parent-artifactid vorbis-java-parent Medium
Product pom name Ogg and Vorbis for Java, Core High
Version central version 0.1 Highest
Version file version 0.1 Highest
Version pom version 0.1 Highest
juniversalchardet-1.0.3.jar
Description: Java port of universalchardet
License:
Mozilla Public License 1.1 (MPL 1.1): http://www.mozilla.org/MPL/MPL-1.1.html
File Path: /home/ciagent/.m2/repository/com/googlecode/juniversalchardet/juniversalchardet/1.0.3/juniversalchardet-1.0.3.jar
MD5: d9ea0a9a275336c175b343f2e4cd8f27
SHA1: cd49678784c46aa8789c060538e0154013bb421b
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid juniversalchardet Low
Vendor pom name juniversalchardet High
Vendor jar package name universalchardet Low
Vendor pom description Java port of universalchardet Medium
Vendor jar package name mozilla Low
Vendor central groupid com.googlecode.juniversalchardet High
Vendor pom groupid com.googlecode.juniversalchardet Highest
Vendor pom url http://juniversalchardet.googlecode.com/ Highest
Vendor file name juniversalchardet High
Vendor jar package name prober Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor pom groupid googlecode.juniversalchardet Highest
Product pom name juniversalchardet High
Product pom url http://juniversalchardet.googlecode.com/ Medium
Product jar package name universalchardet Low
Product pom groupid googlecode.juniversalchardet Low
Product pom description Java port of universalchardet Medium
Product central artifactid juniversalchardet-1.0.3 High
Product jar package name prober Low
Product pom artifactid juniversalchardet Highest
Product file name juniversalchardet High
Product central artifactid juniversalchardet High
Version file version 1.0.3 Highest
Version central version 1.0.3 High
Version file name juniversalchardet Medium
Version pom version 1.0.3 Highest
Version central version 2.0 High
jhighlight-1.0.jar
Description:
JHighlight is an embeddable pure Java syntax highlighting
library that supports Java, HTML, XHTML, XML and LZX
languages and outputs to XHTML.
It also supports RIFE templates tags and highlights them
clearly so that you can easily identify the difference
between your RIFE markup and the actual marked up source.
License:
CDDL, v1.0: http://www.opensource.org/licenses/cddl1.php
LGPL, v2.1 or later: http://www.opensource.org/licenses/lgpl-license.php
File Path: /home/ciagent/.m2/repository/com/uwyn/jhighlight/1.0/jhighlight-1.0.jar
MD5: 0ad5cf1bc56657f5e9e327e5e768da0a
SHA1: 0b1774029ee29472df8c25e5ba796431f7689fd6
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JHighlight High
Vendor pom artifactid jhighlight Low
Vendor pom groupid com.uwyn Highest
Vendor pom description JHighlight is an embeddable pure Java syntax highlighting library that supports Java, HTML, XHTML, XML and LZX languages and outputs to XHTML. It also supports RIFE templates tags and highlights them clearly so that you can easily identify the difference between your RIFE markup and the actual marked up source. Low
Vendor pom url https://jhighlight.dev.java.net/ Highest
Vendor pom groupid uwyn Highest
Vendor pom organization url http://uwyn.com/ Medium
Vendor jar package name uwyn Low
Vendor file name jhighlight High
Vendor central groupid com.uwyn Highest
Vendor pom organization name Uwyn High
Vendor jar package name jhighlight Low
Product pom artifactid jhighlight Highest
Product pom name JHighlight High
Product pom groupid uwyn Low
Product pom organization url http://uwyn.com/ Low
Product central artifactid jhighlight Highest
Product file name jhighlight High
Product pom organization name Uwyn Low
Product pom description JHighlight is an embeddable pure Java syntax highlighting library that supports Java, HTML, XHTML, XML and LZX languages and outputs to XHTML. It also supports RIFE templates tags and highlights them clearly so that you can easily identify the difference between your RIFE markup and the actual marked up source. Low
Product pom url https://jhighlight.dev.java.net/ Medium
Product jar package name jhighlight Low
Version file version 1.0 Highest
Version central version 1.0 Highest
Version pom version 1.0 Highest
xmlbeans-2.6.0.jar
Description: XmlBeans main jar
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/xmlbeans/xmlbeans/2.6.0/xmlbeans-2.6.0.jar
MD5: 6591c08682d613194dacb01e95c78c2c
SHA1: 29e80d2dd51f9dcdef8f9ffaee0d4dc1c9bbfc87
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid xmlbeans Low
Vendor pom name XmlBeans High
Vendor pom description XmlBeans main jar Medium
Vendor pom groupid org.apache.xmlbeans Highest
Vendor manifest: org/apache/xmlbeans/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom groupid apache.xmlbeans Highest
Vendor pom organization url http://xmlbeans.apache.org/ Medium
Vendor pom url http://xmlbeans.apache.org Highest
Vendor pom organization name XmlBeans High
Vendor file name xmlbeans High
Vendor central groupid org.apache.xmlbeans Highest
Product pom name XmlBeans High
Product pom description XmlBeans main jar Medium
Product pom organization name XmlBeans Low
Product pom groupid apache.xmlbeans Low
Product manifest: org/apache/xmlbeans/ Implementation-Title org.apache.xmlbeans Medium
Product central artifactid xmlbeans Highest
Product pom organization url http://xmlbeans.apache.org/ Low
Product pom url http://xmlbeans.apache.org Medium
Product pom artifactid xmlbeans Highest
Product file name xmlbeans High
Version pom version 2.6.0 Highest
Version central version 2.6.0 Highest
Version file version 2.6.0 Highest
exo.core.component.document-5.3.x-SNAPSHOT.jar
Description: Implementation of Document Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.document/5.3.x-SNAPSHOT/exo.core.component.document-5.3.x-SNAPSHOT.jar
MD5: f45710d396a164821cae9d6be2c43dea
SHA1: 3816bb2203bb3f7c818df5a3a3949a093bd74d02
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name eXo PLF Core :: Component :: Document Service High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor file name exo.core.component.document High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom description Implementation of Document Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom artifactid exo.core.component.document Low
Product pom parent-groupid org.exoplatform.core Low
Product pom name eXo PLF Core :: Component :: Document Service High
Product pom artifactid exo.core.component.document Highest
Product file name exo.core.component.document High
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product pom description Implementation of Document Service of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest Implementation-Title eXo PLF Core :: Component :: Document Service High
Product Manifest specification-title exo-core Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.document:5.3.x-SNAPSHOT
Confidence :High
lucene-analyzers-3.6.2.jar
Description: Additional Analyzers
File Path: /home/ciagent/.m2/repository/org/apache/lucene/lucene-analyzers/3.6.2/lucene-analyzers-3.6.2.jar
MD5: 13f8241b6991bd1349c05369a7c0f002
SHA1: 3a083510dcb0d0fc67f8456cdac6f48aa0da2993
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid lucene-parent Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid lucene-analyzers Low
Vendor file name lucene-analyzers High
Vendor pom groupid org.apache.lucene Highest
Vendor pom groupid apache.lucene Highest
Vendor pom description Additional Analyzers Medium
Vendor Manifest extension-name org.apache.lucene Medium
Vendor pom name Lucene Common Analyzers High
Vendor central groupid org.apache.lucene Highest
Vendor pom parent-groupid org.apache.lucene Medium
Product pom groupid apache.lucene Low
Product pom description Additional Analyzers Medium
Product Manifest extension-name org.apache.lucene Medium
Product pom parent-artifactid lucene-parent Medium
Product pom artifactid lucene-analyzers Highest
Product pom name Lucene Common Analyzers High
Product Manifest Implementation-Title org.apache.lucene High
Product central artifactid lucene-analyzers Highest
Product Manifest specification-title Lucene Search Engine: analyzers Medium
Product file name lucene-analyzers High
Product pom parent-groupid org.apache.lucene Low
Version file version 3.6.2 Highest
Version pom version 3.6.2 Highest
Version central version 3.6.2 Highest
lucene-spellchecker-3.6.2.jar
Description: Spell Checker
File Path: /home/ciagent/.m2/repository/org/apache/lucene/lucene-spellchecker/3.6.2/lucene-spellchecker-3.6.2.jar
MD5: a4b684913f93aea76f5dbd7e479f19c5
SHA1: 15db0c0cfee44e275f15ad046e46b9a05910ad24
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid lucene-parent Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid lucene-spellchecker Low
Vendor pom groupid org.apache.lucene Highest
Vendor pom groupid apache.lucene Highest
Vendor file name lucene-spellchecker High
Vendor Manifest extension-name org.apache.lucene Medium
Vendor pom name Lucene Spellchecker High
Vendor central groupid org.apache.lucene Highest
Vendor pom parent-groupid org.apache.lucene Medium
Vendor pom description Spell Checker Medium
Product pom groupid apache.lucene Low
Product file name lucene-spellchecker High
Product Manifest extension-name org.apache.lucene Medium
Product pom parent-artifactid lucene-parent Medium
Product pom name Lucene Spellchecker High
Product central artifactid lucene-spellchecker Highest
Product Manifest Implementation-Title org.apache.lucene High
Product pom artifactid lucene-spellchecker Highest
Product pom description Spell Checker Medium
Product Manifest specification-title Lucene Search Engine: spellchecker Medium
Product pom parent-groupid org.apache.lucene Low
Version file version 3.6.2 Highest
Version pom version 3.6.2 Highest
Version central version 3.6.2 Highest
jta-1.1.jar
Description:
The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation.
File Path: /home/ciagent/.m2/repository/javax/transaction/jta/1.1/jta-1.1.jar
MD5: 82a10ce714f411b28f13850059de09ee
SHA1: 2ca09f0b36ca7d71b762e14ea2ff09d5eac57558
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jta Low
Vendor Manifest extension-name javax.transaction Medium
Vendor pom name Java Transaction API High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom url http://java.sun.com/products/jta Highest
Vendor pom description The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation. Low
Vendor central groupid javax.transaction High
Vendor pom groupid javax.transaction Highest
Vendor file name jta High
Product pom artifactid jta Highest
Product central artifactid transaction-api High
Product Manifest extension-name javax.transaction Medium
Product pom name Java Transaction API High
Product Manifest specification-title Java Transaction API Specification Medium
Product pom url http://java.sun.com/products/jta Medium
Product pom groupid javax.transaction Low
Product pom description The javax.transaction package. It is appropriate for inclusion in a classpath, and may be added to a Java 2 installation. Low
Product file name jta High
Product central artifactid jta High
Version file version 1.1 Highest
Version central version 1.1 High
Version pom version 1.1 Highest
concurrent-1.3.4.jar
License:
Public domain, Sun Microsoystems: >http://gee.cs.oswego.edu/dl/classes/EDU/oswego/cs/dl/util/concurrent/intro.html
File Path: /home/ciagent/.m2/repository/concurrent/concurrent/1.3.4/concurrent-1.3.4.jar
MD5: f29b9d930d3426ebc56919eba10fbd4d
SHA1: 1cf394c2a388199db550cda311174a4c6a7d117c
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization name Dough Lea High
Vendor central groupid concurrent Highest
Vendor jar package name edu Low
Vendor jar package name oswego Low
Vendor pom groupid concurrent Highest
Vendor file name concurrent High
Vendor pom name Dough Lea's util.concurrent package High
Vendor pom organization url http://gee.cs.oswego.edu/dl/classes/EDU/oswego/cs/dl/util/concurrent/intro.html Medium
Vendor pom artifactid concurrent Low
Vendor jar package name cs Low
Product pom artifactid concurrent Highest
Product pom groupid concurrent Low
Product jar package name dl Low
Product jar package name oswego Low
Product file name concurrent High
Product pom organization url http://gee.cs.oswego.edu/dl/classes/EDU/oswego/cs/dl/util/concurrent/intro.html Low
Product pom name Dough Lea's util.concurrent package High
Product central artifactid concurrent Highest
Product jar package name cs Low
Product pom organization name Dough Lea Low
Version pom version 1.3.4 Highest
Version central version 1.3.4 Highest
Version file version 1.3.4 Highest
jgroups-3.6.13.Final.jar
Description:
Reliable cluster communication toolkit
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/org/jgroups/jgroups/3.6.13.Final/jgroups-3.6.13.Final.jar
MD5: d7a4d1065e9b09e3f48bfa88ab368a0c
SHA1: 1315a8a1aed98dcafc11a850957ced42dc26bf18
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.jgroups Medium
Vendor pom description
Reliable cluster communication toolkit
Medium
Vendor central groupid org.jgroups Highest
Vendor pom url http://www.jgroups.org Highest
Vendor file name jgroups High
Vendor pom groupid jgroups Highest
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor pom groupid org.jgroups Highest
Vendor pom artifactid jgroups Low
Vendor pom name JGroups High
Vendor pom organization name JBoss, a division of Red Hat High
Vendor pom organization url http://www.jboss.org Medium
Vendor manifest Bundle-Description Ant/ivy based build.xml file for JGroups. Needs ant to run Medium
Product Manifest bundle-symbolicname org.jgroups Medium
Product pom organization name JBoss, a division of Red Hat Low
Product pom description
Reliable cluster communication toolkit
Medium
Product pom artifactid jgroups Highest
Product file name jgroups High
Product pom organization url http://www.jboss.org Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product pom groupid jgroups Low
Product Manifest bundle-docurl http://www.jboss.org Low
Product Manifest Bundle-Name JGroups Medium
Product pom name JGroups High
Product pom url http://www.jgroups.org Medium
Product manifest Bundle-Description Ant/ivy based build.xml file for JGroups. Needs ant to run Medium
Product central artifactid jgroups Highest
Version pom version 3.6.13.Final Highest
Version Manifest Implementation-Version 3.6.13.Final High
Version file version 3.6.13 Highest
Version central version 3.6.13.Final Highest
jbossjta-4.16.6.Final.jar
Description: JBossTS - JBoss Transaction Service. JTA, JTS and XTS (WS-AT, WS-BA)
License:
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/jboss/jbossts/jbossjta/4.16.6.Final/jbossjta-4.16.6.Final.jar
MD5: 9e3c8d7d93b92ab97489aeb5816370c8
SHA1: 99e79e03ced180bea4e3307511d350eb2b88c91c
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest arjuna-properties-file jbossts-properties.xml Low
Vendor pom description JBossTS - JBoss Transaction Service. JTA, JTS and XTS (WS-AT, WS-BA) Medium
Vendor pom groupid jboss.jbossts Highest
Vendor pom artifactid jbossjta Low
Vendor pom groupid org.jboss.jbossts Highest
Vendor central groupid org.jboss.jbossts Highest
Vendor file name jbossjta High
Vendor Manifest arjuna-builder JBoss Inc. [tom] Linux 3.4.11-1.fc16.x86_64 2012/Oct/02 15:05 Low
Vendor pom url http://www.jboss.org/jbosstm/ Highest
Vendor pom name JBossTS jbossjta High
Product Manifest arjuna-properties-file jbossts-properties.xml Low
Product pom description JBossTS - JBoss Transaction Service. JTA, JTS and XTS (WS-AT, WS-BA) Medium
Product central artifactid jbossjta Highest
Product file name jbossjta High
Product pom url http://www.jboss.org/jbosstm/ Medium
Product Manifest arjuna-builder JBoss Inc. [tom] Linux 3.4.11-1.fc16.x86_64 2012/Oct/02 15:05 Low
Product pom artifactid jbossjta Highest
Product pom groupid jboss.jbossts Low
Product pom name JBossTS jbossjta High
Version central version 4.16.6.Final Highest
Version file version 4.16.6 Highest
Version pom version 4.16.6.Final Highest
ws-commons-util-1.0.1.jar
Description: This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/ws/commons/ws-commons-util/1.0.1/ws-commons-util-1.0.1.jar
MD5: 66919d22287ddab742a135da764c2cd6
SHA1: 126e80ff798fece634bc94e61f8be8a8da00be60
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest extension-name ws-commons-util Medium
Vendor file name ws-commons-util High
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor pom organization url http://www.apache.org/ Medium
Vendor pom groupid org.apache.ws.commons Highest
Vendor pom description This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced. Low
Vendor central groupid org.apache.ws.commons High
Vendor pom organization name Apache Software Foundation High
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor pom name Apache WebServices Common Utilities High
Vendor pom groupid apache.ws.commons Highest
Vendor central groupid ws-commons-util High
Vendor pom url http://ws.apache.org/commons/util Highest
Vendor pom artifactid ws-commons-util Low
Product Manifest extension-name ws-commons-util Medium
Product file name ws-commons-util High
Product pom organization name Apache Software Foundation Low
Product central artifactid ws-commons-util High
Product pom description This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced. Low
Product Manifest specification-title This is a small collection of utility classes, that allow high performance XML processing based on SAX. Basically, it is assumed, that you are using an JAXP 1.1 compliant XML parser and nothing else. In particular, no dependency on the javax.xml.transform package is introduced. Medium
Product Manifest Implementation-Title ws-commons-util High
Product pom url http://ws.apache.org/commons/util Medium
Product pom artifactid ws-commons-util Highest
Product pom name Apache WebServices Common Utilities High
Product pom groupid apache.ws.commons Low
Product pom organization url http://www.apache.org/ Low
Version pom version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
Version central version 1.0.1 High
Version file version 1.0.1 Highest
Published Vulnerabilities
CVE-2016-10542 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.
Vulnerable Software & Versions:
jboss-common-core-2.2.22.GA.jar
Description: JBoss Common Core Utility classes
File Path: /home/ciagent/.m2/repository/org/jboss/jboss-common-core/2.2.22.GA/jboss-common-core-2.2.22.GA.jar
MD5: 8c415e1467075a90045a7b0fd19886a3
SHA1: ae1a22412d879c4ac48e35cf00f438bb263d41c3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.jboss.org/jboss-common Highest
Vendor Manifest specification-vendor JBoss, a division of Red Hat, Inc. Low
Vendor Manifest Implementation-Vendor-Id org.jboss Medium
Vendor pom groupid jboss Highest
Vendor pom parent-artifactid jboss-parent Low
Vendor Manifest implementation-url http://www.jboss.org/jboss-common Low
Vendor pom parent-groupid org.jboss Medium
Vendor pom artifactid jboss-common-core Low
Vendor pom description JBoss Common Core Utility classes Medium
Vendor file name jboss-common-core High
Vendor pom groupid org.jboss Highest
Vendor Manifest Implementation-Vendor JBoss, a division of Red Hat, Inc. High
Vendor pom name JBoss Common Classes High
Vendor central groupid org.jboss Highest
Product Manifest Implementation-Title JBoss Common Classes High
Product pom groupid jboss Low
Product pom artifactid jboss-common-core Highest
Product Manifest specification-title JBoss Common Classes Medium
Product pom parent-artifactid jboss-parent Medium
Product Manifest implementation-url http://www.jboss.org/jboss-common Low
Product central artifactid jboss-common-core Highest
Product pom url http://www.jboss.org/jboss-common Medium
Product pom parent-groupid org.jboss Low
Product pom description JBoss Common Core Utility classes Medium
Product file name jboss-common-core High
Product pom name JBoss Common Classes High
Version Manifest Implementation-Version 2.2.22.GA High
Version file version 2.2.22 Highest
Version central version 2.2.22.GA Highest
Version pom version 2.2.22.GA Highest
stringtemplate-3.2.1.jar
Description: StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output.
StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization.
It evolved over years of effort developing jGuru.com.
StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic
is that unlike other engines, it strictly enforces model-view separation.
Strict separation makes websites and code generators more flexible
and maintainable; it also provides an excellent defense against malicious
template authors.
There are currently about 600 StringTemplate source downloads a month.
License:
BSD licence: http://antlr.org/license.html
File Path: /home/ciagent/.m2/repository/org/antlr/stringtemplate/3.2.1/stringtemplate-3.2.1.jar
MD5: b58ca53e518a92a1991eb63b61917582
SHA1: 59ec8083721eae215c6f3caee944c410d2be34de
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.antlr Highest
Vendor pom url http://www.stringtemplate.org Highest
Vendor jar package name stringtemplate Low
Vendor pom artifactid stringtemplate Low
Vendor pom groupid org.antlr Highest
Vendor pom groupid antlr Highest
Vendor file name stringtemplate High
Vendor pom description StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output. StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization. It evolved over years of effort developing jGuru.com. StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic is that un... Low
Vendor jar package name language Low
Vendor pom name ANTLR StringTemplate High
Vendor jar package name antlr Low
Product pom url http://www.stringtemplate.org Medium
Product pom artifactid stringtemplate Highest
Product jar package name stringtemplate Low
Product file name stringtemplate High
Product pom description StringTemplate is a java template engine for generating source code,
web pages, emails, or any other formatted text output. StringTemplate is particularly good at multi-targeted code generators,
multiple site skins, and internationalization/localization. It evolved over years of effort developing jGuru.com. StringTemplate also generates the stringtemplate website: http://www.stringtemplate.org
and powers the ANTLR v3 code generator. Its distinguishing characteristic is that un... Low
Product central artifactid stringtemplate Highest
Product pom groupid antlr Low
Product jar package name language Low
Product pom name ANTLR StringTemplate High
Version pom version 3.2.1 Highest
Version central version 3.2.1 Highest
Version file version 3.2.1 Highest
antlr-runtime-3.5.jar
Description: A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions.
File Path: /home/ciagent/.m2/repository/org/antlr/antlr-runtime/3.5/antlr-runtime-3.5.jar
MD5: aa6d7c8b425df59f5f5bc98c58cfd9fc
SHA1: 0baa82bff19059401e90e1b90020beb9c96305d7
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.antlr Highest
Vendor pom groupid org.antlr Highest
Vendor Manifest Implementation-Vendor-Id org.antlr Medium
Vendor pom name ANTLR 3 Runtime High
Vendor pom groupid antlr Highest
Vendor pom url http://www.antlr.org Highest
Vendor Manifest Implementation-Vendor ANTLR High
Vendor pom parent-groupid org.antlr Medium
Vendor pom artifactid antlr-runtime Low
Vendor pom parent-artifactid antlr-master Low
Vendor file name antlr-runtime High
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom artifactid antlr-runtime Highest
Product Manifest Implementation-Title ANTLR 3 Runtime High
Product pom parent-artifactid antlr-master Medium
Product pom url http://www.antlr.org Medium
Product pom parent-groupid org.antlr Low
Product file name antlr-runtime High
Product pom name ANTLR 3 Runtime High
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product central artifactid antlr-runtime Highest
Product pom groupid antlr Low
Version pom version 3.5 Highest
Version central version 3.5 Highest
Version file version 3.5 Highest
Version Manifest Implementation-Version 3.5 High
jboss-marshalling-osgi-2.0.0.Beta3.jar
Description: JBoss Marshalling OSGi Bundle with API and implementations
License:
http://repository.jboss.org/licenses/cc0-1.0.txt
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar
MD5: 7652392087f6e70312cf0309ab563a4f
SHA1: a55fe6527a2d50dc48ad3f8b9093bd0cb01302b0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.jboss.marshalling Highest
Vendor Manifest Implementation-Vendor-Id org.jboss.marshalling Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom groupid org.jboss.marshalling Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor jar package name jboss Low
Vendor Manifest os-name Linux Medium
Vendor Manifest bundle-docurl http://jboss.org/jbossmarshalling Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor file name jboss-marshalling-osgi High
Vendor Manifest implementation-url http://www.jboss.org/jboss-marshalling-parent/jboss-marshalling-osgi Low
Vendor jar package name marshalling Low
Vendor Manifest bundle-symbolicname org.jboss.marshalling.jboss-marshalling-osgi Medium
Vendor manifest Bundle-Description JBoss Marshalling OSGi Bundle with API and implementations Medium
Product Manifest os-name Linux Medium
Product Manifest specification-title JBoss Marshalling OSGi Bundle Medium
Product pom artifactid jboss-marshalling-osgi Highest
Product Manifest bundle-docurl http://jboss.org/jbossmarshalling Low
Product central artifactid jboss-marshalling-osgi Highest
Product file name jboss-marshalling-osgi High
Product Manifest implementation-url http://www.jboss.org/jboss-marshalling-parent/jboss-marshalling-osgi Low
Product jar package name marshalling Low
Product Manifest Bundle-Name JBoss Marshalling OSGi Bundle Medium
Product Manifest bundle-symbolicname org.jboss.marshalling.jboss-marshalling-osgi Medium
Product manifest Bundle-Description JBoss Marshalling OSGi Bundle with API and implementations Medium
Product Manifest Implementation-Title JBoss Marshalling OSGi Bundle High
Version central version 2.0.0.Beta3 Highest
Version pom version 2.0.0.Beta3 Highest
Version Manifest Implementation-Version 2.0.0.Beta3 High
infinispan-core-8.2.6.Final.jar
Description: Infinispan core module
License:
http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/org/infinispan/infinispan-core/8.2.6.Final/infinispan-core-8.2.6.Final.jar
MD5: 06371c22b39aef4faf1da8d21b2102cb
SHA1: 84937a866a56760b9c50bfbca10442fa14be6375
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname org.infinispan.core Medium
Vendor pom parent-artifactid infinispan-parent Low
Vendor Manifest Implementation-Vendor-Id org.infinispan Medium
Vendor manifest Bundle-Description Infinispan core module Medium
Vendor pom name Infinispan Core High
Vendor Manifest bundle-blueprint OSGI-INF/blueprint/blueprint.xml Low
Vendor Manifest Implementation-Vendor JBoss, a division of Red Hat High
Vendor Manifest bundle-docurl http://www.infinispan.org/ Low
Vendor pom groupid infinispan Highest
Vendor pom parent-groupid org.infinispan Medium
Vendor Manifest specification-vendor JBoss, a division of Red Hat Low
Vendor file name infinispan-core High
Vendor pom groupid org.infinispan Highest
Vendor central groupid org.infinispan Highest
Vendor pom artifactid infinispan-core Low
Vendor pom description Infinispan core module Medium
Product Manifest bundle-symbolicname org.infinispan.core Medium
Product Manifest specification-title Infinispan Core Medium
Product Manifest Implementation-Title Infinispan Core High
Product central artifactid infinispan-core Highest
Product manifest Bundle-Description Infinispan core module Medium
Product pom name Infinispan Core High
Product Manifest Bundle-Name Infinispan Core Medium
Product Manifest bundle-blueprint OSGI-INF/blueprint/blueprint.xml Low
Product pom groupid infinispan Low
Product pom parent-groupid org.infinispan Low
Product pom artifactid infinispan-core Highest
Product Manifest bundle-docurl http://www.infinispan.org/ Low
Product pom parent-artifactid infinispan-parent Medium
Product file name infinispan-core High
Product pom description Infinispan core module Medium
Version pom version 8.2.6.Final Highest
Version file version 8.2.6 Highest
Version central version 8.2.6.Final Highest
Version Manifest Implementation-Version 8.2.6.Final High
Related Dependencies
infinispan-cachestore-jdbc-8.2.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/infinispan/infinispan-cachestore-jdbc/8.2.6.Final/infinispan-cachestore-jdbc-8.2.6.Final.jar
SHA1: 1703f2cae7b2cb483158dca831d68ee711f301ab
MD5: 3ca2e9d4e5ed44fc984fe94c2d943bf2
cpe: cpe:/a:infinispan:infinispan:8.2.6
maven: org.infinispan:infinispan-cachestore-jdbc:8.2.6.Final ✓
infinispan-commons-8.2.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/infinispan/infinispan-commons/8.2.6.Final/infinispan-commons-8.2.6.Final.jar
SHA1: 846b3a39de5f793fb11e70fc70662e4374ffc3c2
MD5: 9da9ef6cf978bf024d377180806414db
cpe: cpe:/a:infinispan:infinispan:8.2.6
maven: org.infinispan:infinispan-commons:8.2.6.Final ✓
Published Vulnerabilities
CVE-2016-0750 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-15089 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-2638 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
CWE: CWE-287 Improper Authentication
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Vulnerable Software & Versions: (show all )
exo.jcr.component.core-5.3.x-SNAPSHOT.jar
Description: Implementation of Core Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/jcr/exo.jcr.component.core/5.3.x-SNAPSHOT/exo.jcr.component.core-5.3.x-SNAPSHOT.jar
MD5: 270fed54370dddb7b6f2a0ac0a53fb19
SHA1: 2e610d06ecc8ae00c94f7504cdef11211515dbd3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name eXo PLF:: JCR :: Component :: Core Service High
Vendor pom parent-groupid org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.jcr Highest
Vendor file name exo.jcr.component.core High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid jcr-parent Low
Vendor pom description Implementation of Core Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom artifactid exo.jcr.component.core Low
Vendor pom groupid exoplatform.jcr Highest
Product Manifest specification-title exo-jcr Medium
Product pom name eXo PLF:: JCR :: Component :: Core Service High
Product pom groupid exoplatform.jcr Low
Product pom parent-groupid org.exoplatform.jcr Low
Product pom artifactid exo.jcr.component.core Highest
Product file name exo.jcr.component.core High
Product pom description Implementation of Core Service of Exoplatform SAS 'eXo Core' project. Medium
Product pom parent-artifactid jcr-parent Medium
Product Manifest Implementation-Title eXo PLF:: JCR :: Component :: Core Service High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.jcr:exo.jcr.component.core:5.3.x-SNAPSHOT
Confidence :High
jtidy-r938.jar
Description:
JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be
used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the
document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML.
License:
Java HTML Tidy License: http://jtidy.svn.sourceforge.net/viewvc/jtidy/trunk/jtidy/LICENSE.txt?revision=95
File Path: /home/ciagent/.m2/repository/net/sf/jtidy/jtidy/r938/jtidy-r938.jar
MD5: 6a9121561b8f98c0a8fb9b6e57f50e6b
SHA1: ab08d87a225a715a69107732b67f21e1da930349
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization url http://sourceforge.net Medium
Vendor pom name JTidy High
Vendor jar package name tidy Low
Vendor pom artifactid jtidy Low
Vendor file name jtidy-r938 High
Vendor pom groupid net.sf.jtidy Highest
Vendor pom organization name sourceforge High
Vendor jar package name w3c Low
Vendor pom description JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML. Low
Vendor central groupid net.sf.jtidy Highest
Vendor pom url http://jtidy.sourceforge.net Highest
Product central artifactid jtidy Highest
Product pom name JTidy High
Product jar package name tidy Low
Product pom organization name sourceforge Low
Product file name jtidy-r938 High
Product pom groupid net.sf.jtidy Low
Product pom description JTidy is a Java port of HTML Tidy, a HTML syntax checker and pretty printer. Like its non-Java cousin, JTidy can be used as a tool for cleaning up malformed and faulty HTML. In addition, JTidy provides a DOM interface to the document that is being processed, which effectively makes you able to use JTidy as a DOM parser for real-world HTML. Low
Product pom url http://jtidy.sourceforge.net Medium
Product pom organization url http://sourceforge.net Low
Product pom artifactid jtidy Highest
Version file version 938 Medium
Version central version r938 Highest
Version file name jtidy-r938 Medium
Version pom version r938 Highest
exo.core.component.xml-processing-5.3.x-SNAPSHOT.jar
Description: Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.xml-processing/5.3.x-SNAPSHOT/exo.core.component.xml-processing-5.3.x-SNAPSHOT.jar
MD5: 72733f679e354536825490dcd09a699a
SHA1: 8abf87f511ed36fa29ee72cd75c7308f852c7b6f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name eXo PLF Core :: Component :: XML Processing Service High
Vendor pom artifactid exo.core.component.xml-processing Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor file name exo.core.component.xml-processing High
Vendor pom description Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project. Medium
Product pom name eXo PLF Core :: Component :: XML Processing Service High
Product pom parent-groupid org.exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: XML Processing Service High
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product pom artifactid exo.core.component.xml-processing Highest
Product file name exo.core.component.xml-processing High
Product Manifest specification-title exo-core Medium
Product pom description Implementation of XML Processing Service of Exoplatform SAS 'eXo Core' project. Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
cpe: cpe:/a:processing:processing:5.3
Confidence :Low
suppress
maven: org.exoplatform.core:exo.core.component.xml-processing:5.3.x-SNAPSHOT
Confidence :High
exo.core.component.script.groovy-5.3.x-SNAPSHOT.jar
Description: Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.script.groovy/5.3.x-SNAPSHOT/exo.core.component.script.groovy-5.3.x-SNAPSHOT.jar
MD5: 7b83e6a1b4a6dad0afeeb2169f8bed89
SHA1: ee331e349386b130980f5564f3ba15a9cba7ebce
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.script.groovy Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor file name exo.core.component.script.groovy High
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom description Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom name eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Product pom artifactid exo.core.component.script.groovy Highest
Product pom parent-groupid org.exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Product file name exo.core.component.script.groovy High
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product pom description Groovy Scripts Instantiator of Exoplatform SAS 'eXo Core' project. Medium
Product Manifest specification-title exo-core Medium
Product pom name eXo PLF Core :: Component :: Groovy Scripts Instantiator High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.script.groovy:5.3.x-SNAPSHOT
Confidence :High
exo.jcr.component.ext-5.3.x-SNAPSHOT.jar
Description: Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/jcr/exo.jcr.component.ext/5.3.x-SNAPSHOT/exo.jcr.component.ext-5.3.x-SNAPSHOT.jar
MD5: 80ba6722d208fa7b15b8c7d090d4c0cc
SHA1: ecd82797b6732d7e1c33328f5970ffd1d7caee03
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.jcr.component.ext High
Vendor pom name eXo PLF:: JCR :: Component :: Extension Service High
Vendor pom parent-groupid org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.jcr Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid jcr-parent Low
Vendor pom artifactid exo.jcr.component.ext Low
Vendor pom groupid exoplatform.jcr Highest
Vendor pom description Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project. Medium
Product file name exo.jcr.component.ext High
Product Manifest specification-title exo-jcr Medium
Product pom name eXo PLF:: JCR :: Component :: Extension Service High
Product pom groupid exoplatform.jcr Low
Product pom parent-groupid org.exoplatform.jcr Low
Product Manifest Implementation-Title eXo PLF:: JCR :: Component :: Extension Service High
Product pom artifactid exo.jcr.component.ext Highest
Product pom parent-artifactid jcr-parent Medium
Product pom description Implementation of Extension Service of Exoplatform SAS 'eXo JCR' project. Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.jcr:exo.jcr.component.ext:5.3.x-SNAPSHOT
Confidence :High
xmlpull-1.1.3.1.jar
License:
Public Domain: http://www.xmlpull.org/v1/download/unpacked/LICENSE.txt
File Path: /home/ciagent/.m2/repository/xmlpull/xmlpull/1.1.3.1/xmlpull-1.1.3.1.jar
MD5: cc57dacc720eca721a50e78934b822d2
SHA1: 2b8e230d2ab644e4ecaa94db7cdedbc40c805dfa
Referenced In Projects/Scopes:
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:runtime
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid xmlpull Low
Vendor pom groupid xmlpull Highest
Vendor pom name XML Pull Parsing API High
Vendor jar package name v1 Low
Vendor file name xmlpull High
Vendor pom url http://www.xmlpull.org Highest
Vendor jar package name xmlpull Low
Vendor central groupid xmlpull Highest
Product central artifactid xmlpull Highest
Product pom name XML Pull Parsing API High
Product pom url http://www.xmlpull.org Medium
Product jar package name v1 Low
Product pom artifactid xmlpull Highest
Product file name xmlpull High
Product pom groupid xmlpull Low
Version pom version 1.1.3.1 Highest
Version file version 1.1.3.1 Highest
Version central version 1.1.3.1 Highest
xpp3_min-1.1.4c.jar
Description: MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs such as Hotspot in JDK 1.4+.
License:
Indiana University Extreme! Lab Software License, vesion 1.1.1: http://www.extreme.indiana.edu/viewcvs/~checkout~/XPP3/java/LICENSE.txt
Public Domain: http://creativecommons.org/licenses/publicdomain
File Path: /home/ciagent/.m2/repository/xpp3/xpp3_min/1.1.4c/xpp3_min-1.1.4c.jar
MD5: dcd95bcb84b09897b2b66d4684c040da
SHA1: 19d4e90b43059058f6e056f794f0ea4030d60b86
Referenced In Projects/Scopes:
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid xpp3_min Low
Vendor pom organization name Extreme! Lab, Indiana University High
Vendor pom name MXP1: Xml Pull Parser 3rd Edition (XPP3) High
Vendor pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Highest
Vendor central groupid xpp3 Highest
Vendor pom description MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs ... Low
Vendor pom organization url http://www.extreme.indiana.edu/ Medium
Vendor file name xpp3_min High
Vendor jar package name v1 Low
Vendor pom groupid xpp3 Highest
Vendor jar package name xmlpull Low
Product central artifactid xpp3_min Highest
Product pom name MXP1: Xml Pull Parser 3rd Edition (XPP3) High
Product pom artifactid xpp3_min Highest
Product pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Medium
Product pom organization name Extreme! Lab, Indiana University Low
Product pom groupid xpp3 Low
Product pom description MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs ... Low
Product file name xpp3_min High
Product jar package name v1 Low
Product pom organization url http://www.extreme.indiana.edu/ Low
Version pom version 1.1.4c Highest
Version central version 1.1.4c Highest
Version file version 1.1.4c Highest
xstream-1.4.10.jar
Description: XStream is a serialization library from Java objects to XML and back.
License:
http://x-stream.github.io/license.html
File Path: /home/ciagent/.m2/repository/com/thoughtworks/xstream/xstream/1.4.10/xstream-1.4.10.jar
MD5: d00eec778910f95b26201395ac64cca0
SHA1: dfecae23647abc9d9fd0416629a4213a3882b101
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:runtime
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest x-compile-source 1.5 Low
Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low
Vendor pom name XStream Core High
Vendor pom parent-artifactid xstream-parent Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low
Vendor Manifest java_1_9_home /opt/oracle-jdk-bin-1.9.0.0_beta167 Low
Vendor Manifest specification-vendor XStream Low
Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.131 Low
Vendor Manifest Implementation-Vendor-Id com.thoughtworks.xstream Medium
Vendor Manifest bundle-docurl http://x-stream.github.io Low
Vendor pom groupid com.thoughtworks.xstream Highest
Vendor central groupid com.thoughtworks.xstream Highest
Vendor Manifest x-builder Maven 3.3.9 Low
Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low
Vendor pom artifactid xstream Low
Vendor Manifest Implementation-Vendor XStream High
Vendor file name xstream High
Vendor Manifest bundle-symbolicname xstream Medium
Vendor manifest Bundle-Description XStream is a serialization library from Java objects to XML and back. Medium
Vendor Manifest x-compile-target 1.5 Low
Vendor Manifest x-build-time 2017-05-23T14:28:02Z Low
Vendor pom parent-groupid com.thoughtworks.xstream Medium
Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low
Vendor pom groupid thoughtworks.xstream Highest
Product Manifest x-compile-source 1.5 Low
Product central artifactid xstream Highest
Product pom parent-groupid com.thoughtworks.xstream Low
Product pom artifactid xstream Highest
Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low
Product pom name XStream Core High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Product pom groupid thoughtworks.xstream Low
Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low
Product Manifest specification-title XStream Core Medium
Product Manifest java_1_9_home /opt/oracle-jdk-bin-1.9.0.0_beta167 Low
Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.131 Low
Product Manifest bundle-docurl http://x-stream.github.io Low
Product Manifest Implementation-Title XStream Core High
Product Manifest x-builder Maven 3.3.9 Low
Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low
Product file name xstream High
Product Manifest bundle-symbolicname xstream Medium
Product manifest Bundle-Description XStream is a serialization library from Java objects to XML and back. Medium
Product Manifest x-compile-target 1.5 Low
Product Manifest Bundle-Name XStream Core Medium
Product Manifest x-build-time 2017-05-23T14:28:02Z Low
Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low
Product pom parent-artifactid xstream-parent Medium
Version file version 1.4.10 Highest
Version Manifest Implementation-Version 1.4.10 High
Version central version 1.4.10 Highest
Version pom version 1.4.10 Highest
Published Vulnerabilities
CVE-2013-7285 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Vulnerable Software & Versions: (show all )
commons-webui-component-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-webui-component/5.3.x-SNAPSHOT/commons-webui-component-5.3.x-SNAPSHOT.jar
MD5: afe16b7e36ecbb581a371dafe5370c3b
SHA1: 3b0b4a1f913cd523987ed381a1d4883f59c3f899
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-component Low
Vendor pom artifactid commons-webui-component Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor file name commons-webui-component High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Vendor pom name eXo PLF:: Commons - Commons WebUI High
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-component Low
Product pom artifactid commons-webui-component Highest
Product Manifest Implementation-Title eXo PLF:: Commons - Commons WebUI High
Product Manifest specification-title eXo PLF:: Commons - Commons WebUI Medium
Product pom groupid exoplatform.commons Low
Product file name commons-webui-component High
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product pom name eXo PLF:: Commons - Commons WebUI High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-webui-component:5.3.x-SNAPSHOT
Confidence :High
commons-webui-ext-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-webui-ext/5.3.x-SNAPSHOT/commons-webui-ext-5.3.x-SNAPSHOT.jar
MD5: 21e85e2bf15d4ab08eaa0374f2b2b4f7
SHA1: 3ef63b11d132511df342085a73b563a8e98f72dc
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor pom name eXo PLF:: Commons - WebUI Extension High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-ext Low
Vendor pom artifactid commons-webui-ext Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Vendor file name commons-webui-ext High
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest Implementation-Title eXo PLF:: Commons - WebUI Extension High
Product pom groupid exoplatform.commons Low
Product Manifest specification-title eXo PLF:: Commons - WebUI Extension Medium
Product pom name eXo PLF:: Commons - WebUI Extension High
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-webui-ext Low
Product pom artifactid commons-webui-ext Highest
Product file name commons-webui-ext High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-webui-ext:5.3.x-SNAPSHOT
Confidence :High
exo.kernel.component.cache-5.3.x-SNAPSHOT.jar
Description: Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.cache/5.3.x-SNAPSHOT/exo.kernel.component.cache-5.3.x-SNAPSHOT.jar
MD5: 6a322bdcc585dcf7bb26e4b7554adf3c
SHA1: 249eab6c763268ea4c6bcc15a6b53bf38c49fb6e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor file name exo.kernel.component.cache High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom name eXo PLF:: Kernel :: Component :: Cache Service High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom description Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor pom parent-artifactid kernel-parent Low
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.component.cache Low
Product file name exo.kernel.component.cache High
Product Manifest specification-title exo-kernel Medium
Product pom artifactid exo.kernel.component.cache Highest
Product pom name eXo PLF:: Kernel :: Component :: Cache Service High
Product pom parent-artifactid kernel-parent Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product pom description Implementation of Cache Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product pom groupid exoplatform.kernel Low
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Cache Service High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.cache:5.3.x-SNAPSHOT
Confidence :High
antlr-2.7.7.jar
Description:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html
File Path: /home/ciagent/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name AntLR Parser Generator High
Vendor pom url http://www.antlr.org/ Highest
Vendor pom groupid antlr Highest
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Vendor pom artifactid antlr Low
Vendor central groupid antlr Highest
Vendor file name antlr High
Vendor jar package name antlr Low
Product pom name AntLR Parser Generator High
Product central artifactid antlr Highest
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom url http://www.antlr.org/ Medium
Product pom groupid antlr Low
Product pom artifactid antlr Highest
Product file name antlr High
Version file version 2.7.7 Highest
Version pom version 2.7.7 Highest
Version central version 2.7.7 Highest
hibernate-core-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-core/4.2.21.Final/hibernate-core-4.2.21.Final.jar
MD5: 492567c1f36fb3a5968ca2d3c452edaf
SHA1: bb587d00287c13d9e4324bc76c13abbd493efa81
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://hibernate.org Highest
Vendor pom groupid hibernate Highest
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom name A Hibernate O/RM Module High
Vendor pom groupid org.hibernate Highest
Vendor manifest Bundle-Description Hibernate ORM Core Medium
Vendor pom artifactid hibernate-core Low
Vendor central groupid org.hibernate Highest
Vendor Manifest bundle-symbolicname org.hibernate.core Medium
Vendor file name hibernate-core High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom organization name Hibernate.org High
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Product pom artifactid hibernate-core Highest
Product pom name A Hibernate O/RM Module High
Product central artifactid hibernate-core Highest
Product Manifest Bundle-Name hibernate-core Medium
Product manifest Bundle-Description Hibernate ORM Core Medium
Product Manifest bundle-symbolicname org.hibernate.core Medium
Product file name hibernate-core High
Product Manifest implementation-url http://hibernate.org Low
Product pom organization url http://hibernate.org Low
Product pom description A module of the Hibernate O/RM project Medium
Product pom organization name Hibernate.org Low
Product pom groupid hibernate Low
Product pom url http://hibernate.org Medium
Version central version 4.2.21.Final Highest
Version file version 4.2.21 Highest
Version pom version 4.2.21.Final Highest
Version Manifest Implementation-Version 4.2.21.Final High
jakarta-regexp-1.4.jar
File Path: /home/ciagent/.m2/repository/jakarta-regexp/jakarta-regexp/1.4/jakarta-regexp-1.4.jar
MD5: 5d8b8c601c21b37aa6142d38f45c0297
SHA1: 0ea514a179ac1dd7e81c7e6594468b9b9910d298
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jakarta-regexp Low
Vendor jar package name regexp Low
Vendor file name jakarta-regexp High
Vendor central groupid jakarta-regexp Highest
Vendor pom groupid jakarta-regexp Highest
Vendor jar package name apache Low
Product pom artifactid jakarta-regexp Highest
Product central artifactid jakarta-regexp Highest
Product jar package name regexp Low
Product file name jakarta-regexp High
Product pom groupid jakarta-regexp Low
Version pom version 1.4 Highest
Version file version 1.4 Highest
Version central version 1.4 Highest
xpp3-1.1.6.jar
Description: XML Pull parser library developed by Extreme Computing Lab, Indiana University
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/ogce/xpp3/1.1.6/xpp3-1.1.6.jar
MD5: 626a429318310e92e3466151e050bdc5
SHA1: dc87e00ddb69341b46a3eb1c331c6fcebf6c8546
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name XPP3 High
Vendor pom artifactid xpp3 Low
Vendor pom description XML Pull parser library developed by Extreme Computing Lab, Indiana University Medium
Vendor pom url http://www.extreme.indiana.edu/xpp/ Highest
Vendor pom groupid org.ogce Highest
Vendor file name xpp3 High
Vendor jar package name builder Low
Vendor jar package name v1 Low
Vendor central groupid org.ogce Highest
Vendor pom groupid ogce Highest
Vendor jar package name xmlpull Low
Product pom artifactid xpp3 Highest
Product pom groupid ogce Low
Product pom name XPP3 High
Product pom description XML Pull parser library developed by Extreme Computing Lab, Indiana University Medium
Product pom url http://www.extreme.indiana.edu/xpp/ Medium
Product file name xpp3 High
Product jar package name builder Low
Product jar package name xpath Low
Product jar package name v1 Low
Product central artifactid xpp3 Highest
Version pom version 1.1.6 Highest
Version file version 1.1.6 Highest
Version central version 1.1.6 Highest
exo.core.component.organization.api-5.3.x-SNAPSHOT.jar
Description: API of Organization Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.organization.api/5.3.x-SNAPSHOT/exo.core.component.organization.api-5.3.x-SNAPSHOT.jar
MD5: dac80c845342c757a54f5b1c780c52d6
SHA1: a07f68213aab5a6dd25dfcc8780e4162c59a7673
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.organization.api Low
Vendor pom name eXo PLF Core :: Component :: Organization Service API High
Vendor pom description API of Organization Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor file name exo.core.component.organization.api High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom parent-groupid org.exoplatform.core Medium
Product pom parent-groupid org.exoplatform.core Low
Product pom name eXo PLF Core :: Component :: Organization Service API High
Product pom artifactid exo.core.component.organization.api Highest
Product pom description API of Organization Service of Exoplatform SAS 'eXo Core' project. Medium
Product file name exo.core.component.organization.api High
Product Manifest Implementation-Title eXo PLF Core :: Component :: Organization Service API High
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product Manifest specification-title exo-core Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
cpe: cpe:/a:api-platform:core:5.3
Confidence :Low
suppress
maven: org.exoplatform.core:exo.core.component.organization.api:5.3.x-SNAPSHOT
Confidence :High
commons-dbcp-1.4.jar
Description: Commons Database Connection Pooling
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-dbcp/commons-dbcp/1.4/commons-dbcp-1.4.jar
MD5: b004158fab904f37f5831860898b3cd9
SHA1: 30be73c965cc990b153a100aaaaafcf239f82d39
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Renderer:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid commons-dbcp Highest
Vendor file name commons-dbcp High
Vendor Manifest bundle-symbolicname org.apache.commons.dbcp Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid commons-dbcp Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom url http://commons.apache.org/dbcp/ Highest
Vendor manifest Bundle-Description Commons Database Connection Pooling Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor Manifest bundle-docurl http://commons.apache.org/dbcp/ Low
Vendor pom artifactid commons-dbcp Low
Vendor pom description Commons Database Connection Pooling Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom name Commons DBCP High
Product Manifest Implementation-Title Commons DBCP High
Product file name commons-dbcp High
Product Manifest bundle-symbolicname org.apache.commons.dbcp Medium
Product pom parent-artifactid commons-parent Medium
Product manifest Bundle-Description Commons Database Connection Pooling Medium
Product pom artifactid commons-dbcp Highest
Product Manifest bundle-docurl http://commons.apache.org/dbcp/ Low
Product central artifactid commons-dbcp Highest
Product pom url http://commons.apache.org/dbcp/ Medium
Product Manifest specification-title Commons DBCP Medium
Product pom description Commons Database Connection Pooling Medium
Product pom groupid commons-dbcp Low
Product pom name Commons DBCP High
Product pom parent-groupid org.apache.commons Low
Product Manifest Bundle-Name Commons DBCP Medium
Version Manifest Implementation-Version 1.4 High
Version pom version 1.4 Highest
Version file version 1.4 Highest
Version central version 1.4 Highest
commons-pool-1.6.jar
Description: Commons Object Pooling Library
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-pool/commons-pool/1.6/commons-pool-1.6.jar
MD5: 5ca02245c829422176d23fa530e919cc
SHA1: 4572d589699f09d866a226a14b7f4323c6d8f040
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Renderer:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low
Vendor pom name Commons Pool High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid commons-pool Highest
Vendor Manifest bundle-symbolicname org.apache.commons.pool Medium
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-docurl http://commons.apache.org/pool/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom description Commons Object Pooling Library Medium
Vendor pom url http://commons.apache.org/pool/ Highest
Vendor file name commons-pool High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor manifest Bundle-Description Commons Object Pooling Library Medium
Vendor pom artifactid commons-pool Low
Vendor pom groupid commons-pool Highest
Product pom url http://commons.apache.org/pool/ Medium
Product Manifest implementation-build UNKNOWN_BRANCH@r??????; 2012-01-04 10:31:47-0500 Low
Product pom name Commons Pool High
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-symbolicname org.apache.commons.pool Medium
Product pom artifactid commons-pool Highest
Product Manifest bundle-docurl http://commons.apache.org/pool/ Low
Product pom description Commons Object Pooling Library Medium
Product Manifest Bundle-Name Commons Pool Medium
Product Manifest Implementation-Title Commons Pool High
Product central artifactid commons-pool Highest
Product Manifest specification-title Commons Pool Medium
Product pom groupid commons-pool Low
Product file name commons-pool High
Product manifest Bundle-Description Commons Object Pooling Library Medium
Product pom parent-groupid org.apache.commons Low
Version file version 1.6 Highest
Version central version 1.6 Highest
Version pom version 1.6 Highest
Version Manifest Implementation-Version 1.6 High
exo.kernel.component.common-5.3.x-SNAPSHOT.jar
Description: Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.common/5.3.x-SNAPSHOT/exo.kernel.component.common-5.3.x-SNAPSHOT.jar
MD5: c57430ba3cc88079d9fe4604fed4798c
SHA1: d3f3536bcb0b5ed4306eaf6896f22d022f844899
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom description Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom artifactid exo.kernel.component.common Low
Vendor pom parent-artifactid kernel-parent Low
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor file name exo.kernel.component.common High
Vendor pom name eXo PLF:: Kernel :: Component :: Common Service High
Product Manifest specification-title exo-kernel Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Common Service High
Product pom description Implementation of Common Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product pom parent-artifactid kernel-parent Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product pom artifactid exo.kernel.component.common Highest
Product file name exo.kernel.component.common High
Product pom groupid exoplatform.kernel Low
Product pom name eXo PLF:: Kernel :: Component :: Common Service High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.common:5.3.x-SNAPSHOT
Confidence :High
exo.core.component.security.core-5.3.x-SNAPSHOT.jar
Description: Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.security.core/5.3.x-SNAPSHOT/exo.core.component.security.core-5.3.x-SNAPSHOT.jar
MD5: 488f425f279a0c228294112bce69f54a
SHA1: 851b19507264b0f4a9f19d3752df3b127276ce2a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name exo.core.component.security.core High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom artifactid exo.core.component.security.core Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom description Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom name eXo PLF Core :: Component :: Security Service High
Product pom parent-groupid org.exoplatform.core Low
Product file name exo.core.component.security.core High
Product Manifest Implementation-Title eXo PLF Core :: Component :: Security Service High
Product pom description Implementation of 'eXo Security' component of Exoplatform SAS 'eXo Core' project. Medium
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product pom artifactid exo.core.component.security.core Highest
Product pom name eXo PLF Core :: Component :: Security Service High
Product Manifest specification-title exo-core Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.security.core:5.3.x-SNAPSHOT
Confidence :High
mime-util-2.1.3.jar
Description: mime-util is a simple to use, small, light weight and fast open source java utility library that can detect
MIME types from files, input streams, URL's and byte arrays.
Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/eu/medsea/mimeutil/mime-util/2.1.3/mime-util-2.1.3.jar
MD5: 3d4f3e1a96eb79683197f1c8b182f4a6
SHA1: 0c9cfae15c74f62491d4f28def0dff1dabe52a47
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://www.medsea.eu/mime-util/ Highest
Vendor manifest Bundle-Description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Vendor Manifest bundle-docurl http://www.medsea.eu Low
Vendor pom organization name Medsea Business Solutions S.L. High
Vendor pom name Mime Detection Utility High
Vendor pom organization url http://www.medsea.eu Medium
Vendor Manifest bundle-symbolicname eu.medsea.mimeutil.mime-util Medium
Vendor Manifest url http://www.medsea.eu/mime-util/ Low
Vendor file name mime-util High
Vendor central groupid eu.medsea.mimeutil Highest
Vendor pom description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Vendor pom groupid eu.medsea.mimeutil Highest
Vendor pom artifactid mime-util Low
Product Manifest Bundle-Name Mime Detection Utility Medium
Product manifest Bundle-Description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Product Manifest bundle-docurl http://www.medsea.eu Low
Product central artifactid mime-util Highest
Product pom artifactid mime-util Highest
Product pom organization name Medsea Business Solutions S.L. Low
Product pom name Mime Detection Utility High
Product Manifest bundle-symbolicname eu.medsea.mimeutil.mime-util Medium
Product Manifest url http://www.medsea.eu/mime-util/ Low
Product pom url http://www.medsea.eu/mime-util/ Medium
Product file name mime-util High
Product pom organization url http://www.medsea.eu Low
Product pom groupid eu.medsea.mimeutil Low
Product pom description mime-util is a simple to use, small, light weight and fast open source java utility library that can detect MIME types from files, input streams, URL's and byte arrays. Due to the use of regular expressions and the java.nio packages it requires at least Java 1.4. Low
Version pom version 2.1.3 Highest
Version central version 2.1.3 Highest
Version file version 2.1.3 Highest
jcl-over-slf4j-1.7.18.jar
Description: JCL 1.1.1 implemented over SLF4J
File Path: /home/ciagent/.m2/repository/org/slf4j/jcl-over-slf4j/1.7.18/jcl-over-slf4j-1.7.18.jar
MD5: 86c8f80da62e4640564effb9dff7e003
SHA1: eca71be00af2579564e9f3a23ce0b245ca79ee5d
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jcl-over-slf4j Low
Vendor pom parent-groupid org.slf4j Medium
Vendor pom url http://www.slf4j.org Highest
Vendor pom groupid slf4j Highest
Vendor pom parent-artifactid slf4j-parent Low
Vendor central groupid org.slf4j Highest
Vendor manifest Bundle-Description JCL 1.1.1 implemented over SLF4J Medium
Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium
Vendor pom description JCL 1.1.1 implemented over SLF4J Medium
Vendor pom name JCL 1.1.1 implemented over SLF4J High
Vendor file name jcl-over-slf4j High
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom groupid org.slf4j Highest
Product pom groupid slf4j Low
Product pom url http://www.slf4j.org Medium
Product Manifest Bundle-Name jcl-over-slf4j Medium
Product Manifest Implementation-Title jcl-over-slf4j High
Product central artifactid jcl-over-slf4j Highest
Product pom parent-artifactid slf4j-parent Medium
Product manifest Bundle-Description JCL 1.1.1 implemented over SLF4J Medium
Product Manifest bundle-symbolicname jcl.over.slf4j Medium
Product pom description JCL 1.1.1 implemented over SLF4J Medium
Product pom name JCL 1.1.1 implemented over SLF4J High
Product pom artifactid jcl-over-slf4j Highest
Product file name jcl-over-slf4j High
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product pom parent-groupid org.slf4j Low
Version central version 1.7.18 Highest
Version pom version 1.7.18 Highest
Version Manifest Implementation-Version 1.7.18 High
Version file version 1.7.18 Highest
exo.kernel.commons-5.3.x-SNAPSHOT.jar
Description: Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.commons/5.3.x-SNAPSHOT/exo.kernel.commons-5.3.x-SNAPSHOT.jar
MD5: e45922985af7344ecbcca4bae3fc09ab
SHA1: c338e8e2fb4598959349acdf407306be46246113
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor pom name eXo PLF:: Kernel :: Commons Utils High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor file name exo.kernel.commons High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom artifactid exo.kernel.commons Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom parent-artifactid kernel-parent Low
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom description Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project. Medium
Product pom name eXo PLF:: Kernel :: Commons Utils High
Product file name exo.kernel.commons High
Product Manifest specification-title exo-kernel Medium
Product pom parent-artifactid kernel-parent Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product pom artifactid exo.kernel.commons Highest
Product Manifest Implementation-Title eXo PLF:: Kernel :: Commons Utils High
Product pom groupid exoplatform.kernel Low
Product pom description Implementation of Commons Utils of Exoplatform SAS 'eXo Kernel' project. Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.commons:5.3.x-SNAPSHOT
Confidence :High
javax.servlet-api-3.0.1.jar
Description: Java.net - The Source for Java Technology Collaboration
License:
CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/ciagent/.m2/repository/javax/servlet/javax.servlet-api/3.0.1/javax.servlet-api-3.0.1.jar
MD5: 3ef236ac4c24850cd54abff60be25f35
SHA1: 6bf0ebb7efd993e222fc1112377b5e92a13b38dd
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:provided
eXo PLF:: Wiki Service:provided
eXo PLF:: Wiki Webapp:provided
eXo Wiki JPA DAO:provided
eXo PLF:: Wiki Upgrade Plugins:provided
eXo Wiki JPA Migration Service:provided
eXo PLF:: Wiki Renderer:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor Oracle Low
Vendor pom parent-artifactid jvnet-parent Low
Vendor pom name Java Servlet API High
Vendor central groupid javax.servlet Highest
Vendor pom organization url https://glassfish.dev.java.net Medium
Vendor pom parent-groupid net.java Medium
Vendor pom url http://servlet-spec.java.net Highest
Vendor Manifest Implementation-Vendor GlassFish Community High
Vendor Manifest extension-name javax.servlet Medium
Vendor Manifest bundle-docurl https://glassfish.dev.java.net Low
Vendor Manifest bundle-symbolicname javax.servlet-api Medium
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor file name javax.servlet-api High
Vendor Manifest (hint) specification-vendor sun Low
Vendor pom organization name GlassFish Community High
Vendor manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium
Vendor pom artifactid javax.servlet-api Low
Vendor pom groupid javax.servlet Highest
Product pom name Java Servlet API High
Product pom parent-artifactid jvnet-parent Medium
Product Manifest Bundle-Name Java Servlet API Medium
Product central artifactid javax.servlet-api Highest
Product Manifest extension-name javax.servlet Medium
Product Manifest bundle-docurl https://glassfish.dev.java.net Low
Product pom parent-groupid net.java Low
Product pom url http://servlet-spec.java.net Medium
Product pom organization url https://glassfish.dev.java.net Low
Product pom groupid javax.servlet Low
Product Manifest bundle-symbolicname javax.servlet-api Medium
Product Manifest specification-title Java(TM) Servlet API Design Specification Medium
Product file name javax.servlet-api High
Product pom artifactid javax.servlet-api Highest
Product manifest Bundle-Description Java.net - The Source for Java Technology Collaboration Medium
Product pom organization name GlassFish Community Low
Version file version 3.0.1 Highest
Version Manifest Implementation-Version 3.0.1 High
Version central version 3.0.1 Highest
Version pom version 3.0.1 Highest
commons-beanutils-1.8.3.jar
Description: BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-beanutils/commons-beanutils/1.8.3/commons-beanutils-1.8.3.jar
MD5: b45be74134796c89db7126083129532f
SHA1: 686ef3410bcf4ab8ce7fd0b899e832aaba5facf7
Referenced In Projects/Scopes:
eXo PLF:: Wiki Macros Iframe:compile
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid commons-beanutils Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Vendor pom parent-artifactid commons-parent Low
Vendor file name commons-beanutils High
Vendor pom name Commons BeanUtils High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url http://commons.apache.org/beanutils/ Highest
Vendor Manifest bundle-docurl http://commons.apache.org/beanutils/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.beanutils Medium
Vendor manifest Bundle-Description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom artifactid commons-beanutils Low
Vendor pom groupid commons-beanutils Highest
Product pom parent-artifactid commons-parent Medium
Product pom description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Product Manifest Bundle-Name Commons BeanUtils Medium
Product file name commons-beanutils High
Product pom name Commons BeanUtils High
Product pom artifactid commons-beanutils Highest
Product Manifest specification-title Commons BeanUtils Medium
Product Manifest bundle-docurl http://commons.apache.org/beanutils/ Low
Product Manifest Implementation-Title Commons BeanUtils High
Product central artifactid commons-beanutils Highest
Product Manifest bundle-symbolicname org.apache.commons.beanutils Medium
Product pom groupid commons-beanutils Low
Product manifest Bundle-Description BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection. Medium
Product pom url http://commons.apache.org/beanutils/ Medium
Product pom parent-groupid org.apache.commons Low
Version file version 1.8.3 Highest
Version Manifest Implementation-Version 1.8.3 High
Version central version 1.8.3 Highest
Version pom version 1.8.3 Highest
Published Vulnerabilities
CVE-2014-0114 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
Vulnerable Software & Versions: (show all )
jibx-run-1.2.6.jar
Description: JiBX runtime code
License:
http://jibx.sourceforge.net/jibx-license.html
File Path: /home/ciagent/.m2/repository/org/jibx/jibx-run/1.2.6/jibx-run-1.2.6.jar
MD5: 4ef53e4279c8440aff2d16c0af024231
SHA1: 544f3ac7887d7eed20ca0420ee1963df6c7ecebb
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description JiBX runtime code Medium
Vendor file name jibx-run High
Vendor central groupid org.jibx Highest
Vendor pom groupid jibx Highest
Vendor pom groupid org.jibx Highest
Vendor pom parent-groupid org.jibx.config Medium
Vendor Manifest bundle-symbolicname jibx-run Medium
Vendor manifest Bundle-Description JiBX runtime code Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor Manifest bundle-docurl http://www.jibx.org Low
Vendor pom parent-artifactid main-reactor Low
Vendor pom artifactid jibx-run Low
Vendor pom name jibx-run - JiBX runtime High
Product pom parent-artifactid main-reactor Medium
Product pom description JiBX runtime code Medium
Product file name jibx-run High
Product pom groupid jibx Low
Product pom parent-groupid org.jibx.config Low
Product Manifest bundle-symbolicname jibx-run Medium
Product manifest Bundle-Description JiBX runtime code Medium
Product central artifactid jibx-run Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product pom artifactid jibx-run Highest
Product Manifest bundle-docurl http://www.jibx.org Low
Product Manifest Bundle-Name jibx-run - JiBX runtime Medium
Product pom name jibx-run - JiBX runtime High
Version central version 1.2.6 Highest
Version pom version 1.2.6 Highest
Version file version 1.2.6 Highest
cdi-api-1.0-SP4.jar
Description: APIs for JSR-299: Contexts and Dependency Injection for Java EE
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/javax/enterprise/cdi-api/1.0-SP4/cdi-api-1.0-SP4.jar
MD5: 6c1e2b4036d64b6ba1a1136a00c7cdaa
SHA1: 6e38490033eb8b36c4cf1f7605163424a574dcf0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.jboss.weld Medium
Vendor pom artifactid cdi-api Low
Vendor file name cdi-api High
Vendor central groupid javax.enterprise Highest
Vendor pom groupid javax.enterprise Highest
Vendor Manifest Implementation-Vendor Seam Framework High
Vendor pom url http://www.seamframework.org/Weld Highest
Vendor pom name CDI APIs High
Vendor pom organization name Seam Framework High
Vendor Manifest implementation-url http://www.seamframework.org/Weld Low
Vendor pom parent-artifactid weld-parent Low
Vendor pom organization url http://seamframework.org Medium
Vendor Manifest specification-vendor Seam Framework Low
Vendor pom description APIs for JSR-299: Contexts and Dependency Injection for Java EE Medium
Product Manifest specification-title CDI APIs Medium
Product file name cdi-api High
Product pom organization name Seam Framework Low
Product pom organization url http://seamframework.org Low
Product pom parent-artifactid weld-parent Medium
Product pom parent-groupid org.jboss.weld Low
Product pom url http://www.seamframework.org/Weld Medium
Product central artifactid cdi-api Highest
Product pom artifactid cdi-api Highest
Product pom name CDI APIs High
Product Manifest Implementation-Title CDI APIs High
Product Manifest implementation-url http://www.seamframework.org/Weld Low
Product pom groupid javax.enterprise Low
Product pom description APIs for JSR-299: Contexts and Dependency Injection for Java EE Medium
Version central version 1.0-SP4 Highest
Version file version 1.0.sp4 Highest
Version pom version 1.0-SP4 Highest
exo.kernel.container-5.3.x-SNAPSHOT.jar
Description: Implementation of Container for Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.container/5.3.x-SNAPSHOT/exo.kernel.container-5.3.x-SNAPSHOT.jar
MD5: e3a9fd28ca075c2222bbeed39e55297d
SHA1: 6a171b6b0e06e09151f08de470d69b3b5358489a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid exo.kernel.container Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom name eXo PLF:: Kernel :: Container High
Vendor pom groupid exoplatform.kernel Highest
Vendor file name exo.kernel.container High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom description Implementation of Container for Exoplatform SAS 'eXo Kernel' project. Medium
Product Manifest Implementation-Title eXo PLF:: Kernel :: Container High
Product Manifest specification-title exo-kernel Medium
Product pom name eXo PLF:: Kernel :: Container High
Product pom parent-artifactid kernel-parent Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product file name exo.kernel.container High
Product pom groupid exoplatform.kernel Low
Product pom description Implementation of Container for Exoplatform SAS 'eXo Kernel' project. Medium
Product pom artifactid exo.kernel.container Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.container:5.3.x-SNAPSHOT
Confidence :High
exo.portal.webui.core-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.core/5.3.x-SNAPSHOT/exo.portal.webui.core-5.3.x-SNAPSHOT.jar
MD5: 4e253065194ba0054c6d12ec0b724bad
SHA1: 40016d9274ed13258c15197a39051966ad7c20f0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.portal Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom artifactid exo.portal.webui.core Low
Vendor pom groupid exoplatform.gatein.portal Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor pom name GateIn Portal WebUI Core High
Vendor pom parent-groupid org.exoplatform.gatein.portal Medium
Vendor Manifest build-timestamp Fri, 24 May 2019 09:23:29 +0000 Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom groupid org.exoplatform.gatein.portal Highest
Vendor pom parent-artifactid exo.portal.webui Low
Vendor Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.webui/exo.portal.webui.core/ Low
Vendor file name exo.portal.webui.core High
Product Manifest specification-title GateIn Portal WebUI Core Medium
Product pom name GateIn Portal WebUI Core High
Product pom parent-groupid org.exoplatform.gatein.portal Low
Product Manifest build-timestamp Fri, 24 May 2019 09:23:29 +0000 Low
Product Manifest Implementation-Title GateIn Portal WebUI Core High
Product pom parent-artifactid exo.portal.webui Medium
Product pom groupid exoplatform.gatein.portal Low
Product Manifest implementation-url www.gatein.org/exo.portal.parent/exo.portal.webui/exo.portal.webui.core/ Low
Product pom artifactid exo.portal.webui.core Highest
Product file name exo.portal.webui.core High
Product Manifest os-name Linux Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Related Dependencies
exo.portal.component.web.controller-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.controller/5.3.x-SNAPSHOT/exo.portal.component.web.controller-5.3.x-SNAPSHOT.jar
SHA1: 3a4bd38a13733428585e9a0d912b575bb0171065
MD5: 6c1694454dfac1798e4a0c331488ef46
exo.portal.component.web.oauth-common-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.oauth-common/5.3.x-SNAPSHOT/exo.portal.component.web.oauth-common-5.3.x-SNAPSHOT.jar
SHA1: 4936fafeba68d81bb3c90d38147bbaf19cc27057
MD5: f19372047bf2fcc6e53988f48acda2be
exo.portal.webui.eXo-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.eXo/5.3.x-SNAPSHOT/exo.portal.webui.eXo-5.3.x-SNAPSHOT.jar
SHA1: b3bdd8a793cb283d9bbf16af2cb13f1675e413f8
MD5: afa037f8dc2dab13c67c2c1d589ea2a8
exo.portal.component.web.server-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.server/5.3.x-SNAPSHOT/exo.portal.component.web.server-5.3.x-SNAPSHOT.jar
SHA1: dc3e363540d3d8f8fec0eab9b678b9b72dd55204
MD5: 596429c3b83eee1fbb9a6900fb5bc767
exo.portal.gadgets-core-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.gadgets-core/5.3.x-SNAPSHOT/exo.portal.gadgets-core-5.3.x-SNAPSHOT.jar
SHA1: 2cbcc3ccdfe72fd9b1758b41de7debffaa4a19b7
MD5: 584daf75b24db418bda422c83db4f06f
exo.portal.component.web.api-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.api/5.3.x-SNAPSHOT/exo.portal.component.web.api-5.3.x-SNAPSHOT.jar
SHA1: f165f72a61ffe9be8cc5439d1e3aad5038cdeeda
MD5: df11e4023eef859c54f42f88ca54bf3c
exo.portal.component.web.resources-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.resources/5.3.x-SNAPSHOT/exo.portal.component.web.resources-5.3.x-SNAPSHOT.jar
SHA1: 4c7c2c7c8a9ef857c5e6795726325b48221a7208
MD5: c26f1dd1af02de020041a91458e46a1b
exo.portal.webui.framework-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.framework/5.3.x-SNAPSHOT/exo.portal.webui.framework-5.3.x-SNAPSHOT.jar
SHA1: ef9436758e0044f245e0fa6b6b7c379ab286c52d
MD5: ac6505c0b91c838e9d5608a3a21349a3
exo.portal.webui.portal-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.portal/5.3.x-SNAPSHOT/exo.portal.webui.portal-5.3.x-SNAPSHOT.jar
SHA1: 07aa539953ad436ea88f9dcf84b22bf69e9f3b65
MD5: c8e2e27703b38aa313c458b73c6868bf
exo.portal.component.resources-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.resources/5.3.x-SNAPSHOT/exo.portal.component.resources-5.3.x-SNAPSHOT.jar
SHA1: c23cb03c0f52b2dd68bcd86b8113a185ed30bd6b
MD5: 123ae03a809ba15e1ba8149c634670ca
exo.portal.component.portal-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.portal/5.3.x-SNAPSHOT/exo.portal.component.portal-5.3.x-SNAPSHOT.jar
SHA1: f951922ad0ef8aca6befdcbafcb827434ab29152
MD5: e25c9bf4891b78d4fdbce23182b4b802
exo.portal.webui.portlet-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.webui.portlet/5.3.x-SNAPSHOT/exo.portal.webui.portlet-5.3.x-SNAPSHOT.jar
SHA1: 5018ace82feea85d91963b5da0960278bb572d86
MD5: a38f6ddb28f8547da691be9b522bec58
exo.portal.component.identity-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.identity/5.3.x-SNAPSHOT/exo.portal.component.identity-5.3.x-SNAPSHOT.jar
SHA1: 8fffa81e8cd85c152feb81dcbfc005d7ceb509c9
MD5: b61dcad072b18546986d710b3bf8279a
exo.portal.component.web.security-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.web.security/5.3.x-SNAPSHOT/exo.portal.component.web.security-5.3.x-SNAPSHOT.jar
SHA1: e37beac9738288445a37d22bb35f7658625cac00
MD5: e5a36a0c806d6c1a5636f000d91d4a15
exo.portal.component.common-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.common/5.3.x-SNAPSHOT/exo.portal.component.common-5.3.x-SNAPSHOT.jar
SHA1: b1490240b45a4cd6c9dafd1a91e699c6fb2105f0
MD5: 2392ffd0fd1d546111f3534caad4c85d
exo.portal.component.pc-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.pc/5.3.x-SNAPSHOT/exo.portal.component.pc-5.3.x-SNAPSHOT.jar
SHA1: da8ee53758da5d87ef6fe43a9c7ad345b1f14b75
MD5: 86fce480119fc8f6c452ef9f986f3a8c
exo.portal.component.application-registry-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.application-registry/5.3.x-SNAPSHOT/exo.portal.component.application-registry-5.3.x-SNAPSHOT.jar
SHA1: 41f3a1ed6ceeced14843f9b2d93b7e140de841f2
MD5: 369c376f07f42f61c2dff876226fa8d9
exo.portal.component.api-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.api/5.3.x-SNAPSHOT/exo.portal.component.api-5.3.x-SNAPSHOT.jar
SHA1: 05b6efbd373dc6066badcca29d5fb105ff35ac37
MD5: 90ddb3572d45c3250425cf477c7e9dcc
exo.portal.component.scripting-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/portal/exo.portal.component.scripting/5.3.x-SNAPSHOT/exo.portal.component.scripting-5.3.x-SNAPSHOT.jar
SHA1: 06f89c090ce9b36c00cc9087ea6769a45901e19b
MD5: 12d3305d4cb34b5807cce436589455b9
maven: org.exoplatform.gatein.portal:exo.portal.webui.core:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:in-portal:in-portal:5.3
Confidence :Low
suppress
htmlcleaner-2.7.jar
Description:
HtmlCleaner is an HTML parser written in Java. It transforms dirty HTML to well-formed XML following
the same rules that most web-browsers use.
License:
BSD License: http://www.opensource.org/licenses/bsd-license.php
File Path: /home/ciagent/.m2/repository/net/sourceforge/htmlcleaner/htmlcleaner/2.7/htmlcleaner-2.7.jar
MD5: 59c43d382a268e31867fcd3de90991a0
SHA1: e2f6f5e109695701578258934d9819379c5bffe4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom description HtmlCleaner is an HTML parser written in Java. It transforms dirty HTML to well-formed XML following the same rules that most web-browsers use. Low
Vendor central groupid net.sourceforge.htmlcleaner Highest
Vendor pom groupid net.sourceforge.htmlcleaner Highest
Vendor pom artifactid htmlcleaner Low
Vendor file name htmlcleaner High
Vendor pom url http://htmlcleaner.sourceforge.net/ Highest
Vendor jar package name htmlcleaner Low
Vendor pom name HtmlCleaner High
Vendor hint analyzer vendor htmlcleaner_project Highest
Product pom groupid net.sourceforge.htmlcleaner Low
Product pom description HtmlCleaner is an HTML parser written in Java. It transforms dirty HTML to well-formed XML following the same rules that most web-browsers use. Low
Product pom url http://htmlcleaner.sourceforge.net/ Medium
Product hint analyzer product htmlcleaner Highest
Product central artifactid htmlcleaner Highest
Product file name htmlcleaner High
Product pom artifactid htmlcleaner Highest
Product pom name HtmlCleaner High
Version pom version 2.7 Highest
Version file version 2.7 Highest
Version central version 2.7 Highest
xercesImpl-2.9.1.jar
Description:
Xerces2 is the next generation of high performance, fully compliant XML parsers in the
Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI),
a complete framework for building parser components and configurations that is extremely
modular and easy to program.
File Path: /home/ciagent/.m2/repository/xerces/xercesImpl/2.9.1/xercesImpl-2.9.1.jar
MD5: f807f86d7d9db25edbfc782aca7ca2a9
SHA1: 7bc7e49ddfe4fb5f193ed37ecc96c12292c8ceb6
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium
Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xerces/impl/Version.class Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom parent-artifactid apache Low
Vendor pom description Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program. Low
Vendor pom name Xerces2 Java Parser High
Vendor pom groupid xerces Highest
Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium
Vendor central groupid xerces Highest
Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium
Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium
Vendor file name xercesImpl High
Vendor pom url http://xerces.apache.org/xerces2-j Highest
Vendor pom artifactid xercesImpl Low
Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/apache/xerces/xni/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom parent-groupid org.apache Medium
Product pom artifactid xercesImpl Highest
Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium
Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium
Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing Medium
Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 3 Core Medium
Product central artifactid xercesImpl Highest
Product pom name Xerces2 Java Parser High
Product manifest: org/apache/xerces/xni/ Specification-Title Xerces Native Interface Medium
Product manifest: org/apache/xerces/xni/ Implementation-Title org.apache.xerces.xni Medium
Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium
Product pom parent-groupid org.apache Low
Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium
Product pom parent-artifactid apache Medium
Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model, Level 3 Load and Save Medium
Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium
Product pom groupid xerces Low
Product pom description Xerces2 is the next generation of high performance, fully compliant XML parsers in the Apache Xerces family. This new version of Xerces introduces the Xerces Native Interface (XNI), a complete framework for building parser components and configurations that is extremely modular and easy to program. Low
Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium
Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing Medium
Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium
Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium
Product manifest: org/apache/xerces/impl/Version.class Implementation-Title org.apache.xerces.impl.Version Medium
Product file name xercesImpl High
Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium
Product pom url http://xerces.apache.org/xerces2-j Medium
Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium
Version file version 2.9.1 Highest
Version central version 2.9.1 Highest
Version pom version 2.9.1 Highest
Published Vulnerabilities
CVE-2012-0881 suppress
Severity:
High
CVSS Score: 7.8
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
CWE: CWE-399 Resource Management Errors
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
Vulnerable Software & Versions:
stax-utils-20070216.jar
Description: Provides a set of utility classes to integrate StAX into existing XML processing applications.
License:
BSD: http://www.opensource.org/licenses/bsd-license.html
File Path: /home/ciagent/.m2/repository/net/java/dev/stax-utils/stax-utils/20070216/stax-utils-20070216.jar
MD5: e4e3c9cad3b8289b1f905d6705bb6368
SHA1: 1d9fc60be26a0482c36b7a04d2c581ddf758b6ea
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor file name stax-utils-20070216 High
Vendor pom artifactid stax-utils Low
Vendor jar package name staxutils Low
Vendor pom description Provides a set of utility classes to integrate StAX into existing XML processing applications. Medium
Vendor pom groupid net.java.dev.stax-utils Highest
Vendor jar package name javanet Low
Vendor central groupid net.java.dev.stax-utils Highest
Vendor pom url http://java.net/projects/stax-utils/ Highest
Vendor pom name StAX Utilities Project High
Product central artifactid stax-utils Highest
Product file name stax-utils-20070216 High
Product pom url http://java.net/projects/stax-utils/ Medium
Product jar package name staxutils Low
Product pom groupid net.java.dev.stax-utils Low
Product pom description Provides a set of utility classes to integrate StAX into existing XML processing applications. Medium
Product pom name StAX Utilities Project High
Product pom artifactid stax-utils Highest
Version central version 20070216 Highest
Version file version 20070216 Medium
Version pom version 20070216 Highest
xwiki-commons-xml-5.4.7.jar
Description: XWiki Commons - XML
License:
http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/xwiki/commons/xwiki-commons-xml/5.4.7/xwiki-commons-xml-5.4.7.jar
MD5: 292ec670c150223faee3a24a5288b9bd
SHA1: 788b59fc9ea9109aacc237a15f059530b1afb793
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid xwiki.commons Highest
Vendor manifest Bundle-Description XWiki Commons - XML Medium
Vendor Manifest bundle-docurl http://xwiki.org/ Low
Vendor pom name XWiki Commons - XML High
Vendor pom artifactid xwiki-commons-xml Low
Vendor pom parent-groupid org.xwiki.commons Medium
Vendor pom parent-artifactid xwiki-commons-core Low
Vendor Manifest xwiki-extension-id org.xwiki.commons:xwiki-commons-xml Low
Vendor pom description XWiki Commons - XML Medium
Vendor file name xwiki-commons-xml High
Vendor Manifest bundle-symbolicname org.xwiki.commons.xwiki-commons-xml Medium
Vendor pom groupid org.xwiki.commons Highest
Product manifest Bundle-Description XWiki Commons - XML Medium
Product pom artifactid xwiki-commons-xml Highest
Product pom parent-groupid org.xwiki.commons Low
Product Manifest bundle-docurl http://xwiki.org/ Low
Product pom name XWiki Commons - XML High
Product Manifest Bundle-Name XWiki Commons - XML Medium
Product Manifest xwiki-extension-id org.xwiki.commons:xwiki-commons-xml Low
Product pom parent-artifactid xwiki-commons-core Medium
Product pom description XWiki Commons - XML Medium
Product file name xwiki-commons-xml High
Product Manifest bundle-symbolicname org.xwiki.commons.xwiki-commons-xml Medium
Product pom groupid xwiki.commons Low
Version file version 5.4.7 Highest
Version pom version 5.4.7 Highest
Related Dependencies
maven: org.xwiki.commons:xwiki-commons-xml:5.4.7
Confidence :High
cpe: cpe:/a:xwiki:xwiki:5.4.7
Confidence :Low
suppress
Published Vulnerabilities
CVE-2018-16277 suppress
Severity:
Low
CVSS Score: 3.5
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The Image Import function in XWiki through 10.7 has XSS.
Vulnerable Software & Versions:
picocontainer-1.1.jar
Description: Please refer to the main website for documentation.
File Path: /home/ciagent/.m2/repository/picocontainer/picocontainer/1.1/picocontainer-1.1.jar
MD5: 98f476491eed3b106b9a015f15bf5fda
SHA1: a2babe80a3af3a3672095341625e4a9ba4278c1b
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name PicoContainer High
Vendor pom description Please refer to the main website for documentation. Medium
Vendor Manifest specification-vendor Codehaus Low
Vendor file name picocontainer High
Vendor pom organization url http://codehaus.org/ Medium
Vendor pom artifactid picocontainer Low
Vendor pom groupid picocontainer Highest
Vendor Manifest Implementation-Vendor Codehaus High
Vendor central groupid picocontainer Highest
Vendor pom organization name Codehaus High
Vendor Manifest extension-name picocontainer Medium
Vendor pom url http://www.picocontainer.org/ Highest
Product pom organization name Codehaus Low
Product pom groupid picocontainer Low
Product pom name PicoContainer High
Product Manifest Implementation-Title org.picocontainer High
Product pom description Please refer to the main website for documentation. Medium
Product file name picocontainer High
Product Manifest specification-title Small footprint Dependency Injection container Medium
Product pom artifactid picocontainer Highest
Product pom organization url http://codehaus.org/ Low
Product Manifest extension-name picocontainer Medium
Product central artifactid picocontainer Highest
Product pom url http://www.picocontainer.org/ Medium
Version file version 1.1 Highest
Version central version 1.1 Highest
Version Manifest Implementation-Version 1.1 High
Version pom version 1.1 Highest
wiki-renderer-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/wiki/wiki-renderer/5.3.x-SNAPSHOT/wiki-renderer-5.3.x-SNAPSHOT.jar
MD5: 20e03d7c2100f6b2547350e871910870
SHA1: 83803dcbe0c8d678c7dbcb02b403b10d680222a1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.wiki Highest
Vendor pom groupid org.exoplatform.wiki Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid wiki Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.wiki Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-renderer Low
Vendor Manifest date 2019-05-24T10:40:54Z Low
Vendor pom artifactid wiki-renderer Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom name eXo PLF:: Wiki Renderer High
Vendor file name wiki-renderer High
Vendor pom parent-groupid org.exoplatform.wiki Medium
Product pom artifactid wiki-renderer Highest
Product pom name eXo PLF:: Wiki Renderer High
Product file name wiki-renderer High
Product pom parent-groupid org.exoplatform.wiki Low
Product Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-renderer Low
Product pom groupid exoplatform.wiki Low
Product Manifest date 2019-05-24T10:40:54Z Low
Product Manifest Implementation-Title eXo PLF:: Wiki Renderer High
Product Manifest specification-title eXo PLF:: Wiki Renderer Medium
Product pom parent-artifactid wiki Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.wiki:wiki-renderer:5.3.x-SNAPSHOT
Confidence :High
commons-chain-1.2.jar
Description:
An implementation of the GoF Chain of Responsibility pattern
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-chain/commons-chain/1.2/commons-chain-1.2.jar
MD5: e18e2c87826644e4c8c08635572c154f
SHA1: 744a13e8766e338bd347b6fbc28c6db12979d0c6
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-docurl http://commons.apache.org/chain/ Low
Vendor file name commons-chain High
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-chain Highest
Vendor Manifest bundle-symbolicname org.apache.commons.chain Medium
Vendor central groupid commons-chain Highest
Vendor pom artifactid commons-chain Low
Vendor pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Vendor pom name Commons Chain High
Vendor pom url http://commons.apache.org/chain/ Highest
Vendor manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest specification-title Commons Chain Medium
Product Manifest bundle-docurl http://commons.apache.org/chain/ Low
Product file name commons-chain High
Product Manifest bundle-symbolicname org.apache.commons.chain Medium
Product Manifest Bundle-Name Commons Chain Medium
Product pom description
An implementation of the GoF Chain of Responsibility pattern
Medium
Product pom name Commons Chain High
Product pom url http://commons.apache.org/chain/ Medium
Product pom artifactid commons-chain Highest
Product Manifest Implementation-Title Commons Chain High
Product manifest Bundle-Description An implementation of the GoF Chain of Responsibility pattern Medium
Product pom groupid commons-chain Low
Product pom parent-groupid org.apache.commons Low
Product central artifactid commons-chain Highest
Version pom version 1.2 Highest
Version file version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
Version central version 1.2 Highest
commons-fileupload-1.3.3.jar
Description:
The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart
file upload functionality to servlets and web applications.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-fileupload/commons-fileupload/1.3.3/commons-fileupload-1.3.3.jar
MD5: dd77e787b7b5dc56f6a1cb658716d55d
SHA1: 04ff14d809195b711fd6bcc87e6777f886730ca1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid commons-fileupload Highest
Vendor Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Vendor pom parent-artifactid commons-parent Low
Vendor pom artifactid commons-fileupload Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor central groupid commons-fileupload Highest
Vendor file name commons-fileupload High
Vendor Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Vendor pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Vendor Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Vendor pom name Apache Commons FileUpload High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom url http://commons.apache.org/proper/commons-fileupload/ Highest
Product Manifest Bundle-Name Apache Commons FileUpload Medium
Product manifest Bundle-Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product pom parent-artifactid commons-parent Medium
Product Manifest implementation-build UNKNOWN@r18734e9f77a267ebc82ff2ffce6d96e82a34260f; 2017-06-09 22:59:50+0000 Low
Product file name commons-fileupload High
Product Manifest bundle-symbolicname org.apache.commons.fileupload Medium
Product Manifest specification-title Apache Commons FileUpload Medium
Product pom artifactid commons-fileupload Highest
Product Manifest Implementation-Title Apache Commons FileUpload High
Product pom description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-fileupload/ Low
Product central artifactid commons-fileupload Highest
Product Manifest implementation-url http://commons.apache.org/proper/commons-fileupload/ Low
Product pom groupid commons-fileupload Low
Product pom name Apache Commons FileUpload High
Product pom parent-groupid org.apache.commons Low
Product pom url http://commons.apache.org/proper/commons-fileupload/ Medium
Version pom version 1.3.3 Highest
Version file version 1.3.3 Highest
Version Manifest Implementation-Version 1.3.3 High
Version central version 1.3.3 Highest
activation-1.1.1.jar
Description: The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/activation/activation/1.1.1/activation-1.1.1.jar
MD5: 46a37512971d8eca81c3fcf245bf07d2
SHA1: 485de3a253e23f645037828c07f1d7f1af40763a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor pom name JavaBeans(TM) Activation Framework High
Vendor pom description The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data Medium
Vendor pom artifactid activation Low
Vendor pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Highest
Vendor central groupid javax.activation Highest
Vendor Manifest extension-name javax.activation Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom groupid javax.activation Highest
Vendor file name activation High
Product pom name JavaBeans(TM) Activation Framework High
Product pom description The JavaBeans(TM) Activation Framework is used by the JavaMail(TM) API to manage MIME data Medium
Product pom url http://java.sun.com/javase/technologies/desktop/javabeans/jaf/index.jsp Medium
Product Manifest extension-name javax.activation Medium
Product central artifactid activation Highest
Product pom artifactid activation Highest
Product pom groupid javax.activation Low
Product Manifest specification-title JavaBeans(TM) Activation Framework Specification Medium
Product file name activation High
Version pom version 1.1.1 Highest
Version file version 1.1.1 Highest
Version Manifest Implementation-Version 1.1.1 High
Version central version 1.1.1 Highest
mail-1.4.7.jar
Description: JavaMail API (compat)
License:
http://www.sun.com/cddl, https://glassfish.java.net/public/CDDL+GPL_1_1.html
File Path: /home/ciagent/.m2/repository/javax/mail/mail/1.4.7/mail-1.4.7.jar
MD5: 77f53ff0c78ba43c4812ecc9f53e20f8
SHA1: 9add058589d5d85adeb625859bf2c5eeaaedf12d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor Oracle Low
Vendor Manifest bundle-docurl http://www.oracle.com Low
Vendor pom name JavaMail API (compat) High
Vendor Manifest extension-name javax.mail Medium
Vendor pom parent-artifactid all Low
Vendor Manifest bundle-symbolicname javax.mail Medium
Vendor Manifest originally-created-by 1.7.0_15 (Oracle Corporation) Low
Vendor pom parent-groupid com.sun.mail Medium
Vendor Manifest Implementation-Vendor Oracle High
Vendor Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Vendor manifest Bundle-Description JavaMail API (compat) Medium
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor central groupid javax.mail High
Vendor Manifest (hint) specification-vendor sun Low
Vendor Manifest (hint) Implementation-Vendor sun High
Vendor pom groupid javax.mail Highest
Vendor file name mail High
Vendor pom artifactid mail Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Product pom artifactid mail Highest
Product Manifest bundle-docurl http://www.oracle.com Low
Product pom groupid javax.mail Low
Product pom name JavaMail API (compat) High
Product Manifest extension-name javax.mail Medium
Product Manifest specification-title JavaMail(TM) API Design Specification Medium
Product Manifest Implementation-Title javax.mail High
Product Manifest bundle-symbolicname javax.mail Medium
Product Manifest originally-created-by 1.7.0_15 (Oracle Corporation) Low
Product Manifest probe-provider-xml-file-names META-INF/gfprobe-provider.xml Medium
Product manifest Bundle-Description JavaMail API (compat) Medium
Product Manifest Bundle-Name JavaMail API (compat) Medium
Product pom parent-groupid com.sun.mail Low
Product file name mail High
Product central artifactid mail High
Product pom parent-artifactid all Medium
Product central artifactid mail-1.4.7 High
Version Manifest Implementation-Version 1.4.7 High
Version file version 1.4.7 Highest
jsr311-api-1.1.1.jar
License:
CDDL License
: http://www.opensource.org/licenses/cddl1.php
File Path: /home/ciagent/.m2/repository/javax/ws/rs/jsr311-api/1.1.1/jsr311-api-1.1.1.jar
MD5: c9803468299ec255c047a280ddec510f
SHA1: 59033da2a1afd56af1ac576750a8d0b1830d59e6
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.sun.com/ Low
Vendor pom url https://jsr311.dev.java.net Highest
Vendor pom organization name Sun Microsystems, Inc High
Vendor pom name jsr311-api High
Vendor Manifest extension-name javax.ws.rs Medium
Vendor central groupid javax.ws.rs Highest
Vendor Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Vendor file name jsr311-api High
Vendor pom artifactid jsr311-api Low
Vendor pom groupid javax.ws.rs Highest
Vendor pom organization url http://www.sun.com/ Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Product Manifest bundle-docurl http://www.sun.com/ Low
Product pom name jsr311-api High
Product Manifest extension-name javax.ws.rs Medium
Product Manifest specification-title JAX-RS: Java API for RESTful Web Services Medium
Product Manifest bundle-symbolicname javax.ws.rs.jsr311-api Medium
Product pom groupid javax.ws.rs Low
Product file name jsr311-api High
Product pom organization url http://www.sun.com/ Low
Product pom artifactid jsr311-api Highest
Product pom organization name Sun Microsystems, Inc Low
Product Manifest Bundle-Name jsr311-api Medium
Product pom url https://jsr311.dev.java.net Medium
Product central artifactid jsr311-api Highest
Version pom version 1.1.1 Highest
Version file version 1.1.1 Highest
Version central version 1.1.1 Highest
lucene-core-3.6.2.jar
Description: Apache Lucene Java Core
File Path: /home/ciagent/.m2/repository/org/apache/lucene/lucene-core/3.6.2/lucene-core-3.6.2.jar
MD5: ee396d04f5a35557b424025f5382c815
SHA1: 9ec77e2507f9cc01756964c71d91efd8154a8c47
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid lucene-parent Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom description Apache Lucene Java Core Medium
Vendor pom groupid org.apache.lucene Highest
Vendor pom groupid apache.lucene Highest
Vendor Manifest extension-name org.apache.lucene Medium
Vendor pom name Lucene Core High
Vendor file name lucene-core High
Vendor central groupid org.apache.lucene Highest
Vendor pom parent-groupid org.apache.lucene Medium
Vendor pom artifactid lucene-core Low
Product pom groupid apache.lucene Low
Product Manifest extension-name org.apache.lucene Medium
Product pom parent-artifactid lucene-parent Medium
Product Manifest Implementation-Title org.apache.lucene High
Product pom name Lucene Core High
Product file name lucene-core High
Product pom artifactid lucene-core Highest
Product pom description Apache Lucene Java Core Medium
Product pom parent-groupid org.apache.lucene Low
Product central artifactid lucene-core Highest
Product Manifest specification-title Lucene Search Engine: core Medium
Version file version 3.6.2 Highest
Version pom version 3.6.2 Highest
Version central version 3.6.2 Highest
chromattic.api-1.3.0.jar
Description: Chromattic Framework API
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.api/1.3.0/chromattic.api-1.3.0.jar
MD5: 11f2df6e3a3b4451719710c0f4c08103
SHA1: 4f60a9585bd6e68833eaaea1f1a615c682adbe27
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Chromattic Framework API High
Vendor pom description Chromattic Framework API Medium
Vendor pom artifactid chromattic.api Low
Vendor pom groupid org.chromattic Highest
Vendor pom parent-artifactid chromattic.parent Low
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor file name chromattic.api High
Vendor pom groupid chromattic Highest
Vendor pom parent-groupid org.chromattic Medium
Vendor jar package name api Low
Product pom name Chromattic Framework API High
Product pom description Chromattic Framework API Medium
Product pom artifactid chromattic.api Highest
Product pom parent-groupid org.chromattic Low
Product central artifactid chromattic.api Highest
Product pom groupid chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Product file name chromattic.api High
Product jar package name api Low
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
reflext.api-1.1.0.jar
Description: The Reflext Framework API
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.api/1.1.0/reflext.api-1.1.0.jar
MD5: fe732172fa2fb5ae4b63866ef15da41f
SHA1: 28374c509099736aeedc52fef3d7b8e78238c2a0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid reflext Highest
Vendor pom description The Reflext Framework API Medium
Vendor file name reflext.api High
Vendor pom parent-groupid org.reflext Medium
Vendor central groupid org.reflext Highest
Vendor pom parent-artifactid reflext.parent Low
Vendor jar package name reflext Low
Vendor pom groupid org.reflext Highest
Vendor pom artifactid reflext.api Low
Vendor pom name Reflext Framework API High
Vendor jar package name api Low
Product pom description The Reflext Framework API Medium
Product file name reflext.api High
Product pom groupid reflext Low
Product pom artifactid reflext.api Highest
Product pom parent-artifactid reflext.parent Medium
Product central artifactid reflext.api Highest
Product pom name Reflext Framework API High
Product pom parent-groupid org.reflext Low
Product jar package name api Low
Version pom version 1.1.0 Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
reflext.core-1.1.0.jar
Description: The Reflect Framework Core
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.core/1.1.0/reflext.core-1.1.0.jar
MD5: cc65231f60a70dec43a57ccba5adce81
SHA1: 56316a714b99d7ac85d23d0f1a4680149c3273d6
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid reflext Highest
Vendor jar package name core Low
Vendor pom parent-groupid org.reflext Medium
Vendor pom name Reflext Framework Core High
Vendor central groupid org.reflext Highest
Vendor pom parent-artifactid reflext.parent Low
Vendor jar package name reflext Low
Vendor pom artifactid reflext.core Low
Vendor pom groupid org.reflext Highest
Vendor pom description The Reflect Framework Core Medium
Vendor file name reflext.core High
Product jar package name core Low
Product pom groupid reflext Low
Product pom name Reflext Framework Core High
Product pom parent-artifactid reflext.parent Medium
Product central artifactid reflext.core Highest
Product pom artifactid reflext.core Highest
Product pom description The Reflect Framework Core Medium
Product file name reflext.core High
Product pom parent-groupid org.reflext Low
Version pom version 1.1.0 Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
reflext.spi-1.1.0.jar
Description: The Reflext Framework SPI
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.spi/1.1.0/reflext.spi-1.1.0.jar
MD5: 2c967ae0c3078d23b615f8825377f304
SHA1: 4df0428c39922079c53955602bce66735f9d20a8
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name reflext.spi High
Vendor pom groupid reflext Highest
Vendor pom description The Reflext Framework SPI Medium
Vendor pom parent-groupid org.reflext Medium
Vendor pom artifactid reflext.spi Low
Vendor jar package name model Low
Vendor pom parent-artifactid reflext.parent Low
Vendor jar package name spi Low
Vendor pom name Reflext Framework SPI High
Vendor central groupid org.reflext Highest
Vendor jar package name reflext Low
Vendor pom groupid org.reflext Highest
Product file name reflext.spi High
Product pom description The Reflext Framework SPI Medium
Product central artifactid reflext.spi Highest
Product pom groupid reflext Low
Product jar package name spi Low
Product pom artifactid reflext.spi Highest
Product pom parent-artifactid reflext.parent Medium
Product jar package name model Low
Product pom name Reflext Framework SPI High
Product pom parent-groupid org.reflext Low
Version pom version 1.1.0 Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
reflext.apt-1.1.0.jar
Description: The Reflext Framework Annotation Processing Tool Plugin
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.apt/1.1.0/reflext.apt-1.1.0.jar
MD5: e6bb0195d6cdd15b618939c78999ea4e
SHA1: 093ab21e03197c1c7a2d2d20da4d3dd34a60ac24
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Reflext Framework Annotation Processing Tool Plugin High
Vendor pom groupid reflext Highest
Vendor pom description The Reflext Framework Annotation Processing Tool Plugin Medium
Vendor file name reflext.apt High
Vendor pom parent-groupid org.reflext Medium
Vendor central groupid org.reflext Highest
Vendor pom parent-artifactid reflext.parent Low
Vendor jar package name reflext Low
Vendor pom groupid org.reflext Highest
Vendor jar package name apt Low
Vendor pom artifactid reflext.apt Low
Product pom name Reflext Framework Annotation Processing Tool Plugin High
Product pom description The Reflext Framework Annotation Processing Tool Plugin Medium
Product pom artifactid reflext.apt Highest
Product file name reflext.apt High
Product pom groupid reflext Low
Product pom parent-artifactid reflext.parent Medium
Product central artifactid reflext.apt Highest
Product jar package name apt Low
Product pom parent-groupid org.reflext Low
Version pom version 1.1.0 Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
Published Vulnerabilities
CVE-2018-1000840 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrate their contents via HTTP requests. This attack appear to be exploitable via The victim must use Processing to parse a crafted XML document.
Vulnerable Software & Versions:
chromattic.apt-1.3.0.jar
Description: Chromattic Framework APT Plugin
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.apt/1.3.0/chromattic.apt-1.3.0.jar
MD5: 5f51682435a2e2014a9bd9c5936a5cc5
SHA1: f2e219c2b8e13983a26b4c3f4e8eb54d71730b4d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid chromattic.apt Low
Vendor pom name Chromattic Framework APT Plugin High
Vendor pom groupid org.chromattic Highest
Vendor pom parent-artifactid chromattic.parent Low
Vendor jar package name chromattic Low
Vendor central groupid org.chromattic Highest
Vendor pom description Chromattic Framework APT Plugin Medium
Vendor jar package name apt Low
Vendor pom groupid chromattic Highest
Vendor pom parent-groupid org.chromattic Medium
Vendor file name chromattic.apt High
Product pom artifactid chromattic.apt Highest
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework APT Plugin High
Product central artifactid chromattic.apt Highest
Product pom groupid chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Product pom description Chromattic Framework APT Plugin Medium
Product jar package name apt Low
Product file name chromattic.apt High
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
chromattic.common-1.3.0.jar
Description: Chromattic Framework Common
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.common/1.3.0/chromattic.common-1.3.0.jar
MD5: 15bfb4cc0312aefffb25952cdf18b2cd
SHA1: 55470175c1ba46a917504acf97018e6ef2932659
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.chromattic Highest
Vendor file name chromattic.common High
Vendor jar package name chromattic Low
Vendor jar package name common Low
Vendor pom artifactid chromattic.common Low
Vendor pom description Chromattic Framework Common Medium
Vendor pom groupid chromattic Highest
Vendor pom name Chromattic Framework Common High
Vendor jar package name collection Low
Vendor pom parent-artifactid chromattic.parent Low
Vendor central groupid org.chromattic Highest
Vendor pom parent-groupid org.chromattic Medium
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework Common High
Product jar package name collection Low
Product pom artifactid chromattic.common Highest
Product file name chromattic.common High
Product jar package name common Low
Product pom groupid chromattic Low
Product pom description Chromattic Framework Common Medium
Product pom parent-artifactid chromattic.parent Medium
Product central artifactid chromattic.common Highest
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
reflext.jlr-1.1.0.jar
Description: The Reflext Framework Java Lang Reflect Plugin
File Path: /home/ciagent/.m2/repository/org/reflext/reflext.jlr/1.1.0/reflext.jlr-1.1.0.jar
MD5: 1103f3b1ed3762e0bd100cbee6e7f345
SHA1: 79ad1a5053213cbb350d37ff12d5f767243c8c46
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid reflext.jlr Low
Vendor pom groupid reflext Highest
Vendor pom name Reflext Framework Java Lang Reflect Plugin High
Vendor file name reflext.jlr High
Vendor jar package name jlr Low
Vendor pom parent-groupid org.reflext Medium
Vendor central groupid org.reflext Highest
Vendor pom parent-artifactid reflext.parent Low
Vendor jar package name reflext Low
Vendor pom description The Reflext Framework Java Lang Reflect Plugin Medium
Vendor pom groupid org.reflext Highest
Product pom name Reflext Framework Java Lang Reflect Plugin High
Product central artifactid reflext.jlr Highest
Product file name reflext.jlr High
Product jar package name jlr Low
Product pom groupid reflext Low
Product pom parent-artifactid reflext.parent Medium
Product pom description The Reflext Framework Java Lang Reflect Plugin Medium
Product pom artifactid reflext.jlr Highest
Product pom parent-groupid org.reflext Low
Version pom version 1.1.0 Highest
Version central version 1.1.0 Highest
Version file version 1.1.0 Highest
chromattic.core-1.3.0.jar
Description: Chromattic Framework Core
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.core/1.3.0/chromattic.core-1.3.0.jar
MD5: 9ece56be0e1e1b3289bbe177e8e1b4ab
SHA1: 1bc4ebc89d7b47af394b920f44a0b51409343034
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Chromattic Framework Core Medium
Vendor pom artifactid chromattic.core Low
Vendor jar package name core Low
Vendor file name chromattic.core High
Vendor pom groupid org.chromattic Highest
Vendor pom parent-artifactid chromattic.parent Low
Vendor jar package name chromattic Low
Vendor pom name Chromattic Framework Core High
Vendor central groupid org.chromattic Highest
Vendor pom groupid chromattic Highest
Vendor pom parent-groupid org.chromattic Medium
Product pom description Chromattic Framework Core Medium
Product central artifactid chromattic.core Highest
Product jar package name core Low
Product pom artifactid chromattic.core Highest
Product file name chromattic.core High
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework Core High
Product pom groupid chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
chromattic.ext-1.3.0.jar
Description: Chromattic Framework Extensions
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.ext/1.3.0/chromattic.ext-1.3.0.jar
MD5: a8482bb9fe7572e77a58627251740ee1
SHA1: ea3bd25892c827d9b830aea768de69e200a93165
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name ext Low
Vendor pom groupid org.chromattic Highest
Vendor jar package name chromattic Low
Vendor pom groupid chromattic Highest
Vendor pom artifactid chromattic.ext Low
Vendor pom parent-artifactid chromattic.parent Low
Vendor file name chromattic.ext High
Vendor central groupid org.chromattic Highest
Vendor pom description Chromattic Framework Extensions Medium
Vendor pom name Chromattic Framework Extensions High
Vendor pom parent-groupid org.chromattic Medium
Vendor jar package name ntdef Low
Product pom artifactid chromattic.ext Highest
Product pom parent-groupid org.chromattic Low
Product jar package name ext Low
Product file name chromattic.ext High
Product pom description Chromattic Framework Extensions Medium
Product pom groupid chromattic Low
Product pom name Chromattic Framework Extensions High
Product pom parent-artifactid chromattic.parent Medium
Product central artifactid chromattic.ext Highest
Product jar package name ntdef Low
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
chromattic.metamodel-1.3.0.jar
Description: Chromattic Framework Metamodel
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.metamodel/1.3.0/chromattic.metamodel-1.3.0.jar
MD5: 0d534975c688ebabbc232601c6bc13da
SHA1: fbaa10037faf34a2d4d8eeb4e6b5ce28c95a9455
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name chromattic.metamodel High
Vendor pom artifactid chromattic.metamodel Low
Vendor pom groupid org.chromattic Highest
Vendor pom parent-artifactid chromattic.parent Low
Vendor pom description Chromattic Framework Metamodel Medium
Vendor jar package name chromattic Low
Vendor jar package name metamodel Low
Vendor central groupid org.chromattic Highest
Vendor pom groupid chromattic Highest
Vendor pom parent-groupid org.chromattic Medium
Vendor pom name Chromattic Framework Metamodel High
Product file name chromattic.metamodel High
Product pom parent-groupid org.chromattic Low
Product pom description Chromattic Framework Metamodel Medium
Product jar package name metamodel Low
Product central artifactid chromattic.metamodel Highest
Product pom artifactid chromattic.metamodel Highest
Product pom groupid chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Product pom name Chromattic Framework Metamodel High
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
chromattic.spi-1.3.0.jar
Description: Chromattic Framework SPI
File Path: /home/ciagent/.m2/repository/org/chromattic/chromattic.spi/1.3.0/chromattic.spi-1.3.0.jar
MD5: e440e3f5a8e5ad38720975546ab7f06d
SHA1: 64c36f826b832acab48fea793b7c70b019a46181
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Chromattic Framework SPI High
Vendor pom groupid org.chromattic Highest
Vendor jar package name chromattic Low
Vendor pom description Chromattic Framework SPI Medium
Vendor pom groupid chromattic Highest
Vendor jar package name type Low
Vendor file name chromattic.spi High
Vendor pom parent-artifactid chromattic.parent Low
Vendor jar package name spi Low
Vendor central groupid org.chromattic Highest
Vendor pom artifactid chromattic.spi Low
Vendor pom parent-groupid org.chromattic Medium
Product pom artifactid chromattic.spi Highest
Product jar package name type Low
Product pom parent-groupid org.chromattic Low
Product pom name Chromattic Framework SPI High
Product file name chromattic.spi High
Product jar package name spi Low
Product central artifactid chromattic.spi Highest
Product pom groupid chromattic Low
Product pom parent-artifactid chromattic.parent Medium
Product pom description Chromattic Framework SPI Medium
Version file version 1.3.0 Highest
Version central version 1.3.0 Highest
Version pom version 1.3.0 Highest
exo.jcr.component.webdav-5.3.x-SNAPSHOT.jar
Description: Implementation of Webdav Service of Exoplatform SAS 'eXo JCR' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/jcr/exo.jcr.component.webdav/5.3.x-SNAPSHOT/exo.jcr.component.webdav-5.3.x-SNAPSHOT.jar
MD5: 8aecb716c94f1eba325d18df977af0e6
SHA1: d57042632271dc768d64aa23fd4cb5fa9fe2d598
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor-Id org.exoplatform.jcr Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.jcr Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid jcr-parent Low
Vendor pom artifactid exo.jcr.component.webdav Low
Vendor pom name eXo PLF:: JCR :: Component :: Webdav Service High
Vendor pom description Implementation of Webdav Service of Exoplatform SAS 'eXo JCR' project. Medium
Vendor pom groupid exoplatform.jcr Highest
Vendor file name exo.jcr.component.webdav High
Product Manifest specification-title exo-jcr Medium
Product pom groupid exoplatform.jcr Low
Product pom parent-groupid org.exoplatform.jcr Low
Product pom parent-artifactid jcr-parent Medium
Product pom name eXo PLF:: JCR :: Component :: Webdav Service High
Product pom description Implementation of Webdav Service of Exoplatform SAS 'eXo JCR' project. Medium
Product pom artifactid exo.jcr.component.webdav Highest
Product Manifest Implementation-Title eXo PLF:: JCR :: Component :: Webdav Service High
Product file name exo.jcr.component.webdav High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.jcr:exo.jcr.component.webdav:5.3.x-SNAPSHOT
Confidence :High
commons-digester-2.1.jar
Description:
The Digester package lets you configure an XML to Java object mapping module
which triggers certain actions called rules whenever a particular
pattern of nested XML elements is recognized.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-digester/commons-digester/2.1/commons-digester-2.1.jar
MD5: 528445033f22da28f5047b6abcd1c7c9
SHA1: 73a8001e7a54a255eef0f03521ec1805dc738ca0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid commons-digester Low
Vendor pom groupid commons-digester Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom url http://commons.apache.org/digester/ Highest
Vendor Manifest bundle-docurl http://commons.apache.org/digester/ Low
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor manifest Bundle-Description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Vendor central groupid commons-digester Highest
Vendor file name commons-digester High
Vendor pom name Commons Digester High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Vendor Manifest bundle-symbolicname org.apache.commons.digester Medium
Product pom parent-artifactid commons-parent Medium
Product Manifest bundle-docurl http://commons.apache.org/digester/ Low
Product manifest Bundle-Description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Product file name commons-digester High
Product Manifest Bundle-Name Commons Digester Medium
Product central artifactid commons-digester Highest
Product pom artifactid commons-digester Highest
Product pom name Commons Digester High
Product pom groupid commons-digester Low
Product pom parent-groupid org.apache.commons Low
Product pom description The Digester package lets you configure an XML to Java object mapping module which triggers certain actions called rules whenever a particular pattern of nested XML elements is recognized. Low
Product Manifest specification-title Commons Digester Medium
Product pom url http://commons.apache.org/digester/ Medium
Product Manifest bundle-symbolicname org.apache.commons.digester Medium
Product Manifest Implementation-Title Commons Digester High
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version Manifest Implementation-Version 2.1 High
Version central version 2.1 Highest
exo.kernel.component.command-5.3.x-SNAPSHOT.jar
Description: Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.command/5.3.x-SNAPSHOT/exo.kernel.component.command-5.3.x-SNAPSHOT.jar
MD5: c8e34b4521db08641687547b1fbc1ce5
SHA1: 1527c8dccb38e62fb298b68bda8263e9005bc6c1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor file name exo.kernel.component.command High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.kernel Highest
Vendor pom parent-artifactid kernel-parent Low
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom description Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project. Medium
Vendor pom name eXo PLF:: Kernel :: Component :: Command Service High
Vendor pom artifactid exo.kernel.component.command Low
Product Manifest specification-title exo-kernel Medium
Product pom artifactid exo.kernel.component.command Highest
Product file name exo.kernel.component.command High
Product Manifest Implementation-Title eXo PLF:: Kernel :: Component :: Command Service High
Product pom parent-artifactid kernel-parent Medium
Product pom parent-groupid org.exoplatform.kernel Low
Product pom description Implementation of Command Service of Exoplatform SAS 'eXo Kernel' project. Medium
Product pom groupid exoplatform.kernel Low
Product pom name eXo PLF:: Kernel :: Component :: Command Service High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.command:5.3.x-SNAPSHOT
Confidence :High
exo.ws.rest.core-5.3.x-SNAPSHOT.jar
Description: Implementation of REST Core for Exoplatform SAS 'Web Services' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.core/5.3.x-SNAPSHOT/exo.ws.rest.core-5.3.x-SNAPSHOT.jar
MD5: 44bf545ee3d289362f22532c0760547b
SHA1: 03ac20ae6703e58212d45e4e153056957e97d413
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.ws Highest
Vendor pom parent-artifactid ws-parent Low
Vendor pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Vendor pom groupid org.exoplatform.ws Highest
Vendor file name exo.ws.rest.core High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom artifactid exo.ws.rest.core Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.ws Medium
Vendor pom name eXo PLF:: WS :: REST :: Core High
Vendor pom parent-groupid org.exoplatform.ws Medium
Product pom description Implementation of REST Core for Exoplatform SAS 'Web Services' project. Medium
Product Manifest Implementation-Title eXo PLF:: WS :: REST :: Core High
Product pom groupid exoplatform.ws Low
Product file name exo.ws.rest.core High
Product pom parent-artifactid ws-parent Medium
Product Manifest specification-title exo-ws Medium
Product pom parent-groupid org.exoplatform.ws Low
Product pom artifactid exo.ws.rest.core Highest
Product pom name eXo PLF:: WS :: REST :: Core High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
Related Dependencies
exo.ws.rest.ext-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.rest.ext/5.3.x-SNAPSHOT/exo.ws.rest.ext-5.3.x-SNAPSHOT.jar
SHA1: 88042104a09fa910f5bb1adb127d1920006a2c70
MD5: a6475d4ab27f39f470a8f262c7d59c56
exo.ws.frameworks.json-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.frameworks.json/5.3.x-SNAPSHOT/exo.ws.frameworks.json-5.3.x-SNAPSHOT.jar
SHA1: df209c8abb20a199ff8f2565e38bba1377c83823
MD5: c303411215db30445ba0f14bef9d6e66
exo.ws.commons-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/ws/exo.ws.commons/5.3.x-SNAPSHOT/exo.ws.commons-5.3.x-SNAPSHOT.jar
SHA1: e3f538d0cc5bcf6360c9e00a0a4a4faabaf4ec6f
MD5: 916508b41039c72e9c729da2a0093689
maven: org.exoplatform.ws:exo.ws.rest.core:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:ws_project:ws:5.3
Confidence :Low
suppress
jboss-logging-annotations-1.2.0.Beta1.jar
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging-annotations/1.2.0.Beta1/jboss-logging-annotations-1.2.0.Beta1.jar
MD5: 938e552e319015a8863dd91284aada54
SHA1: 2f437f37bb265d9f8f1392823dbca12d2bec06d6
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid jboss-logging-tools-parent Low
Vendor central groupid org.jboss.logging Highest
Vendor pom groupid org.jboss.logging Highest
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom artifactid jboss-logging-annotations Low
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor pom groupid jboss.logging Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Vendor pom name JBoss Logging I18n Annotations High
Vendor Manifest os-name Linux Medium
Vendor Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor file name jboss-logging-annotations High
Vendor pom parent-groupid org.jboss.logging Medium
Product pom parent-artifactid jboss-logging-tools-parent Medium
Product Manifest Implementation-Title JBoss Logging I18n Annotations High
Product Manifest specification-title JBoss Logging I18n Annotations Medium
Product pom groupid jboss.logging Low
Product Manifest implementation-url http://www.jboss.org/jboss-logging-tools-parent/jboss-logging-annotations Low
Product pom name JBoss Logging I18n Annotations High
Product Manifest os-name Linux Medium
Product pom artifactid jboss-logging-annotations Highest
Product Manifest build-timestamp Tue, 18 Jun 2013 18:41:43 -0500 Low
Product pom parent-groupid org.jboss.logging Low
Product file name jboss-logging-annotations High
Product central artifactid jboss-logging-annotations Highest
Version central version 1.2.0.Beta1 Highest
Version Manifest Implementation-Version 1.2.0.Beta1 High
Version pom version 1.2.0.Beta1 Highest
hibernate-commons-annotations-4.0.5.Final.jar
Description: Common reflection code used in support of annotation processing
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/common/hibernate-commons-annotations/4.0.5.Final/hibernate-commons-annotations-4.0.5.Final.jar
MD5: 5dadbafd7c7bc1168c10a2ba87e927a2
SHA1: 2a581b9edb8168e45060d8bad8b7f46712d2c52c
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Hibernate Commons Annotations High
Vendor pom url http://hibernate.org Highest
Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor central groupid org.hibernate.common Highest
Vendor pom groupid hibernate.common Highest
Vendor pom groupid org.hibernate.common Highest
Vendor file name hibernate-commons-annotations High
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom organization name Hibernate.org High
Vendor pom description Common reflection code used in support of annotation processing Medium
Vendor pom artifactid hibernate-commons-annotations Low
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Product pom name Hibernate Commons Annotations High
Product pom groupid hibernate.common Low
Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium
Product pom artifactid hibernate-commons-annotations Highest
Product central artifactid hibernate-commons-annotations Highest
Product Manifest Bundle-Name hibernate-commons-annotations Medium
Product file name hibernate-commons-annotations High
Product Manifest implementation-url http://hibernate.org Low
Product pom organization url http://hibernate.org Low
Product pom organization name Hibernate.org Low
Product pom description Common reflection code used in support of annotation processing Medium
Product pom url http://hibernate.org Medium
Version Manifest Implementation-Version 4.0.5.Final High
Version central version 4.0.5.Final Highest
Version pom version 4.0.5.Final Highest
Version file version 4.0.5 Highest
log4j-1.2.17.jar
Description: Apache Log4j 1.2
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/log4j/log4j/1.2.17/log4j-1.2.17.jar
MD5: 04a41f0a068986f0f73485cf507c0f40
SHA1: 5af35056b4d257e4b64b9e8069c0746e8b08629f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Apache Log4j 1.2 Medium
Vendor Manifest bundle-symbolicname log4j Medium
Vendor file name log4j High
Vendor manifest Bundle-Description Apache Log4j 1.2 Medium
Vendor pom groupid log4j Highest
Vendor pom organization name Apache Software Foundation High
Vendor Manifest bundle-docurl http://logging.apache.org/log4j/1.2 Low
Vendor pom url http://logging.apache.org/log4j/1.2/ Highest
Vendor pom name Apache Log4j High
Vendor pom artifactid log4j Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor pom organization url http://www.apache.org Medium
Vendor manifest: org.apache.log4j Implementation-Vendor "Apache Software Foundation" Medium
Vendor central groupid log4j High
Product pom groupid log4j Low
Product pom organization url http://www.apache.org Low
Product central artifactid log4j High
Product pom description Apache Log4j 1.2 Medium
Product pom artifactid log4j Highest
Product manifest: org.apache.log4j Implementation-Title log4j Medium
Product pom organization name Apache Software Foundation Low
Product Manifest bundle-symbolicname log4j Medium
Product central artifactid log4j-1.2.17 High
Product file name log4j High
Product manifest Bundle-Description Apache Log4j 1.2 Medium
Product Manifest bundle-docurl http://logging.apache.org/log4j/1.2 Low
Product pom name Apache Log4j High
Product pom url http://logging.apache.org/log4j/1.2/ Medium
Product Manifest Bundle-Name Apache Log4j Medium
Version file name log4j Medium
Version pom version 1.2.17 Highest
Version manifest: org.apache.log4j Implementation-Version 1.2.17 Medium
Version file version 1.2.17 Highest
Version central version 1.2.17 High
Version Manifest Bundle-Version 1.2.17 High
Version central version 2.0 High
Published Vulnerabilities
CVE-2017-5645 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
Vulnerable Software & Versions: (show all )
stax-api-1.0-2.jar
Description:
StAX is a standard XML processing API that allows you to stream XML data from and to your application.
License:
GNU General Public Library: http://www.gnu.org/licenses/gpl.txt
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: http://www.sun.com/cddl/cddl.html
File Path: /home/ciagent/.m2/repository/javax/xml/stream/stax-api/1.0-2/stax-api-1.0-2.jar
MD5: 7d18b63063580284c3f5734081fdc99f
SHA1: d6337b0de8b25e53e81b922352fbea9f9f57ba0b
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid javax.xml.stream Highest
Vendor pom artifactid stax-api Low
Vendor file name stax-api High
Vendor pom description StAX is a standard XML processing API that allows you to stream XML data from and to your application. Low
Vendor jar package name javax Low
Vendor pom name Streaming API for XML High
Vendor jar package name stream Low
Vendor jar package name xml Low
Vendor central groupid javax.xml.stream Highest
Product pom artifactid stax-api Highest
Product central artifactid stax-api Highest
Product file name stax-api High
Product pom groupid javax.xml.stream Low
Product pom description StAX is a standard XML processing API that allows you to stream XML data from and to your application. Low
Product pom name Streaming API for XML High
Product jar package name stream Low
Product jar package name xml Low
Version central version 1.0-2 Highest
Version pom version 1.0-2 Highest
Version file version 1.0.2 Highest
jaxb-api-2.1.jar
File Path: /home/ciagent/.m2/repository/javax/xml/bind/jaxb-api/2.1/jaxb-api-2.1.jar
MD5: 9534ce6506dc96bac3944423d804be30
SHA1: d68570e722cffe2000358ce9c661a0b0bf1ebe11
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid javax.xml.bind Highest
Vendor file name jaxb-api High
Vendor Manifest extension-name javax.xml.bind Medium
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid jaxb-api Low
Vendor pom groupid javax.xml.bind Highest
Product Manifest specification-title Java Architecture for XML Binding Medium
Product pom groupid javax.xml.bind Low
Product file name jaxb-api High
Product Manifest extension-name javax.xml.bind Medium
Product central artifactid jaxb-api Highest
Product pom artifactid jaxb-api Highest
Version pom version 2.1 Highest
Version file version 2.1 Highest
Version central version 2.1 Highest
jaxb-impl-2.1.8.jar
File Path: /home/ciagent/.m2/repository/com/sun/xml/bind/jaxb-impl/2.1.8/jaxb-impl-2.1.8.jar
MD5: 1340264c75ea00b3d4d83e1ba57b606a
SHA1: 41b915446cb6962f9b403d1a5da3817a95ee579e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id com.sun Medium
Vendor Manifest Implementation-Vendor Sun Microsystems, Inc. High
Vendor pom groupid sun.xml.bind Highest
Vendor pom groupid com.sun.xml.bind Highest
Vendor file name jaxb-impl High
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom artifactid jaxb-impl Low
Vendor central groupid com.sun.xml.bind Highest
Vendor Manifest extension-name com.sun.xml.bind Medium
Product pom artifactid jaxb-impl Highest
Product Manifest specification-title Java Architecture for XML Binding Medium
Product pom groupid sun.xml.bind Low
Product Manifest Implementation-Title JAXB Reference Implementation High
Product file name jaxb-impl High
Product central artifactid jaxb-impl Highest
Product Manifest extension-name com.sun.xml.bind Medium
Version file version 2.1.8 Highest
Version Manifest Implementation-Version 2.1.8 High
Version central version 2.1.8 Highest
Version pom version 2.1.8 Highest
picketlink-idm-core-1.4.6.Final.jar
Description: PicketLink IDM IMPL contains the implementation of the API and the Identity Model.
License:
lgpl: http://repository.jboss.com/licenses/lgpl.txt
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-core/1.4.6.Final/picketlink-idm-core-1.4.6.Final.jar
MD5: a5c21c2186c186bc296d9909bcb11616
SHA1: 30d4385012393e4c50a82f8b84153eb6ee301a7d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.picketlink.idm Medium
Vendor pom groupid org.picketlink.idm Highest
Vendor Manifest java-vendor Sun Microsystems Inc. Medium
Vendor pom groupid picketlink.idm Highest
Vendor pom artifactid picketlink-idm-core Low
Vendor Manifest implementation-url http://www.jboss.org/picketlink-idm-parent/picketlink-idm-core Low
Vendor Manifest specification-vendor JBoss Inc. Low
Vendor Manifest os-name Linux Medium
Vendor file name picketlink-idm-core High
Vendor pom parent-groupid org.picketlink.idm Medium
Vendor pom description PicketLink IDM IMPL contains the implementation of the API and the Identity Model. Medium
Vendor pom organization name JBoss Inc. High
Vendor pom name PicketLink IDM Implementation High
Vendor pom parent-artifactid picketlink-idm-parent Low
Vendor pom organization url http://www.jboss.org Medium
Vendor Manifest build-timestamp Fri, 27 Feb 2015 09:44:09 +0100 Low
Vendor Manifest Implementation-Vendor JBoss Inc. High
Vendor central groupid org.picketlink.idm Highest
Product Manifest specification-title PicketLink IDM Implementation Medium
Product pom organization url http://www.jboss.org Low
Product pom artifactid picketlink-idm-core Highest
Product pom groupid picketlink.idm Low
Product Manifest implementation-url http://www.jboss.org/picketlink-idm-parent/picketlink-idm-core Low
Product Manifest os-name Linux Medium
Product file name picketlink-idm-core High
Product pom description PicketLink IDM IMPL contains the implementation of the API and the Identity Model. Medium
Product Manifest Implementation-Title PicketLink IDM Implementation High
Product pom parent-groupid org.picketlink.idm Low
Product pom parent-artifactid picketlink-idm-parent Medium
Product pom name PicketLink IDM Implementation High
Product pom organization name JBoss Inc. Low
Product central artifactid picketlink-idm-core Highest
Product Manifest build-timestamp Fri, 27 Feb 2015 09:44:09 +0100 Low
Version file version 1.4.6 Highest
Version Manifest Implementation-Version 1.4.6.Final High
Version pom version 1.4.6.Final Highest
Version central version 1.4.6.Final Highest
Related Dependencies
picketlink-idm-api-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-api/1.4.6.Final/picketlink-idm-api-1.4.6.Final.jar
SHA1: 6af0f6f08add632a442a6a415907460f9e8a9913
MD5: b85343ae7bcc7162b42ed3aaac08322a
maven: org.picketlink.idm:picketlink-idm-api:1.4.6.Final ✓
picketlink-idm-ldap-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-ldap/1.4.6.Final/picketlink-idm-ldap-1.4.6.Final.jar
SHA1: b52fefb76b4f2d047422f4ff5caff9c7a18001f3
MD5: 7da4240664f237384cd33b35939ff153
maven: org.picketlink.idm:picketlink-idm-ldap:1.4.6.Final ✓
picketlink-idm-hibernate-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-hibernate/1.4.6.Final/picketlink-idm-hibernate-1.4.6.Final.jar
SHA1: 4cd6d4e7bc818d5d89e06d268302908903cd3447
MD5: 4e80873b893295bab629a5764c40b345
maven: org.picketlink.idm:picketlink-idm-hibernate:1.4.6.Final ✓
picketlink-idm-common-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-common/1.4.6.Final/picketlink-idm-common-1.4.6.Final.jar
SHA1: 37c1309fd376db4f4ff969fb0df4f8c388e2022c
MD5: 1ad4f8384e856abf4696895d7647dabf
maven: org.picketlink.idm:picketlink-idm-common:1.4.6.Final ✓
picketlink-idm-spi-1.4.6.Final.jar
File Path: /home/ciagent/.m2/repository/org/picketlink/idm/picketlink-idm-spi/1.4.6.Final/picketlink-idm-spi-1.4.6.Final.jar
SHA1: 0804a3a34b7d031cc8daab4f4a8cbac1c00e98dd
MD5: 7289815e139890cb98b0f5a80e7b7a59
maven: org.picketlink.idm:picketlink-idm-spi:1.4.6.Final ✓
Published Vulnerabilities
CVE-2015-0277 suppress
Severity:
Medium
CVSS Score: 6.0
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users' accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.
Vulnerable Software & Versions:
CVE-2015-3158 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.
Vulnerable Software & Versions:
CVE-2015-6254 suppress
Severity:
Medium
CVSS Score: 6.0
(AV:N/AC:M/Au:S/C:P/I:P/A:P)
CWE: CWE-17 Code
The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.
Vulnerable Software & Versions:
nekohtml-1.9.22.jar
Description: An HTML parser and tag balancer.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/net/sourceforge/nekohtml/nekohtml/1.9.22/nekohtml-1.9.22.jar
MD5: a97dfe2d0ceb81ffbdd15436961b0f23
SHA1: 4f54af68ecb345f2453fb6884672ad08414154e3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Neko HTML High
Vendor pom url http://nekohtml.sourceforge.net/ Highest
Vendor central groupid net.sourceforge.nekohtml Highest
Vendor pom description An HTML parser and tag balancer. Medium
Vendor file name nekohtml High
Vendor manifest: org/cyberneko/html/ Implementation-Vendor Andy Clark, Marc Guillemot Medium
Vendor pom groupid net.sourceforge.nekohtml Highest
Vendor pom artifactid nekohtml Low
Product manifest: org/cyberneko/html/ Implementation-Title CyberNeko HTML Parser Medium
Product pom name Neko HTML High
Product pom url http://nekohtml.sourceforge.net/ Medium
Product pom groupid net.sourceforge.nekohtml Low
Product pom artifactid nekohtml Highest
Product pom description An HTML parser and tag balancer. Medium
Product file name nekohtml High
Product central artifactid nekohtml Highest
Product manifest: org/cyberneko/html/ Specification-Title Hyper-Text Markup Language (HTML) Medium
Version central version 1.9.22 Highest
Version pom version 1.9.22 Highest
Version file version 1.9.22 Highest
social-component-service-5.3.x-SNAPSHOT.jar
Description: eXo Social Service Component
File Path: /home/ciagent/.m2/repository/org/exoplatform/social/social-component-service/5.3.x-SNAPSHOT/social-component-service-5.3.x-SNAPSHOT.jar
MD5: 5656117cbf0d7ba9a5f944e0920ae5b5
SHA1: 0a50203c211eb19e29aded4f6ad4c113403ac6a4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.social Medium
Vendor pom description eXo Social Service Component Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom artifactid social-component-service Low
Vendor Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-service Low
Vendor pom name eXo PLF:: Social Service Component High
Vendor pom groupid exoplatform.social Highest
Vendor pom groupid org.exoplatform.social Highest
Vendor Manifest date 2019-05-24T10:23:51Z Low
Vendor pom parent-artifactid social-component Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.social Medium
Vendor file name social-component-service High
Product pom artifactid social-component-service Highest
Product pom parent-groupid org.exoplatform.social Low
Product pom description eXo Social Service Component Medium
Product Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-service Low
Product pom groupid exoplatform.social Low
Product pom name eXo PLF:: Social Service Component High
Product Manifest Implementation-Title eXo PLF:: Social Service Component High
Product file name social-component-service High
Product Manifest specification-title eXo PLF:: Social Service Component Medium
Product pom parent-artifactid social-component Medium
Product Manifest date 2019-05-24T10:23:51Z Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.social:social-component-service:5.3.x-SNAPSHOT
Confidence :High
itext-2.1.7.jar
Description: iText, a free Java-PDF library
License:
Mozilla Public License: http://www.mozilla.org/MPL/MPL-1.1.html
File Path: /home/ciagent/.m2/repository/com/lowagie/itext/2.1.7/itext-2.1.7.jar
MD5: 7587a618197a065eac4a453d173d4ed6
SHA1: 892bfb3e97074a61123b3b2d7caa2db112750864
Referenced In Projects/Scopes:
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
Evidence
Type Source Name Value Confidence
Vendor pom description iText, a free Java-PDF library Medium
Vendor file name itext High
Vendor jar package name pdf Low
Vendor jar package name text Low
Vendor pom groupid lowagie Highest
Vendor pom groupid com.lowagie Highest
Vendor pom url http://www.lowagie.com/iText/ Highest
Vendor pom artifactid itext Low
Vendor jar package name lowagie Low
Vendor central groupid com.lowagie Highest
Vendor pom name iText, a Free Java-PDF library High
Product pom description iText, a free Java-PDF library Medium
Product pom groupid lowagie Low
Product file name itext High
Product jar package name pdf Low
Product jar package name text Low
Product pom url http://www.lowagie.com/iText/ Medium
Product central artifactid itext Highest
Product pom artifactid itext Highest
Product pom name iText, a Free Java-PDF library High
Version central version 2.1.7 Highest
Version file version 2.1.7 Highest
Version pom version 2.1.7 Highest
validation-api-1.1.0.Final.jar
Description:
Bean Validation API
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/javax/validation/validation-api/1.1.0.Final/validation-api-1.1.0.Final.jar
MD5: 4c257f52462860b62ab3cdab45f53082
SHA1: 8613ae82954779d518631e05daa73a6a954817d5
Referenced In Projects/Scopes:
eXo PLF:: Wiki Macros Iframe:compile
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid validation-api Low
Vendor Manifest bundle-symbolicname javax.validation.api Medium
Vendor pom name Bean Validation API High
Vendor central groupid javax.validation Highest
Vendor pom url http://beanvalidation.org Highest
Vendor pom description
Bean Validation API
Medium
Vendor pom groupid javax.validation Highest
Vendor file name validation-api High
Vendor manifest Bundle-Description Bean Validation API Medium
Product Manifest bundle-symbolicname javax.validation.api Medium
Product central artifactid validation-api Highest
Product pom name Bean Validation API High
Product pom url http://beanvalidation.org Medium
Product pom artifactid validation-api Highest
Product pom groupid javax.validation Low
Product Manifest Bundle-Name Bean Validation API Medium
Product pom description
Bean Validation API
Medium
Product file name validation-api High
Product manifest Bundle-Description Bean Validation API Medium
Version pom version 1.1.0.Final Highest
Version file version 1.1.0 Highest
Version central version 1.1.0.Final Highest
sac-1.3.jar
Description: SAC is a standard interface for CSS parsers.
License:
The W3C Software License: http://www.w3.org/Consortium/Legal/copyright-software-19980720
File Path: /home/ciagent/.m2/repository/org/w3c/css/sac/1.3/sac-1.3.jar
MD5: eb04fa63fc70c722f2b8ec156166343b
SHA1: cdb2dcb4e22b83d6b32b93095f644c3462739e82
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name sac High
Vendor pom organization name World Wide Web Consortium High
Vendor pom url http://www.w3.org/Style/CSS/SAC/ Highest
Vendor pom name Simple API for CSS High
Vendor jar package name w3c Low
Vendor pom description SAC is a standard interface for CSS parsers. Medium
Vendor jar package name css Low
Vendor jar package name sac Low
Vendor pom artifactid sac Low
Vendor pom groupid org.w3c.css Highest
Vendor pom groupid w3c.css Highest
Vendor pom organization url http://www.w3.org/ Medium
Vendor central groupid org.w3c.css Highest
Product pom organization url http://www.w3.org/ Low
Product central artifactid sac Highest
Product file name sac High
Product pom name Simple API for CSS High
Product pom url http://www.w3.org/Style/CSS/SAC/ Medium
Product pom organization name World Wide Web Consortium Low
Product pom description SAC is a standard interface for CSS parsers. Medium
Product pom groupid w3c.css Low
Product jar package name css Low
Product jar package name sac Low
Product pom artifactid sac Highest
Version pom version 1.3 Highest
Version central version 1.3 Highest
Version file version 1.3 Highest
cssparser-0.9.18.jar
Description: A CSS parser which implements SAC (the Simple API for CSS).
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl.txt
File Path: /home/ciagent/.m2/repository/net/sourceforge/cssparser/cssparser/0.9.18/cssparser-0.9.18.jar
MD5: dc57713d4c7a54a569fc67529ce3b525
SHA1: 61c015378d27b5e245a5deb7a324c7e716b4706a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id net.sourceforge.cssparser Medium
Vendor pom groupid net.sourceforge.cssparser Highest
Vendor central groupid net.sourceforge.cssparser Highest
Vendor pom artifactid cssparser Low
Vendor pom url http://cssparser.sourceforge.net/ Highest
Vendor Manifest build-time 2015-10-27 19:57 Low
Vendor file name cssparser High
Vendor pom name CSS Parser High
Vendor Manifest url http://cssparser.sourceforge.net/ Low
Vendor pom description A CSS parser which implements SAC (the Simple API for CSS). Medium
Vendor Manifest implementation-url http://cssparser.sourceforge.net/ Low
Product pom url http://cssparser.sourceforge.net/ Medium
Product central artifactid cssparser Highest
Product Manifest Implementation-Title CSS Parser High
Product Manifest build-time 2015-10-27 19:57 Low
Product pom name CSS Parser High
Product pom groupid net.sourceforge.cssparser Low
Product file name cssparser High
Product Manifest specification-title CSS Parser Medium
Product Manifest url http://cssparser.sourceforge.net/ Low
Product pom description A CSS parser which implements SAC (the Simple API for CSS). Medium
Product Manifest implementation-url http://cssparser.sourceforge.net/ Low
Product pom artifactid cssparser Highest
Version central version 0.9.18 Highest
Version file version 0.9.18 Highest
Version Manifest Implementation-Version 0.9.18 High
Version pom version 0.9.18 Highest
mchange-commons-java-0.2.3.4.jar
Description: a library of arguably useful Java utilities.
License:
GNU Lesser General Public License, Version 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Eclipse Public License, Version 1.0: http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/com/mchange/mchange-commons-java/0.2.3.4/mchange-commons-java-0.2.3.4.jar
MD5: cc99f685b11309071e1e94fd758c372b
SHA1: 5eb5a801d96f65912bcf418a831fa23c663b029b
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom name mchange-commons-java library High
Vendor jar package name mchange Low
Vendor pom groupid mchange Highest
Vendor pom description a library of arguably useful Java utilities. Medium
Vendor pom groupid com.mchange Highest
Vendor file name mchange-commons-java High
Vendor pom url swaldman/mchange-commons-java Highest
Vendor central groupid com.mchange Highest
Vendor pom artifactid mchange-commons-java Low
Product pom artifactid mchange-commons-java Highest
Product pom name mchange-commons-java library High
Product pom description a library of arguably useful Java utilities. Medium
Product pom groupid mchange Low
Product file name mchange-commons-java High
Product central artifactid mchange-commons-java Highest
Product pom url swaldman/mchange-commons-java High
Version central version 0.2.3.4 Highest
Version file version 0.2.3.4 Highest
Version pom version 0.2.3.4 Highest
c3p0-0.9.2.1.jar
Description: a JDBC Connection pooling / Statement caching library
License:
GNU Lesser General Public License, Version 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Eclipse Public License, Version 1.0: http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/com/mchange/c3p0/0.9.2.1/c3p0-0.9.2.1.jar
MD5: 35085ff8cfaf6576d118ad4492236ae6
SHA1: 11b29ccb286d34eb804b7f6a3786809c9bd2e1b7
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name c3p0 High
Vendor pom name c3p0 High
Vendor Manifest extension-name com.mchange.v2.c3p0 Medium
Vendor pom groupid com.mchange Highest
Vendor Manifest Implementation-Vendor Machinery For Change, Inc. High
Vendor pom artifactid c3p0 Low
Vendor pom url swaldman/c3p0 Highest
Vendor pom groupid mchange Highest
Vendor Manifest Implementation-Vendor-Id com.mchange Medium
Vendor pom description a JDBC Connection pooling / Statement caching library Medium
Vendor central groupid com.mchange Highest
Vendor Manifest specification-vendor Machinery For Change, Inc. Low
Product pom url swaldman/c3p0 High
Product central artifactid c3p0 Highest
Product file name c3p0 High
Product pom name c3p0 High
Product pom description a JDBC Connection pooling / Statement caching library Medium
Product pom groupid mchange Low
Product pom artifactid c3p0 Highest
Product Manifest extension-name com.mchange.v2.c3p0 Medium
Version central version 0.9.2.1 Highest
Version pom version 0.9.2.1 Highest
Version file version 0.9.2.1 Highest
Version Manifest Implementation-Version 0.9.2.1 High
Published Vulnerabilities
CVE-2019-5427 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Vulnerable Software & Versions: (show all )
hibernate-c3p0-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-c3p0/4.2.21.Final/hibernate-c3p0-4.2.21.Final.jar
MD5: a020364e0f8e4997c889977e491d0084
SHA1: 838aaf84a93af3930c1e30d314a242f34aeee57a
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name hibernate-c3p0 High
Vendor manifest Bundle-Description Hibernate ORM C3P0 Medium
Vendor pom url http://hibernate.org Highest
Vendor pom groupid hibernate Highest
Vendor Manifest bundle-symbolicname org.hibernate.c3p0 Medium
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom artifactid hibernate-c3p0 Low
Vendor pom name A Hibernate O/RM Module High
Vendor pom groupid org.hibernate Highest
Vendor central groupid org.hibernate Highest
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom organization name Hibernate.org High
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor pom organization url http://hibernate.org Medium
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Product file name hibernate-c3p0 High
Product manifest Bundle-Description Hibernate ORM C3P0 Medium
Product Manifest Bundle-Name hibernate-c3p0 Medium
Product pom artifactid hibernate-c3p0 Highest
Product Manifest bundle-symbolicname org.hibernate.c3p0 Medium
Product pom name A Hibernate O/RM Module High
Product central artifactid hibernate-c3p0 Highest
Product Manifest implementation-url http://hibernate.org Low
Product pom organization url http://hibernate.org Low
Product pom description A module of the Hibernate O/RM project Medium
Product pom organization name Hibernate.org Low
Product pom groupid hibernate Low
Product pom url http://hibernate.org Medium
Version central version 4.2.21.Final Highest
Version file version 4.2.21 Highest
Version pom version 4.2.21.Final Highest
Version Manifest Implementation-Version 4.2.21.Final High
exo.core.component.organization.jdbc-5.3.x-SNAPSHOT.jar
Description: Implementation of JDBC Service of Exoplatform SAS 'eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.organization.jdbc/5.3.x-SNAPSHOT/exo.core.component.organization.jdbc-5.3.x-SNAPSHOT.jar
MD5: 2caf7cb0b21b88bd8ac3dfe114c4d93e
SHA1: 6347529dec556074b85276396924ff76862ae6b5
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name exo.core.component.organization.jdbc High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom name eXo PLF Core :: Component :: Organization Service JDBC High
Vendor pom description Implementation of JDBC Service of Exoplatform SAS 'eXo Core' project. Medium
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor pom artifactid exo.core.component.organization.jdbc Low
Product pom parent-groupid org.exoplatform.core Low
Product Manifest Implementation-Title eXo PLF Core :: Component :: Organization Service JDBC High
Product file name exo.core.component.organization.jdbc High
Product pom artifactid exo.core.component.organization.jdbc Highest
Product pom name eXo PLF Core :: Component :: Organization Service JDBC High
Product pom description Implementation of JDBC Service of Exoplatform SAS 'eXo Core' project. Medium
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product Manifest specification-title exo-core Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.organization.jdbc:5.3.x-SNAPSHOT
Confidence :High
jrcs.rcs-0.4.2.jar
File Path: /home/ciagent/.m2/repository/org/suigeneris/jrcs.rcs/0.4.2/jrcs.rcs-0.4.2.jar
MD5: 39a0ad326f371e1b1b0b1f35cf0f6efb
SHA1: 50fde3e7078afa87aea35a11be3ee01e7805a103
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor jar package name jrcs Low
Vendor central groupid org.jvnet.hudson Highest
Vendor pom groupid org.suigeneris Highest
Vendor jar package name suigeneris Low
Vendor file name jrcs.rcs High
Vendor jar package name rcs Low
Vendor pom artifactid jrcs.rcs Low
Vendor pom groupid suigeneris Highest
Product jar package name jrcs Low
Product central artifactid org.suigeneris.jrcs.rcs Highest
Product pom artifactid jrcs.rcs Highest
Product pom groupid suigeneris Low
Product file name jrcs.rcs High
Product jar package name rcs Low
Version central version 0.4.2 Highest
Version file version 0.4.2 Highest
Version pom version 0.4.2 Highest
flying-saucer-core-9.0.8.jar
Description: Flying Saucer is a CSS 2.1 renderer written in Java. This artifact contains the core rendering and layout code as well as Java2D output.
License:
GNU Lesser General Public License (LGPL), version 2.1 or later: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ciagent/.m2/repository/org/xhtmlrenderer/flying-saucer-core/9.0.8/flying-saucer-core-9.0.8.jar
MD5: f95e2ae188539bb7c4d675c8c435660e
SHA1: 9c5a8fcd423e4a86d9f460a240f43911a5824a40
Referenced In Projects/Scopes:
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.xhtmlrenderer Highest
Vendor pom description Flying Saucer is a CSS 2.1 renderer written in Java. This artifact contains the core rendering and layout code as well as Java2D output. Low
Vendor pom artifactid flying-saucer-core Low
Vendor pom parent-artifactid flying-saucer-parent Low
Vendor pom groupid xhtmlrenderer Highest
Vendor file name flying-saucer-core High
Vendor pom name Flying Saucer Core Renderer High
Vendor pom parent-groupid org.xhtmlrenderer Medium
Vendor jar package name xhtmlrenderer Low
Vendor central groupid org.xhtmlrenderer Highest
Product pom parent-artifactid flying-saucer-parent Medium
Product pom description Flying Saucer is a CSS 2.1 renderer written in Java. This artifact contains the core rendering and layout code as well as Java2D output. Low
Product pom artifactid flying-saucer-core Highest
Product file name flying-saucer-core High
Product pom parent-groupid org.xhtmlrenderer Low
Product pom name Flying Saucer Core Renderer High
Product pom groupid xhtmlrenderer Low
Product central artifactid flying-saucer-core Highest
Version pom version 9.0.8 Highest
Version file version 9.0.8 Highest
Version central version 9.0.8 Highest
xpp3-1.1.4c.jar
Description: MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs such as Hotspot in JDK 1.4+.
License:
Indiana University Extreme! Lab Software License, vesion 1.1.1: http://www.extreme.indiana.edu/viewcvs/~checkout~/XPP3/java/LICENSE.txt
Public Domain: http://creativecommons.org/licenses/publicdomain
Apache Software License, version 1.1: http://www.apache.org/licenses/LICENSE-1.1
File Path: /home/ciagent/.m2/repository/xpp3/xpp3/1.1.4c/xpp3-1.1.4c.jar
MD5: 6e3c39f391e4994888b7d0030f775804
SHA1: 9b988ea84b9e4e9f1874e390ce099b8ac12cfff5
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom organization name Extreme! Lab, Indiana University High
Vendor pom artifactid xpp3 Low
Vendor pom name MXP1: Xml Pull Parser 3rd Edition (XPP3) High
Vendor pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Highest
Vendor file name xpp3 High
Vendor jar package name v1 Low
Vendor pom groupid xpp3 Highest
Vendor jar package name xmlpull Low
Vendor central groupid xpp3 Highest
Vendor jar package name builder Low
Vendor pom description MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs ... Low
Vendor pom organization url http://www.extreme.indiana.edu/ Medium
Product pom artifactid xpp3 Highest
Product pom name MXP1: Xml Pull Parser 3rd Edition (XPP3) High
Product pom url http://www.extreme.indiana.edu/xgws/xsoap/xpp/mxp1/ Medium
Product file name xpp3 High
Product pom organization name Extreme! Lab, Indiana University Low
Product jar package name builder Low
Product pom groupid xpp3 Low
Product pom description MXP1 is a stable XmlPull parsing engine that is based on ideas from XPP and in particular XPP2 but completely revised and rewritten to take the best advantage of latest JIT JVMs ... Low
Product jar package name v1 Low
Product pom organization url http://www.extreme.indiana.edu/ Low
Product central artifactid xpp3 Highest
Version pom version 1.1.4c Highest
Version central version 1.1.4c Highest
Version file version 1.1.4c Highest
wiki-service-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/wiki/wiki-service/5.3.x-SNAPSHOT/wiki-service-5.3.x-SNAPSHOT.jar
MD5: b98a3ec99d6d30a051bd2479b784d270
SHA1: 8e2ca37e77852ebc0aeacadcd658f0560782960d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.wiki Highest
Vendor pom groupid org.exoplatform.wiki Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid wiki Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.wiki Medium
Vendor Manifest date 2019-05-24T10:40:54Z Low
Vendor pom artifactid wiki-service Low
Vendor Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-service Low
Vendor file name wiki-service High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom name eXo PLF:: Wiki Service High
Vendor pom parent-groupid org.exoplatform.wiki Medium
Product Manifest Implementation-Title eXo PLF:: Wiki Service High
Product file name wiki-service High
Product pom artifactid wiki-service Highest
Product pom parent-groupid org.exoplatform.wiki Low
Product pom name eXo PLF:: Wiki Service High
Product Manifest specification-title eXo PLF:: Wiki Service Medium
Product pom groupid exoplatform.wiki Low
Product Manifest date 2019-05-24T10:40:54Z Low
Product Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-service Low
Product pom parent-artifactid wiki Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.wiki:wiki-service:5.3.x-SNAPSHOT
Confidence :High
common-common-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-common/2.2.2.Final/common-common-2.2.2.Final.jar
MD5: 8ce16b5e3991285cd27e553740d09d1f
SHA1: 44522d899e31a5a10dbd70f7b0ca2fe5a614f740
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name common-common High
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom parent-artifactid common-parent Low
Vendor Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Vendor central groupid org.gatein.common Highest
Vendor pom parent-groupid org.gatein.common Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom name GateIn - Common component (common) High
Vendor Manifest os-name Linux Medium
Vendor pom groupid org.gatein.common Highest
Vendor pom groupid gatein.common Highest
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Vendor pom artifactid common-common Low
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product file name common-common High
Product Manifest Implementation-Title GateIn - Common component (common) High
Product Manifest implementation-url www.gatein.org/common-parent/common-common/ Low
Product pom name GateIn - Common component (common) High
Product pom parent-artifactid common-parent Medium
Product central artifactid common-common Highest
Product Manifest os-name Linux Medium
Product pom parent-groupid org.gatein.common Low
Product pom artifactid common-common Highest
Product Manifest specification-title GateIn - Common component (common) Medium
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product pom groupid gatein.common Low
Version Manifest Implementation-Version 2.2.2.Final High
Version file version 2.2.2 Highest
Version pom version 2.2.2.Final Highest
Version central version 2.2.2.Final Highest
exo.kernel.component.ext.cache.impl.infinispan.v8-5.3.x-SNAPSHOT.jar
Description: Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/kernel/exo.kernel.component.ext.cache.impl.infinispan.v8/5.3.x-SNAPSHOT/exo.kernel.component.ext.cache.impl.infinispan.v8-5.3.x-SNAPSHOT.jar
MD5: 2bd82588a1d04ea435de3b334321abb1
SHA1: 1008ebec01e1a674843d64dee25fdd0daf31078e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.exoplatform.kernel Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.kernel Medium
Vendor pom description Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project. Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor file name exo.kernel.component.ext.cache.impl.infinispan.v8 High
Vendor pom groupid exoplatform.kernel Highest
Vendor pom name eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Vendor pom parent-artifactid kernel-parent Low
Vendor pom parent-groupid org.exoplatform.kernel Medium
Vendor pom artifactid exo.kernel.component.ext.cache.impl.infinispan.v8 Low
Product pom artifactid exo.kernel.component.ext.cache.impl.infinispan.v8 Highest
Product Manifest specification-title exo-kernel Medium
Product pom description Infinispan Implementation of Cache Service for Exoplatform SAS 'eXo Kernel' project. Medium
Product file name exo.kernel.component.ext.cache.impl.infinispan.v8 High
Product pom parent-artifactid kernel-parent Medium
Product pom name eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Product pom parent-groupid org.exoplatform.kernel Low
Product pom groupid exoplatform.kernel Low
Product Manifest Implementation-Title eXo PLF:: Kernel :: Cache Extension :: Infinispan Implementation High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.kernel:exo.kernel.component.ext.cache.impl.infinispan.v8:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:infinispan:infinispan:5.3.0
Confidence :Highest
suppress
Published Vulnerabilities
CVE-2016-0750 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain events. A malicious user could exploit this flaw by injecting a specially-crafted serialized object to attain remote code execution or conduct other attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-15089 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
It was found that the Hotrod client in Infinispan before 9.2.0.CR1 would unsafely read deserialized data on information from the cache. An authenticated attacker could inject a malicious object into the data cache and attain deserialization on the client, and possibly conduct further attacks.
Vulnerable Software & Versions: (show all )
CVE-2017-2638 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
CWE: CWE-287 Improper Authentication
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a known cache name.
Vulnerable Software & Versions: (show all )
exo.core.component.database-5.3.x-SNAPSHOT.jar
Description: Implementation of Database Service of Exoplatform SAS eXo Core' project.
File Path: /home/ciagent/.m2/repository/org/exoplatform/core/exo.core.component.database/5.3.x-SNAPSHOT/exo.core.component.database-5.3.x-SNAPSHOT.jar
MD5: 92c38f5d3a2df6c2b885ad7408b22678
SHA1: 5b5bff26d83127aa80f76883395a4db05c39a4ff
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid exo.core.component.database Low
Vendor pom name eXo PLF Core :: Component :: Database Service High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.core Highest
Vendor Manifest Implementation-Vendor-Id org.exoplatform.core Medium
Vendor pom groupid org.exoplatform.core Highest
Vendor pom parent-artifactid core-parent Low
Vendor pom parent-groupid org.exoplatform.core Medium
Vendor file name exo.core.component.database High
Vendor pom description Implementation of Database Service of Exoplatform SAS eXo Core' project. Medium
Product pom parent-groupid org.exoplatform.core Low
Product pom artifactid exo.core.component.database Highest
Product Manifest Implementation-Title eXo PLF Core :: Component :: Database Service High
Product pom name eXo PLF Core :: Component :: Database Service High
Product pom groupid exoplatform.core Low
Product pom parent-artifactid core-parent Medium
Product file name exo.core.component.database High
Product Manifest specification-title exo-core Medium
Product pom description Implementation of Database Service of Exoplatform SAS eXo Core' project. Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.core:exo.core.component.database:5.3.x-SNAPSHOT
Confidence :High
staxnav.core-0.9.8.jar
File Path: /home/ciagent/.m2/repository/org/staxnav/staxnav.core/0.9.8/staxnav.core-0.9.8.jar
MD5: 0f786e5be21df9fbe8753175564564c7
SHA1: 27bd12d4d74b0851e38de79f8299462d93ba3d7f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.staxnav Highest
Vendor pom parent-artifactid staxnav.parent Low
Vendor pom groupid staxnav Highest
Vendor pom artifactid staxnav.core Low
Vendor jar package name staxnav Low
Vendor file name staxnav.core High
Vendor pom parent-groupid org.staxnav Medium
Vendor pom name Staxnav - Core High
Vendor central groupid org.staxnav Highest
Product pom parent-artifactid staxnav.parent Medium
Product central artifactid staxnav.core Highest
Product pom parent-groupid org.staxnav Low
Product file name staxnav.core High
Product pom name Staxnav - Core High
Product pom artifactid staxnav.core Highest
Product pom groupid staxnav Low
Version central version 0.9.8 Highest
Version pom version 0.9.8 Highest
Version file version 0.9.8 Highest
pc-portlet-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/pc/pc-portlet/5.3.x-SNAPSHOT/pc-portlet-5.3.x-SNAPSHOT.jar
MD5: 471a9c4fc6eb53f16cd833eedcd1069f
SHA1: 4a9cf81176c3da5bc100a8f90a87a151a20c4123
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor GateIn High
Vendor pom name GateIn - Portlet Container (pc) High
Vendor pom artifactid pc-portlet Low
Vendor pom parent-groupid org.exoplatform.gatein.pc Medium
Vendor file name pc-portlet High
Vendor Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-portlet Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor pom groupid org.exoplatform.gatein.pc Highest
Vendor Manifest specification-vendor GateIn Low
Vendor pom groupid exoplatform.gatein.pc Highest
Vendor Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Vendor pom parent-artifactid pc-parent Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.pc Medium
Product pom name GateIn - Portlet Container (pc) High
Product Manifest specification-title GateIn - Portlet Container (pc) Medium
Product pom artifactid pc-portlet Highest
Product Manifest Implementation-Title GateIn - Portlet Container (pc) High
Product pom parent-artifactid pc-parent Medium
Product file name pc-portlet High
Product Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Product Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-portlet Low
Product pom groupid exoplatform.gatein.pc Low
Product Manifest os-name Linux Medium
Product pom parent-groupid org.exoplatform.gatein.pc Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.gatein.pc:pc-portlet:5.3.x-SNAPSHOT
Confidence :High
pc-federation-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/pc/pc-federation/5.3.x-SNAPSHOT/pc-federation-5.3.x-SNAPSHOT.jar
MD5: dd4ce55f7c860bb7d016dce9d657b75c
SHA1: 6740d145021ee194ff19685821bb77cf57ad1ec1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor GateIn High
Vendor pom name GateIn - Portlet Container (federation) High
Vendor pom artifactid pc-federation Low
Vendor pom parent-groupid org.exoplatform.gatein.pc Medium
Vendor file name pc-federation High
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-federation Low
Vendor pom groupid org.exoplatform.gatein.pc Highest
Vendor Manifest specification-vendor GateIn Low
Vendor pom groupid exoplatform.gatein.pc Highest
Vendor Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Vendor pom parent-artifactid pc-parent Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.pc Medium
Product pom name GateIn - Portlet Container (federation) High
Product pom artifactid pc-federation Highest
Product pom parent-artifactid pc-parent Medium
Product file name pc-federation High
Product Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Product Manifest Implementation-Title GateIn - Portlet Container (federation) High
Product pom groupid exoplatform.gatein.pc Low
Product Manifest specification-title GateIn - Portlet Container (federation) Medium
Product Manifest os-name Linux Medium
Product Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-federation Low
Product pom parent-groupid org.exoplatform.gatein.pc Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.gatein.pc:pc-federation:5.3.x-SNAPSHOT
Confidence :High
pc-bridge-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/pc/pc-bridge/5.3.x-SNAPSHOT/pc-bridge-5.3.x-SNAPSHOT.jar
MD5: a8031f45e408fb5a638da0e001313c6e
SHA1: 807ded891c83a604160e6eac68bbaf3d6c071da9
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor GateIn High
Vendor pom name GateIn - Portlet Container (bridge) High
Vendor pom artifactid pc-bridge Low
Vendor pom parent-groupid org.exoplatform.gatein.pc Medium
Vendor file name pc-bridge High
Vendor Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-bridge Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor pom groupid org.exoplatform.gatein.pc Highest
Vendor Manifest specification-vendor GateIn Low
Vendor pom groupid exoplatform.gatein.pc Highest
Vendor Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Vendor pom parent-artifactid pc-parent Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.pc Medium
Product pom artifactid pc-bridge Highest
Product Manifest specification-title GateIn - Portlet Container (bridge) Medium
Product pom name GateIn - Portlet Container (bridge) High
Product Manifest Implementation-Title GateIn - Portlet Container (bridge) High
Product pom parent-artifactid pc-parent Medium
Product file name pc-bridge High
Product Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Product Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-bridge Low
Product pom groupid exoplatform.gatein.pc Low
Product Manifest os-name Linux Medium
Product pom parent-groupid org.exoplatform.gatein.pc Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.gatein.pc:pc-bridge:5.3.x-SNAPSHOT
Confidence :High
common-logging-2.2.2.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/common/common-logging/2.2.2.Final/common-logging-2.2.2.Final.jar
MD5: 28b7108ee63899bca08636d360e7df11
SHA1: aee18008518671fb10982c0fe5f7383e98f71c47
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url www.gatein.org/common-parent/common-logging/ Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom parent-artifactid common-parent Low
Vendor central groupid org.gatein.common Highest
Vendor pom parent-groupid org.gatein.common Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor pom groupid org.gatein.common Highest
Vendor pom groupid gatein.common Highest
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.gatein.common Medium
Vendor pom artifactid common-logging Low
Vendor pom name GateIn - Common component (logging) High
Vendor Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Vendor file name common-logging High
Product Manifest implementation-url www.gatein.org/common-parent/common-logging/ Low
Product central artifactid common-logging Highest
Product Manifest specification-title GateIn - Common component (logging) Medium
Product pom parent-artifactid common-parent Medium
Product Manifest os-name Linux Medium
Product Manifest Implementation-Title GateIn - Common component (logging) High
Product pom parent-groupid org.gatein.common Low
Product pom name GateIn - Common component (logging) High
Product pom artifactid common-logging Highest
Product Manifest build-timestamp Mon, 17 Mar 2014 20:43:14 +0100 Low
Product pom groupid gatein.common Low
Product file name common-logging High
Version Manifest Implementation-Version 2.2.2.Final High
Version file version 2.2.2 Highest
Version pom version 2.2.2.Final Highest
Version central version 2.2.2.Final Highest
mop-api-1.3.2.Final.jar
Description: API of the Object Model for Portal
File Path: /home/ciagent/.m2/repository/org/gatein/mop/mop-api/1.3.2.Final/mop-api-1.3.2.Final.jar
MD5: 4f2c10678f3c5850bb85c25514469e2e
SHA1: 78f9c03a23ec1c3564e827d3927ce53eca6d919d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name MOP API High
Vendor pom parent-artifactid mop-parent Low
Vendor pom parent-groupid org.gatein.mop Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest build-timestamp Mon, 14 Apr 2014 17:58:13 +0200 Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor-Id org.gatein.mop Medium
Vendor file name mop-api High
Vendor pom groupid gatein.mop Highest
Vendor pom description API of the Object Model for Portal Medium
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest os-name Mac OS X Medium
Vendor Manifest implementation-url www.gatein.org/mop-parent/mop-api/ Low
Vendor pom groupid org.gatein.mop Highest
Vendor pom artifactid mop-api Low
Product pom groupid gatein.mop Low
Product pom parent-artifactid mop-parent Medium
Product pom name MOP API High
Product pom artifactid mop-api Highest
Product Manifest build-timestamp Mon, 14 Apr 2014 17:58:13 +0200 Low
Product Manifest specification-title MOP API Medium
Product file name mop-api High
Product pom description API of the Object Model for Portal Medium
Product Manifest Implementation-Title MOP API High
Product Manifest os-name Mac OS X Medium
Product Manifest implementation-url www.gatein.org/mop-parent/mop-api/ Low
Product pom parent-groupid org.gatein.mop Low
Version Manifest Implementation-Version 1.3.2.Final High
Version file version 1.3.2 Highest
Version pom version 1.3.2.Final Highest
maven: org.gatein.mop:mop-api:1.3.2.Final
Confidence :High
mop-spi-1.3.2.Final.jar
Description: SPI of the Object Model for Portal
File Path: /home/ciagent/.m2/repository/org/gatein/mop/mop-spi/1.3.2.Final/mop-spi-1.3.2.Final.jar
MD5: 6ef18d761e625d923ec01c6e5283026e
SHA1: 4fe3a673d58c85d2f6c9ad4446b90229f46c8987
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid mop-parent Low
Vendor pom parent-groupid org.gatein.mop Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom name MOP SPI High
Vendor Manifest build-timestamp Mon, 14 Apr 2014 17:58:13 +0200 Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor-Id org.gatein.mop Medium
Vendor Manifest implementation-url www.gatein.org/mop-parent/mop-spi/ Low
Vendor pom description SPI of the Object Model for Portal Medium
Vendor pom groupid gatein.mop Highest
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom artifactid mop-spi Low
Vendor file name mop-spi High
Vendor Manifest os-name Mac OS X Medium
Vendor pom groupid org.gatein.mop Highest
Product pom artifactid mop-spi Highest
Product pom groupid gatein.mop Low
Product pom parent-artifactid mop-parent Medium
Product pom name MOP SPI High
Product Manifest build-timestamp Mon, 14 Apr 2014 17:58:13 +0200 Low
Product Manifest specification-title MOP SPI Medium
Product Manifest Implementation-Title MOP SPI High
Product Manifest implementation-url www.gatein.org/mop-parent/mop-spi/ Low
Product pom description SPI of the Object Model for Portal Medium
Product file name mop-spi High
Product Manifest os-name Mac OS X Medium
Product pom parent-groupid org.gatein.mop Low
Version Manifest Implementation-Version 1.3.2.Final High
Version file version 1.3.2 Highest
Version pom version 1.3.2.Final Highest
maven: org.gatein.mop:mop-spi:1.3.2.Final
Confidence :High
mop-core-1.3.2.Final.jar
Description: Model Object for Portal Core
File Path: /home/ciagent/.m2/repository/org/gatein/mop/mop-core/1.3.2.Final/mop-core-1.3.2.Final.jar
MD5: 7d5eb7a5c2ed2d88362f9d8a9413a475
SHA1: d27e4c960aefd919f7c25049b72a9bc225cd6548
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid mop-parent Low
Vendor pom name MOP Core High
Vendor file name mop-core High
Vendor pom parent-groupid org.gatein.mop Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom artifactid mop-core Low
Vendor Manifest build-timestamp Mon, 14 Apr 2014 17:58:13 +0200 Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest Implementation-Vendor-Id org.gatein.mop Medium
Vendor pom groupid gatein.mop Highest
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest implementation-url www.gatein.org/mop-parent/mop-core/ Low
Vendor Manifest os-name Mac OS X Medium
Vendor pom description Model Object for Portal Core Medium
Vendor pom groupid org.gatein.mop Highest
Product pom groupid gatein.mop Low
Product pom parent-artifactid mop-parent Medium
Product pom name MOP Core High
Product file name mop-core High
Product Manifest build-timestamp Mon, 14 Apr 2014 17:58:13 +0200 Low
Product Manifest specification-title MOP Core Medium
Product Manifest implementation-url www.gatein.org/mop-parent/mop-core/ Low
Product Manifest os-name Mac OS X Medium
Product Manifest Implementation-Title MOP Core High
Product pom description Model Object for Portal Core Medium
Product pom artifactid mop-core Highest
Product pom parent-groupid org.gatein.mop Low
Version Manifest Implementation-Version 1.3.2.Final High
Version file version 1.3.2 Highest
Version pom version 1.3.2.Final Highest
maven: org.gatein.mop:mop-core:1.3.2.Final
Confidence :High
gatein-management-api-2.1.0.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/management/gatein-management-api/2.1.0.Final/gatein-management-api-2.1.0.Final.jar
MD5: dde253e45fefd580cab7a4ee75c6d92e
SHA1: 5c73b152fe9497eb37386052f86bfa7ee7d33b87
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url www.gatein.org/gatein-management-parent/gatein-management-api/ Low
Vendor pom parent-artifactid gatein-management-parent Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom parent-groupid org.gatein.management Medium
Vendor pom groupid org.gatein.management Highest
Vendor pom artifactid gatein-management-api Low
Vendor file name gatein-management-api High
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor Manifest build-timestamp Mon, 17 Mar 2014 21:15:40 +0100 Low
Vendor pom name GateIn Management - API High
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.gatein.management Medium
Vendor pom groupid gatein.management Highest
Product Manifest build-timestamp Mon, 17 Mar 2014 21:15:40 +0100 Low
Product Manifest specification-title GateIn Management - API Medium
Product pom parent-groupid org.gatein.management Low
Product pom name GateIn Management - API High
Product Manifest implementation-url www.gatein.org/gatein-management-parent/gatein-management-api/ Low
Product Manifest Implementation-Title GateIn Management - API High
Product pom groupid gatein.management Low
Product pom artifactid gatein-management-api Highest
Product file name gatein-management-api High
Product pom parent-artifactid gatein-management-parent Medium
Product Manifest os-name Linux Medium
Version Manifest Implementation-Version 2.1.0.Final High
Version pom version 2.1.0.Final Highest
Version file version 2.1.0 Highest
maven: org.gatein.management:gatein-management-api:2.1.0.Final
Confidence :High
gatein-management-spi-2.1.0.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/management/gatein-management-spi/2.1.0.Final/gatein-management-spi-2.1.0.Final.jar
MD5: 4e10565858662ec9eea75cfbd3544ba1
SHA1: 79670b2dd849b49e145b7122cbff4ef83116157f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid gatein-management-parent Low
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest implementation-url www.gatein.org/gatein-management-parent/gatein-management-spi/ Low
Vendor pom parent-groupid org.gatein.management Medium
Vendor pom groupid org.gatein.management Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest os-name Linux Medium
Vendor file name gatein-management-spi High
Vendor Manifest build-timestamp Mon, 17 Mar 2014 21:15:40 +0100 Low
Vendor pom name GateIn Management - SPI High
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor Manifest Implementation-Vendor-Id org.gatein.management Medium
Vendor pom artifactid gatein-management-spi Low
Vendor pom groupid gatein.management Highest
Product file name gatein-management-spi High
Product Manifest build-timestamp Mon, 17 Mar 2014 21:15:40 +0100 Low
Product pom parent-groupid org.gatein.management Low
Product Manifest Implementation-Title GateIn Management - SPI High
Product pom name GateIn Management - SPI High
Product Manifest implementation-url www.gatein.org/gatein-management-parent/gatein-management-spi/ Low
Product pom artifactid gatein-management-spi Highest
Product pom groupid gatein.management Low
Product Manifest specification-title GateIn Management - SPI Medium
Product pom parent-artifactid gatein-management-parent Medium
Product Manifest os-name Linux Medium
Version Manifest Implementation-Version 2.1.0.Final High
Version pom version 2.1.0.Final Highest
Version file version 2.1.0 Highest
maven: org.gatein.management:gatein-management-spi:2.1.0.Final
Confidence :High
json-20070829.jar
Description:
JSON (JavaScript Object Notation) is a lightweight data-interchange format.
It is easy for humans to read and write. It is easy for machines to parse and generate.
It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition
- December 1999. JSON is a text format that is completely language independent but uses
conventions that are familiar to programmers of the C-family of languages, including C, C++, C#,
Java, JavaScript, Perl, Python, and many others.
These properties make JSON an ideal data-interchange language.
File Path: /home/ciagent/.m2/repository/org/json/json/20070829/json-20070829.jar
MD5: 4a913140f9099519dfc0212fa5d9a457
SHA1: 89190ff77b57203c3417555f32226998da97ff38
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid json Low
Vendor pom organization url http://json.org/ Medium
Vendor pom url http://www.json.org/java/index.html Highest
Vendor jar package name json Low
Vendor file name json-20070829 High
Vendor pom groupid org.json Highest
Vendor pom organization name JSON High
Vendor pom name JSON (JavaScript Object Notation) High
Vendor pom groupid json Highest
Vendor pom description JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but... Low
Vendor central groupid org.json Highest
Product pom artifactid json Highest
Product pom url http://www.json.org/java/index.html Medium
Product file name json-20070829 High
Product pom groupid json Low
Product pom name JSON (JavaScript Object Notation) High
Product pom description JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but... Low
Product pom organization name JSON Low
Product pom organization url http://json.org/ Low
Product central artifactid json Highest
Version central version 20070829 Highest
Version file version 20070829 Medium
Version pom version 20070829 Highest
closure-compiler-externs-v20170910.jar
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler-externs/v20170910/closure-compiler-externs-v20170910.jar
MD5: 573e49fb83760d25b675028eb612e2b2
SHA1: 036e801a929fcd121d212093923daf34986f5572
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid com.google.javascript Medium
Vendor file name closure-compiler-externs-v20170910 High
Vendor pom artifactid closure-compiler-externs Low
Vendor pom groupid com.google.javascript Highest
Vendor pom groupid google.javascript Highest
Vendor pom name Closure Compiler Externs High
Vendor central groupid com.google.javascript Highest
Vendor pom parent-artifactid closure-compiler-parent Low
Product file name closure-compiler-externs-v20170910 High
Product pom parent-artifactid closure-compiler-parent Medium
Product pom parent-groupid com.google.javascript Low
Product central artifactid closure-compiler-externs Highest
Product pom groupid google.javascript Low
Product pom artifactid closure-compiler-externs Highest
Product pom name Closure Compiler Externs High
Version file name closure-compiler-externs-v20170910 Medium
Version pom version v20170910 Highest
Version central version v20170910 Highest
Version file version 20170910 Medium
args4j-2.33.jar
Description: args4j : Java command line arguments parser
License:
http://www.opensource.org/licenses/mit-license.php
File Path: /home/ciagent/.m2/repository/args4j/args4j/2.33/args4j-2.33.jar
MD5: 0a6d515f76b15d29e3cd529de9319739
SHA1: bd87a75374a6d6523de82fef51fc3cfe9baf9fc9
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description args4j : Java command line arguments parser Medium
Vendor central groupid args4j Highest
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Vendor pom parent-artifactid args4j-site Low
Vendor pom artifactid args4j Low
Vendor Manifest bundle-docurl http://www.kohsuke.org/ Low
Vendor Manifest bundle-symbolicname org.kohsuke.args4j Medium
Vendor pom groupid args4j Highest
Vendor file name args4j High
Vendor pom name args4j High
Product manifest Bundle-Description args4j : Java command line arguments parser Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.5))" Low
Product Manifest bundle-docurl http://www.kohsuke.org/ Low
Product Manifest bundle-symbolicname org.kohsuke.args4j Medium
Product central artifactid args4j Highest
Product file name args4j High
Product pom artifactid args4j Highest
Product pom name args4j High
Product pom parent-artifactid args4j-site Medium
Product Manifest Bundle-Name args4j Medium
Product pom groupid args4j Low
Version pom version 2.33 Highest
Version file version 2.33 Highest
Version central version 2.33 Highest
error_prone_annotations-2.0.18.jar
File Path: /home/ciagent/.m2/repository/com/google/errorprone/error_prone_annotations/2.0.18/error_prone_annotations-2.0.18.jar
MD5: 98051758c08c9b7111b3268655069432
SHA1: 5f65affce1684999e2f4024983835efc3504012e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor pom parent-groupid com.google.errorprone Medium
Vendor jar package name google Low
Vendor central groupid com.google.errorprone Highest
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid google.errorprone Highest
Vendor pom parent-artifactid error_prone_parent Low
Vendor jar package name annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor jar package name errorprone Low
Vendor pom name error-prone annotations High
Product file name error_prone_annotations High
Product pom groupid google.errorprone Low
Product pom artifactid error_prone_annotations Highest
Product central artifactid error_prone_annotations Highest
Product pom parent-artifactid error_prone_parent Medium
Product pom parent-groupid com.google.errorprone Low
Product jar package name annotations Low
Product jar package name errorprone Low
Product pom name error-prone annotations High
Version pom version 2.0.18 Highest
Version central version 2.0.18 Highest
Version file version 2.0.18 Highest
guava-20.0.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/google/guava/guava/20.0/guava-20.0.jar
MD5: f32a8a2524620dbecc9f6bf6a20c293f
SHA1: 89507701249388e1ed5ddcf8c41f4ce1be7831ef
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Guava: Google Core Libraries for Java High
Vendor file name guava High
Vendor manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom artifactid guava Low
Vendor pom groupid google.guava Highest
Vendor pom groupid com.google.guava Highest
Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Vendor pom parent-artifactid guava-parent Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom parent-groupid com.google.guava Medium
Vendor central groupid com.google.guava Highest
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Product pom name Guava: Google Core Libraries for Java High
Product pom artifactid guava Highest
Product file name guava High
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Product pom parent-artifactid guava-parent Medium
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product pom groupid google.guava Low
Product central artifactid guava Highest
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product pom parent-groupid com.google.guava Low
Version pom version 20.0 Highest
Version file version 20.0 Highest
Version central version 20.0 Highest
Published Vulnerabilities
CVE-2018-10237 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable.
Vulnerable Software & Versions: (show all )
gson-2.7.jar
Description: Gson JSON library
File Path: /home/ciagent/.m2/repository/com/google/code/gson/gson/2.7/gson-2.7.jar
MD5: 5134a2350f58890ffb9db0b40047195d
SHA1: 751f548c85fa49f330cecbb1875893f971b33c4e
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low
Vendor pom parent-groupid com.google.code.gson Medium
Vendor file name gson High
Vendor manifest Bundle-Description Gson JSON library Medium
Vendor Manifest bundle-symbolicname com.google.gson Medium
Vendor pom groupid google.code.gson Highest
Vendor pom artifactid gson Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom parent-artifactid gson-parent Low
Vendor pom groupid com.google.code.gson Highest
Vendor Manifest bundle-contactaddress https://github.com/google/gson Low
Vendor central groupid com.google.code.gson High
Vendor pom name Gson High
Vendor central groupid org.netbeans.external High
Product central artifactid com-google-gson High
Product pom artifactid gson Highest
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6, JavaSE-1.7, JavaSE-1.8 Low
Product central artifactid gson High
Product pom groupid google.code.gson Low
Product file name gson High
Product manifest Bundle-Description Gson JSON library Medium
Product Manifest bundle-symbolicname com.google.gson Medium
Product pom parent-groupid com.google.code.gson Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest bundle-contactaddress https://github.com/google/gson Low
Product pom parent-artifactid gson-parent Medium
Product pom name Gson High
Product Manifest Bundle-Name Gson Medium
Version pom version 2.7 Highest
Version central version RELEASE110 High
Version central version RELEASE100 High
Version central version 2.7 High
Version file version 2.7 Highest
jsinterop-annotations-1.0.0.jar
File Path: /home/ciagent/.m2/repository/com/google/jsinterop/jsinterop-annotations/1.0.0/jsinterop-annotations-1.0.0.jar
MD5: 93302e3d0cc146097ecd08039dc1de52
SHA1: 23c3a3c060ffe4817e67673cc8294e154b0a4a95
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.jsinterop Highest
Vendor pom artifactid jsinterop-annotations Low
Vendor file name jsinterop-annotations High
Vendor pom groupid google.jsinterop Highest
Vendor pom parent-groupid com.google.jsinterop Medium
Vendor jar package name jsinterop Low
Vendor pom parent-artifactid jsinterop Low
Vendor jar package name annotations Low
Vendor central groupid com.google.jsinterop Highest
Product central artifactid jsinterop-annotations Highest
Product file name jsinterop-annotations High
Product pom parent-groupid com.google.jsinterop Low
Product pom artifactid jsinterop-annotations Highest
Product pom parent-artifactid jsinterop Medium
Product jar package name annotations Low
Product pom groupid google.jsinterop Low
Version pom version 1.0.0 Highest
Version file version 1.0.0 Highest
Version central version 1.0.0 Highest
closure-compiler-v20170910.jar
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar
MD5: ca8e9f88ba9aad9c5e2c0f8f937fe869
SHA1: 3b87499e9ed3f068e69889182ab95cff92de0932
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name google Low
Vendor jar package name javascript Low
Vendor file name closure-compiler-v20170910 High
Vendor pom groupid com.google.javascript Highest
Vendor central groupid com.google.javascript Highest
Product pom artifactid closure-compiler Highest
Product jar package name javascript Low
Product file name closure-compiler-v20170910 High
Product central artifactid closure-compiler Highest
Version file name closure-compiler-v20170910 Medium
Version pom version v20170910 Highest
Version central version v20170910 Highest
Version file version 20170910 Medium
twitter4j-core-3.0.5.jar
Description: A Java library for the Twitter API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/org/twitter4j/twitter4j-core/3.0.5/twitter4j-core-3.0.5.jar
MD5: e6c8d2b10c621b2bbd7809bad9cedca3
SHA1: c38ad47bc8ba5991886ce2c0e0acd76d0fdd6e6d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.twitter4j Medium
Vendor pom description A Java library for the Twitter API Medium
Vendor file name twitter4j-core High
Vendor pom name twitter4j-core High
Vendor pom groupid twitter4j Highest
Vendor central groupid org.twitter4j Highest
Vendor pom groupid org.twitter4j Highest
Vendor pom artifactid twitter4j-core Low
Vendor pom url http://twitter4j.org/ Highest
Product pom groupid twitter4j Low
Product pom description A Java library for the Twitter API Medium
Product file name twitter4j-core High
Product central artifactid twitter4j-core Highest
Product pom name twitter4j-core High
Product pom artifactid twitter4j-core Highest
Product Manifest Implementation-Title twitter4j-core High
Product Manifest specification-title twitter4j-core Medium
Product pom url http://twitter4j.org/ Medium
Version Manifest Implementation-Version 3.0.5 High
Version pom version 3.0.5 Highest
Version file version 3.0.5 Highest
Version central version 3.0.5 Highest
cpe: cpe:/a:twitter_project:twitter:3.0.5
Confidence :Low
suppress
maven: org.twitter4j:twitter4j-core:3.0.5 ✓
Confidence :Highest
cpe: cpe:/a:twitter:twitter:3.0.5
Confidence :Low
suppress
scribe-1.3.5.jar
Description: The best OAuth library out there
License:
MIT: http://github.com/fernandezpablo85/scribe-java/blob/master/LICENSE.txt
File Path: /home/ciagent/.m2/repository/org/scribe/scribe/1.3.5/scribe-1.3.5.jar
MD5: 0abb910da19741cd84aabf5520385bc2
SHA1: a3b3deded9d241d9f2c8aa9c9bcd90ad29e2581e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name scribe Low
Vendor central groupid org.scribe Highest
Vendor pom artifactid scribe Low
Vendor pom groupid scribe Highest
Vendor jar package name builder Low
Vendor pom description The best OAuth library out there Medium
Vendor file name scribe High
Vendor pom groupid org.scribe Highest
Vendor pom url http://github.com/fernandezpablo85/scribe-java Highest
Vendor pom name Scribe OAuth Library High
Vendor jar package name api Low
Product pom url http://github.com/fernandezpablo85/scribe-java Medium
Product central artifactid scribe Highest
Product jar package name builder Low
Product pom description The best OAuth library out there Medium
Product file name scribe High
Product pom groupid scribe Low
Product pom artifactid scribe Highest
Product pom name Scribe OAuth Library High
Product jar package name api Low
Version central version 1.3.5 Highest
Version pom version 1.3.5 Highest
Version file version 1.3.5 Highest
google-http-client-1.14.1-beta.jar
Description:
Google HTTP Client Library for Java. Functionality that works on all supported Java platforms,
including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine.
File Path: /home/ciagent/.m2/repository/com/google/http-client/google-http-client/1.14.1-beta/google-http-client-1.14.1-beta.jar
MD5: 8a3711522ebceef2531d455e2f04a639
SHA1: cb503d4021739e6bac39442ac87b4e311ec77b5e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id com.google.http-client Medium
Vendor pom artifactid google-http-client Low
Vendor Manifest Implementation-Vendor Google High
Vendor pom groupid google.http-client Highest
Vendor central groupid com.google.http-client Highest
Vendor pom groupid com.google.http-client Highest
Vendor pom parent-groupid com.google.http-client Medium
Vendor pom description Google HTTP Client Library for Java. Functionality that works on all supported Java platforms, including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine. Low
Vendor pom parent-artifactid google-http-client-parent Low
Vendor file name google-http-client High
Vendor pom name Google HTTP Client Library for Java High
Product pom description Google HTTP Client Library for Java. Functionality that works on all supported Java platforms, including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine. Low
Product pom groupid google.http-client Low
Product central artifactid google-http-client Highest
Product Manifest Implementation-Title Google HTTP Client Library for Java High
Product pom parent-groupid com.google.http-client Low
Product pom artifactid google-http-client Highest
Product file name google-http-client High
Product pom parent-artifactid google-http-client-parent Medium
Product pom name Google HTTP Client Library for Java High
Version Manifest Implementation-Version 1.14.1-beta High
Version pom version 1.14.1-beta Highest
Version file version 1.14.1.beta Highest
Version central version 1.14.1-beta Highest
jsr305-1.3.9.jar
Description: JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/google/code/findbugs/jsr305/1.3.9/jsr305-1.3.9.jar
MD5: 1d5a772e400b04bb67a7ef4a0e0996d8
SHA1: 40719ea6961c0cb6afaeb6a921eaa1f6afd4cfdf
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom artifactid jsr305 Low
Vendor pom groupid google.code.findbugs Highest
Vendor jar package name annotation Low
Vendor pom url http://findbugs.sourceforge.net/ Highest
Vendor jar package name javax Low
Vendor pom description JSR305 Annotations for Findbugs Medium
Vendor file name jsr305 High
Vendor pom name FindBugs-jsr305 High
Vendor central groupid com.google.code.findbugs Highest
Product central artifactid jsr305 Highest
Product jar package name annotation Low
Product pom url http://findbugs.sourceforge.net/ Medium
Product pom description JSR305 Annotations for Findbugs Medium
Product pom groupid google.code.findbugs Low
Product file name jsr305 High
Product pom name FindBugs-jsr305 High
Product pom artifactid jsr305 Highest
Version pom version 1.3.9 Highest
Version file version 1.3.9 Highest
Version central version 1.3.9 Highest
google-oauth-client-1.14.1-beta.jar
Description:
Google OAuth Client Library for Java. Functionality that works on all supported Java platforms,
including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine.
File Path: /home/ciagent/.m2/repository/com/google/oauth-client/google-oauth-client/1.14.1-beta/google-oauth-client-1.14.1-beta.jar
MD5: 71feea1d54eb7878c12855b7c47ef289
SHA1: 7260cd30808a6d1d4ddef6250e3d92d814aaa4cb
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.oauth-client Highest
Vendor pom parent-artifactid google-oauth-client-parent Low
Vendor Manifest Implementation-Vendor Google High
Vendor pom description Google OAuth Client Library for Java. Functionality that works on all supported Java platforms, including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine. Low
Vendor pom name Google OAuth Client Library for Java High
Vendor Manifest Implementation-Vendor-Id com.google.oauth-client Medium
Vendor pom artifactid google-oauth-client Low
Vendor pom parent-groupid com.google.oauth-client Medium
Vendor pom groupid google.oauth-client Highest
Vendor file name google-oauth-client High
Vendor central groupid com.google.oauth-client Highest
Product pom description Google OAuth Client Library for Java. Functionality that works on all supported Java platforms, including Java 5 (or higher) desktop (SE) and web (EE), Android, and Google App Engine. Low
Product pom name Google OAuth Client Library for Java High
Product pom groupid google.oauth-client Low
Product pom parent-groupid com.google.oauth-client Low
Product Manifest Implementation-Title Google OAuth Client Library for Java High
Product central artifactid google-oauth-client Highest
Product pom artifactid google-oauth-client Highest
Product file name google-oauth-client High
Product pom parent-artifactid google-oauth-client-parent Medium
Version Manifest Implementation-Version 1.14.1-beta High
Version pom version 1.14.1-beta Highest
Version file version 1.14.1.beta Highest
Version central version 1.14.1-beta Highest
google-api-client-1.14.1-beta.jar
File Path: /home/ciagent/.m2/repository/com/google/api-client/google-api-client/1.14.1-beta/google-api-client-1.14.1-beta.jar
MD5: 6832804471d4d635ed74ae1fbd5d9d86
SHA1: e95d3b6e36fc67bffd7e71ef60bc5af623e73843
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.api-client Highest
Vendor Manifest Implementation-Vendor Google High
Vendor Manifest Implementation-Vendor-Id com.google.api-client Medium
Vendor pom groupid google.api-client Highest
Vendor pom artifactid google-api-client Low
Vendor pom name Google APIs Client Library for Java High
Vendor pom parent-groupid com.google.api-client Medium
Vendor central groupid com.google.api-client Highest
Vendor file name google-api-client High
Vendor pom parent-artifactid google-api-client-parent Low
Product pom artifactid google-api-client Highest
Product pom groupid google.api-client Low
Product pom name Google APIs Client Library for Java High
Product pom parent-artifactid google-api-client-parent Medium
Product central artifactid google-api-client Highest
Product Manifest Implementation-Title Google APIs Client Library for Java High
Product pom parent-groupid com.google.api-client Low
Product file name google-api-client High
Version Manifest Implementation-Version 1.14.1-beta High
Version pom version 1.14.1-beta Highest
Version file version 1.14.1.beta Highest
Version central version 1.14.1-beta Highest
jackson-core-asl-1.9.11.jar
Description: Jackson is a high-performance JSON processor (parser, generator)
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/codehaus/jackson/jackson-core-asl/1.9.11/jackson-core-asl-1.9.11.jar
MD5: 49801a6d43725d5c3a1a52ca021d7dc5
SHA1: e32303ef8bd18a5c9272780d49b81c95e05ddf43
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor http://www.ietf.org/rfc/rfc4627.txt Low
Vendor pom name Jackson High
Vendor file name jackson-core-asl High
Vendor pom organization name FasterXML High
Vendor pom organization url http://fasterxml.com Medium
Vendor pom artifactid jackson-core-asl Low
Vendor central groupid org.codehaus.jackson Highest
Vendor pom description Jackson is a high-performance JSON processor (parser, generator)
Medium
Vendor pom groupid codehaus.jackson Highest
Vendor pom groupid org.codehaus.jackson Highest
Vendor pom url http://jackson.codehaus.org Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname jackson-core-asl Medium
Vendor Manifest Implementation-Vendor http://fasterxml.com High
Product pom groupid codehaus.jackson Low
Product pom name Jackson High
Product pom organization name FasterXML Low
Product Manifest specification-title JSON - JavaScript Object Notation Medium
Product file name jackson-core-asl High
Product pom description Jackson is a high-performance JSON processor (parser, generator)
Medium
Product pom artifactid jackson-core-asl Highest
Product Manifest Bundle-Name Jackson JSON processor Medium
Product pom url http://jackson.codehaus.org Medium
Product pom organization url http://fasterxml.com Low
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5, JavaSE-1.6 Low
Product Manifest Implementation-Title Jackson JSON processor High
Product central artifactid jackson-core-asl Highest
Product Manifest bundle-symbolicname jackson-core-asl Medium
Version central version 1.9.11 Highest
Version pom version 1.9.11 Highest
Version Manifest Implementation-Version 1.9.11 High
Version file version 1.9.11 Highest
google-http-client-jackson-1.14.1-beta.jar
File Path: /home/ciagent/.m2/repository/com/google/http-client/google-http-client-jackson/1.14.1-beta/google-http-client-jackson-1.14.1-beta.jar
MD5: 85d9f42910a68e85ff22d24805688da9
SHA1: 3cfc08bf4b0f62234ff69ff2a0b3c26d7e447829
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id com.google.http-client Medium
Vendor Manifest Implementation-Vendor Google High
Vendor pom groupid google.http-client Highest
Vendor central groupid com.google.http-client Highest
Vendor pom groupid com.google.http-client Highest
Vendor pom parent-groupid com.google.http-client Medium
Vendor pom artifactid google-http-client-jackson Low
Vendor pom parent-artifactid google-http-client-parent Low
Vendor pom name Jackson extensions to the Google HTTP Client Library for Java. High
Vendor file name google-http-client-jackson High
Product pom artifactid google-http-client-jackson Highest
Product central artifactid google-http-client-jackson Highest
Product Manifest Implementation-Title Jackson extensions to the Google HTTP Client Library for Java. High
Product pom groupid google.http-client Low
Product pom parent-groupid com.google.http-client Low
Product pom name Jackson extensions to the Google HTTP Client Library for Java. High
Product pom parent-artifactid google-http-client-parent Medium
Product file name google-http-client-jackson High
Version Manifest Implementation-Version 1.14.1-beta High
Version pom version 1.14.1-beta Highest
Version file version 1.14.1.beta Highest
Version central version 1.14.1-beta Highest
google-api-services-plus-v1-rev69-1.14.2-beta.jar
File Path: /home/ciagent/.m2/repository/com/google/apis/google-api-services-plus/v1-rev69-1.14.2-beta/google-api-services-plus-v1-rev69-1.14.2-beta.jar
MD5: fbddf71619f41f1359f0b3abff442444
SHA1: a6c5cc69690a3bd7777025a65b0f1abe66112a5e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid google Low
Vendor pom artifactid google-api-services-plus Low
Vendor jar package name google Low
Vendor jar package name services Low
Vendor file name google-api-services-plus-v1-rev69 High
Vendor pom parent-groupid com.google Medium
Vendor pom groupid google.apis Highest
Vendor central groupid com.google.apis Highest
Vendor pom groupid com.google.apis Highest
Vendor pom name Google+ API v1 (revision 69) High
Vendor jar package name api Low
Product pom parent-artifactid google Medium
Product central artifactid google-api-services-plus Highest
Product jar package name services Low
Product file name google-api-services-plus-v1-rev69 High
Product pom artifactid google-api-services-plus Highest
Product pom parent-groupid com.google Low
Product pom groupid google.apis Low
Product pom name Google+ API v1 (revision 69) High
Product jar package name plus Low
Product jar package name api Low
Version pom version v1-rev69-1.14.2-beta Highest
Version file name google-api-services-plus-v1-rev69 Medium
Version file version 1.14.2.beta Highest
Version pom parent-version v1-rev69-1.14.2-beta Low
Version central version v1-rev69-1.14.2-beta Highest
google-api-services-oauth2-v2-rev36-1.14.2-beta.jar
File Path: /home/ciagent/.m2/repository/com/google/apis/google-api-services-oauth2/v2-rev36-1.14.2-beta/google-api-services-oauth2-v2-rev36-1.14.2-beta.jar
MD5: cd2ac31ad0317e53e660c2a4578749f3
SHA1: c7249e1e4832f6e6585f7b7db307585b3ae53881
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name google-api-services-oauth2-v2-rev36 High
Vendor pom parent-artifactid google Low
Vendor pom artifactid google-api-services-oauth2 Low
Vendor jar package name google Low
Vendor jar package name services Low
Vendor pom parent-groupid com.google Medium
Vendor pom groupid google.apis Highest
Vendor pom name Google OAuth2 API v2 (revision 36) High
Vendor central groupid com.google.apis Highest
Vendor pom groupid com.google.apis Highest
Vendor jar package name api Low
Product pom artifactid google-api-services-oauth2 Highest
Product file name google-api-services-oauth2-v2-rev36 High
Product pom parent-artifactid google Medium
Product jar package name services Low
Product jar package name oauth2 Low
Product pom name Google OAuth2 API v2 (revision 36) High
Product pom parent-groupid com.google Low
Product pom groupid google.apis Low
Product central artifactid google-api-services-oauth2 Highest
Product jar package name api Low
Version pom version v2-rev36-1.14.2-beta Highest
Version file name google-api-services-oauth2-v2-rev36 Medium
Version central version v2-rev36-1.14.2-beta Highest
Version pom parent-version v2-rev36-1.14.2-beta Low
Version file version 1.14.2.beta Highest
groovy-all-2.4.12.jar
Description: Groovy: A powerful, dynamic language for the JVM
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/codehaus/groovy/groovy-all/2.4.12/groovy-all-2.4.12.jar
MD5: dddb0b3d3619875fa1c538c743ae8f99
SHA1: 760afc568cbd94c09d78f801ce51aed1326710af
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.codehaus.groovy Highest
Vendor pom groupid codehaus.groovy Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom description Groovy: A powerful, dynamic language for the JVM Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor manifest Bundle-Description Groovy Runtime Medium
Vendor pom artifactid groovy-all Low
Vendor Manifest originally-created-by 1.8.0_131-b11 (Oracle Corporation) Low
Vendor pom organization name Apache Software Foundation High
Vendor file name groovy-all High
Vendor pom name Apache Groovy High
Vendor pom organization url http://groovy-lang.org Medium
Vendor Manifest extension-name groovy Medium
Vendor pom url http://groovy-lang.org Highest
Vendor Manifest bundle-symbolicname groovy-all Medium
Vendor central groupid org.codehaus.groovy Highest
Product Manifest Bundle-Name Groovy Runtime Medium
Product pom organization url http://groovy-lang.org Low
Product pom description Groovy: A powerful, dynamic language for the JVM Medium
Product Manifest specification-title Groovy: a powerful, dynamic language for the JVM Medium
Product pom organization name Apache Software Foundation Low
Product manifest Bundle-Description Groovy Runtime Medium
Product Manifest originally-created-by 1.8.0_131-b11 (Oracle Corporation) Low
Product Manifest Implementation-Title Groovy: a powerful, dynamic language for the JVM High
Product pom groupid codehaus.groovy Low
Product file name groovy-all High
Product pom name Apache Groovy High
Product pom artifactid groovy-all Highest
Product Manifest extension-name groovy Medium
Product Manifest bundle-symbolicname groovy-all Medium
Product pom url http://groovy-lang.org Medium
Product central artifactid groovy-all Highest
Version file version 2.4.12 Highest
Version Manifest Implementation-Version 2.4.12 High
Version pom version 2.4.12 Highest
Version central version 2.4.12 Highest
aopalliance-1.0.jar
Description: AOP Alliance
License:
Public Domain
File Path: /home/ciagent/.m2/repository/aopalliance/aopalliance/1.0/aopalliance-1.0.jar
MD5: 04177054e180d09e3998808efa0401c7
SHA1: 0235ba8b489512805ac13a8f9ea77a1ca5ebe3e8
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid aopalliance Low
Vendor pom description AOP Alliance Medium
Vendor jar package name aopalliance Low
Vendor pom groupid aopalliance Highest
Vendor pom url http://aopalliance.sourceforge.net Highest
Vendor jar package name intercept Low
Vendor central groupid aopalliance Highest
Vendor file name aopalliance High
Vendor pom name AOP alliance High
Product pom description AOP Alliance Medium
Product central artifactid aopalliance Highest
Product pom artifactid aopalliance Highest
Product jar package name intercept Low
Product pom groupid aopalliance Low
Product file name aopalliance High
Product pom url http://aopalliance.sourceforge.net Medium
Product pom name AOP alliance High
Version file version 1.0 Highest
Version central version 1.0 Highest
Version pom version 1.0 Highest
guice-3.0.jar
Description: Guice is a lightweight dependency injection framework for Java 5 and above
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/google/inject/guice/3.0/guice-3.0.jar
MD5: ca1c7ba366884cfcd2cfb48d2395c400
SHA1: 9d84f15fe35e2c716a02979fb62f50a29f38aefa
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium
Vendor pom parent-groupid com.google.inject Medium
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low
Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low
Vendor pom parent-artifactid guice-parent Low
Vendor Manifest bundle-symbolicname com.google.inject Medium
Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low
Vendor pom artifactid guice Low
Vendor file name guice High
Vendor central groupid com.google.inject Highest
Vendor pom name Google Guice - Core Library High
Vendor pom groupid google.inject Highest
Vendor pom groupid com.google.inject Highest
Product pom parent-groupid com.google.inject Low
Product manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low
Product pom groupid google.inject Low
Product pom artifactid guice Highest
Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low
Product Manifest bundle-symbolicname com.google.inject Medium
Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low
Product file name guice High
Product Manifest Bundle-Name guice Medium
Product pom name Google Guice - Core Library High
Product pom parent-artifactid guice-parent Medium
Product central artifactid guice Highest
Version pom version 3.0 Highest
Version file version 3.0 Highest
Version central version 3.0 Highest
joda-time-2.4.jar
Description: Date and time library to replace JDK date handling
License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/joda-time/joda-time/2.4/joda-time-2.4.jar
MD5: 1231c3e09de6aa5d6b6d9982c0224e20
SHA1: 89e9725439adffbbd41c5f5c215c136082b34a7f
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Joda.org High
Vendor Manifest specification-vendor Joda.org Low
Vendor Manifest bundle-docurl http://www.joda.org/joda-time/ Low
Vendor pom groupid joda-time Highest
Vendor Manifest Implementation-Vendor-Id org.joda Medium
Vendor pom name Joda-Time High
Vendor pom artifactid joda-time Low
Vendor pom description Date and time library to replace JDK date handling Medium
Vendor file name joda-time High
Vendor Manifest extension-name joda-time Medium
Vendor Manifest bundle-symbolicname joda-time Medium
Vendor central groupid joda-time Highest
Vendor pom url http://www.joda.org/joda-time/ Highest
Vendor pom organization url http://www.joda.org Medium
Vendor pom organization name Joda.org High
Product Manifest specification-title Joda-Time Medium
Product pom artifactid joda-time Highest
Product pom organization url http://www.joda.org Low
Product Manifest bundle-docurl http://www.joda.org/joda-time/ Low
Product Manifest Bundle-Name Joda-Time Medium
Product pom groupid joda-time Low
Product pom name Joda-Time High
Product pom description Date and time library to replace JDK date handling Medium
Product file name joda-time High
Product Manifest extension-name joda-time Medium
Product Manifest bundle-symbolicname joda-time Medium
Product central artifactid joda-time Highest
Product Manifest Implementation-Title org.joda.time High
Product pom organization name Joda.org Low
Product pom url http://www.joda.org/joda-time/ Medium
Version file version 2.4 Highest
Version central version 2.4 Highest
Version pom version 2.4 Highest
Version Manifest Implementation-Version 2.4 High
oauth-20100527.jar
File Path: /home/ciagent/.m2/repository/net/oauth/core/oauth/20100527/oauth-20100527.jar
MD5: 91c7c70579f95b7ddee95b2143a49b41
SHA1: a84c5331e225bc25a5a288db328048d6b1bb6fd5
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor pom groupid net.oauth.core Highest
Vendor pom artifactid oauth Low
Vendor jar package name oauth Low
Vendor pom parent-artifactid oauth-core-parent Low
Vendor pom name OAuth Core High
Vendor file name oauth-20100527 High
Vendor central groupid net.oauth.core Highest
Product pom parent-artifactid oauth-core-parent Medium
Product central artifactid oauth Highest
Product jar package name oauth Low
Product pom artifactid oauth Highest
Product pom name OAuth Core High
Product pom groupid net.oauth.core Low
Product file name oauth-20100527 High
Version file version 20100527 Medium
Version pom version 20100527 Highest
Version central version 20100527 Highest
ehcache-core-2.6.9.jar
Description: This is the ehcache core module. Pair it with other modules for added functionality.
License:
The Apache Software License, Version 2.0: src/assemble/EHCACHE-CORE-LICENSE.txt
File Path: /home/ciagent/.m2/repository/net/sf/ehcache/ehcache-core/2.6.9/ehcache-core-2.6.9.jar
MD5: 521348c6da7c20dba2058917a6a8c0a9
SHA1: e892585cc2cf95d46a2533df438a1d3323034ae8
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid ehcache-core Low
Vendor pom name Ehcache Core High
Vendor central groupid net.sf.ehcache Highest
Vendor pom url http://ehcache.org Highest
Vendor file name ehcache-core High
Vendor pom description This is the ehcache core module. Pair it with other modules for added functionality. Medium
Vendor pom groupid net.sf.ehcache Highest
Vendor pom parent-artifactid ehcache-parent Low
Product pom artifactid ehcache-core Highest
Product central artifactid ehcache-core Highest
Product pom name Ehcache Core High
Product pom groupid net.sf.ehcache Low
Product pom parent-artifactid ehcache-parent Medium
Product file name ehcache-core High
Product pom description This is the ehcache core module. Pair it with other modules for added functionality. Medium
Product pom url http://ehcache.org Medium
Version central version 2.6.9 Highest
Version file version 2.6.9 Highest
Version pom version 2.6.9 Highest
juel-impl-2.2.7.jar
File Path: /home/ciagent/.m2/repository/de/odysseus/juel/juel-impl/2.2.7/juel-impl-2.2.7.jar
MD5: c5d7a62edafb5706b6beadbbcfd8f57d
SHA1: 97958467acef4c2b230b72354a4eefc66628dd99
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid juel-parent Low
Vendor Manifest bundle-symbolicname de.odysseus.juel-impl Medium
Vendor central groupid de.odysseus.juel Highest
Vendor Manifest Implementation-Vendor-Id de.odysseus Medium
Vendor pom groupid de.odysseus.juel Highest
Vendor pom artifactid juel-impl Low
Vendor Manifest service-component OSGI-INF/services.xml Low
Vendor Manifest Implementation-Vendor Odysseus Software GmbH High
Vendor file name juel-impl High
Vendor pom name Java Unified Expression Language Implementation High
Vendor Manifest specification-vendor Sun Microsystems Inc. Low
Product pom groupid de.odysseus.juel Low
Product Manifest bundle-symbolicname de.odysseus.juel-impl Medium
Product pom parent-artifactid juel-parent Medium
Product Manifest Implementation-Title JUEL High
Product Manifest specification-title Expression Language Medium
Product central artifactid juel-impl Highest
Product Manifest service-component OSGI-INF/services.xml Low
Product pom artifactid juel-impl Highest
Product file name juel-impl High
Product pom name Java Unified Expression Language Implementation High
Product Manifest Bundle-Name Expression Language Implementation Medium
Version central version 2.2.7 Highest
Version Manifest Implementation-Version 2.2.7 High
Version file version 2.2.7 Highest
Version pom version 2.2.7 Highest
el-api-6.0.41.jar
Description: Expression language package
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tomcat/el-api/6.0.41/el-api-6.0.41.jar
MD5: 7073be2b44ca903e88ef0d36794cbfd8
SHA1: 9b2915f70905fcd366c7cde00cf25ccd2246e38b
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid apache.tomcat Highest
Vendor file name el-api High
Vendor manifest: javax/el/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid el-api Low
Vendor pom groupid org.apache.tomcat Highest
Vendor pom url http://tomcat.apache.org/ Highest
Vendor pom description Expression language package Medium
Vendor central groupid org.apache.tomcat Highest
Product central artifactid el-api Highest
Product file name el-api High
Product manifest: javax/el/ Implementation-Title javax.el Medium
Product manifest: javax/el/ Specification-Title Expression Language Medium
Product pom url http://tomcat.apache.org/ Medium
Product pom description Expression language package Medium
Product pom artifactid el-api Highest
Product pom groupid apache.tomcat Low
Version pom version 6.0.41 Highest
Version central version 6.0.41 Highest
Version file version 6.0.41 Highest
Published Vulnerabilities
CVE-2012-5568 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-16 Configuration
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
Vulnerable Software & Versions: (show all )
CVE-2013-2185 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
** DISPUTED ** The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue.
Vulnerable Software & Versions: (show all )
CVE-2013-4444 suppress
Severity:
Medium
CVSS Score: 6.8
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
CWE: CWE-94 Improper Control of Generation of Code ('Code Injection')
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Vulnerable Software & Versions: (show all )
CVE-2014-0227 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-19 Data Handling
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.
Vulnerable Software & Versions: (show all )
CVE-2014-0230 suppress
Severity:
High
CVSS Score: 7.8
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
CWE: CWE-399 Resource Management Errors
Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
Vulnerable Software & Versions: (show all )
CVE-2014-7810 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-284 Improper Access Control
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
Vulnerable Software & Versions: (show all )
CVE-2015-5174 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.
Vulnerable Software & Versions: (show all )
CVE-2015-5345 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
Vulnerable Software & Versions: (show all )
CVE-2016-0706 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application.
Vulnerable Software & Versions: (show all )
CVE-2016-0714 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.
Vulnerable Software & Versions: (show all )
CVE-2016-0762 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
Vulnerable Software & Versions: (show all )
CVE-2016-5018 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-254 Security Features
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
Vulnerable Software & Versions: (show all )
CVE-2016-5388 suppress
Severity:
Medium
CVSS Score: 5.1
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.
Vulnerable Software & Versions: (show all )
CVE-2016-5425 suppress
Severity:
High
CVSS Score: 7.2
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
Vulnerable Software & Versions:
CVE-2016-6325 suppress
Severity:
High
CVSS Score: 7.2
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Vulnerable Software & Versions:
CVE-2016-6794 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.
Vulnerable Software & Versions: (show all )
CVE-2016-6796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-254 Security Features
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
Vulnerable Software & Versions: (show all )
CVE-2016-6797 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-284 Improper Access Control
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
Vulnerable Software & Versions: (show all )
CVE-2016-6816 suppress
Severity:
Medium
CVSS Score: 6.8
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.
Vulnerable Software & Versions: (show all )
CVE-2016-8735 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Vulnerable Software & Versions: (show all )
CVE-2017-5647 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.
Vulnerable Software & Versions: (show all )
CVE-2017-6056 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-19 Data Handling
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
Vulnerable Software & Versions:
jasper-el-6.0.41.jar
Description: Jasper Expression Language Impl
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/tomcat/jasper-el/6.0.41/jasper-el-6.0.41.jar
MD5: a8ff295523ea0b4c08f9ff75f41b3ccd
SHA1: ea8e38e8f754e69f0ca05cbdcc675d822ef68d8e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid apache.tomcat Highest
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor pom artifactid jasper-el Low
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor pom description Jasper Expression Language Impl Medium
Vendor pom groupid org.apache.tomcat Highest
Vendor file name jasper-el High
Vendor pom url http://tomcat.apache.org/ Highest
Vendor central groupid org.apache.tomcat Highest
Product pom artifactid jasper-el Highest
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest specification-title Apache Tomcat Medium
Product pom description Jasper Expression Language Impl Medium
Product pom url http://tomcat.apache.org/ Medium
Product file name jasper-el High
Product central artifactid jasper-el Highest
Product pom groupid apache.tomcat Low
Version pom version 6.0.41 Highest
Version Manifest Implementation-Version 6.0.41 High
Version central version 6.0.41 Highest
Version file version 6.0.41 Highest
maven: org.apache.tomcat:jasper-el:6.0.41 ✓
Confidence :Highest
cpe: cpe:/a:apache_tomcat:apache_tomcat:6.0.41
Confidence :Low
suppress
cpe: cpe:/a:apache:tomcat:6.0.41
Confidence :Highest
suppress
cpe: cpe:/a:apache_software_foundation:tomcat:6.0.41
Confidence :Low
suppress
cpe: cpe:/a:jasper_project:jasper:6.0.41
Confidence :Low
suppress
Published Vulnerabilities
CVE-2012-5568 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-16 Configuration
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
Vulnerable Software & Versions: (show all )
CVE-2013-2185 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
** DISPUTED ** The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue.
Vulnerable Software & Versions: (show all )
CVE-2013-4444 suppress
Severity:
Medium
CVSS Score: 6.8
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
CWE: CWE-94 Improper Control of Generation of Code ('Code Injection')
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Vulnerable Software & Versions: (show all )
CVE-2014-0227 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-19 Data Handling
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.
Vulnerable Software & Versions: (show all )
CVE-2014-0230 suppress
Severity:
High
CVSS Score: 7.8
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
CWE: CWE-399 Resource Management Errors
Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
Vulnerable Software & Versions: (show all )
CVE-2014-7810 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-284 Improper Access Control
The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider the possibility of an accessible interface implemented by an inaccessible class, which allows attackers to bypass a SecurityManager protection mechanism via a web application that leverages use of incorrect privileges during EL evaluation.
Vulnerable Software & Versions: (show all )
CVE-2015-5174 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getResourcePaths call, as demonstrated by the $CATALINA_BASE/webapps directory.
Vulnerable Software & Versions: (show all )
CVE-2015-5345 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
Vulnerable Software & Versions: (show all )
CVE-2016-0706 suppress
Severity:
Medium
CVSS Score: 4.0
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and consequently discover session ID values, via a crafted web application.
Vulnerable Software & Versions: (show all )
CVE-2016-0714 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted object in a session.
Vulnerable Software & Versions: (show all )
CVE-2016-0762 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
Vulnerable Software & Versions: (show all )
CVE-2016-5018 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-254 Security Features
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
Vulnerable Software & Versions: (show all )
CVE-2016-5388 suppress
Severity:
Medium
CVSS Score: 5.1
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.
Vulnerable Software & Versions: (show all )
CVE-2016-5425 suppress
Severity:
High
CVSS Score: 7.2
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
Vulnerable Software & Versions:
CVE-2016-6325 suppress
Severity:
High
CVSS Score: 7.2
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
CWE: CWE-264 Permissions, Privileges, and Access Controls
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
Vulnerable Software & Versions:
CVE-2016-6794 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.
Vulnerable Software & Versions: (show all )
CVE-2016-6796 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-254 Security Features
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
Vulnerable Software & Versions: (show all )
CVE-2016-6797 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-284 Improper Access Control
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
Vulnerable Software & Versions: (show all )
CVE-2016-6816 suppress
Severity:
Medium
CVSS Score: 6.8
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
CWE: CWE-20 Improper Input Validation
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.
Vulnerable Software & Versions: (show all )
CVE-2016-8735 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-284 Improper Access Control
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.
Vulnerable Software & Versions: (show all )
CVE-2017-5647 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the wrong request. For example, a user agent that sent requests A, B and C could see the correct response for request A, the response for request C for request B and no response for request C.
Vulnerable Software & Versions: (show all )
CVE-2017-6056 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-19 Data Handling
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backporting a CVE-2016-6816 fix but not backporting the fix for Tomcat bug 57544. Distributions affected by this backporting issue include Debian (before 7.0.56-3+deb8u8 and 8.0.14-1+deb8u7 in jessie) and Ubuntu.
Vulnerable Software & Versions:
shindig-common-2.5.2.jar
Description: Common java code for Shindig
File Path: /home/ciagent/.m2/repository/org/apache/shindig/shindig-common/2.5.2/shindig-common-2.5.2.jar
MD5: 9deeebec74d0530849d5dd42e19ee9cd
SHA1: 8e3d0ee31607e7a18f20612ef705b32ab8eace2b
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name shindig-common High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom parent-groupid org.apache.shindig Medium
Vendor pom name Apache Shindig Common Code High
Vendor pom groupid org.apache.shindig Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid shindig-common Low
Vendor pom description Common java code for Shindig Medium
Vendor central groupid org.apache.shindig Highest
Vendor pom parent-artifactid shindig-project Low
Vendor Manifest Implementation-Vendor-Id org.apache.shindig Medium
Vendor pom groupid apache.shindig Highest
Product pom parent-groupid org.apache.shindig Low
Product central artifactid shindig-common Highest
Product file name shindig-common High
Product Manifest Implementation-Title Apache Shindig Common Code High
Product pom parent-artifactid shindig-project Medium
Product pom name Apache Shindig Common Code High
Product pom artifactid shindig-common Highest
Product pom groupid apache.shindig Low
Product Manifest specification-title Apache Shindig Common Code Medium
Product pom description Common java code for Shindig Medium
Version central version 2.5.2 Highest
Version file version 2.5.2 Highest
Version Manifest Implementation-Version 2.5.2 High
Version pom version 2.5.2 Highest
Related Dependencies
shindig-gadgets-2.5.2.jar
File Path: /home/ciagent/.m2/repository/org/apache/shindig/shindig-gadgets/2.5.2/shindig-gadgets-2.5.2.jar
SHA1: ad7a540e121450a885d053c9edf59eae423a64c5
MD5: aaca1591b9f8b82ac1859b56184711b0
maven: org.apache.shindig:shindig-gadgets:2.5.2 ✓
shindig-features-2.5.2.jar
File Path: /home/ciagent/.m2/repository/org/apache/shindig/shindig-features/2.5.2/shindig-features-2.5.2.jar
SHA1: 8da6aa8af98070e4aefe9434628db2f23cfea80d
MD5: ae2ff4a2cfe4dff4897273cb28906654
maven: org.apache.shindig:shindig-features:2.5.2 ✓
shindig-social-api-2.5.2.jar
File Path: /home/ciagent/.m2/repository/org/apache/shindig/shindig-social-api/2.5.2/shindig-social-api-2.5.2.jar
SHA1: d8eba76e26bc2e2c4b34d0ee4575816a27f26c96
MD5: eac1069ed022e9ba99b6d9703022cb99
maven: org.apache.shindig:shindig-social-api:2.5.2 ✓
filters-2.0.235.jar
Description: A collection of image processing filters.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /home/ciagent/.m2/repository/com/jhlabs/filters/2.0.235/filters-2.0.235.jar
MD5: d91073d6b28e2505e96620709626495f
SHA1: af6a2dfefef70f1ab2d7a8d1f8173f67e276b3f4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid filters Low
Vendor pom description A collection of image processing filters. Medium
Vendor pom name JHLabs Image Processing Filters High
Vendor file name filters High
Vendor Manifest Implementation-Vendor-Id com.jhlabs Medium
Vendor central groupid com.jhlabs Highest
Vendor pom groupid jhlabs Highest
Vendor pom groupid com.jhlabs Highest
Vendor pom url http://www.jhlabs.com/ip/index.html Highest
Product pom description A collection of image processing filters. Medium
Product pom url http://www.jhlabs.com/ip/index.html Medium
Product central artifactid filters Highest
Product Manifest specification-title JHLabs Image Processing Filters Medium
Product pom groupid jhlabs Low
Product pom name JHLabs Image Processing Filters High
Product pom artifactid filters Highest
Product file name filters High
Product Manifest Implementation-Title JHLabs Image Processing Filters High
Version central version 2.0.235 Highest
Version Manifest Implementation-Version 2.0.235 High
Version file version 2.0.235 Highest
Version pom version 2.0.235 Highest
Published Vulnerabilities
CVE-2005-0406 suppress
Severity:
Low
CVSS Score: 2.1
(AV:L/AC:L/Au:N/C:P/I:N/A:N)
A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.
Vulnerable Software & Versions:
CVE-2018-1000840 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in An attacker can read arbitrary files and exfiltrate their contents via HTTP requests. This attack appear to be exploitable via The victim must use Processing to parse a crafted XML document.
Vulnerable Software & Versions:
simplecaptcha-1.1.1.Final-gatein-4.jar
File Path: /home/ciagent/.m2/repository/org/gatein/captcha/simplecaptcha/1.1.1.Final-gatein-4/simplecaptcha-1.1.1.Final-gatein-4.jar
MD5: a8b83c67e6fd04cd02d8ebcfd47348c1
SHA1: 964c53fedc87745494c5f8f2cd62b2548dbdeff5
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url www.gatein.org/simplecaptcha/ Low
Vendor pom groupid org.gatein.captcha Highest
Vendor Manifest Implementation-Vendor-Id org.gatein.captcha Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom artifactid simplecaptcha Low
Vendor pom parent-groupid org.gatein Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom parent-artifactid gatein-parent Low
Vendor Manifest os-name Linux Medium
Vendor file name simplecaptcha High
Vendor pom name GateIn SimpleCaptcha High
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom groupid gatein.captcha Highest
Vendor Manifest build-timestamp Mon, 17 Jun 2013 09:04:01 +0200 Low
Product Manifest implementation-url www.gatein.org/simplecaptcha/ Low
Product file name simplecaptcha High
Product pom groupid gatein.captcha Low
Product Manifest Implementation-Title GateIn SimpleCaptcha High
Product pom name GateIn SimpleCaptcha High
Product pom parent-artifactid gatein-parent Medium
Product pom parent-groupid org.gatein Low
Product pom artifactid simplecaptcha Highest
Product Manifest specification-title GateIn SimpleCaptcha Medium
Product Manifest build-timestamp Mon, 17 Jun 2013 09:04:01 +0200 Low
Product Manifest os-name Linux Medium
Version pom version 1.1.1.Final-gatein-4 Highest
Version Manifest Implementation-Version 1.1.1.Final-gatein-4 High
maven: org.gatein.captcha:simplecaptcha:1.1.1.Final-gatein-4
Confidence :High
gatein-api-1.0.1.Final.jar
File Path: /home/ciagent/.m2/repository/org/gatein/api/gatein-api/1.0.1.Final/gatein-api-1.0.1.Final.jar
MD5: 04d51eb4e2734df16f83e514b7110000
SHA1: b67727b03994e6081e2e411804c25bd5d0d919a6
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.gatein.api Medium
Vendor file name gatein-api High
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor pom groupid org.gatein.api Highest
Vendor pom parent-groupid org.gatein Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom parent-artifactid gatein-parent Low
Vendor central groupid org.gatein.api Highest
Vendor Manifest os-name Linux Medium
Vendor Manifest implementation-url www.gatein.org/gatein-api/ Low
Vendor Manifest build-timestamp Tue, 30 Jul 2013 09:10:07 -0400 Low
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom groupid gatein.api Highest
Vendor pom artifactid gatein-api Low
Product Manifest build-timestamp Tue, 30 Jul 2013 09:10:07 -0400 Low
Product file name gatein-api High
Product Manifest Implementation-Title gatein-api High
Product pom groupid gatein.api Low
Product pom parent-artifactid gatein-parent Medium
Product pom artifactid gatein-api Highest
Product Manifest specification-title gatein-api Medium
Product pom parent-groupid org.gatein Low
Product central artifactid gatein-api Highest
Product Manifest os-name Linux Medium
Product Manifest implementation-url www.gatein.org/gatein-api/ Low
Version Manifest Implementation-Version 1.0.1.Final High
Version central version 1.0.1.Final Highest
Version file version 1.0.1 Highest
Version pom version 1.0.1.Final Highest
icu4j-56.1.jar
Description:
International Component for Unicode for Java (ICU4J) is a mature, widely used Java library
providing Unicode and Globalization support
License:
ICU License: http://source.icu-project.org/repos/icu/icu/trunk/license.html
File Path: /home/ciagent/.m2/repository/com/ibm/icu/icu4j/56.1/icu4j-56.1.jar
MD5: 7bd1a7a1295868726f991c7593dce442
SHA1: 8dd6671f52165a0419e6de5e1016400875a90fa9
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name ICU4J High
Vendor pom groupid ibm.icu Highest
Vendor pom artifactid icu4j Low
Vendor central groupid com.ibm.icu Highest
Vendor file name icu4j High
Vendor Manifest bundle-copyright Copyright 2000-2015, International Business Machines Corporation and others. All Rights Reserved. Low
Vendor Manifest specification-vendor icu-project.org Low
Vendor manifest Bundle-Description International Components for Unicode for Java Medium
Vendor pom description International Component for Unicode for Java (ICU4J) is a mature, widely used Java library providing Unicode and Globalization support Low
Vendor pom groupid com.ibm.icu Highest
Vendor Manifest Implementation-Vendor-Id com.ibm Medium
Vendor Manifest bundle-symbolicname com.ibm.icu Medium
Vendor Manifest Implementation-Vendor IBM Corporation High
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor pom url http://icu-project.org/ Highest
Product pom name ICU4J High
Product Manifest Bundle-Name ICU4J Medium
Product file name icu4j High
Product Manifest bundle-copyright Copyright 2000-2015, International Business Machines Corporation and others. All Rights Reserved. Low
Product manifest Bundle-Description International Components for Unicode for Java Medium
Product pom description International Component for Unicode for Java (ICU4J) is a mature, widely used Java library providing Unicode and Globalization support Low
Product pom artifactid icu4j Highest
Product central artifactid icu4j Highest
Product pom url http://icu-project.org/ Medium
Product Manifest bundle-symbolicname com.ibm.icu Medium
Product pom groupid ibm.icu Low
Product Manifest Implementation-Title International Components for Unicode for Java High
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product Manifest specification-title International Components for Unicode for Java Medium
Version file version 56.1 Highest
Version Manifest Implementation-Version 56.1 High
Version central version 56.1 Highest
Version pom version 56.1 Highest
Published Vulnerabilities
CVE-2016-6293 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a call with a long httpAcceptLanguage argument.
Vulnerable Software & Versions:
CVE-2016-7415 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long locale string.
Vulnerable Software & Versions:
CVE-2017-14952 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-415 Double Free
Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue.
Vulnerable Software & Versions:
CVE-2017-15396 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Vulnerable Software & Versions: (show all )
CVE-2017-15422 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-190 Integer Overflow or Wraparound
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Vulnerable Software & Versions: (show all )
CVE-2017-17484 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.
Vulnerable Software & Versions:
CVE-2017-7867 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-787 Out-of-bounds Write
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.
Vulnerable Software & Versions:
CVE-2017-7868 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-787 Out-of-bounds Write
International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.
Vulnerable Software & Versions:
commons-component-product-5.3.x-SNAPSHOT.jar
Description: Product informations: version, revision and build numbers
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-component-product/5.3.x-SNAPSHOT/commons-component-product-5.3.x-SNAPSHOT.jar
MD5: b8901f4806b4b15c95950919ab4e22cc
SHA1: 18deee3c16a7fbe462e1ffe37e4317fe89a9d24c
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor file name commons-component-product High
Vendor pom description Product informations: version, revision and build numbers Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-component-product Low
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Vendor pom name eXo PLF:: Commons - Product Informations High
Vendor pom artifactid commons-component-product Low
Product pom parent-groupid org.exoplatform.commons Low
Product file name commons-component-product High
Product pom description Product informations: version, revision and build numbers Medium
Product pom artifactid commons-component-product Highest
Product Manifest Implementation-Title eXo PLF:: Commons - Product Informations High
Product Manifest specification-title eXo PLF:: Commons - Product Informations Medium
Product pom groupid exoplatform.commons Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-component-product Low
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product pom name eXo PLF:: Commons - Product Informations High
Version pom version 5.3.x-20190524.100457-53 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-component-product:5.3.x-SNAPSHOT
Confidence :High
commons-component-upgrade-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-component-upgrade/5.3.x-SNAPSHOT/commons-component-upgrade-5.3.x-SNAPSHOT.jar
MD5: dec94676448b6445d4b46241496bdc51
SHA1: 8a096fb70e071ea70a19721012cd6e425cdd3ff4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:provided
Evidence
Type Source Name Value Confidence
Vendor file name commons-component-upgrade High
Vendor pom artifactid commons-component-upgrade Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-component-upgrade Low
Vendor pom name eXo PLF:: Commons - Transparent Upgrade Framework High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Product pom parent-groupid org.exoplatform.commons Low
Product file name commons-component-upgrade High
Product Manifest Implementation-Title eXo PLF:: Commons - Transparent Upgrade Framework High
Product Manifest specification-title eXo PLF:: Commons - Transparent Upgrade Framework Medium
Product pom groupid exoplatform.commons Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-component-upgrade Low
Product pom artifactid commons-component-upgrade Highest
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product pom name eXo PLF:: Commons - Transparent Upgrade Framework High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-component-upgrade:5.3.x-SNAPSHOT
Confidence :High
social-component-common-5.3.x-SNAPSHOT.jar
Description: eXo Social Common Component
File Path: /home/ciagent/.m2/repository/org/exoplatform/social/social-component-common/5.3.x-SNAPSHOT/social-component-common-5.3.x-SNAPSHOT.jar
MD5: 97c9ee7e9fb1105d2e2fdcd4fdbb3ce4
SHA1: c470e3e88396adeeeb78ac742d2fe3d2a906c57f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.social Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom description eXo Social Common Component Medium
Vendor pom groupid exoplatform.social Highest
Vendor Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-common Low
Vendor pom groupid org.exoplatform.social Highest
Vendor Manifest date 2019-05-24T10:23:51Z Low
Vendor file name social-component-common High
Vendor pom parent-artifactid social-component Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.social Medium
Vendor pom name eXo PLF:: Social Common Component High
Vendor pom artifactid social-component-common Low
Product file name social-component-common High
Product pom parent-groupid org.exoplatform.social Low
Product Manifest Implementation-Title eXo PLF:: Social Common Component High
Product pom description eXo Social Common Component Medium
Product pom groupid exoplatform.social Low
Product pom artifactid social-component-common Highest
Product Manifest specification-title eXo PLF:: Social Common Component Medium
Product pom name eXo PLF:: Social Common Component High
Product Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-common Low
Product pom parent-artifactid social-component Medium
Product Manifest date 2019-05-24T10:23:51Z Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.social:social-component-common:5.3.x-SNAPSHOT
Confidence :High
pc-api-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/pc/pc-api/5.3.x-SNAPSHOT/pc-api-5.3.x-SNAPSHOT.jar
MD5: e995d3069d7ca3308034dcb2ccd06d09
SHA1: 7c15dad670317a24d7e12ff353aa252eb170165b
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor GateIn High
Vendor pom artifactid pc-api Low
Vendor pom name GateIn - Portlet Container (api) High
Vendor file name pc-api High
Vendor pom parent-groupid org.exoplatform.gatein.pc Medium
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-api Low
Vendor Manifest os-name Linux Medium
Vendor pom groupid org.exoplatform.gatein.pc Highest
Vendor Manifest specification-vendor GateIn Low
Vendor pom groupid exoplatform.gatein.pc Highest
Vendor Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Vendor pom parent-artifactid pc-parent Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.pc Medium
Product Manifest specification-title GateIn - Portlet Container (api) Medium
Product pom name GateIn - Portlet Container (api) High
Product pom artifactid pc-api Highest
Product file name pc-api High
Product pom parent-artifactid pc-parent Medium
Product Manifest Implementation-Title GateIn - Portlet Container (api) High
Product Manifest build-timestamp Thu, 23 May 2019 15:08:34 +0000 Low
Product pom groupid exoplatform.gatein.pc Low
Product Manifest implementation-url http://www.jboss.org/gatein/portletcontainer.html/pc-api Low
Product Manifest os-name Linux Medium
Product pom parent-groupid org.exoplatform.gatein.pc Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.gatein.pc:pc-api:5.3.x-SNAPSHOT
Confidence :High
caja-r5054.jar
Description:
Caja is a HTML/CSS/JavaScript compiler which allows websites to safely embed web applications
from third parties, and enables rich interaction between the embedding page and the embedded
applications using an object-capability security model.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/caja/caja/r5054/caja-r5054.jar
MD5: 7379ecf5bc7945ca6ab533b905e449a3
SHA1: 18b47afa0172413346d9c8ae1595b6ffbbddd499
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid google.caja Highest
Vendor pom groupid caja Highest
Vendor pom artifactid caja Low
Vendor pom url http://code.google.com/p/google-caja Highest
Vendor jar package name google Low
Vendor pom organization name Google High
Vendor jar package name caja Low
Vendor file name caja-r5054 High
Vendor pom name Caja High
Vendor pom description Caja is a HTML/CSS/JavaScript compiler which allows websites to safely embed web applications from third parties, and enables rich interaction between the embedding page and the embedded applications using an object-capability security model. Low
Vendor pom organization url http://www.google.com Medium
Product pom organization name Google Low
Product pom url http://code.google.com/p/google-caja Medium
Product pom organization url http://www.google.com Low
Product pom groupid google.caja Low
Product pom artifactid caja Highest
Product jar package name caja Low
Product file name caja-r5054 High
Product pom name Caja High
Product pom description Caja is a HTML/CSS/JavaScript compiler which allows websites to safely embed web applications from third parties, and enables rich interaction between the embedding page and the embedded applications using an object-capability security model. Low
Version pom version r5054 Highest
Version file version 5054 Medium
Version file name caja-r5054 Medium
maven: com.google.caja:caja:r5054
Confidence :High
htmlparser-r4209.jar
Description:
A patched version of the nu.validator v1.2.1 HTML parser.
License:
No Warranty
File Path: /home/ciagent/.m2/repository/caja/htmlparser/r4209/htmlparser-r4209.jar
MD5: 31c18bc52991e53ed4eaa28347c44189
SHA1: 0573217e5c9bf8fad6ce827a94191ca0f5785087
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid caja Highest
Vendor file name htmlparser-r4209 High
Vendor pom organization url http://validator.nu Medium
Vendor pom url http://code.google.com/p/google-caja Highest
Vendor pom artifactid htmlparser Low
Vendor pom name HtmlParser High
Vendor jar package name validator Low
Vendor jar package name nu Low
Vendor pom description
A patched version of the nu.validator v1.2.1 HTML parser.
Medium
Vendor pom organization name Validator.nu High
Vendor jar package name htmlparser Low
Product pom url http://code.google.com/p/google-caja Medium
Product pom artifactid htmlparser Highest
Product file name htmlparser-r4209 High
Product pom organization url http://validator.nu Low
Product pom name HtmlParser High
Product jar package name validator Low
Product pom description
A patched version of the nu.validator v1.2.1 HTML parser.
Medium
Product pom groupid caja Low
Product pom organization name Validator.nu Low
Product jar package name htmlparser Low
Version file version 4209 Medium
Version file name htmlparser-r4209 Medium
Version pom version r4209 Highest
maven: caja:htmlparser:r4209
Confidence :High
oauth-consumer-20090617.jar
File Path: /home/ciagent/.m2/repository/net/oauth/core/oauth-consumer/20090617/oauth-consumer-20090617.jar
MD5: f0e2849d152f4d8bf725aa4e11b8f969
SHA1: fb70a4c98119c27e78320c5e42a99f0b9eb7c356
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor pom groupid net.oauth.core Highest
Vendor pom artifactid oauth-consumer Low
Vendor pom name OAuth Core: Consumer High
Vendor jar package name client Low
Vendor jar package name oauth Low
Vendor pom parent-artifactid oauth-core-parent Low
Vendor file name oauth-consumer-20090617 High
Product pom parent-artifactid oauth-core-parent Medium
Product pom name OAuth Core: Consumer High
Product jar package name client Low
Product jar package name oauth Low
Product pom artifactid oauth-consumer Highest
Product pom groupid net.oauth.core Low
Product file name oauth-consumer-20090617 High
Version pom version 20090617 Highest
Version file version 20090617 Medium
maven: net.oauth.core:oauth-consumer:20090617
Confidence :High
oauth-httpclient4-20090913.jar
File Path: /home/ciagent/.m2/repository/net/oauth/core/oauth-httpclient4/20090913/oauth-httpclient4-20090913.jar
MD5: 577e1f28c28bc5006b8adcf838ffd46d
SHA1: a42f9135d3d72e77274982c4aa14fa0f4dab882f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor pom name OAuth Core: HttpClient4 High
Vendor pom groupid net.oauth.core Highest
Vendor jar package name client Low
Vendor jar package name oauth Low
Vendor pom parent-artifactid oauth-core-parent Low
Vendor pom artifactid oauth-httpclient4 Low
Vendor file name oauth-httpclient4-20090913 High
Product pom parent-artifactid oauth-core-parent Medium
Product jar package name httpclient4 Low
Product pom name OAuth Core: HttpClient4 High
Product jar package name client Low
Product jar package name oauth Low
Product pom artifactid oauth-httpclient4 Highest
Product pom groupid net.oauth.core Low
Product file name oauth-httpclient4-20090913 High
Version pom parent-version 20090913 Low
Version pom version 20090913 Highest
Version file name oauth-httpclient4-20090913 Medium
Version file version 4.20090913 Highest
maven: net.oauth.core:oauth-httpclient4:20090913
Confidence :High
oauth-provider-20100527.jar
File Path: /home/ciagent/.m2/repository/net/oauth/core/oauth-provider/20100527/oauth-provider-20100527.jar
MD5: afdc85d3f14481e4842c317c4f414f7e
SHA1: 165bfc97e63e5af8e052a47f4dee832ce06bf7d7
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name net Low
Vendor pom name OAuth Core: Provider High
Vendor file name oauth-provider-20100527 High
Vendor pom groupid net.oauth.core Highest
Vendor jar package name oauth Low
Vendor pom parent-artifactid oauth-core-parent Low
Vendor pom artifactid oauth-provider Low
Vendor central groupid net.oauth.core Highest
Product pom parent-artifactid oauth-core-parent Medium
Product pom name OAuth Core: Provider High
Product file name oauth-provider-20100527 High
Product jar package name oauth Low
Product pom artifactid oauth-provider Highest
Product pom groupid net.oauth.core Low
Product central artifactid oauth-provider Highest
Version file version 20100527 Medium
Version pom version 20100527 Highest
Version central version 20100527 Highest
guice-multibindings-3.0.jar
Description: Guice is a lightweight dependency injection framework for Java 5 and above
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/google/inject/extensions/guice-multibindings/3.0/guice-multibindings-3.0.jar
MD5: 4be1e91408e173eb10ed53a1a565a793
SHA1: 5e670615a927571234df68a8b1fe1a16272be555
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname com.google.inject.multibindings Medium
Vendor manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium
Vendor central groupid com.google.inject.extensions Highest
Vendor pom groupid com.google.inject.extensions Highest
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low
Vendor pom groupid google.inject.extensions Highest
Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low
Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low
Vendor pom name Google Guice - Extensions - MultiBindings High
Vendor pom artifactid guice-multibindings Low
Vendor pom parent-artifactid extensions-parent Low
Vendor file name guice-multibindings High
Vendor pom parent-groupid com.google.inject.extensions Medium
Product central artifactid guice-multibindings Highest
Product Manifest bundle-symbolicname com.google.inject.multibindings Medium
Product manifest Bundle-Description Guice is a lightweight dependency injection framework for Java 5 and above Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low
Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low
Product Manifest Bundle-Name guice-multibindings Medium
Product pom parent-artifactid extensions-parent Medium
Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low
Product pom name Google Guice - Extensions - MultiBindings High
Product pom parent-groupid com.google.inject.extensions Low
Product pom groupid google.inject.extensions Low
Product pom artifactid guice-multibindings Highest
Product file name guice-multibindings High
Version pom version 3.0 Highest
Version file version 3.0 Highest
Version central version 3.0 Highest
sanselan-0.97-incubator.jar
Description: Apache Sanselan is a pure-Java image library.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/sanselan/sanselan/0.97-incubator/sanselan-0.97-incubator.jar
MD5: 84f823e61d93fcedcb3c10a827c45989
SHA1: 8396778b076a2eaf62024b64f6d924e4e0095fca
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Apache Sanselan is a pure-Java image library. Medium
Vendor central groupid org.apache.sanselan Highest
Vendor pom parent-artifactid apache Low
Vendor pom organization url http://cwiki.apache.org/SANSELAN/ Medium
Vendor Manifest bundle-symbolicname org.apache.sanselan.sanselan Medium
Vendor manifest Bundle-Description Apache Sanselan is a pure-Java image library. Medium
Vendor pom name Apache Sanselan High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor file name sanselan High
Vendor Manifest bundle-docurl http://cwiki.apache.org/SANSELAN/ Low
Vendor pom url http://sanselan.apache.org/ Highest
Vendor pom groupid apache.sanselan Highest
Vendor pom groupid org.apache.sanselan Highest
Vendor pom artifactid sanselan Low
Vendor pom parent-groupid org.apache Medium
Product pom artifactid sanselan Highest
Product pom description Apache Sanselan is a pure-Java image library. Medium
Product central artifactid sanselan Highest
Product pom parent-groupid org.apache Low
Product pom groupid apache.sanselan Low
Product Manifest bundle-symbolicname org.apache.sanselan.sanselan Medium
Product Manifest Bundle-Name Apache Sanselan Medium
Product manifest Bundle-Description Apache Sanselan is a pure-Java image library. Medium
Product pom name Apache Sanselan High
Product pom parent-artifactid apache Medium
Product file name sanselan High
Product pom organization url http://cwiki.apache.org/SANSELAN/ Low
Product pom url http://sanselan.apache.org/ Medium
Product Manifest bundle-docurl http://cwiki.apache.org/SANSELAN/ Low
Product Manifest specification-title Apache Sanselan Medium
Product Manifest Implementation-Title Apache Sanselan High
Version Manifest Implementation-Version 0.97-incubator High
Version central version 0.97-incubator Highest
Version file version 0.97 Highest
Version pom version 0.97-incubator Highest
social-component-core-5.3.x-SNAPSHOT.jar
Description: eXo Social Core Component: People and Space
File Path: /home/ciagent/.m2/repository/org/exoplatform/social/social-component-core/5.3.x-SNAPSHOT/social-component-core-5.3.x-SNAPSHOT.jar
MD5: e316fbfba9fa30e37a9d370db43643f9
SHA1: cd72311e8b68d1ad544934b2e2f0ba33bcaed44d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.social Medium
Vendor pom name eXo PLF:: Social Core Component High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom groupid exoplatform.social Highest
Vendor Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-core Low
Vendor pom groupid org.exoplatform.social Highest
Vendor Manifest date 2019-05-24T10:23:51Z Low
Vendor file name social-component-core High
Vendor pom artifactid social-component-core Low
Vendor pom parent-artifactid social-component Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.social Medium
Vendor pom description eXo Social Core Component: People and Space Medium
Product file name social-component-core High
Product pom parent-groupid org.exoplatform.social Low
Product Manifest specification-title eXo PLF:: Social Core Component Medium
Product pom name eXo PLF:: Social Core Component High
Product pom groupid exoplatform.social Low
Product Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-core Low
Product pom artifactid social-component-core Highest
Product Manifest Implementation-Title eXo PLF:: Social Core Component High
Product pom parent-artifactid social-component Medium
Product Manifest date 2019-05-24T10:23:51Z Low
Product pom description eXo Social Core Component: People and Space Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.social:social-component-core:5.3.x-SNAPSHOT
Confidence :High
social-component-webui-5.3.x-SNAPSHOT.jar
Description: eXo Social Web UI Component
File Path: /home/ciagent/.m2/repository/org/exoplatform/social/social-component-webui/5.3.x-SNAPSHOT/social-component-webui-5.3.x-SNAPSHOT.jar
MD5: d5d875799fa1c7be83a5010d42ea56e5
SHA1: a1eac43938ba4e11dd95ad6e33f980b8c70e6b62
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.social Medium
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom artifactid social-component-webui Low
Vendor pom name eXo PLF:: Social Web UI Component High
Vendor pom groupid exoplatform.social Highest
Vendor file name social-component-webui High
Vendor pom groupid org.exoplatform.social Highest
Vendor pom description eXo Social Web UI Component Medium
Vendor Manifest date 2019-05-24T10:23:51Z Low
Vendor Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-webui Low
Vendor pom parent-artifactid social-component Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.social Medium
Product pom parent-groupid org.exoplatform.social Low
Product Manifest implementation-url https://projects.exoplatform.org/social/social-component/social-component-webui Low
Product pom groupid exoplatform.social Low
Product pom name eXo PLF:: Social Web UI Component High
Product file name social-component-webui High
Product Manifest Implementation-Title eXo PLF:: Social Web UI Component High
Product pom artifactid social-component-webui Highest
Product pom parent-artifactid social-component Medium
Product pom description eXo Social Web UI Component Medium
Product Manifest date 2019-05-24T10:23:51Z Low
Product Manifest specification-title eXo PLF:: Social Web UI Component Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.social:social-component-webui:5.3.x-SNAPSHOT
Confidence :High
flying-saucer-pdf-9.0.8.jar
Description: Flying Saucer is a CSS 2.1 renderer written in Java. This artifact supports PDF output.
License:
GNU Lesser General Public License (LGPL), version 2.1 or later: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ciagent/.m2/repository/org/xhtmlrenderer/flying-saucer-pdf/9.0.8/flying-saucer-pdf-9.0.8.jar
MD5: 7e9a77a1e8234ba5f1751376b7f152f9
SHA1: b7f04073f273918f81be38b1db1f3b2a93e7984b
Referenced In Projects/Scopes:
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.xhtmlrenderer Highest
Vendor file name flying-saucer-pdf High
Vendor pom parent-artifactid flying-saucer-parent Low
Vendor pom groupid xhtmlrenderer Highest
Vendor jar package name pdf Low
Vendor pom artifactid flying-saucer-pdf Low
Vendor pom parent-groupid org.xhtmlrenderer Medium
Vendor jar package name xhtmlrenderer Low
Vendor pom description Flying Saucer is a CSS 2.1 renderer written in Java. This artifact supports PDF output. Medium
Vendor central groupid org.xhtmlrenderer Highest
Vendor pom name Flying Saucer PDF Rendering High
Product pom parent-artifactid flying-saucer-parent Medium
Product central artifactid flying-saucer-pdf Highest
Product file name flying-saucer-pdf High
Product jar package name pdf Low
Product pom parent-groupid org.xhtmlrenderer Low
Product pom description Flying Saucer is a CSS 2.1 renderer written in Java. This artifact supports PDF output. Medium
Product pom groupid xhtmlrenderer Low
Product pom name Flying Saucer PDF Rendering High
Product pom artifactid flying-saucer-pdf Highest
Version pom version 9.0.8 Highest
Version file version 9.0.8 Highest
Version central version 9.0.8 Highest
bcmail-jdk15-1.45.jar
Description: The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. If the S/MIME API is used, the JavaMail API and the Java activation framework will also be needed.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcmail-jdk15/1.45/bcmail-jdk15-1.45.jar
MD5: 13321fc7eff7bcada7b4fedfb592025c
SHA1: 3aed7e642dd8d39dc14ed1dec3ff79e084637148
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.bouncycastle Highest
Vendor file name bcmail-jdk15 High
Vendor pom groupid bouncycastle Highest
Vendor pom name Bouncy Castle CMS and S/MIME API High
Vendor pom groupid org.bouncycastle Highest
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor Manifest extension-name org.bouncycastle.bcmail Medium
Vendor pom artifactid bcmail-jdk15 Low
Vendor pom description The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Product file name bcmail-jdk15 High
Product pom url http://www.bouncycastle.org/java.html Medium
Product central artifactid bcmail-jdk15 Highest
Product pom name Bouncy Castle CMS and S/MIME API High
Product Manifest extension-name org.bouncycastle.bcmail Medium
Product pom artifactid bcmail-jdk15 Highest
Product pom groupid bouncycastle Low
Product pom description The Bouncy Castle Java CMS and S/MIME APIs for handling the CMS and S/MIME protocols. This jar contains CMS and S/MIME APIs for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Version file version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version central version 1.45 Highest
Version pom version 1.45 Highest
bcprov-jdk15-1.45.jar
Description: The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bcprov-jdk15/1.45/bcprov-jdk15-1.45.jar
MD5: 2062f8e3d15748443ea60a94b266371c
SHA1: 7741883cb07b4634e8b5fd3337113b6ea770a9bb
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo PLF:: Wiki Renderer:compile
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.bouncycastle Highest
Vendor pom groupid bouncycastle Highest
Vendor pom name Bouncy Castle Provider High
Vendor pom groupid org.bouncycastle Highest
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor pom artifactid bcprov-jdk15 Low
Vendor file name bcprov-jdk15 High
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Vendor pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5. Low
Vendor Manifest extension-name org.bouncycastle.bcprovider Medium
Product pom artifactid bcprov-jdk15 Highest
Product pom url http://www.bouncycastle.org/java.html Medium
Product pom name Bouncy Castle Provider High
Product pom description The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5. Low
Product central artifactid bcprov-jdk15 Highest
Product Manifest extension-name org.bouncycastle.bcprovider Medium
Product pom groupid bouncycastle Low
Product file name bcprov-jdk15 High
Version file version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version central version 1.45 Highest
Version pom version 1.45 Highest
cpe: cpe:/a:bouncycastle:bouncy-castle-crypto-package:1.45
Confidence :Low
suppress
maven: org.bouncycastle:bcprov-jdk15:1.45 ✓
Confidence :Highest
cpe: cpe:/a:bouncycastle:bouncy_castle_crypto_package:1.45
Confidence :Low
suppress
Published Vulnerabilities
CVE-2015-7940 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
Vulnerable Software & Versions: (show all )
bctsp-jdk15-1.45.jar
Description: The Bouncy Castle Java API for handling the Time Stamp Protocol (TSP). This jar contains the TSP API for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs.
License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html
File Path: /home/ciagent/.m2/repository/org/bouncycastle/bctsp-jdk15/1.45/bctsp-jdk15-1.45.jar
MD5: 84a2c3383fc991fb9d3902e723d96b7a
SHA1: 60647c99cbcd06b27987cb07643fb68b10c2eb74
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Service:runtime
eXo Wiki JPA Migration Service:runtime
eXo PLF:: Wiki Upgrade Plugins:runtime
eXo Wiki JPA DAO:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor central groupid org.bouncycastle Highest
Vendor pom description The Bouncy Castle Java API for handling the Time Stamp Protocol (TSP). This jar contains the TSP API for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Vendor pom groupid bouncycastle Highest
Vendor pom groupid org.bouncycastle Highest
Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium
Vendor pom artifactid bctsp-jdk15 Low
Vendor file name bctsp-jdk15 High
Vendor Manifest extension-name org.bouncycastle.bctsp Medium
Vendor pom url http://www.bouncycastle.org/java.html Highest
Vendor Manifest specification-vendor BouncyCastle.org Low
Vendor Manifest Implementation-Vendor BouncyCastle.org High
Vendor pom name Bouncy Castle OpenPGP API High
Product pom description The Bouncy Castle Java API for handling the Time Stamp Protocol (TSP). This jar contains the TSP API for JDK 1.5. The APIs can be used in conjunction with a JCE/JCA provider ... Low
Product pom url http://www.bouncycastle.org/java.html Medium
Product central artifactid bctsp-jdk15 Highest
Product pom groupid bouncycastle Low
Product pom artifactid bctsp-jdk15 Highest
Product file name bctsp-jdk15 High
Product Manifest extension-name org.bouncycastle.bctsp Medium
Product pom name Bouncy Castle OpenPGP API High
Version file version 1.45 Highest
Version Manifest Implementation-Version 1.45.0 High
Version central version 1.45 Highest
Version pom version 1.45 Highest
jsr250-api-1.0.jar
Description: JSR-250 Reference Implementation by Glassfish
License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html
File Path: /home/ciagent/.m2/repository/javax/annotation/jsr250-api/1.0/jsr250-api-1.0.jar
MD5: 4cd56b2e4977e541186de69f5126b4a6
SHA1: 5025422767732a1ab45d93abfea846513d742dcf
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Highest
Vendor pom name JSR-250 Common Annotations for the JavaTM Platform High
Vendor jar package name annotation Low
Vendor jar package name javax Low
Vendor file name jsr250-api High
Vendor pom description JSR-250 Reference Implementation by Glassfish Medium
Vendor pom groupid javax.annotation Highest
Vendor central groupid javax.annotation Highest
Vendor pom artifactid jsr250-api Low
Product pom artifactid jsr250-api Highest
Product central artifactid jsr250-api Highest
Product pom name JSR-250 Common Annotations for the JavaTM Platform High
Product jar package name annotation Low
Product pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Medium
Product file name jsr250-api High
Product pom groupid javax.annotation Low
Product pom description JSR-250 Reference Implementation by Glassfish Medium
Version file version 1.0 Highest
Version central version 1.0 Highest
Version pom version 1.0 Highest
bayeux-api-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/bayeux-api/3.0.8/bayeux-api-3.0.8.jar
MD5: a09842b7f274cefffa408299b5fc8dd0
SHA1: d5aceb0e7fef4a140f7e95be48338b97723d3163
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor pom name CometD :: Bayeux API High
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor file name bayeux-api High
Vendor Manifest bundle-symbolicname bayeux-api Medium
Vendor pom parent-artifactid cometd-java Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom artifactid bayeux-api Low
Vendor pom groupid org.cometd.java Highest
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/bayeux-api Low
Product pom name CometD :: Bayeux API High
Product central artifactid bayeux-api Highest
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product file name bayeux-api High
Product Manifest bundle-symbolicname bayeux-api Medium
Product Manifest Bundle-Name CometD :: Bayeux API Medium
Product pom parent-artifactid cometd-java Medium
Product pom artifactid bayeux-api Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/bayeux-api Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-common-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-common/3.0.8/cometd-java-common-3.0.8.jar
MD5: 70c7cc13ecc20634a6b357e33134d551
SHA1: 5e2134a1b3bc6e03b7e1666a74e9993d0bb52a7d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-symbolicname cometd-java-common Medium
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom name CometD :: Java :: Bayeux Common High
Vendor pom parent-artifactid cometd-java Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom artifactid cometd-java-common Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-common Low
Vendor file name cometd-java-common High
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Product pom artifactid cometd-java-common Highest
Product central artifactid cometd-java-common Highest
Product Manifest bundle-symbolicname cometd-java-common Medium
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest Bundle-Name CometD :: Java :: Bayeux Common Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom name CometD :: Java :: Bayeux Common High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-common Low
Product pom parent-artifactid cometd-java Medium
Product file name cometd-java-common High
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-websocket-javax-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-javax-server/3.0.8/cometd-java-websocket-javax-server-3.0.8.jar
MD5: afa5e80138d48292a6f93b708257d2fc
SHA1: 353860f809886a58c181dd9e273ee7b79e133277
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname cometd-java-websocket-javax-server Medium
Vendor central groupid org.cometd.java Highest
Vendor file name cometd-java-websocket-javax-server High
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-server Low
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom name CometD :: Java :: WebSocket :: JSR 356 Server High
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Vendor pom artifactid cometd-java-websocket-javax-server Low
Product Manifest bundle-symbolicname cometd-java-websocket-javax-server Medium
Product file name cometd-java-websocket-javax-server High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-server Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: JSR 356 Server Medium
Product pom artifactid cometd-java-websocket-javax-server Highest
Product central artifactid cometd-java-websocket-javax-server Highest
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom name CometD :: Java :: WebSocket :: JSR 356 Server High
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-websocket-common-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-common-server/3.0.8/cometd-java-websocket-common-server-3.0.8.jar
MD5: 5772b2360cec4ff610e62151fb4deb62
SHA1: 61538a1231b700bf045fa197514f63509960985e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor pom artifactid cometd-java-websocket-common-server Low
Vendor pom groupid cometd.java Highest
Vendor file name cometd-java-websocket-common-server High
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-server Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest bundle-symbolicname cometd-java-websocket-common-server Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Vendor pom name CometD :: Java :: WebSocket :: Common Server High
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: Common Server Medium
Product file name cometd-java-websocket-common-server High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-server Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest bundle-symbolicname cometd-java-websocket-common-server Medium
Product central artifactid cometd-java-websocket-common-server Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom artifactid cometd-java-websocket-common-server Highest
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom name CometD :: Java :: WebSocket :: Common Server High
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-annotations-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-annotations/3.0.8/cometd-java-annotations-3.0.8.jar
MD5: 98b60697675562cf957655c3239a1ad3
SHA1: 5b56875b2ac024b5666633596abb90702ec35e81
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-symbolicname cometd-java-annotations Medium
Vendor central groupid org.cometd.java Highest
Vendor pom name CometD :: Java :: Annotations High
Vendor file name cometd-java-annotations High
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-artifactid cometd-java Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom artifactid cometd-java-annotations Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-annotations Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Product Manifest bundle-symbolicname cometd-java-annotations Medium
Product pom name CometD :: Java :: Annotations High
Product file name cometd-java-annotations High
Product pom artifactid cometd-java-annotations Highest
Product Manifest Bundle-Name CometD :: Java :: Annotations Medium
Product central artifactid cometd-java-annotations Highest
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-annotations Low
Product pom parent-artifactid cometd-java Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
jetty-io-9.2.14.v20151106.jar
Description: Administrative parent pom for Jetty modules
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-io/9.2.14.v20151106/jetty-io-9.2.14.v20151106.jar
MD5: 94d0e857144c7615b6fd65019cd32b59
SHA1: dfa4137371a3f08769820138ca1a2184dacda267
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor manifest Bundle-Description Administrative parent pom for Jetty modules Medium
Vendor pom name Jetty :: IO Utility High
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor pom parent-artifactid jetty-project Low
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor pom groupid eclipse.jetty Highest
Vendor pom artifactid jetty-io Low
Vendor pom groupid org.eclipse.jetty Highest
Vendor file name jetty-io High
Vendor Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Vendor Manifest bundle-docurl http://www.eclipse.org/jetty Low
Vendor central groupid org.eclipse.jetty Highest
Vendor Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Vendor pom parent-groupid org.eclipse.jetty Medium
Vendor pom url http://www.eclipse.org/jetty Highest
Product central artifactid jetty-io Highest
Product pom groupid eclipse.jetty Low
Product pom url http://www.eclipse.org/jetty Medium
Product pom artifactid jetty-io Highest
Product manifest Bundle-Description Administrative parent pom for Jetty modules Medium
Product pom name Jetty :: IO Utility High
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product Manifest url http://www.eclipse.org/jetty Low
Product Manifest Bundle-Name Jetty :: IO Utility Medium
Product pom parent-groupid org.eclipse.jetty Low
Product file name jetty-io High
Product Manifest bundle-symbolicname org.eclipse.jetty.io Medium
Product pom parent-artifactid jetty-project Medium
Product Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Version file version 9.2.14.v20151106 Highest
Version central version 9.2.14.v20151106 Highest
Version Manifest Implementation-Version 9.2.14.v20151106 High
Version pom version 9.2.14.v20151106 Highest
cometd-java-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-client/3.0.8/cometd-java-client-3.0.8.jar
MD5: 24f1367fb4d96fe70a3f07a1f48e447e
SHA1: 826d4ae9402e7c48cc98fe287389788134e4986f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor pom name CometD :: Java :: Bayeux Client High
Vendor pom groupid cometd.java Highest
Vendor pom artifactid cometd-java-client Low
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-client Low
Vendor file name cometd-java-client High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor Manifest bundle-symbolicname cometd-java-client Medium
Vendor pom parent-artifactid cometd-java Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Product pom name CometD :: Java :: Bayeux Client High
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-client Low
Product file name cometd-java-client High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product pom artifactid cometd-java-client Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest bundle-symbolicname cometd-java-client Medium
Product central artifactid cometd-java-client Highest
Product pom parent-artifactid cometd-java Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest Bundle-Name CometD :: Java :: Bayeux Client Medium
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-websocket-common-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-common-client/3.0.8/cometd-java-websocket-common-client-3.0.8.jar
MD5: c17616c290c54ffc4a70dda2b901919a
SHA1: 8b75f11de5bba306d0bcb20a6c1bed89675579cd
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-client Low
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-symbolicname cometd-java-websocket-common-client Medium
Vendor file name cometd-java-websocket-common-client High
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom name CometD :: Java :: WebSocket :: Common Client High
Vendor pom parent-groupid org.cometd.java Medium
Vendor pom artifactid cometd-java-websocket-common-client Low
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Product pom artifactid cometd-java-websocket-common-client Highest
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-common-client Low
Product central artifactid cometd-java-websocket-common-client Highest
Product Manifest bundle-symbolicname cometd-java-websocket-common-client Medium
Product file name cometd-java-websocket-common-client High
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product pom parent-artifactid cometd-java-websocket Medium
Product pom name CometD :: Java :: WebSocket :: Common Client High
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: Common Client Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-websocket-javax-client-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-websocket-javax-client/3.0.8/cometd-java-websocket-javax-client-3.0.8.jar
MD5: 433dd449f689697bbe1a75b0ed2788f8
SHA1: b44bcf098667f0112301d75f73adb5ba3295699d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-symbolicname cometd-java-websocket-javax-client Medium
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-client Low
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom parent-artifactid cometd-java-websocket Low
Vendor pom artifactid cometd-java-websocket-javax-client Low
Vendor file name cometd-java-websocket-javax-client High
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Vendor pom name CometD :: Java :: WebSocket :: JSR 356 Client High
Product central artifactid cometd-java-websocket-javax-client Highest
Product pom artifactid cometd-java-websocket-javax-client Highest
Product Manifest bundle-symbolicname cometd-java-websocket-javax-client Medium
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-websocket/cometd-java-websocket-javax-client Low
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest Bundle-Name CometD :: Java :: WebSocket :: JSR 356 Client Medium
Product pom parent-artifactid cometd-java-websocket Medium
Product file name cometd-java-websocket-javax-client High
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom name CometD :: Java :: WebSocket :: JSR 356 Client High
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
cometd-java-oort-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-oort/3.0.8/cometd-java-oort-3.0.8.jar
MD5: 62dbbecedab27927495fc9c9e0b70505
SHA1: a72695546e010c250ba65519fc91867b208fc8f9
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor pom name CometD :: Java :: Oort High
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-oort Low
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor file name cometd-java-oort High
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid cometd-java-oort Low
Vendor pom parent-artifactid cometd-java Low
Vendor pom parent-groupid org.cometd.java Medium
Vendor Manifest bundle-symbolicname cometd-java-oort Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Product pom name CometD :: Java :: Oort High
Product pom artifactid cometd-java-oort Highest
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-oort Low
Product central artifactid cometd-java-oort Highest
Product Manifest bundle-docurl http://docs.cometd.org Low
Product file name cometd-java-oort High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest bundle-symbolicname cometd-java-oort Medium
Product pom parent-artifactid cometd-java Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product Manifest Bundle-Name CometD :: Java :: Oort Medium
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
jetty-jmx-9.2.14.v20151106.jar
Description: JMX management artifact for jetty.
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-jmx/9.2.14.v20151106/jetty-jmx-9.2.14.v20151106.jar
MD5: 5eccc25d22921cb4787812d0687a2978
SHA1: 617edc5e966b4149737811ef8b289cd94b831bab
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor pom name Jetty :: JMX Management High
Vendor Manifest Implementation-Vendor Eclipse.org - Jetty High
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Vendor manifest Bundle-Description JMX management artifact for jetty. Medium
Vendor pom parent-artifactid jetty-project Low
Vendor Manifest url http://www.eclipse.org/jetty Low
Vendor pom groupid eclipse.jetty Highest
Vendor Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Vendor pom groupid org.eclipse.jetty Highest
Vendor file name jetty-jmx High
Vendor Manifest bundle-docurl http://www.eclipse.org/jetty Low
Vendor central groupid org.eclipse.jetty Highest
Vendor pom artifactid jetty-jmx Low
Vendor Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Vendor pom parent-groupid org.eclipse.jetty Medium
Vendor pom description JMX management artifact for jetty. Medium
Vendor pom url http://www.eclipse.org/jetty Highest
Product pom artifactid jetty-jmx Highest
Product pom name Jetty :: JMX Management High
Product pom groupid eclipse.jetty Low
Product pom url http://www.eclipse.org/jetty Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.7 Low
Product manifest Bundle-Description JMX management artifact for jetty. Medium
Product central artifactid jetty-jmx Highest
Product Manifest url http://www.eclipse.org/jetty Low
Product Manifest bundle-symbolicname org.eclipse.jetty.jmx Medium
Product pom parent-groupid org.eclipse.jetty Low
Product file name jetty-jmx High
Product pom parent-artifactid jetty-project Medium
Product Manifest bundle-docurl http://www.eclipse.org/jetty Low
Product Manifest Bundle-Name Jetty :: JMX Management Medium
Product Manifest bundle-copyright Copyright (c) 2008-2014 Mort Bay Consulting Pty. Ltd. Low
Product pom description JMX management artifact for jetty. Medium
Version file version 9.2.14.v20151106 Highest
Version central version 9.2.14.v20151106 Highest
Version Manifest Implementation-Version 9.2.14.v20151106 High
Version pom version 9.2.14.v20151106 Highest
Related Dependencies
jetty-util-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-util/9.2.14.v20151106/jetty-util-9.2.14.v20151106.jar
SHA1: 0057e00b912ae0c35859ac81594a996007706a0b
MD5: 15eae2dc1689fa8c72652b156d2619d3
maven: org.eclipse.jetty:jetty-util:9.2.14.v20151106 ✓
jetty-client-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-client/9.2.14.v20151106/jetty-client-9.2.14.v20151106.jar
SHA1: d02985c3a5bd974dacbb4c3d7cf71169135a8e7a
MD5: c400f74ab61fc17fafd19144b548bede
maven: org.eclipse.jetty:jetty-client:9.2.14.v20151106 ✓
jetty-http-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-http/9.2.14.v20151106/jetty-http-9.2.14.v20151106.jar
SHA1: 699ad1f2fa6fb0717e1b308a8c9e1b8c69d81ef6
MD5: 2e42ff59b2a5e8525f0fa1b55351d161
maven: org.eclipse.jetty:jetty-http:9.2.14.v20151106 ✓
jetty-util-ajax-9.2.14.v20151106.jar
File Path: /home/ciagent/.m2/repository/org/eclipse/jetty/jetty-util-ajax/9.2.14.v20151106/jetty-util-ajax-9.2.14.v20151106.jar
SHA1: 13470555681de54a10cfed3ab15b1554765d1171
MD5: 1623fc2d77b1bd864a2416e2da15cd9b
maven: org.eclipse.jetty:jetty-util-ajax:9.2.14.v20151106 ✓
Published Vulnerabilities
CVE-2017-7656 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-284 Improper Access Control
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was accepted and treated as a 0.9 request. If deployed behind an intermediary that also accepted and passed through the 0.9 version (but did not act on it), then the response sent could be interpreted by the intermediary as HTTP/1 headers. This could be used to poison the cache if the server allowed the origin client to generate arbitrary content in the response.
Vulnerable Software & Versions: (show all )
CVE-2017-7657 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-190 Integer Overflow or Wraparound
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk size and content sent as chunk body could be interpreted as a pipelined request. If Jetty was deployed behind an intermediary that imposed some authorization and that intermediary allowed arbitrarily large chunks to be passed on unchanged, then this flaw could be used to bypass the authorization imposed by the intermediary as the fake pipelined request would not be interpreted by the intermediary as a request.
Vulnerable Software & Versions: (show all )
CVE-2017-7658 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-19 Data Handling
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC 2616). If an intermediary decided on the shorter length, but still passed on the longer body, then body content could be interpreted by Jetty as a pipelined request. If the intermediary was imposing authorization, the fake pipelined request would bypass that authorization.
Vulnerable Software & Versions: (show all )
CVE-2017-9735 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
Vulnerable Software & Versions:
cometd-java-server-3.0.8.jar
Description: The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques
License:
http://www.apache.org/licenses/LICENSE-2.0, http://www.opensource.org/licenses/bsd-license.html, http://opensource-definition.org/licenses/afl-2.1.html
File Path: /home/ciagent/.m2/repository/org/cometd/java/cometd-java-server/3.0.8/cometd-java-server-3.0.8.jar
MD5: c55eb617762fad72683da9de856e008c
SHA1: 11d535c657bdb491abc2ccd820118f9d6a8f44e0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid org.cometd.java Highest
Vendor pom groupid cometd.java Highest
Vendor Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-server Low
Vendor Manifest bundle-symbolicname cometd-java-server Medium
Vendor Manifest bundle-docurl http://docs.cometd.org Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom artifactid cometd-java-server Low
Vendor pom parent-artifactid cometd-java Low
Vendor file name cometd-java-server High
Vendor pom parent-groupid org.cometd.java Medium
Vendor manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Vendor pom groupid org.cometd.java Highest
Vendor pom name CometD :: Java :: Bayeux Server High
Product central artifactid cometd-java-server Highest
Product pom artifactid cometd-java-server Highest
Product Manifest bundle-contactaddress http://cometd.org/cometd-java/cometd-java-server Low
Product Manifest bundle-symbolicname cometd-java-server Medium
Product Manifest bundle-docurl http://docs.cometd.org Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product file name cometd-java-server High
Product pom parent-artifactid cometd-java Medium
Product manifest Bundle-Description The CometD project is a scalable web messaging bus that uses WebSocketand HTTP AJAX push technology patterns known as "Comet" techniques Low
Product pom groupid cometd.java Low
Product pom parent-groupid org.cometd.java Low
Product pom name CometD :: Java :: Bayeux Server High
Product Manifest Bundle-Name CometD :: Java :: Bayeux Server Medium
Version file version 3.0.8 Highest
Version central version 3.0.8 Highest
Version pom version 3.0.8 Highest
commons-comet-service-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-comet-service/5.3.x-SNAPSHOT/commons-comet-service-5.3.x-SNAPSHOT.jar
MD5: 7c020a92d3114dc217efa8f161b3738a
SHA1: 24540f023fd116f3ccf2ef430b9dffb38a1b90ed
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-comet-service Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid commons-comet-service Low
Vendor pom name eXo PLF:: Commons - Comet Services High
Vendor pom groupid org.exoplatform.commons Highest
Vendor file name commons-comet-service High
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-comet-service Low
Product pom name eXo PLF:: Commons - Comet Services High
Product pom groupid exoplatform.commons Low
Product file name commons-comet-service High
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product pom artifactid commons-comet-service Highest
Product Manifest Implementation-Title eXo PLF:: Commons - Comet Services High
Product Manifest specification-title eXo PLF:: Commons - Comet Services Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-comet-service:5.3.x-SNAPSHOT
Confidence :High
aspectjrt-1.8.8.jar
Description: The runtime needed to execute a program using AspectJ
License:
Eclipse Public License - v 1.0: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/ciagent/.m2/repository/org/aspectj/aspectjrt/1.8.8/aspectjrt-1.8.8.jar
MD5: 2e448cd7ae0bdc357cb2b6e892ba9c9d
SHA1: 7c5b26f24375685e34a50c2d765ebc40a96a5280
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.aspectj Highest
Vendor pom url http://www.aspectj.org Highest
Vendor pom name AspectJ runtime High
Vendor pom description The runtime needed to execute a program using AspectJ Medium
Vendor file name aspectjrt High
Vendor central groupid org.aspectj Highest
Vendor pom artifactid aspectjrt Low
Vendor pom groupid aspectj Highest
Vendor manifest: org/aspectj/lang/ Implementation-Vendor aspectj.org Medium
Product pom name AspectJ runtime High
Product pom description The runtime needed to execute a program using AspectJ Medium
Product pom url http://www.aspectj.org Medium
Product central artifactid aspectjrt Highest
Product file name aspectjrt High
Product manifest: org/aspectj/lang/ Specification-Title AspectJ Runtime Classes Medium
Product manifest: org/aspectj/lang/ Implementation-Title org.aspectj.tools Medium
Product pom groupid aspectj Low
Product pom artifactid aspectjrt Highest
Version central version 1.8.8 Highest
Version pom version 1.8.8 Highest
Version file version 1.8.8 Highest
c3p0-0.9.1.1.jar
Description:
c3p0 is an easy-to-use library for augmenting traditional (DriverManager-based) JDBC drivers with JNDI-bindable DataSources,
including DataSources that implement Connection and Statement Pooling, as described by the jdbc3 spec and jdbc2 std extension.
License:
GNU LESSER GENERAL PUBLIC LICENSE: http://www.gnu.org/licenses/lgpl.txt
File Path: /home/ciagent/.m2/repository/c3p0/c3p0/0.9.1.1/c3p0-0.9.1.1.jar
MD5: 640c58226e7bb6beacc8ac3f6bb533d1
SHA1: 302704f30c6e7abb7a0457f7771739e03c973e80
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid c3p0 Highest
Vendor pom name c3p0:JDBC DataSources/Resource Pools High
Vendor file name c3p0 High
Vendor central groupid c3p0 Highest
Vendor Manifest Implementation-Vendor-Id com.mchange Medium
Vendor Manifest extension-name com.mchange.v2.c3p0 Medium
Vendor Manifest Implementation-Vendor Machinery For Change, Inc. High
Vendor Manifest specification-vendor Machinery For Change, Inc. Low
Vendor pom url http://c3p0.sourceforge.net Highest
Vendor pom description c3p0 is an easy-to-use library for augmenting traditional (DriverManager-based) JDBC drivers with JNDI-bindable DataSources, including DataSources that implement Connection and Statement Pooling, as described by the jdbc3 spec and jdbc2 std extension. Low
Vendor pom artifactid c3p0 Low
Product pom name c3p0:JDBC DataSources/Resource Pools High
Product central artifactid c3p0 Highest
Product file name c3p0 High
Product pom url http://c3p0.sourceforge.net Medium
Product pom groupid c3p0 Low
Product pom artifactid c3p0 Highest
Product Manifest extension-name com.mchange.v2.c3p0 Medium
Product pom description c3p0 is an easy-to-use library for augmenting traditional (DriverManager-based) JDBC drivers with JNDI-bindable DataSources, including DataSources that implement Connection and Statement Pooling, as described by the jdbc3 spec and jdbc2 std extension. Low
Version pom version 0.9.1.1 Highest
Version file version 0.9.1.1 Highest
Version central version 0.9.1.1 Highest
Version Manifest Implementation-Version 0.9.1.1 High
Published Vulnerabilities
CVE-2019-5427 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-399 Resource Management Errors
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Vulnerable Software & Versions: (show all )
quartz-2.2.2.jar
Description: Enterprise Job Scheduler
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
Apache Software License, Version 2.0
File Path: /home/ciagent/.m2/repository/org/quartz-scheduler/quartz/2.2.2/quartz-2.2.2.jar
MD5: 6acfd6ada2f4ad0abf4de916654dcaea
SHA1: 6fd24da6803ab7c3a08bc519a62219a9bebeb0df
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.quartz-scheduler Medium
Vendor Manifest buildinfo-host tc-c65-jenkins-slave-001.eur.ad.sag Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor pom artifactid quartz Low
Vendor manifest terracotta-description Enterprise Job Scheduler Medium
Vendor pom parent-artifactid quartz-parent Low
Vendor manifest Bundle-Description Enterprise Job Scheduler Medium
Vendor Manifest buildinfo-revision 2464 Low
Vendor file name quartz High
Vendor Manifest bundle-symbolicname org.quartz-scheduler.quartz Medium
Vendor Manifest buildinfo-url https://svn.terracotta.org/repo/quartz/tags/quartz-2.2.2 Low
Vendor Manifest terracotta-name quartz Medium
Vendor Manifest buildinfo-user jenkins-slave Low
Vendor central groupid org.quartz-scheduler Highest
Vendor pom groupid quartz-scheduler Highest
Vendor Manifest bundle-docurl http://www.terracotta.org Low
Vendor pom groupid org.quartz-scheduler Highest
Vendor pom description Enterprise Job Scheduler Medium
Vendor pom name quartz High
Vendor Manifest buildinfo-timestamp 20151012-045213 Low
Product Manifest buildinfo-host tc-c65-jenkins-slave-001.eur.ad.sag Low
Product pom groupid quartz-scheduler Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product pom parent-groupid org.quartz-scheduler Low
Product manifest terracotta-description Enterprise Job Scheduler Medium
Product manifest Bundle-Description Enterprise Job Scheduler Medium
Product Manifest buildinfo-revision 2464 Low
Product file name quartz High
Product Manifest bundle-symbolicname org.quartz-scheduler.quartz Medium
Product pom artifactid quartz Highest
Product Manifest buildinfo-url https://svn.terracotta.org/repo/quartz/tags/quartz-2.2.2 Low
Product Manifest terracotta-name quartz Medium
Product Manifest buildinfo-user jenkins-slave Low
Product central artifactid quartz Highest
Product Manifest bundle-docurl http://www.terracotta.org Low
Product pom description Enterprise Job Scheduler Medium
Product pom parent-artifactid quartz-parent Medium
Product pom name quartz High
Product Manifest Bundle-Name quartz Medium
Product Manifest buildinfo-timestamp 20151012-045213 Low
Version pom version 2.2.2 Highest
Version central version 2.2.2 Highest
Version file version 2.2.2 Highest
owasp-java-html-sanitizer-20160413.1.jar
File Path: /home/ciagent/.m2/repository/com/googlecode/owasp-java-html-sanitizer/owasp-java-html-sanitizer/20160413.1/owasp-java-html-sanitizer-20160413.1.jar
MD5: f2dbfedbd7bea844cedc1fc1e95fca80
SHA1: 61780b5d65c39013d733b70b2d2968f72f83aa0a
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor jar package name owasp Low
Vendor pom parent-groupid com.googlecode.owasp-java-html-sanitizer Medium
Vendor jar package name html Low
Vendor pom groupid com.googlecode.owasp-java-html-sanitizer Highest
Vendor pom parent-artifactid parent Low
Vendor pom artifactid owasp-java-html-sanitizer Low
Vendor file name owasp-java-html-sanitizer High
Vendor pom name OWASP Java HTML Sanitizer High
Vendor pom groupid googlecode.owasp-java-html-sanitizer Highest
Vendor central groupid com.googlecode.owasp-java-html-sanitizer Highest
Product pom parent-artifactid parent Medium
Product jar package name html Low
Product pom parent-groupid com.googlecode.owasp-java-html-sanitizer Low
Product pom groupid googlecode.owasp-java-html-sanitizer Low
Product central artifactid owasp-java-html-sanitizer Highest
Product pom artifactid owasp-java-html-sanitizer Highest
Product file name owasp-java-html-sanitizer High
Product pom name OWASP Java HTML Sanitizer High
Version pom version 20160413.1 Highest
Version file version 20160413.1 Highest
Version central version 20160413.1 Highest
jrcs.diff-0.4.2.jar
File Path: /home/ciagent/.m2/repository/org/suigeneris/jrcs.diff/0.4.2/jrcs.diff-0.4.2.jar
MD5: a05e71b59b7099da7844fd3b5f38e299
SHA1: 6e8eea2281426cd791a64b348c0932c88b966f39
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor jar package name jrcs Low
Vendor central groupid org.jvnet.hudson Highest
Vendor pom artifactid jrcs.diff Low
Vendor pom groupid org.suigeneris Highest
Vendor jar package name suigeneris Low
Vendor file name jrcs.diff High
Vendor jar package name diff Low
Vendor pom groupid suigeneris Highest
Product jar package name jrcs Low
Product pom artifactid jrcs.diff Highest
Product pom groupid suigeneris Low
Product file name jrcs.diff High
Product central artifactid org.suigeneris.jrcs.diff Highest
Product jar package name diff Low
Version central version 0.4.2 Highest
Version file version 0.4.2 Highest
Version pom version 0.4.2 Highest
ecs-1.4.2.jar
File Path: /home/ciagent/.m2/repository/ecs/ecs/1.4.2/ecs-1.4.2.jar
MD5: 62d53be190ca9cbfe01bec9fc3396934
SHA1: f9bc5fdde56d60876c1785087ce2a301b4e4a676
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor jar package name ecs Low
Vendor pom groupid ecs Highest
Vendor pom artifactid ecs Low
Vendor central groupid ecs Highest
Vendor file name ecs High
Vendor jar package name apache Low
Product pom artifactid ecs Highest
Product jar package name ecs Low
Product central artifactid ecs Highest
Product pom groupid ecs Low
Product file name ecs High
Version pom version 1.4.2 Highest
Version central version 1.4.2 Highest
Version file version 1.4.2 Highest
liquibase-core-3.4.2.jar
File Path: /home/ciagent/.m2/repository/org/liquibase/liquibase-core/3.4.2/liquibase-core-3.4.2.jar
MD5: d4ad6d5f7958b69b8fbd01a5564ae45b
SHA1: c91ccf342466857251cf6795b0cecc42509206f2
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid liquibase-parent Low
Vendor pom artifactid liquibase-core Low
Vendor pom groupid org.liquibase Highest
Vendor pom name Liquibase Core High
Vendor central groupid org.liquibase Highest
Vendor file name liquibase-core High
Vendor pom groupid liquibase Highest
Vendor jar package name liquibase Low
Vendor pom parent-groupid org.liquibase Medium
Product pom name Liquibase Core High
Product pom artifactid liquibase-core Highest
Product file name liquibase-core High
Product pom parent-artifactid liquibase-parent Medium
Product pom parent-groupid org.liquibase Low
Product pom groupid liquibase Low
Product central artifactid liquibase-core Highest
Version central version 3.4.2 Highest
Version file version 3.4.2 Highest
Version pom version 3.4.2 Highest
stax2-api-3.1.4.jar
Description: tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API.
License:
The BSD License: http://www.opensource.org/licenses/bsd-license.php
File Path: /home/ciagent/.m2/repository/org/codehaus/woodstox/stax2-api/3.1.4/stax2-api-3.1.4.jar
MD5: c08e89de601b0a78f941b2c29db565c3
SHA1: ac19014b1e6a7c08aad07fe114af792676b685b7
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.codehaus.woodstox Highest
Vendor pom groupid codehaus.woodstox Highest
Vendor pom organization url http://fasterxml.com Medium
Vendor Manifest bundle-symbolicname stax2-api Medium
Vendor pom url http://wiki.fasterxml.com/WoodstoxStax2 Highest
Vendor manifest Bundle-Description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low
Vendor pom description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low
Vendor Manifest bundle-docurl http://fasterxml.com Low
Vendor file name stax2-api High
Vendor pom name Stax2 API High
Vendor pom groupid org.codehaus.woodstox Highest
Vendor pom artifactid stax2-api Low
Vendor pom organization name fasterxml.com High
Product pom artifactid stax2-api Highest
Product pom groupid codehaus.woodstox Low
Product central artifactid stax2-api Highest
Product Manifest bundle-symbolicname stax2-api Medium
Product Manifest Bundle-Name Stax2 API Medium
Product manifest Bundle-Description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low
Product pom description tax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API. Low
Product Manifest bundle-docurl http://fasterxml.com Low
Product pom organization name fasterxml.com Low
Product pom organization url http://fasterxml.com Low
Product file name stax2-api High
Product pom name Stax2 API High
Product pom url http://wiki.fasterxml.com/WoodstoxStax2 Medium
Version pom version 3.1.4 Highest
Version file version 3.1.4 Highest
Version central version 3.1.4 Highest
jackson-dataformat-xml-2.4.2.jar
Description: Data format extension for Jackson (http://jackson.codehaus.org) to offer
alternative support for serializing POJOs as XML and deserializing XML as pojos.
Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types like JsonGenerator, JsonParser and JsonFactory.
Some data-binding types overridden as well (ObjectMapper sub-classed as XmlMapper).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-xml/2.4.2/jackson-dataformat-xml-2.4.2.jar
MD5: 1fa55358af6a1364e72e24d9ca4d58e7
SHA1: 02f2d96f68b2d3475452d95dde7a3fbee225f6ae
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium
Vendor manifest Bundle-Description Data format extension for Jackson (http://jackson.codehaus.org) to offeralternative support for serializing POJOs as XML and deserializing XML as pojos.Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types ... Low
Vendor central groupid com.fasterxml.jackson.dataformat Highest
Vendor pom groupid com.fasterxml.jackson.dataformat Highest
Vendor file name jackson-dataformat-xml High
Vendor pom url http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding Highest
Vendor Manifest implementation-build-date 2014-08-15 18:38:26-0700 Low
Vendor pom groupid fasterxml.jackson.dataformat Highest
Vendor pom name Jackson-dataformat-XML High
Vendor pom artifactid jackson-dataformat-xml Low
Vendor Manifest Implementation-Vendor FasterXML High
Vendor pom parent-artifactid jackson-parent Low
Vendor pom description Data format extension for Jackson (http://jackson.codehaus.org) to offer
alternative support for serializing POJOs as XML and deserializing XML as pojos.
Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types ... Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-xml Medium
Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding Low
Product Manifest Bundle-Name Jackson-dataformat-XML Medium
Product manifest Bundle-Description Data format extension for Jackson (http://jackson.codehaus.org) to offeralternative support for serializing POJOs as XML and deserializing XML as pojos.Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types ... Low
Product pom parent-groupid com.fasterxml.jackson Low
Product file name jackson-dataformat-xml High
Product pom groupid fasterxml.jackson.dataformat Low
Product Manifest implementation-build-date 2014-08-15 18:38:26-0700 Low
Product pom parent-artifactid jackson-parent Medium
Product pom name Jackson-dataformat-XML High
Product Manifest Implementation-Title Jackson-dataformat-XML High
Product pom url http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding Medium
Product pom artifactid jackson-dataformat-xml Highest
Product pom description Data format extension for Jackson (http://jackson.codehaus.org) to offer
alternative support for serializing POJOs as XML and deserializing XML as pojos.
Support implemented on top of Stax API (javax.xml.stream), by implementing core Jackson Streaming API types ... Low
Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-xml Medium
Product Manifest specification-title Jackson-dataformat-XML Medium
Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonExtensionXmlDataBinding Low
Product central artifactid jackson-dataformat-xml Highest
Version pom version 2.4.2 Highest
Version file version 2.4.2 Highest
Version Manifest Implementation-Version 2.4.2 High
Version central version 2.4.2 Highest
Published Vulnerabilities
CVE-2016-3720 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
Vulnerable Software & Versions:
CVE-2016-7051 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
CWE: CWE-918 Server-Side Request Forgery (SSRF)
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.
Vulnerable Software & Versions: (show all )
CVE-2017-15095 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.
Vulnerable Software & Versions: (show all )
CVE-2017-17485 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
Vulnerable Software & Versions: (show all )
CVE-2017-7525 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.
BID - 99623
CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
CONFIRM - http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1462702
CONFIRM - https://cwiki.apache.org/confluence/display/WW/S2-055
CONFIRM - https://github.com/FasterXML/jackson-databind/issues/1599
CONFIRM - https://github.com/FasterXML/jackson-databind/issues/1723
CONFIRM - https://security.netapp.com/advisory/ntap-20171214-0002/
CONFIRM - https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03902en_us
CONFIRM - https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
DEBIAN - DSA-4004
MISC - https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
MLIST - [lucene-dev] 20190325 [jira] [Assigned] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Closed] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Resolved] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
MLIST - [lucene-dev] 20190325 [jira] [Updated] (SOLR-13110) CVE-2017-7525 Threat Level 9 Against Solr v7.6. org.codehaus.jackson : jackson-mapper-asl : 1.9.13. .A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, ...
REDHAT - RHSA-2017:1834
REDHAT - RHSA-2017:1835
REDHAT - RHSA-2017:1836
REDHAT - RHSA-2017:1837
REDHAT - RHSA-2017:1839
REDHAT - RHSA-2017:1840
REDHAT - RHSA-2017:2477
REDHAT - RHSA-2017:2546
REDHAT - RHSA-2017:2547
REDHAT - RHSA-2017:2633
REDHAT - RHSA-2017:2635
REDHAT - RHSA-2017:2636
REDHAT - RHSA-2017:2637
REDHAT - RHSA-2017:2638
REDHAT - RHSA-2017:3141
REDHAT - RHSA-2017:3454
REDHAT - RHSA-2017:3455
REDHAT - RHSA-2017:3456
REDHAT - RHSA-2017:3458
REDHAT - RHSA-2018:0294
REDHAT - RHSA-2018:0342
REDHAT - RHSA-2018:1449
REDHAT - RHSA-2018:1450
REDHAT - RHSA-2019:0910
SECTRACK - 1039744
SECTRACK - 1039947
SECTRACK - 1040360
Vulnerable Software & Versions: (show all )
CVE-2018-1000873 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.
Vulnerable Software & Versions: (show all )
CVE-2018-14719 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-14720 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-14721 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-918 Server-Side Request Forgery (SSRF)
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-19360 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-19361 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2018-19362 suppress
Severity:
High
CVSS Score: 7.5
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
Vulnerable Software & Versions: (show all )
CVE-2019-12086 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
CWE: CWE-200 Information Exposure
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.
Vulnerable Software & Versions: (show all )
swagger-annotations-1.5.0.jar
Description: Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/
License:
http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/io/swagger/swagger-annotations/1.5.0/swagger-annotations-1.5.0.jar
MD5: c16eb2bdd9f90e97849950178c4c543d
SHA1: f7497f7887e65277c0dab1da1148cf211083f3d4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name swagger-annotations High
Vendor manifest Bundle-Description Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/ Medium
Vendor pom groupid io.swagger Highest
Vendor Manifest bundle-symbolicname io.swagger.annotations Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low
Vendor central groupid io.swagger Highest
Vendor file name swagger-annotations High
Vendor pom parent-artifactid swagger-project Low
Vendor pom artifactid swagger-annotations Low
Product pom artifactid swagger-annotations Highest
Product pom name swagger-annotations High
Product manifest Bundle-Description Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/ Medium
Product pom parent-artifactid swagger-project Medium
Product Manifest bundle-symbolicname io.swagger.annotations Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low
Product Manifest Bundle-Name swagger-annotations Medium
Product file name swagger-annotations High
Product central artifactid swagger-annotations Highest
Product pom groupid io.swagger Low
Version central version 1.5.0 Highest
Version file version 1.5.0 Highest
Version pom version 1.5.0 Highest
swagger-models-1.5.0.jar
Description: Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/
License:
http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/ciagent/.m2/repository/io/swagger/swagger-models/1.5.0/swagger-models-1.5.0.jar
MD5: 5c3d553535fddea14a4e7e87c5fc59fa
SHA1: d2566bfc270073a559b342089f54086ee64ca5b1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name swagger-models High
Vendor manifest Bundle-Description Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/ Medium
Vendor pom groupid io.swagger Highest
Vendor pom artifactid swagger-models Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor file name swagger-models High
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-models Low
Vendor central groupid io.swagger Highest
Vendor Manifest bundle-symbolicname io.swagger.models Medium
Vendor pom parent-artifactid swagger-project Low
Product pom artifactid swagger-models Highest
Product pom name swagger-models High
Product manifest Bundle-Description Sonatype helps open source projects to set up Maven repositories on https://oss.sonatype.org/ Medium
Product pom parent-artifactid swagger-project Medium
Product central artifactid swagger-models Highest
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product file name swagger-models High
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-models Low
Product Manifest Bundle-Name swagger-models Medium
Product Manifest bundle-symbolicname io.swagger.models Medium
Product pom groupid io.swagger Low
Version central version 1.5.0 Highest
Version file version 1.5.0 Highest
Version pom version 1.5.0 Highest
swagger-core-1.5.0.jar
File Path: /home/ciagent/.m2/repository/io/swagger/swagger-core/1.5.0/swagger-core-1.5.0.jar
MD5: abc2015d9e823cb96abfa7e2937b43fb
SHA1: 09d5cfb8188ac316bad3a7b38c46bac0568c60e4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid swagger-core Low
Vendor pom groupid io.swagger Highest
Vendor file name swagger-core High
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-core Low
Vendor central groupid io.swagger Highest
Vendor pom parent-artifactid swagger-project Low
Vendor pom name swagger-core High
Product central artifactid swagger-core Highest
Product pom parent-artifactid swagger-project Medium
Product file name swagger-core High
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-core Low
Product pom artifactid swagger-core Highest
Product pom groupid io.swagger Low
Product pom name swagger-core High
Version central version 1.5.0 Highest
Version file version 1.5.0 Highest
Version pom version 1.5.0 Highest
annotations-2.0.1.jar
Description: Annotation supports the FindBugs tool
License:
GNU Lesser Public License: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ciagent/.m2/repository/com/google/code/findbugs/annotations/2.0.1/annotations-2.0.1.jar
MD5: 35ef911c85603829ded63f211feb2d68
SHA1: 9ef6656259841cebfb9fb0697bb122ada4485498
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom description Annotation supports the FindBugs tool Medium
Vendor pom groupid google.code.findbugs Highest
Vendor pom artifactid annotations Low
Vendor pom url http://findbugs.sourceforge.net/ Highest
Vendor Manifest bundle-symbolicname findbugsAnnotations Medium
Vendor pom name FindBugs-Annotations High
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Vendor file name annotations High
Vendor central groupid com.google.code.findbugs Highest
Product central artifactid annotations Highest
Product pom description Annotation supports the FindBugs tool Medium
Product Manifest Bundle-Name FindbugsAnnotations Medium
Product pom url http://findbugs.sourceforge.net/ Medium
Product Manifest bundle-symbolicname findbugsAnnotations Medium
Product pom name FindBugs-Annotations High
Product pom groupid google.code.findbugs Low
Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low
Product file name annotations High
Product pom artifactid annotations Highest
Version pom version 2.0.1 Highest
Version central version 2.0.1 Highest
Version file version 2.0.1 Highest
reflections-0.9.9.jar
Description: Reflections - a Java runtime metadata analysis
License:
WTFPL: http://www.wtfpl.net/
The New BSD License: http://www.opensource.org/licenses/bsd-license.html
File Path: /home/ciagent/.m2/repository/org/reflections/reflections/0.9.9/reflections-0.9.9.jar
MD5: 5f13944b355f927f956b6298136ad959
SHA1: 0296d8adb2f22a38025f44b45cac89835ff0bbaf
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://github.com/ronmamo/reflections Highest
Vendor jar package name reflections Low
Vendor pom artifactid reflections Low
Vendor pom groupid org.reflections Highest
Vendor file name reflections High
Vendor pom groupid reflections Highest
Vendor pom description Reflections - a Java runtime metadata analysis Medium
Vendor central groupid org.reflections Highest
Vendor pom name Reflections High
Product pom url http://github.com/ronmamo/reflections Medium
Product pom artifactid reflections Highest
Product file name reflections High
Product pom groupid reflections Low
Product central artifactid reflections Highest
Product pom description Reflections - a Java runtime metadata analysis Medium
Product pom name Reflections High
Version central version 0.9.9 Highest
Version file version 0.9.9 Highest
Version pom version 0.9.9 Highest
swagger-jaxrs-1.5.0.jar
File Path: /home/ciagent/.m2/repository/io/swagger/swagger-jaxrs/1.5.0/swagger-jaxrs-1.5.0.jar
MD5: a09d96c899411ac57a479c6635829600
SHA1: 04a77f3f95bfec3073d9d20660c16f54886dfc9f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid swagger-jaxrs Low
Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs Low
Vendor pom name swagger-jaxrs High
Vendor pom groupid io.swagger Highest
Vendor central groupid io.swagger Highest
Vendor file name swagger-jaxrs High
Vendor pom parent-artifactid swagger-project Low
Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-jaxrs Low
Product central artifactid swagger-jaxrs Highest
Product pom name swagger-jaxrs High
Product pom parent-artifactid swagger-project Medium
Product pom artifactid swagger-jaxrs Highest
Product file name swagger-jaxrs High
Product pom groupid io.swagger Low
Version central version 1.5.0 Highest
Version file version 1.5.0 Highest
Version pom version 1.5.0 Highest
commons-component-common-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-component-common/5.3.x-SNAPSHOT/commons-component-common-5.3.x-SNAPSHOT.jar
MD5: 68e71cc3a18338cdd93d6eb873ec340a
SHA1: e177099769562ebf444b664181284a611c0a1ea7
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor file name commons-component-common High
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor pom artifactid commons-component-common Low
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-component-common Low
Vendor pom name eXo PLF:: Commons - Common Services High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Product pom parent-groupid org.exoplatform.commons Low
Product file name commons-component-common High
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-component-common Low
Product pom name eXo PLF:: Commons - Common Services High
Product pom artifactid commons-component-common Highest
Product pom groupid exoplatform.commons Low
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product Manifest Implementation-Title eXo PLF:: Commons - Common Services High
Product Manifest specification-title eXo PLF:: Commons - Common Services Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-component-common:5.3.x-SNAPSHOT
Confidence :High
wiki-macros-iframe-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/wiki/wiki-macros-iframe/5.3.x-SNAPSHOT/wiki-macros-iframe-5.3.x-SNAPSHOT.jar
MD5: 0b533573312842d4d8c75b83284f94b9
SHA1: 2a25f98ad63d5a969140a8390835bcf368297a20
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.wiki Highest
Vendor pom artifactid wiki-macros-iframe Low
Vendor pom groupid org.exoplatform.wiki Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.wiki Medium
Vendor pom name eXo PLF:: Wiki Macros Iframe High
Vendor file name wiki-macros-iframe High
Vendor Manifest date 2019-05-24T10:40:54Z Low
Vendor Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-macros/wiki-macros-iframe Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-artifactid wiki-macros Low
Vendor pom parent-groupid org.exoplatform.wiki Medium
Product pom artifactid wiki-macros-iframe Highest
Product Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-macros/wiki-macros-iframe Low
Product Manifest Implementation-Title eXo PLF:: Wiki Macros Iframe High
Product pom parent-groupid org.exoplatform.wiki Low
Product Manifest specification-title eXo PLF:: Wiki Macros Iframe Medium
Product pom name eXo PLF:: Wiki Macros Iframe High
Product file name wiki-macros-iframe High
Product pom parent-artifactid wiki-macros Medium
Product pom groupid exoplatform.wiki Low
Product Manifest date 2019-05-24T10:40:54Z Low
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.wiki:wiki-macros-iframe:5.3.x-SNAPSHOT
Confidence :High
wci-wci-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/gatein/wci/wci-wci/5.3.x-SNAPSHOT/wci-wci-5.3.x-SNAPSHOT.jar
MD5: 2ab001252fa543ff2b30839d5d8b60ec
SHA1: 70f414374362f77fa7ec7a35797e32395bbf36ee
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.exoplatform.gatein.wci Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest build-timestamp Thu, 23 May 2019 09:57:20 +0000 Low
Vendor pom groupid exoplatform.gatein.wci Highest
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor pom artifactid wci-wci Low
Vendor Manifest os-name Linux Medium
Vendor Manifest implementation-url www.gatein.org/wci-parent/wci-wci/ Low
Vendor file name wci-wci High
Vendor Manifest Implementation-Vendor-Id org.exoplatform.gatein.wci Medium
Vendor pom groupid org.exoplatform.gatein.wci Highest
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor pom parent-artifactid wci-parent Low
Vendor pom name GateIn - Web Container Integration component (wci) High
Product pom parent-artifactid wci-parent Medium
Product Manifest implementation-url www.gatein.org/wci-parent/wci-wci/ Low
Product file name wci-wci High
Product pom parent-groupid org.exoplatform.gatein.wci Low
Product Manifest Implementation-Title GateIn - Web Container Integration component (wci) High
Product pom artifactid wci-wci Highest
Product Manifest build-timestamp Thu, 23 May 2019 09:57:20 +0000 Low
Product Manifest specification-title GateIn - Web Container Integration component (wci) Medium
Product pom name GateIn - Web Container Integration component (wci) High
Product pom groupid exoplatform.gatein.wci Low
Product Manifest os-name Linux Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.gatein.wci:wci-wci:5.3.x-SNAPSHOT
Confidence :High
jython-standalone-2.5.4-rc1.jar
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar
MD5: 947e7602dd7ff324e67b0557c088570d
SHA1: 2c7f8e1a5bcc210a686d15f372276365ccd5dffc
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.python Highest
Vendor file name jython-standalone High
Vendor jar package name python Low
Vendor central groupid org.python Highest
Product central artifactid jython-standalone Highest
Product file name jython-standalone High
Product pom artifactid jython-standalone Highest
Version central version 2.5.4-rc1 Highest
Version file version 2.5.4.rc1 Highest
Version pom version 2.5.4-rc1 Highest
pygments-1.6.jar
Description: pygments
License:
Simplified BSD License: http://www.opensource.org/licenses/BSD-2-Clause
File Path: /home/ciagent/.m2/repository/org/pygments/pygments/1.6/pygments-1.6.jar
MD5: a2522f9d0b69803307071c79d2e6f00f
SHA1: 0ca48ef8f443c2c01679414d15e2f2c525583a43
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid pygments Highest
Vendor file name pygments High
Vendor pom description pygments Medium
Vendor pom artifactid pygments Low
Vendor central groupid org.pygments Highest
Vendor pom groupid org.pygments Highest
Vendor pom name pygments High
Vendor pom url http://www.pygments.org Highest
Product file name pygments High
Product central artifactid pygments Highest
Product pom description pygments Medium
Product pom artifactid pygments Highest
Product pom url http://www.pygments.org Medium
Product pom name pygments High
Product pom groupid pygments Low
Version file version 1.6 Highest
Version central version 1.6 Highest
Version pom version 1.6 Highest
Published Vulnerabilities
CVE-2015-8557 suppress
Severity:
High
CVSS Score: 9.3
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
Vulnerable Software & Versions: (show all )
jdom2-2.0.5.jar
Description:
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
License:
Similar to Apache License but with the acknowledgment clause removed: https://raw.github.com/hunterhacker/jdom/master/LICENSE.txt
File Path: /home/ciagent/.m2/repository/org/jdom/jdom2/2.0.5/jdom2-2.0.5.jar
MD5: 302db3c65c38d3c10ef31bca76bd76b4
SHA1: 2001db51c131e555bafdb77fc52af6a9408c505e
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor manifest: org/jdom2/adapters/ Implementation-Vendor jdom.org Medium
Vendor pom groupid org.jdom Highest
Vendor manifest: org/jdom2/ Implementation-Vendor jdom.org Medium
Vendor file name jdom2 High
Vendor manifest: org/jdom2/input/ Implementation-Vendor jdom.org Medium
Vendor pom organization url http://www.jdom.org Medium
Vendor pom groupid jdom Highest
Vendor central groupid org.jdom Highest
Vendor pom url http://www.jdom.org Highest
Vendor manifest: org/jdom2/transform/ Implementation-Vendor jdom.org Medium
Vendor pom name JDOM High
Vendor manifest: org/jdom2/output/ Implementation-Vendor jdom.org Medium
Vendor pom artifactid jdom2 Low
Vendor manifest: org/jdom2/xpath/ Implementation-Vendor jdom.org Medium
Vendor pom organization name JDOM High
Vendor pom description
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
Medium
Vendor manifest: org/jdom2/filter/ Implementation-Vendor jdom.org Medium
Product pom url http://www.jdom.org Medium
Product manifest: org/jdom2/output/ Implementation-Title org.jdom2.output Medium
Product central artifactid jdom2 Highest
Product manifest: org/jdom2/input/ Specification-Title JDOM Input Classes Medium
Product manifest: org/jdom2/transform/ Implementation-Title org.jdom2.transform Medium
Product manifest: org/jdom2/adapters/ Specification-Title JDOM Adapter Classes Medium
Product manifest: org/jdom2/xpath/ Specification-Title JDOM XPath Classes Medium
Product file name jdom2 High
Product pom groupid jdom Low
Product manifest: org/jdom2/filter/ Implementation-Title org.jdom2.filter Medium
Product manifest: org/jdom2/xpath/ Implementation-Title org.jdom2.xpath Medium
Product pom artifactid jdom2 Highest
Product manifest: org/jdom2/ Specification-Title JDOM Classes Medium
Product manifest: org/jdom2/output/ Specification-Title JDOM Output Classes Medium
Product pom name JDOM High
Product manifest: org/jdom2/filter/ Specification-Title JDOM Filter Classes Medium
Product manifest: org/jdom2/adapters/ Implementation-Title org.jdom2.adapters Medium
Product manifest: org/jdom2/transform/ Specification-Title JDOM Transformation Classes Medium
Product manifest: org/jdom2/ Implementation-Title org.jdom2 Medium
Product pom organization url http://www.jdom.org Low
Product pom organization name JDOM Low
Product pom description
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
Medium
Product manifest: org/jdom2/input/ Implementation-Title org.jdom2.input Medium
Version pom version 2.0.5 Highest
Version central version 2.0.5 Highest
Version file version 2.0.5 Highest
wiki-webui-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/wiki/wiki-webui/5.3.x-SNAPSHOT/wiki-webui-5.3.x-SNAPSHOT.jar
MD5: fab8630f8923298c0a8413257ff4a15a
SHA1: 0e0389fddab816ad0a7435a4f0f80327e9595182
Referenced In Project/Scope:
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.wiki Highest
Vendor pom groupid org.exoplatform.wiki Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid wiki Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.wiki Medium
Vendor Manifest date 2019-05-24T10:40:54Z Low
Vendor file name wiki-webui High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom name eXo PLF:: Wiki Webui High
Vendor pom parent-groupid org.exoplatform.wiki Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-webui Low
Vendor pom artifactid wiki-webui Low
Product file name wiki-webui High
Product pom artifactid wiki-webui Highest
Product pom parent-groupid org.exoplatform.wiki Low
Product pom name eXo PLF:: Wiki Webui High
Product Manifest Implementation-Title eXo PLF:: Wiki Webui High
Product pom groupid exoplatform.wiki Low
Product Manifest date 2019-05-24T10:40:54Z Low
Product Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-webui Low
Product Manifest specification-title eXo PLF:: Wiki Webui Medium
Product pom parent-artifactid wiki Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.wiki:wiki-webui:5.3.x-SNAPSHOT
Confidence :High
json-simple-1.1.1.jar
Description: A simple Java toolkit for JSON
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/googlecode/json-simple/json-simple/1.1.1/json-simple-1.1.1.jar
MD5: 5cc2c478d73e8454b4c369cee66c5bc7
SHA1: c9ad4a0850ab676c5c64461a05ca524cdfff59f1
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name JSON.simple High
Vendor file name json-simple High
Vendor central groupid com.googlecode.json-simple Highest
Vendor pom artifactid json-simple Low
Vendor manifest Bundle-Description A simple Java toolkit for JSON Medium
Vendor pom description A simple Java toolkit for JSON Medium
Vendor pom groupid com.googlecode.json-simple Highest
Vendor Manifest bundle-symbolicname com.googlecode.json-simple Medium
Vendor pom groupid googlecode.json-simple Highest
Vendor pom url http://code.google.com/p/json-simple/ Highest
Product central artifactid json-simple Highest
Product pom name JSON.simple High
Product pom url http://code.google.com/p/json-simple/ Medium
Product file name json-simple High
Product pom groupid googlecode.json-simple Low
Product manifest Bundle-Description A simple Java toolkit for JSON Medium
Product pom description A simple Java toolkit for JSON Medium
Product Manifest Bundle-Name JSON.simple Medium
Product pom artifactid json-simple Highest
Product Manifest bundle-symbolicname com.googlecode.json-simple Medium
Version pom version 1.1.1 Highest
Version file version 1.1.1 Highest
Version central version 1.1.1 Highest
httpcore-4.3.3.jar
Description:
HttpComponents Core (blocking I/O)
File Path: /home/ciagent/.m2/repository/org/apache/httpcomponents/httpcore/4.3.3/httpcore-4.3.3.jar
MD5: c26171852f9810cd3d2416604a387e71
SHA1: f91b7a4aadc5cf486df6e4634748d7dd7a73f06d
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest
Vendor pom name Apache HttpCore High
Vendor pom groupid org.apache.httpcomponents Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Vendor Manifest implementation-build tags/4.3.3-RC1/httpcore@r1632770; 2014-10-18 13:50:12+0200 Low
Vendor central groupid org.apache.httpcomponents Highest
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom artifactid httpcore Low
Vendor pom description
HttpComponents Core (blocking I/O)
Medium
Vendor pom parent-artifactid httpcomponents-core Low
Vendor file name httpcore High
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom groupid apache.httpcomponents Highest
Vendor pom parent-groupid org.apache.httpcomponents Medium
Product pom name Apache HttpCore High
Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low
Product Manifest implementation-build tags/4.3.3-RC1/httpcore@r1632770; 2014-10-18 13:50:12+0200 Low
Product Manifest Implementation-Title HttpComponents Apache HttpCore High
Product pom parent-groupid org.apache.httpcomponents Low
Product pom parent-artifactid httpcomponents-core Medium
Product pom description
HttpComponents Core (blocking I/O)
Medium
Product pom url http://hc.apache.org/httpcomponents-core-ga Medium
Product pom artifactid httpcore Highest
Product file name httpcore High
Product Manifest specification-title HttpComponents Apache HttpCore Medium
Product pom groupid apache.httpcomponents Low
Product central artifactid httpcore Highest
Version file version 4.3.3 Highest
Version Manifest Implementation-Version 4.3.3 High
Version central version 4.3.3 Highest
Version pom version 4.3.3 Highest
commons-logging-1.1.3.jar
Description: Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/commons-logging/commons-logging/1.1.3/commons-logging-1.1.3.jar
MD5: 92eb5aabc1b47287de53d45c086a435c
SHA1: f6f66e966c70a83ffbdb6f17a0919eaf7c8aca7f
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid commons-logging Highest
Vendor pom parent-artifactid commons-parent Low
Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium
Vendor pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom artifactid commons-logging Low
Vendor pom groupid commons-logging Highest
Vendor file name commons-logging High
Vendor Manifest implementation-build tags/LOGGING_1_1_3_RC2@r1483540; 2013-05-16 22:04:41+0200 Low
Vendor manifest Bundle-Description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom name Commons Logging High
Product pom parent-artifactid commons-parent Medium
Product pom artifactid commons-logging Highest
Product Manifest bundle-symbolicname org.apache.commons.logging Medium
Product pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low
Product file name commons-logging High
Product Manifest implementation-build tags/LOGGING_1_1_3_RC2@r1483540; 2013-05-16 22:04:41+0200 Low
Product pom url http://commons.apache.org/proper/commons-logging/ Medium
Product Manifest specification-title Commons Logging Medium
Product Manifest Implementation-Title Commons Logging High
Product pom groupid commons-logging Low
Product manifest Bundle-Description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product central artifactid commons-logging Highest
Product pom parent-groupid org.apache.commons Low
Product pom name Commons Logging High
Product Manifest Bundle-Name Commons Logging Medium
Version file version 1.1.3 Highest
Version Manifest Implementation-Version 1.1.3 High
Version central version 1.1.3 Highest
Version pom version 1.1.3 Highest
httpclient-4.3.6.jar
Description:
HttpComponents Client
File Path: /home/ciagent/.m2/repository/org/apache/httpcomponents/httpclient/4.3.6/httpclient-4.3.6.jar
MD5: 2d29a27bb6c6b44bc8a608a0e5d09735
SHA1: 4c47155e3e6c9a41a28db36680b828ced53b8af4
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor file name httpclient High
Vendor pom groupid org.apache.httpcomponents Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor central groupid org.apache.httpcomponents Highest
Vendor pom parent-artifactid httpcomponents-client Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest implementation-build tags/4.3.6-RC1/httpclient@r1636012; 2014-11-02 14:45:03+0100 Low
Vendor pom url http://hc.apache.org/httpcomponents-client Highest
Vendor Manifest url http://hc.apache.org/httpcomponents-client Low
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom groupid apache.httpcomponents Highest
Vendor pom artifactid httpclient Low
Vendor pom description
HttpComponents Client
Medium
Vendor pom parent-groupid org.apache.httpcomponents Medium
Vendor pom name Apache HttpClient High
Product file name httpclient High
Product pom parent-artifactid httpcomponents-client Medium
Product Manifest specification-title HttpComponents Apache HttpClient Medium
Product pom url http://hc.apache.org/httpcomponents-client Medium
Product pom parent-groupid org.apache.httpcomponents Low
Product Manifest implementation-build tags/4.3.6-RC1/httpclient@r1636012; 2014-11-02 14:45:03+0100 Low
Product central artifactid httpclient Highest
Product Manifest url http://hc.apache.org/httpcomponents-client Low
Product Manifest Implementation-Title HttpComponents Apache HttpClient High
Product pom groupid apache.httpcomponents Low
Product pom artifactid httpclient Highest
Product pom description
HttpComponents Client
Medium
Product pom name Apache HttpClient High
Version pom version 4.3.6 Highest
Version file version 4.3.6 Highest
Version Manifest Implementation-Version 4.3.6 High
Version central version 4.3.6 Highest
commons-search-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-search/5.3.x-SNAPSHOT/commons-search-5.3.x-SNAPSHOT.jar
MD5: 8ccf64594bae4e03e2353ad010d9178e
SHA1: 91c4fd04f1d21d7bf52691a22c236732ec66cd53
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-search Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid commons-search Low
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor file name commons-search High
Vendor pom groupid exoplatform.commons Highest
Vendor pom name eXo PLF:: Commons - Commons Search High
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-search Low
Product Manifest Implementation-Title eXo PLF:: Commons - Commons Search High
Product Manifest specification-title eXo PLF:: Commons - Commons Search Medium
Product pom groupid exoplatform.commons Low
Product pom artifactid commons-search Highest
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product file name commons-search High
Product pom name eXo PLF:: Commons - Commons Search High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-search:5.3.x-SNAPSHOT
Confidence :High
cpe: cpe:/a:pro_search:pro_search:5.3
Confidence :Low
suppress
commons-api-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-api/5.3.x-SNAPSHOT/commons-api-5.3.x-SNAPSHOT.jar
MD5: 2c3b7dfa120a9e5572d3b2c600e4ca02
SHA1: 3405ca34dc1ae7aa88efe1c0c1f2eb4168dd3c60
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
eXo Wiki JPA Migration Service:provided
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-api Low
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor file name commons-api High
Vendor pom name eXo PLF:: Commons - API High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid commons-api Low
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Product pom parent-groupid org.exoplatform.commons Low
Product Manifest specification-title eXo PLF:: Commons - API Medium
Product pom name eXo PLF:: Commons - API High
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-api Low
Product pom groupid exoplatform.commons Low
Product Manifest Implementation-Title eXo PLF:: Commons - API High
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product pom artifactid commons-api Highest
Product file name commons-api High
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-api:5.3.x-SNAPSHOT
Confidence :High
commons-file-storage-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/commons/commons-file-storage/5.3.x-SNAPSHOT/commons-file-storage-5.3.x-SNAPSHOT.jar
MD5: d200ecfb46339a97646183edbf00ad49
SHA1: 5a2b78f6f8a3654b8909a179845df4f15964620e
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor Manifest implementation-url https://projects.exoplatform.org/commons/commons-file-storage Low
Vendor pom parent-groupid org.exoplatform.commons Medium
Vendor pom parent-artifactid commons Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.commons Medium
Vendor pom name eXo PLF:: Commons - Common File Storage High
Vendor file name commons-file-storage High
Vendor pom artifactid commons-file-storage Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom groupid org.exoplatform.commons Highest
Vendor Manifest date 2019-05-24T09:54:58Z Low
Vendor pom groupid exoplatform.commons Highest
Product pom parent-groupid org.exoplatform.commons Low
Product file name commons-file-storage High
Product Manifest Implementation-Title eXo PLF:: Commons - Common File Storage High
Product Manifest specification-title eXo PLF:: Commons - Common File Storage Medium
Product Manifest implementation-url https://projects.exoplatform.org/commons/commons-file-storage Low
Product pom groupid exoplatform.commons Low
Product pom artifactid commons-file-storage Highest
Product pom parent-artifactid commons Medium
Product Manifest date 2019-05-24T09:54:58Z Low
Product pom name eXo PLF:: Commons - Common File Storage High
Version pom version 5.3.x-20190524.100552-53 Highest
Version pom version 5.3.x-SNAPSHOT Highest
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.commons:commons-file-storage:5.3.x-SNAPSHOT
Confidence :High
jboss-logging-3.3.0.Final.jar
Description: The JBoss Logging Framework
License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/jboss/logging/jboss-logging/3.3.0.Final/jboss-logging-3.3.0.Final.jar
MD5: bc11af4b8ce7138cdc79b7ba8561638c
SHA1: 3616bb87707910296e2c195dc016287080bba5af
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor central groupid org.jboss.logging Highest
Vendor pom groupid org.jboss.logging Highest
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium
Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low
Vendor pom name JBoss Logging 3 High
Vendor pom groupid jboss.logging Highest
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor pom parent-artifactid jboss-parent Low
Vendor Manifest java-vendor Oracle Corporation Medium
Vendor Manifest implementation-url http://www.jboss.org Low
Vendor manifest Bundle-Description The JBoss Logging Framework Medium
Vendor Manifest os-name Linux Medium
Vendor pom parent-groupid org.jboss Medium
Vendor pom url http://www.jboss.org Highest
Vendor Manifest specification-vendor JBoss by Red Hat Low
Vendor file name jboss-logging High
Vendor pom artifactid jboss-logging Low
Vendor pom description The JBoss Logging Framework Medium
Vendor Manifest build-timestamp Thu, 28 May 2015 09:49:28 -0700 Low
Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Product Manifest Bundle-Name JBoss Logging 3 Medium
Product pom url http://www.jboss.org Medium
Product Manifest originally-created-by Apache Maven Bundle Plugin Low
Product Manifest specification-title JBoss Logging 3 Medium
Product pom groupid jboss.logging Low
Product pom parent-artifactid jboss-parent Medium
Product pom name JBoss Logging 3 High
Product Manifest bundle-docurl http://www.jboss.org Low
Product Manifest implementation-url http://www.jboss.org Low
Product manifest Bundle-Description The JBoss Logging Framework Medium
Product central artifactid jboss-logging Highest
Product Manifest os-name Linux Medium
Product Manifest Implementation-Title JBoss Logging 3 High
Product pom parent-groupid org.jboss Low
Product pom artifactid jboss-logging Highest
Product file name jboss-logging High
Product pom description The JBoss Logging Framework Medium
Product Manifest build-timestamp Thu, 28 May 2015 09:49:28 -0700 Low
Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium
Version file version 3.3.0 Highest
Version pom version 3.3.0.Final Highest
Version central version 3.3.0.Final Highest
Version Manifest Implementation-Version 3.3.0.Final High
dom4j-1.6.1.jar
Description: dom4j: the flexible XML framework for Java
File Path: /home/ciagent/.m2/repository/dom4j/dom4j/1.6.1/dom4j-1.6.1.jar
MD5: 4d8f51d3fe3900efc6e395be48030d6d
SHA1: 5d3ccc056b6f056dbf0dddfdf43894b9065a8f94
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name dom4j High
Vendor pom artifactid dom4j Low
Vendor file name dom4j High
Vendor Manifest extension-name dom4j Medium
Vendor Manifest Implementation-Vendor MetaStuff Ltd. High
Vendor pom description dom4j: the flexible XML framework for Java Medium
Vendor pom organization name MetaStuff Ltd. High
Vendor pom organization url http://sourceforge.net/projects/dom4j Medium
Vendor pom url http://dom4j.org Highest
Vendor pom groupid dom4j Highest
Vendor Manifest specification-vendor MetaStuff Ltd. Low
Vendor central groupid org.zenframework.z8.dependencies.commons High
Vendor central groupid dom4j High
Product pom name dom4j High
Product pom url http://dom4j.org Medium
Product file name dom4j High
Product Manifest extension-name dom4j Medium
Product pom organization name MetaStuff Ltd. Low
Product pom description dom4j: the flexible XML framework for Java Medium
Product pom artifactid dom4j Highest
Product central artifactid dom4j-1.6.1 High
Product central artifactid dom4j High
Product Manifest specification-title dom4j : XML framework for Java Medium
Product Manifest Implementation-Title org.dom4j High
Product pom groupid dom4j Low
Product pom organization url http://sourceforge.net/projects/dom4j Low
Version pom version 1.6.1 Highest
Version file version 1.6.1 Highest
Version central version 2.0 High
Version Manifest Implementation-Version 1.6.1 High
Version central version 1.6.1 High
Published Vulnerabilities
CVE-2018-1000632 suppress
Severity:
Medium
CVSS Score: 6.4
(AV:N/AC:L/Au:N/C:N/I:P/A:P)
CWE: CWE-91 XML Injection (aka Blind XPath Injection)
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability appears to have been fixed in 2.1.1 or later.
Vulnerable Software & Versions: (show all )
javassist-3.20.0-GA.jar
Description:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/
File Path: /home/ciagent/.m2/repository/org/javassist/javassist/3.20.0-GA/javassist-3.20.0-GA.jar
MD5: a89dd7907d76e061ec2c07e762a74256
SHA1: a9cbcdfb7e9f86fbc74d3afae65f2248bfbf82a0
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor manifest Bundle-Description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Vendor central groupid org.javassist Highest
Vendor pom artifactid javassist Low
Vendor pom groupid org.javassist Highest
Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low
Vendor file name javassist High
Vendor Manifest bundle-symbolicname javassist Medium
Vendor pom groupid javassist Highest
Vendor pom name Javassist High
Vendor pom organization name Shigeru Chiba, www.javassist.org High
Vendor pom url http://www.javassist.org/ Highest
Vendor pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Product manifest Bundle-Description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Product pom groupid javassist Low
Product central artifactid javassist Highest
Product pom artifactid javassist Highest
Product file name javassist High
Product Manifest bundle-symbolicname javassist Medium
Product pom url http://www.javassist.org/ Medium
Product Manifest Bundle-Name Javassist Medium
Product pom organization name Shigeru Chiba, www.javassist.org Low
Product pom name Javassist High
Product Manifest specification-title Javassist Medium
Product pom description Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation simple. It is a class library for editing bytecodes in Java. Low
Version file version 3.20.0 Highest
Version central version 3.20.0-GA Highest
Version pom version 3.20.0-GA Highest
jboss-transaction-api_1.1_spec-1.0.1.Final.jar
Description: The Java Transaction 1.1 API classes
License:
Common Development and Distribution License: http://repository.jboss.org/licenses/cddl.txt
GNU General Public License, Version 2 with the Classpath Exception: http://repository.jboss.org/licenses/gpl-2.0-ce.txt
File Path: /home/ciagent/.m2/repository/org/jboss/spec/javax/transaction/jboss-transaction-api_1.1_spec/1.0.1.Final/jboss-transaction-api_1.1_spec-1.0.1.Final.jar
MD5: 679cd909d6130e6bf467b291031e1e2d
SHA1: 18f0e1d42f010a8b53aa447bf274a706d5148852
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.jboss.spec.javax.transaction Medium
Vendor pom artifactid jboss-transaction-api_1.1_spec Low
Vendor pom name Java Transaction API High
Vendor Manifest java-vendor Sun Microsystems Inc. Medium
Vendor Manifest Implementation-Vendor JBoss by Red Hat High
Vendor Manifest implementation-url http://www.jboss.org/jboss-transaction-api_1.1_spec Low
Vendor central groupid org.jboss.spec.javax.transaction Highest
Vendor pom description The Java Transaction 1.1 API classes Medium
Vendor Manifest bundle-docurl http://www.jboss.org Low
Vendor pom parent-artifactid jboss-parent Low
Vendor pom groupid org.jboss.spec.javax.transaction Highest
Vendor Manifest build-timestamp Sat, 17 Mar 2012 11:49:45 -0500 Low
Vendor Manifest os-name Linux Medium
Vendor pom parent-groupid org.jboss Medium
Vendor Manifest bundle-symbolicname org.jboss.spec.javax.transaction.jboss-transaction-api_1.1_spec Medium
Vendor file name jboss-transaction-api_1.1_spec-1.0.1.Final High
Vendor pom groupid jboss.spec.javax.transaction Highest
Vendor manifest Bundle-Description The Java Transaction 1.1 API classes Medium
Product Manifest specification-title JSR 907: Java Transaction API (JTA) Medium
Product pom name Java Transaction API High
Product Manifest implementation-url http://www.jboss.org/jboss-transaction-api_1.1_spec Low
Product pom parent-artifactid jboss-parent Medium
Product Manifest Bundle-Name Java Transaction API Medium
Product pom description The Java Transaction 1.1 API classes Medium
Product Manifest bundle-docurl http://www.jboss.org Low
Product Manifest Implementation-Title Java Transaction API High
Product Manifest build-timestamp Sat, 17 Mar 2012 11:49:45 -0500 Low
Product Manifest os-name Linux Medium
Product pom artifactid jboss-transaction-api_1.1_spec Highest
Product pom parent-groupid org.jboss Low
Product Manifest bundle-symbolicname org.jboss.spec.javax.transaction.jboss-transaction-api_1.1_spec Medium
Product file name jboss-transaction-api_1.1_spec-1.0.1.Final High
Product pom groupid jboss.spec.javax.transaction Low
Product central artifactid jboss-transaction-api_1.1_spec Highest
Product manifest Bundle-Description The Java Transaction 1.1 API classes Medium
Version Manifest Implementation-Version 1.0.1.Final High
Version central version 1.0.1.Final Highest
Version pom version 1.0.1.Final Highest
hibernate-jpa-2.0-api-1.0.1.Final.jar
Description:
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
License:
license.txt
File Path: /home/ciagent/.m2/repository/org/hibernate/javax/persistence/hibernate-jpa-2.0-api/1.0.1.Final/hibernate-jpa-2.0-api-1.0.1.Final.jar
MD5: d7e7d8f60fc44a127ba702d43e71abec
SHA1: 3306a165afa81938fc3d8a0948e891de9f6b192b
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://hibernate.org Highest
Vendor central groupid org.hibernate.javax.persistence Highest
Vendor Manifest Implementation-Vendor hibernate.org High
Vendor file name hibernate-jpa-2.0-api-1.0.1.Final High
Vendor pom groupid hibernate.javax.persistence Highest
Vendor pom groupid org.hibernate.javax.persistence Highest
Vendor Manifest specification-vendor Sun Microsystems, Inc. Low
Vendor pom organization name Hibernate.org High
Vendor pom artifactid hibernate-jpa-2.0-api Low
Vendor pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Vendor pom organization url http://hibernate.org Medium
Vendor pom name JPA 2.0 API High
Product Manifest Implementation-Title JPA API High
Product pom groupid hibernate.javax.persistence Low
Product pom artifactid hibernate-jpa-2.0-api Highest
Product Manifest specification-title Java Persistence API, Version 2.0 Medium
Product pom organization url http://hibernate.org Low
Product file name hibernate-jpa-2.0-api-1.0.1.Final High
Product pom organization name Hibernate.org Low
Product pom description
Hibernate definition of the Java Persistence 2.0 (JSR 317) API.
Medium
Product pom url http://hibernate.org Medium
Product pom name JPA 2.0 API High
Product central artifactid hibernate-jpa-2.0-api Highest
Version Manifest Implementation-Version 1.0.1.Final High
Version central version 1.0.1.Final Highest
Version pom version 1.0.1.Final Highest
hibernate-entitymanager-4.2.21.Final.jar
Description: A module of the Hibernate O/RM project
License:
GNU Lesser General Public License: http://www.gnu.org/licenses/lgpl-2.1.html
File Path: /home/ciagent/.m2/repository/org/hibernate/hibernate-entitymanager/4.2.21.Final/hibernate-entitymanager-4.2.21.Final.jar
MD5: 2c1a3f1c7bb83b730ab3db1fe588904e
SHA1: a6675070b4c7bb843d74d6ab3bc9440fd315dbb3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid hibernate-entitymanager Low
Vendor pom url http://hibernate.org Highest
Vendor pom groupid hibernate Highest
Vendor Manifest Implementation-Vendor Hibernate.org High
Vendor pom name A Hibernate O/RM Module High
Vendor pom groupid org.hibernate Highest
Vendor Manifest bundle-symbolicname org.hibernate.entitymanager Medium
Vendor central groupid org.hibernate Highest
Vendor manifest Bundle-Description Hibernate ORM JPA Entity Manager Medium
Vendor Manifest implementation-url http://hibernate.org Low
Vendor pom organization name Hibernate.org High
Vendor pom description A module of the Hibernate O/RM project Medium
Vendor pom organization url http://hibernate.org Medium
Vendor file name hibernate-entitymanager High
Vendor Manifest Implementation-Vendor-Id org.hibernate Medium
Product Manifest Bundle-Name hibernate-entitymanager Medium
Product pom name A Hibernate O/RM Module High
Product central artifactid hibernate-entitymanager Highest
Product Manifest bundle-symbolicname org.hibernate.entitymanager Medium
Product manifest Bundle-Description Hibernate ORM JPA Entity Manager Medium
Product Manifest implementation-url http://hibernate.org Low
Product pom organization url http://hibernate.org Low
Product pom description A module of the Hibernate O/RM project Medium
Product pom organization name Hibernate.org Low
Product pom artifactid hibernate-entitymanager Highest
Product file name hibernate-entitymanager High
Product pom groupid hibernate Low
Product pom url http://hibernate.org Medium
Version central version 4.2.21.Final Highest
Version file version 4.2.21 Highest
Version pom version 4.2.21.Final Highest
Version Manifest Implementation-Version 4.2.21.Final High
wiki-jpa-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/wiki/wiki-jpa/5.3.x-SNAPSHOT/wiki-jpa-5.3.x-SNAPSHOT.jar
MD5: a1a567c9ccad2f1892eba2f76286076c
SHA1: 09724285a688dc20fc08a90eb4de8d31078795e5
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid exoplatform.wiki Highest
Vendor pom artifactid wiki-jpa Low
Vendor pom groupid org.exoplatform.wiki Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid wiki Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.wiki Medium
Vendor Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-jpa Low
Vendor pom name eXo Wiki JPA DAO High
Vendor Manifest date 2019-05-24T10:40:54Z Low
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom parent-groupid org.exoplatform.wiki Medium
Vendor file name wiki-jpa High
Product pom parent-groupid org.exoplatform.wiki Low
Product Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-jpa Low
Product Manifest specification-title eXo Wiki JPA DAO Medium
Product pom artifactid wiki-jpa Highest
Product pom name eXo Wiki JPA DAO High
Product file name wiki-jpa High
Product Manifest Implementation-Title eXo Wiki JPA DAO High
Product pom groupid exoplatform.wiki Low
Product Manifest date 2019-05-24T10:40:54Z Low
Product pom parent-artifactid wiki Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.wiki:wiki-jpa:5.3.x-SNAPSHOT
Confidence :High
wiki-jpa-migration-5.3.x-SNAPSHOT.jar
File Path: /home/ciagent/.m2/repository/org/exoplatform/wiki/wiki-jpa-migration/5.3.x-SNAPSHOT/wiki-jpa-migration-5.3.x-SNAPSHOT.jar
MD5: 803a026031a53e3e69a9950da51ea06b
SHA1: f505aec96aa0d84bf62d86ed9947ef7c27b8d731
Referenced In Project/Scope:
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-jpa-migration Low
Vendor pom groupid exoplatform.wiki Highest
Vendor pom groupid org.exoplatform.wiki Highest
Vendor Manifest specification-vendor eXo Platform SAS Low
Vendor pom parent-artifactid wiki Low
Vendor Manifest Implementation-Vendor-Id org.exoplatform.wiki Medium
Vendor pom name eXo Wiki JPA Migration Service High
Vendor Manifest date 2019-05-24T10:40:54Z Low
Vendor file name wiki-jpa-migration High
Vendor Manifest Implementation-Vendor eXo Platform SAS High
Vendor pom artifactid wiki-jpa-migration Low
Vendor pom parent-groupid org.exoplatform.wiki Medium
Product Manifest implementation-url https://projects.exoplatform.org/wiki/wiki-jpa-migration Low
Product Manifest Implementation-Title eXo Wiki JPA Migration Service High
Product file name wiki-jpa-migration High
Product pom artifactid wiki-jpa-migration Highest
Product pom parent-groupid org.exoplatform.wiki Low
Product Manifest specification-title eXo Wiki JPA Migration Service Medium
Product pom name eXo Wiki JPA Migration Service High
Product pom groupid exoplatform.wiki Low
Product Manifest date 2019-05-24T10:40:54Z Low
Product pom parent-artifactid wiki Medium
Version file version 5.3 Highest
Version Manifest Implementation-Version 5.3.x-SNAPSHOT High
maven: org.exoplatform.wiki:wiki-jpa-migration:5.3.x-SNAPSHOT
Confidence :High
commons-lang3-3.3.2.jar
Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/commons/commons-lang3/3.3.2/commons-lang3-3.3.2.jar
MD5: 3128bf75a2549ebe38663401191bacab
SHA1: 90a3822c38ec8c996e84c16a3477ef632cbc87a3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.apache.commons Highest
Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom groupid apache.commons Highest
Vendor pom parent-artifactid commons-parent Low
Vendor pom description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low
Vendor central groupid org.apache.commons Highest
Vendor pom artifactid commons-lang3 Low
Vendor manifest Bundle-Description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom name Apache Commons Lang High
Vendor Manifest implementation-build tags/LANG_3_3_2_RC1@r1585295; 2014-04-06 14:18:52+0200 Low
Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor file name commons-lang3 High
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Product pom parent-artifactid commons-parent Medium
Product pom description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang.
Low
Product Manifest specification-title Apache Commons Lang Medium
Product manifest Bundle-Description Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. Low
Product Manifest Bundle-Name Apache Commons Lang Medium
Product Manifest Implementation-Title Apache Commons Lang High
Product pom name Apache Commons Lang High
Product pom groupid apache.commons Low
Product Manifest implementation-build tags/LANG_3_3_2_RC1@r1585295; 2014-04-06 14:18:52+0200 Low
Product pom url http://commons.apache.org/proper/commons-lang/ Medium
Product central artifactid commons-lang3 Highest
Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium
Product pom parent-groupid org.apache.commons Low
Product file name commons-lang3 High
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low
Product pom artifactid commons-lang3 Highest
Version pom version 3.3.2 Highest
Version central version 3.3.2 Highest
Version Manifest Implementation-Version 3.3.2 High
Version file version 3.3.2 Highest
gwt-user-2.6.1.jar
File Path: /home/ciagent/.m2/repository/com/google/gwt/gwt-user/2.6.1/gwt-user-2.6.1.jar
MD5: ce17f82bb92e3a7416a9be5659cbcc89
SHA1: c078b1b8cc0281214b0eb458d2c283d039374fad
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:provided
eXo PLF:: Wiki Service:provided
Evidence
Type Source Name Value Confidence
Vendor central groupid com.google.gwt Highest
Vendor file name gwt-user High
Vendor jar package name google Low
Vendor pom artifactid gwt-user Low
Vendor pom parent-artifactid gwt Low
Vendor jar package name gwt Low
Vendor pom groupid com.google.gwt Highest
Vendor pom parent-groupid com.google.gwt Medium
Vendor pom groupid google.gwt Highest
Product central artifactid gwt-user Highest
Product file name gwt-user High
Product jar package name client Low
Product pom groupid google.gwt Low
Product pom artifactid gwt-user Highest
Product pom parent-artifactid gwt Medium
Product pom parent-groupid com.google.gwt Low
Product jar package name gwt Low
Version central version 2.6.1 Highest
Version file version 2.6.1 Highest
Version pom version 2.6.1 Highest
jdom-1.0.jar
File Path: /home/ciagent/.m2/repository/jdom/jdom/1.0/jdom-1.0.jar
MD5: 0b8f97de82fc9529b1028a77125ce4f8
SHA1: a2ac1cd690ab4c80defe7f9bce14d35934c35cec
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor manifest: org/jdom/output/ Implementation-Vendor jdom.org Medium
Vendor central groupid com.sun.phobos High
Vendor manifest: org/jdom/xpath/ Implementation-Vendor jdom.org Medium
Vendor central groupid jdom High
Vendor manifest: org/jdom/adapters/ Implementation-Vendor jdom.org Medium
Vendor manifest: org/jdom/transform/ Implementation-Vendor jdom.org Medium
Vendor pom groupid jdom Highest
Vendor manifest: org/jdom/filter/ Implementation-Vendor jdom.org Medium
Vendor pom artifactid jdom Low
Vendor file name jdom High
Vendor manifest: org/jdom/input/ Implementation-Vendor jdom.org Medium
Vendor manifest: org/jdom/ Implementation-Vendor jdom.org Medium
Product manifest: org/jdom/ Specification-Title JDOM Classes Medium
Product pom artifactid jdom Highest
Product manifest: org/jdom/output/ Specification-Title JDOM Output Classes Medium
Product manifest: org/jdom/adapters/ Specification-Title JDOM Adapter Classes Medium
Product manifest: org/jdom/transform/ Specification-Title JDOM Transformation Classes Medium
Product manifest: org/jdom/ Implementation-Title org.jdom Medium
Product central artifactid jdom High
Product manifest: org/jdom/input/ Specification-Title JDOM Input Classes Medium
Product manifest: org/jdom/input/ Implementation-Title org.jdom.input Medium
Product manifest: org/jdom/transform/ Implementation-Title org.jdom.transform Medium
Product manifest: org/jdom/adapters/ Implementation-Title org.jdom.adapters Medium
Product pom groupid jdom Low
Product manifest: org/jdom/filter/ Implementation-Title org.jdom.filter Medium
Product manifest: org/jdom/output/ Implementation-Title org.jdom.output Medium
Product manifest: org/jdom/xpath/ Implementation-Title org.jdom.xpath Medium
Product file name jdom High
Product manifest: org/jdom/xpath/ Specification-Title JDOM XPath Classes Medium
Product manifest: org/jdom/filter/ Specification-Title JDOM Filter Classes Medium
Version file version 1.0 Highest
Version central version 1.0 High
Version pom version 1.0 Highest
modules-0.3.2.jar
Description: A collection of ROME modules
File Path: /home/ciagent/.m2/repository/rome/modules/0.3.2/modules-0.3.2.jar
MD5: 0bfe56efb3460cc74d4053ef61635131
SHA1: e696eccbad985f8be6c2299b3aee8010f1cd204f
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name syndication Low
Vendor central groupid rome Highest
Vendor pom description A collection of ROME modules Medium
Vendor file name modules High
Vendor pom url https://rome.dev.java.net/ Highest
Vendor jar package name sun Low
Vendor jar (hint) package name oracle Low
Vendor pom artifactid modules Low
Vendor jar package name feed Low
Vendor pom groupid rome Highest
Vendor pom name ROME Modules High
Product jar package name syndication Low
Product jar package name module Low
Product pom groupid rome Low
Product pom description A collection of ROME modules Medium
Product pom artifactid modules Highest
Product file name modules High
Product jar package name feed Low
Product pom url https://rome.dev.java.net/ Medium
Product pom name ROME Modules High
Product central artifactid modules Highest
Version file version 0.3.2 Highest
Version central version 0.3.2 Highest
Version pom version 0.3.2 Highest
protobuf-java-3.0.2.jar
Description:
Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an
efficient yet extensible format.
License:
http://www.opensource.org/licenses/bsd-license.php
File Path: /home/ciagent/.m2/repository/com/google/protobuf/protobuf-java/3.0.2/protobuf-java-3.0.2.jar
MD5: fca93e016f4dd35aacde356a4b711423
SHA1: ee55e8e697d10b6643d77bb1f686bac3b9ba8579
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom name Protocol Buffers [Core] High
Vendor manifest Bundle-Description Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Vendor Manifest bundle-docurl https://developers.google.com/protocol-buffers/ Low
Vendor central groupid com.google.protobuf Highest
Vendor pom groupid com.google.protobuf Highest
Vendor pom parent-artifactid protobuf-parent Low
Vendor file name protobuf-java High
Vendor pom artifactid protobuf-java Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Vendor pom parent-groupid com.google.protobuf Medium
Vendor pom groupid google.protobuf Highest
Vendor pom description Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Vendor Manifest bundle-symbolicname com.google.protobuf Medium
Product pom name Protocol Buffers [Core] High
Product manifest Bundle-Description Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Product Manifest bundle-docurl https://developers.google.com/protocol-buffers/ Low
Product central artifactid protobuf-java Highest
Product pom parent-artifactid protobuf-parent Medium
Product pom parent-groupid com.google.protobuf Low
Product pom artifactid protobuf-java Highest
Product file name protobuf-java High
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low
Product Manifest Bundle-Name Protocol Buffers [Core] Medium
Product pom groupid google.protobuf Low
Product pom description Core Protocol Buffers library. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Low
Product Manifest bundle-symbolicname com.google.protobuf Medium
Version file version 3.0.2 Highest
Version central version 3.0.2 Highest
Version pom version 3.0.2 Highest
Published Vulnerabilities
CVE-2015-5237 suppress
Severity:
Medium
CVSS Score: 6.5
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
protobuf allows remote authenticated attackers to cause a heap-based buffer overflow.
Vulnerable Software & Versions: (show all )
geronimo-stax-api_1.0_spec-1.0.1.jar
Description: Provides open-source implementations of Sun specifications.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/org/apache/geronimo/specs/geronimo-stax-api_1.0_spec/1.0.1/geronimo-stax-api_1.0_spec-1.0.1.jar
MD5: b7c2a715cd3d1c43dc4ccfae426e8e2e
SHA1: 1c171093a8b43aa550c6050ac441abe713ebb4f2
Referenced In Project/Scope:
eXo PLF:: Wiki Renderer:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest bundle-docurl http://www.apache.org Low
Vendor file name geronimo-stax-api_1.0_spec-1.0.1 High
Vendor pom parent-artifactid specs Low
Vendor central groupid org.apache.geronimo.specs Highest
Vendor pom artifactid geronimo-stax-api_1.0_spec Low
Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-stax-api_1.0_spec Medium
Vendor pom parent-groupid org.apache.geronimo.specs Medium
Vendor pom groupid apache.geronimo.specs Highest
Vendor pom name Streaming API for XML (STAX API 1.0) High
Vendor pom groupid org.apache.geronimo.specs Highest
Vendor manifest Bundle-Description Provides open-source implementations of Sun specifications. Medium
Product Manifest Implementation-Title Apache Geronimo High
Product pom groupid apache.geronimo.specs Low
Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-stax-api_1.0_spec Medium
Product Manifest bundle-docurl http://www.apache.org Low
Product file name geronimo-stax-api_1.0_spec-1.0.1 High
Product Manifest Bundle-Name geronimo-stax-api_1.0_spec Medium
Product pom artifactid geronimo-stax-api_1.0_spec Highest
Product pom parent-groupid org.apache.geronimo.specs Low
Product pom name Streaming API for XML (STAX API 1.0) High
Product central artifactid geronimo-stax-api_1.0_spec Highest
Product manifest Bundle-Description Provides open-source implementations of Sun specifications. Medium
Product pom parent-artifactid specs Medium
Version pom version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
Version central version 1.0.1 Highest
xml-apis-1.0.b2.jar
Description: xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier. The External Components portion of xml-commons contains
interfaces that are defined by external standards organizations. For DOM,
that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for
JAXP it's Sun.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/xml-apis/xml-apis/1.0.b2/xml-apis-1.0.b2.jar
MD5: 458715c0f7646a56b1c6ad3138098beb
SHA1: 3136ca936f64c9d68529f048c2618bd356bf85c9
Referenced In Project/Scope:
eXo PLF:: Wiki Renderer:compile
Evidence
Type Source Name Value Confidence
Vendor file name xml-apis High
Vendor pom groupid xml-apis Highest
Vendor manifest: javax/xml/parsers/ Implementation-Vendor Sun Microsystems Inc. Medium
Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium
Vendor pom description xml-commons provides an Apache-hosted set of DOM, SAX, and JAXP interfaces for use in other xml-based projects. Our hope is that we can standardize on both a common version and packaging scheme for these critical XML standards interfaces to make the lives of both our developers and users easier. The External Components portion of xml-commons contains interfaces that are defined by external standards organizations. For DOM, that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for JAXP it's Sun. Low
Vendor manifest: javax/xml/transform/ Implementation-Vendor Sun Microsystems Inc. Medium
Vendor pom name XML Commons External Components XML APIs High
Vendor pom artifactid xml-apis Low
Vendor pom organization url http://www.apache.org/ Medium
Vendor central groupid xml-apis High
Vendor pom url http://xml.apache.org/commons/#external Highest
Vendor pom organization name Apache Software Foundation High
Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium
Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium
Product file name xml-apis High
Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium
Product pom url http://xml.apache.org/commons/#external Medium
Product pom description xml-commons provides an Apache-hosted set of DOM, SAX, and JAXP interfaces for use in other xml-based projects. Our hope is that we can standardize on both a common version and packaging scheme for these critical XML standards interfaces to make the lives of both our developers and users easier. The External Components portion of xml-commons contains interfaces that are defined by external standards organizations. For DOM, that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for JAXP it's Sun. Low
Product pom name XML Commons External Components XML APIs High
Product pom organization name Apache Software Foundation Low
Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium
Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium
Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing Medium
Product manifest: org/w3c/dom/ Specification-Title Document Object Model, Level 2 Core Medium
Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.transform Medium
Product pom groupid xml-apis Low
Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium
Product central artifactid xml-apis High
Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium
Product pom artifactid xml-apis Highest
Product pom organization url http://www.apache.org/ Low
Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing Medium
Version central version 2.0.2 High
Version pom version 1.0.b2 Highest
Version central version 2.0.0 High
Version central version 1.0.b2 High
Version file version 1.0.b2 Highest
xml-apis-1.4.01.jar
Description: xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier. The External Components portion of xml-commons contains
interfaces that are defined by external standards organizations. For DOM,
that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for
JAXP it's Sun.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
The SAX License: http://www.saxproject.org/copying.html
The W3C License: http://www.w3.org/TR/2004/REC-DOM-Level-3-Core-20040407/java-binding.zip
File Path: /home/ciagent/.m2/repository/xml-apis/xml-apis/1.4.01/xml-apis-1.4.01.jar
MD5: 7eaad6fea5925cca6c36ee8b3e02ac9d
SHA1: 3789d9fada2d3d458c4ba2de349d48780f381ee3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor file name xml-apis High
Vendor manifest: org/w3c/dom/ls/ Implementation-Vendor World Wide Web Consortium Medium
Vendor manifest: javax/xml/datatype/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom groupid xml-apis Highest
Vendor manifest: org/apache/xmlcommons/Version Implementation-Vendor Apache Software Foundation Medium
Vendor central groupid xml-apis Highest
Vendor manifest: javax/xml/xpath/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom description xml-commons provides an Apache-hosted set of DOM, SAX, and JAXP interfaces for use in other xml-based projects. Our hope is that we can standardize on both a common version and packaging scheme for these critical XML standards interfaces to make the lives of both our developers and users easier. The External Components portion of xml-commons contains interfaces that are defined by external standards organizations. For DOM, that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for JAXP it's Sun. Low
Vendor pom name XML Commons External Components XML APIs High
Vendor pom artifactid xml-apis Low
Vendor pom url http://xml.apache.org/commons/components/external/ Highest
Vendor manifest: javax/xml/transform/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: org/xml/sax/ Implementation-Vendor David Megginson Medium
Vendor manifest: org/w3c/dom/ Implementation-Vendor World Wide Web Consortium Medium
Vendor manifest: javax/xml/stream/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/namespace/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/parsers/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: javax/xml/validation/ Implementation-Vendor Apache Software Foundation Medium
Product file name xml-apis High
Product manifest: javax/xml/datatype/ Implementation-Title javax.xml.datatype Medium
Product manifest: org/w3c/dom/ Implementation-Title org.w3c.dom Medium
Product pom url http://xml.apache.org/commons/components/external/ Medium
Product manifest: javax/xml/datatype/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium
Product pom description xml-commons provides an Apache-hosted set of DOM, SAX, and JAXP interfaces for use in other xml-based projects. Our hope is that we can standardize on both a common version and packaging scheme for these critical XML standards interfaces to make the lives of both our developers and users easier. The External Components portion of xml-commons contains interfaces that are defined by external standards organizations. For DOM, that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for JAXP it's Sun. Low
Product pom name XML Commons External Components XML APIs High
Product manifest: org/apache/xmlcommons/Version Implementation-Title org.apache.xmlcommons.Version Medium
Product manifest: javax/xml/parsers/ Implementation-Title javax.xml.parsers Medium
Product manifest: javax/xml/parsers/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium
Product manifest: javax/xml/namespace/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium
Product pom groupid xml-apis Low
Product manifest: org/w3c/dom/ls/ Implementation-Title org.w3c.dom.ls Medium
Product manifest: javax/xml/xpath/ Implementation-Title javax.xml.xpath Medium
Product manifest: javax/xml/validation/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium
Product manifest: org/xml/sax/ Implementation-Title org.xml.sax Medium
Product manifest: javax/xml/namespace/ Implementation-Title javax.xml.namespace Medium
Product manifest: javax/xml/stream/ Specification-Title Streaming API for XML (StAX) 1.0 Medium
Product manifest: javax/xml/transform/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium
Product manifest: javax/xml/stream/ Implementation-Title javax.xml.stream Medium
Product manifest: javax/xml/transform/ Implementation-Title javax.xml.transform Medium
Product manifest: org/w3c/dom/ Specification-Title Document Object Model (DOM) Level 3 Core Medium
Product manifest: org/xml/sax/ Specification-Title Simple API for XML Medium
Product pom artifactid xml-apis Highest
Product manifest: javax/xml/xpath/ Specification-Title Java API for XML Processing (JAXP) 1.4 Medium
Product manifest: javax/xml/validation/ Implementation-Title javax.xml.validation Medium
Product manifest: org/w3c/dom/ls/ Specification-Title Document Object Model (DOM) Level 3 Load and Save Medium
Product central artifactid xml-apis Highest
Version pom version 1.4.01 Highest
Version file version 1.4.01 Highest
Version central version 1.4.01 Highest
jmock-1.0.1.jar
File Path: /home/ciagent/.m2/repository/jmock/jmock/1.0.1/jmock-1.0.1.jar
MD5: d45c5ca4c1063d508ca8df00538decc1
SHA1: 87a39d1a62ea94be5453ecdbb97cd81c978622d3
Referenced In Projects/Scopes:
eXo Wiki JPA DAO:compile
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor file name jmock High
Vendor jar package name core Low
Vendor pom groupid jmock Highest
Vendor pom artifactid jmock Low
Vendor jar package name jmock Low
Vendor central groupid jmock Highest
Product central artifactid jmock Highest
Product file name jmock High
Product jar package name core Low
Product pom groupid jmock Low
Product pom artifactid jmock Highest
Version pom version 1.0.1 Highest
Version central version 1.0.1 Highest
Version file version 1.0.1 Highest
jsr305-3.0.1.jar
Description: JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/google/code/findbugs/jsr305/3.0.1/jsr305-3.0.1.jar
MD5: c6532beb3f7cc54a8d73d25d5602b9e4
SHA1: f7be08ec23c21485b9b5a1cf1654c2ec8c58168d
Referenced In Project/Scope:
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom artifactid jsr305 Low
Vendor pom groupid google.code.findbugs Highest
Vendor pom url http://findbugs.sourceforge.net/ Highest
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom description JSR305 Annotations for Findbugs Medium
Vendor file name jsr305 High
Vendor manifest Bundle-Description JSR305 Annotations for Findbugs Medium
Vendor pom name FindBugs-jsr305 High
Vendor central groupid com.google.code.findbugs Highest
Product central artifactid jsr305 Highest
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom url http://findbugs.sourceforge.net/ Medium
Product pom description JSR305 Annotations for Findbugs Medium
Product pom groupid google.code.findbugs Low
Product file name jsr305 High
Product manifest Bundle-Description JSR305 Annotations for Findbugs Medium
Product pom name FindBugs-jsr305 High
Product pom artifactid jsr305 Highest
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Version file version 3.0.1 Highest
Version central version 3.0.1 Highest
Version pom version 3.0.1 Highest
jackson-core-2.4.2.jar
Description: Core Jackson abstractions, basic JSON streaming API implementation
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.4.2/jackson-core-2.4.2.jar
MD5: 1800d8b5c3324eaa7cff549bad28a98b
SHA1: ceb72830d95c512b4b300a38f29febc85bdf6e4b
Referenced In Project/Scope:
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom artifactid jackson-core Low
Vendor pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium
Vendor pom name Jackson-core High
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor Manifest implementation-build-date 2014-08-13 20:54:03-0700 Low
Vendor pom parent-artifactid jackson-parent Low
Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest
Vendor file name jackson-core High
Product pom url http://wiki.fasterxml.com/JacksonHome Medium
Product Manifest Bundle-Name Jackson-core Medium
Product pom description Core Jackson abstractions, basic JSON streaming API implementation
Medium
Product pom parent-groupid com.fasterxml.jackson Low
Product pom name Jackson-core High
Product pom parent-artifactid jackson-parent Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium
Product Manifest specification-title Jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product manifest Bundle-Description Core Jackson abstractions, basic JSON streaming API implementation Medium
Product central artifactid jackson-core Highest
Product Manifest implementation-build-date 2014-08-13 20:54:03-0700 Low
Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Product pom artifactid jackson-core Highest
Product pom groupid fasterxml.jackson.core Low
Product file name jackson-core High
Version pom version 2.4.2 Highest
Version file version 2.4.2 Highest
Version Manifest Implementation-Version 2.4.2 High
Version central version 2.4.2 Highest
Related Dependencies
jackson-datatype-joda-2.4.2.jar
jackson-dataformat-yaml-2.4.2.jar
jackson-jaxrs-base-2.4.2.jar
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/jaxrs/jackson-jaxrs-base/2.4.2/jackson-jaxrs-base-2.4.2.jar
SHA1: 304e6e60d495095bdae65f80462afc26d76dded4
MD5: 2764d307011e399f6cfde3d931325366
maven: com.fasterxml.jackson.jaxrs:jackson-jaxrs-base:2.4.2 ✓
jackson-module-jaxb-annotations-2.4.2.jar
jackson-jaxrs-json-provider-2.4.2.jar
jackson-annotations-2.4.0.jar
Description: Core annotations used for value types, used by Jackson data binding package.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.4.0/jackson-annotations-2.4.0.jar
MD5: 6df1b79ec2e57d62106eb47129e4f7a3
SHA1: d6a66c7a5f01cf500377bd669507a08cfeba882a
Referenced In Project/Scope:
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor FasterXML Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom description Core annotations used for value types, used by Jackson data binding package.
Medium
Vendor pom artifactid jackson-annotations Low
Vendor file name jackson-annotations High
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest implementation-build-date 2014-05-29 09:46:52-0700 Low
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor pom groupid fasterxml.jackson.core Highest
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor central groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor pom parent-artifactid jackson-parent Low
Vendor Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Vendor manifest Bundle-Description Core annotations used for value types, used by Jackson data binding package. Medium
Vendor pom url http://wiki.fasterxml.com/JacksonHome Highest
Product pom url http://wiki.fasterxml.com/JacksonHome Medium
Product pom artifactid jackson-annotations Highest
Product pom description Core annotations used for value types, used by Jackson data binding package.
Medium
Product Manifest Bundle-Name Jackson-annotations Medium
Product pom parent-groupid com.fasterxml.jackson Low
Product pom parent-artifactid jackson-parent Medium
Product file name jackson-annotations High
Product Manifest implementation-build-date 2014-05-29 09:46:52-0700 Low
Product pom name Jackson-annotations High
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product central artifactid jackson-annotations Highest
Product Manifest bundle-docurl http://wiki.fasterxml.com/JacksonHome Low
Product Manifest Implementation-Title Jackson-annotations High
Product pom groupid fasterxml.jackson.core Low
Product manifest Bundle-Description Core annotations used for value types, used by Jackson data binding package. Medium
Product Manifest specification-title Jackson-annotations Medium
Version central version 2.4.0 Highest
Version file version 2.4.0 Highest
Version pom version 2.4.0 Highest
Version Manifest Implementation-Version 2.4.0 High
commons-logging-1.0.4.jar
Description: Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems.
License:
The Apache Software License, Version 2.0: /LICENSE.txt
File Path: /home/ciagent/.m2/repository/commons-logging/commons-logging/1.0.4/commons-logging-1.0.4.jar
MD5: 8a507817b28077e0478add944c64586a
SHA1: f029a2aefe2b3e1517573c580f948caac31b1056
Referenced In Project/Scope:
eXo Wiki JPA Migration Service:compile
Evidence
Type Source Name Value Confidence
Vendor pom url http://jakarta.apache.org/commons/logging/ Highest
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor pom name Logging High
Vendor central groupid commons-logging Highest
Vendor pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Vendor pom artifactid commons-logging Low
Vendor pom groupid commons-logging Highest
Vendor Manifest extension-name org.apache.commons.logging Medium
Vendor file name commons-logging High
Vendor pom organization name The Apache Software Foundation High
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor pom organization url http://jakarta.apache.org Medium
Product pom name Logging High
Product pom url http://jakarta.apache.org/commons/logging/ Medium
Product pom artifactid commons-logging Highest
Product pom groupid commons-logging Low
Product pom description Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product pom organization url http://jakarta.apache.org Low
Product pom organization name The Apache Software Foundation Low
Product central artifactid commons-logging Highest
Product Manifest extension-name org.apache.commons.logging Medium
Product file name commons-logging High
Version file version 1.0.4 Highest
Version central version 1.0.4 Highest
Version pom version 1.0.4 Highest
Version Manifest Implementation-Version 1.0.4 High
smartgwt-lgpl-6.0-p20170514.jar: isomorphic_applets.jar
File Path: /home/ciagent/.m2/repository/com/isomorphic/smartgwt/lgpl/smartgwt-lgpl/6.0-p20170514/smartgwt-lgpl-6.0-p20170514.jar/com/smartclient/public/sc/system/helpers/isomorphic_applets.jar
MD5: 0f754cb070377f2176d66ab61c1adafe
SHA1: b1cfc819d68ad2ecb419ce92f2c36bfceebf0d09
Referenced In Project/Scope:
eXo PLF:: Wiki Webapp:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name applets Low
Vendor Manifest isomorphic-smartclient-package-date 2017-05-14 Low
Vendor file name isomorphic_applets High
Vendor jar package name isomorphic Low
Vendor Manifest Implementation-Vendor Isomorphic Software, Inc. High
Product jar package name applets Low
Product Manifest isomorphic-smartclient-package-date 2017-05-14 Low
Product file name isomorphic_applets High
Version Manifest isomorphic-smartclient-version v11.0p_2017-05-14/LGPL Development Only Medium
ehcache-core-2.6.9.jar: sizeof-agent.jar
File Path: /home/ciagent/.m2/repository/net/sf/ehcache/ehcache-core/2.6.9/ehcache-core-2.6.9.jar/net/sf/ehcache/pool/sizeof/sizeof-agent.jar
MD5: 5ad919b3ac0516897bdca079c9a222a8
SHA1: e86399a80ae6a6c7a563717eaa0ce9ba4708571c
Referenced In Projects/Scopes:
eXo PLF:: Wiki Renderer:compile
eXo PLF:: Wiki Service:compile
eXo PLF:: Wiki Webapp:runtime
eXo Wiki JPA Migration Service:compile
eXo PLF:: Wiki Webui:compile
eXo PLF:: Wiki Upgrade Plugins:compile
Evidence
Type Source Name Value Confidence
Vendor pom artifactid sizeof-agent Low
Vendor Manifest hudson-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Vendor file name sizeof-agent High
Vendor Manifest jenkins-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Vendor Manifest hudson-build-number 6 Low
Vendor pom name Ehcache Size-Of Agent High
Vendor pom url http://www.ehcache.org Highest
Vendor pom groupid net.sf.ehcache Highest
Vendor pom parent-artifactid ehcache-parent Low
Vendor Manifest jenkins-build-number 6 Low
Product Manifest hudson-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Product file name sizeof-agent High
Product pom artifactid sizeof-agent Highest
Product pom groupid net.sf.ehcache Low
Product pom parent-artifactid ehcache-parent Medium
Product Manifest jenkins-project sizeof-agent_sizeof-agent-1.0.1_publisher Low
Product Manifest hudson-build-number 6 Low
Product pom name Ehcache Size-Of Agent High
Product Manifest jenkins-build-number 6 Low
Product pom url http://www.ehcache.org Medium
Version pom parent-version 1.0.1 Low
Version pom version 1.0.1 Highest
Version Manifest hudson-version 1.449 Medium
Version Manifest hudson-build-number 6 Low
Version Manifest jenkins-version 1.449 Medium
Version Manifest jenkins-build-number 6 Low
maven: net.sf.ehcache:sizeof-agent:1.0.1
Confidence :High
jython-standalone-2.5.4-rc1.jar: jline64.dll
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/jline/jline64.dll
MD5: d2f7b0db1231aac1846a857f5c0c4f2c
SHA1: e297e4e990ce820e64d41f3f27b9be90283f3f96
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name jline64 High
Product file name jline64 High
Version file name jline64 Medium
Version file version 64 Medium
jython-standalone-2.5.4-rc1.jar: jline32.dll
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/jline/jline32.dll
MD5: b3d9a08ff70440ba3638a325512f2cd8
SHA1: 67a55d8f8ca4937d784d4334e554770adc2a1079
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name jline32 High
Product file name jline32 High
Version file version 32 Medium
Version file name jline32 Medium
jython-standalone-2.5.4-rc1.jar: wininst-7.1.exe
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/Lib/distutils/command/wininst-7.1.exe
MD5: 60ca8d5d30a48745d2918fc59f663d82
SHA1: f1eceea0200b381e8df1bd21febe4d86216d3a9d
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name wininst High
Product file name wininst High
Version file version 7.1 Highest
Version file name wininst Medium
jython-standalone-2.5.4-rc1.jar: wininst-6.exe
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/Lib/distutils/command/wininst-6.exe
MD5: 2af1ae03a9ada576bbf62fab00b69be9
SHA1: 0f042eb468c23b791446c1594f8f3bb5023eea36
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name wininst-6 High
Product file name wininst-6 High
Version file version 6 Medium
Version file name wininst-6 Medium
jython-standalone-2.5.4-rc1.jar: jffi-1.0.dll
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/jni/x86_64-Windows/jffi-1.0.dll
MD5: 63e4285e98616f329c88d741ca6f65e8
SHA1: 966259febd6c05d8287b7dd75be57bfcd77fd400
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name jffi High
Product file name jffi High
Version file version 1.0 Highest
Version file name jffi Medium
jython-standalone-2.5.4-rc1.jar: jffi-1.0.dll
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/jni/i386-Windows/jffi-1.0.dll
MD5: 570f7ce3eae96b92eb4aab891c076b50
SHA1: c35b34b1cf7a20c0478d34bcfbde3d75905a8b19
Referenced In Projects/Scopes:
eXo PLF:: Wiki Webui:runtime
eXo PLF:: Wiki Webapp:runtime
Evidence
Type Source Name Value Confidence
Vendor file name jffi High
Product file name jffi High
Version file version 1.0 Highest
Version file name jffi Medium
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling/pom.xml
Description: JBoss Marshalling API
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling/pom.xml
MD5: 2b0e9541ec4a0f19e378eaabc5e85ea0
SHA1: da91abf3554dceed9454faa89acafc48c0649df5
Evidence
Type Source Name Value Confidence
Vendor pom description JBoss Marshalling API Medium
Vendor pom groupid jboss.marshalling Highest
Vendor pom parent-artifactid jboss-marshalling-parent Low
Vendor pom artifactid jboss-marshalling Low
Vendor pom name JBoss Marshalling API High
Vendor pom parent-groupid org.jboss.marshalling Medium
Product pom artifactid jboss-marshalling Highest
Product pom parent-groupid org.jboss.marshalling Low
Product pom description JBoss Marshalling API Medium
Product pom groupid jboss.marshalling Low
Product pom parent-artifactid jboss-marshalling-parent Medium
Product pom name JBoss Marshalling API High
Version pom version 2.0.0.Beta3 Highest
maven: org.jboss.marshalling:jboss-marshalling:2.0.0.Beta3
Confidence :High
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-river/pom.xml
Description: JBoss Marshalling River Implementation
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-river/pom.xml
MD5: 1dda062cdd15bd160a4ee6cf1be9f93d
SHA1: 366411529f00ec1eb4451b9b45012bfc09bde34b
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jboss-marshalling-river Low
Vendor pom description JBoss Marshalling River Implementation Medium
Vendor pom groupid jboss.marshalling Highest
Vendor pom parent-artifactid jboss-marshalling-parent Low
Vendor pom name JBoss Marshalling River High
Vendor pom parent-groupid org.jboss.marshalling Medium
Product pom parent-groupid org.jboss.marshalling Low
Product pom description JBoss Marshalling River Implementation Medium
Product pom artifactid jboss-marshalling-river Highest
Product pom name JBoss Marshalling River High
Product pom groupid jboss.marshalling Low
Product pom parent-artifactid jboss-marshalling-parent Medium
Version pom version 2.0.0.Beta3 Highest
maven: org.jboss.marshalling:jboss-marshalling-river:2.0.0.Beta3
Confidence :High
jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-serial/pom.xml
Description: JBoss Marshalling Serial Implementation
File Path: /home/ciagent/.m2/repository/org/jboss/marshalling/jboss-marshalling-osgi/2.0.0.Beta3/jboss-marshalling-osgi-2.0.0.Beta3.jar/META-INF/maven/org.jboss.marshalling/jboss-marshalling-serial/pom.xml
MD5: 16b74097e7ec70db37b74205776ad0a7
SHA1: cf519c8805a14e6ce20933b7a89bfe0d5a7dbf0f
Evidence
Type Source Name Value Confidence
Vendor pom name JBoss Marshalling Serial High
Vendor pom description JBoss Marshalling Serial Implementation Medium
Vendor pom groupid jboss.marshalling Highest
Vendor pom parent-artifactid jboss-marshalling-parent Low
Vendor pom artifactid jboss-marshalling-serial Low
Vendor pom parent-groupid org.jboss.marshalling Medium
Product pom parent-groupid org.jboss.marshalling Low
Product pom name JBoss Marshalling Serial High
Product pom description JBoss Marshalling Serial Implementation Medium
Product pom groupid jboss.marshalling Low
Product pom artifactid jboss-marshalling-serial Highest
Product pom parent-artifactid jboss-marshalling-parent Medium
Version pom version 2.0.0.Beta3 Highest
maven: org.jboss.marshalling:jboss-marshalling-serial:2.0.0.Beta3
Confidence :High
closure-compiler-v20170910.jar/META-INF/maven/com.google.javascript/closure-compiler/pom.xml
Description:
Closure Compiler is a JavaScript optimizing compiler. It parses your
JavaScript, analyzes it, removes dead code and rewrites and minimizes
what's left. It also checks syntax, variable references, and types, and
warns about common JavaScript pitfalls. It is used in many of Google's
JavaScript apps, including Gmail, Google Web Search, Google Maps, and
Google Docs.
File Path: /home/ciagent/.m2/repository/com/google/javascript/closure-compiler/v20170910/closure-compiler-v20170910.jar/META-INF/maven/com.google.javascript/closure-compiler/pom.xml
MD5: 1b66a934999bffadab1ef6f26b68288b
SHA1: c4f1e36254f80d8b202705a678e804bc484c1e27
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid com.google.javascript Medium
Vendor pom name Closure Compiler High
Vendor pom description Closure Compiler is a JavaScript optimizing compiler. It parses your JavaScript, analyzes it, removes dead code and rewrites and minimizes what's left. It also checks syntax, variable references, and types, and warns about common JavaScript pitfalls. It is used in many of Google's JavaScript apps, including Gmail, Google Web Search, Google Maps, and Google Docs. Low
Vendor pom url https://developers.google.com/closure/compiler/ Highest
Vendor pom groupid google.javascript Highest
Vendor pom artifactid closure-compiler Low
Vendor pom parent-artifactid closure-compiler-main Low
Product pom parent-groupid com.google.javascript Low
Product pom groupid google.javascript Low
Product pom artifactid closure-compiler Highest
Product pom name Closure Compiler High
Product pom description Closure Compiler is a JavaScript optimizing compiler. It parses your JavaScript, analyzes it, removes dead code and rewrites and minimizes what's left. It also checks syntax, variable references, and types, and warns about common JavaScript pitfalls. It is used in many of Google's JavaScript apps, including Gmail, Google Web Search, Google Maps, and Google Docs. Low
Product pom parent-artifactid closure-compiler-main Medium
Product pom url https://developers.google.com/closure/compiler/ Medium
Version pom version v20170910 Highest
maven: com.google.javascript:closure-compiler:v20170910
Confidence :High
cpe: cpe:/a:google:gmail:-
Confidence :Low
suppress
Published Vulnerabilities
CVE-2017-17689 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:P/I:N/A:N)
CWE: CWE-310 Cryptographic Issues
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
Vulnerable Software & Versions: (show all )
jackson-dataformat-yaml-2.4.2.jar/META-INF/maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml/pom.xml
Description: Support for reading and writing YAML-encoded data via Jackson abstractions.
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-yaml/2.4.2/jackson-dataformat-yaml-2.4.2.jar/META-INF/maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml/pom.xml
MD5: 287aac9a700de46369cc0e327e3577bc
SHA1: da124b77ecdec56e2af7ef65828ec493590ab214
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url http://wiki.fasterxml.com/JacksonExtensionYAML Highest
Vendor pom description Support for reading and writing YAML-encoded data via Jackson abstractions.
Medium
Vendor pom parent-artifactid jackson-parent Low
Vendor pom groupid fasterxml.jackson.dataformat Highest
Vendor pom artifactid jackson-dataformat-yaml Low
Vendor pom name Jackson-dataformat-YAML High
Product pom url http://wiki.fasterxml.com/JacksonExtensionYAML Medium
Product pom description Support for reading and writing YAML-encoded data via Jackson abstractions.
Medium
Product pom parent-groupid com.fasterxml.jackson Low
Product pom groupid fasterxml.jackson.dataformat Low
Product pom artifactid jackson-dataformat-yaml Highest
Product pom parent-artifactid jackson-parent Medium
Product pom name Jackson-dataformat-YAML High
Version pom version 2.4.2 Highest
Version pom parent-version 2.4.2 Low
maven: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.4.2
Confidence :High
cpe: cpe:/a:fasterxml:jackson:2.4.2
Confidence :Low
suppress
jackson-dataformat-yaml-2.4.2.jar/META-INF/maven/org.yaml/snakeyaml/pom.xml
Description: YAML 1.1 parser and emitter for Java
License:
Apache License Version 2.0: LICENSE.txt
File Path: /home/ciagent/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-yaml/2.4.2/jackson-dataformat-yaml-2.4.2.jar/META-INF/maven/org.yaml/snakeyaml/pom.xml
MD5: d103ace8c756cc13661469b53cff1794
SHA1: c9dbe57a55450ef61cdb139c01a8edea9206949d
Evidence
Type Source Name Value Confidence
Vendor pom description YAML 1.1 parser and emitter for Java Medium
Vendor pom artifactid snakeyaml Low
Vendor pom url http://www.snakeyaml.org Highest
Vendor pom name SnakeYAML High
Vendor pom groupid yaml Highest
Product pom url http://www.snakeyaml.org Medium
Product pom description YAML 1.1 parser and emitter for Java Medium
Product pom groupid yaml Low
Product pom artifactid snakeyaml Highest
Product pom name SnakeYAML High
Version pom version 1.12 Highest
maven: org.yaml:snakeyaml:1.12
Confidence :High
jython-standalone-2.5.4-rc1.jar/META-INF/maven/jline/jline/pom.xml
Description: JLine is a java library for reading and editing user input in console applications. It features tab-completion, command history, password masking, customizable keybindings, and pass-through handlers to use to chain to other console applications.
License:
BSD: LICENSE.txt
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/jline/jline/pom.xml
MD5: 0d6d52cb98633c1b3a711696db169d43
SHA1: 4206e42ea819ceb6d541d9d394c44e2b5344fef2
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jline Low
Vendor pom name JLine High
Vendor pom description JLine is a java library for reading and editing user input in console applications. It features tab-completion, command history, password masking, customizable keybindings, and pass-through handlers to use to chain to other console applications. Low
Vendor pom url http://jline.sourceforge.net Highest
Vendor pom groupid jline Highest
Product pom artifactid jline Highest
Product pom groupid jline Low
Product pom name JLine High
Product pom url http://jline.sourceforge.net Medium
Product pom description JLine is a java library for reading and editing user input in console applications. It features tab-completion, command history, password masking, customizable keybindings, and pass-through handlers to use to chain to other console applications. Low
Version pom version 0.9.95-SNAPSHOT Highest
maven: jline:jline:0.9.95-SNAPSHOT
Confidence :High
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.antlr/antlr-runtime/pom.xml
Description: A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions.
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.antlr/antlr-runtime/pom.xml
MD5: 2663ae2cc7c8739fa5b19e2224ab6e55
SHA1: d72704aaf6a6fd2cd6bc142b959f9206e8f71a90
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.antlr Medium
Vendor pom artifactid antlr-runtime Low
Vendor pom parent-artifactid antlr-master Low
Vendor pom name Antlr 3 Runtime High
Vendor pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Vendor pom groupid antlr Highest
Vendor pom url http://www.antlr.org Highest
Product pom artifactid antlr-runtime Highest
Product pom parent-artifactid antlr-master Medium
Product pom url http://www.antlr.org Medium
Product pom parent-groupid org.antlr Low
Product pom name Antlr 3 Runtime High
Product pom description A framework for constructing recognizers, compilers, and translators from grammatical descriptions containing Java, C#, C++, or Python actions. Low
Product pom groupid antlr Low
Version pom version 3.1.3 Highest
maven: org.antlr:antlr-runtime:3.1.3
Confidence :High
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.ext.posix/jnr-posix/pom.xml
Description:
Common cross-project/cross-platform POSIX APIs
License:
Common Public License - v 1.0: http://www-128.ibm.com/developerworks/library/os-cpl.html
GNU General Public License Version 2: http://www.gnu.org/copyleft/gpl.html
GNU Lesser General Public License Version 2.1: http://www.gnu.org/licenses/lgpl.html
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.ext.posix/jnr-posix/pom.xml
MD5: feaa380889a30e4e2beee4746d9b0b54
SHA1: 28d89352183ec1db9f4cb75efe98f5f0b9ae589d
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jnr-posix Low
Vendor pom name jnr-posix High
Vendor pom description
Common cross-project/cross-platform POSIX APIs
Medium
Vendor pom groupid jruby.ext.posix Highest
Product pom groupid jruby.ext.posix Low
Product pom artifactid jnr-posix Highest
Product pom name jnr-posix High
Product pom description
Common cross-project/cross-platform POSIX APIs
Medium
Version pom version 1.1.4 Highest
Published Vulnerabilities
CVE-2010-1330 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Vulnerable Software & Versions: (show all )
CVE-2011-4838 suppress
Severity:
High
CVSS Score: 7.8
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
CWE: CWE-20 Improper Input Validation
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
Vulnerable Software & Versions: (show all )
CVE-2012-5370 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-310 Cryptographic Issues
JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.
Vulnerable Software & Versions:
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/constantine/pom.xml
Description: A set of platform constants (e.g. errno values)
License:
The MIT License: http://www.opensource.org/licenses/mit-license.php
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/constantine/pom.xml
MD5: 970585d7cb052c21db6caa55c946e35e
SHA1: 7d6faeadd03efb438919ff833a9814728c042f0c
Evidence
Type Source Name Value Confidence
Vendor pom name constantine High
Vendor pom url http://constantine.kenai.com Highest
Vendor pom groupid jruby.extras Highest
Vendor pom description A set of platform constants (e.g. errno values) Medium
Vendor pom artifactid constantine Low
Product pom groupid jruby.extras Low
Product pom name constantine High
Product pom artifactid constantine Highest
Product pom url http://constantine.kenai.com Medium
Product pom description A set of platform constants (e.g. errno values) Medium
Version pom version 0.7 Highest
maven: org.jruby.extras:constantine:0.7
Confidence :High
cpe: cpe:/a:values_project:values:0.7
Confidence :Low
suppress
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jaffl/pom.xml
Description: An abstracted interface to invoking native functions from java
License:
GNU Lesser General Public License Version 3: http://www.gnu.org/licenses/lgpl-3.0.txt
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jaffl/pom.xml
MD5: 486f581e2d6cee3f3c1020bd1cd856e2
SHA1: d833022c9991b70bcf6ebc9924af7da3bc79f5d1
Evidence
Type Source Name Value Confidence
Vendor pom description An abstracted interface to invoking native functions from java Medium
Vendor pom name jaffl High
Vendor pom url http://github.com/wmeissner/jaffl Highest
Vendor pom artifactid jaffl Low
Vendor pom groupid jruby.extras Highest
Product pom groupid jruby.extras Low
Product pom description An abstracted interface to invoking native functions from java Medium
Product pom name jaffl High
Product pom url http://github.com/wmeissner/jaffl Medium
Product pom artifactid jaffl Highest
Version pom version 0.5.1 Highest
maven: org.jruby.extras:jaffl:0.5.1
Confidence :High
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jffi/pom.xml
Description: Java wrapper around libffi
License:
GNU LGPLv3: http://www.gnu.org/licenses/lgpl-3.0.txt
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jffi/pom.xml
MD5: 39e5edd1583d710078ef1f596bb29ce7
SHA1: 5aea815e74debbfc61f10e9274a9ba27cd3e22af
Evidence
Type Source Name Value Confidence
Vendor pom url http://github.com/wmeissner/jffi Highest
Vendor pom name jffi High
Vendor pom artifactid jffi Low
Vendor pom description Java wrapper around libffi Medium
Vendor pom groupid jruby.extras Highest
Product pom groupid jruby.extras Low
Product pom url http://github.com/wmeissner/jffi Medium
Product pom artifactid jffi Highest
Product pom name jffi High
Product pom description Java wrapper around libffi Medium
Version pom version 1.0.1 Highest
Published Vulnerabilities
CVE-2010-1330 suppress
Severity:
Medium
CVSS Score: 4.3
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Vulnerable Software & Versions: (show all )
CVE-2011-4838 suppress
Severity:
High
CVSS Score: 7.8
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
CWE: CWE-20 Improper Input Validation
JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
Vulnerable Software & Versions: (show all )
CVE-2012-5370 suppress
Severity:
Medium
CVSS Score: 5.0
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
CWE: CWE-310 Cryptographic Issues
JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.
Vulnerable Software & Versions:
jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jnr-netdb/pom.xml
Description: Lookup TCP and UDP services from java
License:
GNU Lesser General Public License Version 3: http://www.gnu.org/licenses/lgpl-3.0.txt
File Path: /home/ciagent/.m2/repository/org/python/jython-standalone/2.5.4-rc1/jython-standalone-2.5.4-rc1.jar/META-INF/maven/org.jruby.extras/jnr-netdb/pom.xml
MD5: 303650108f1ec73ff0561d8b3b879769
SHA1: 1cef127eec64ffe5fa5ac078e14b6fd481536436
Evidence
Type Source Name Value Confidence
Vendor pom artifactid jnr-netdb Low
Vendor pom name jnr-netdb High
Vendor pom description Lookup TCP and UDP services from java Medium
Vendor pom url http://github.com/wmeissner/jnr-netdb Highest
Vendor pom groupid jruby.extras Highest
Product pom groupid jruby.extras Low
Product pom name jnr-netdb High
Product pom description Lookup TCP and UDP services from java Medium
Product pom url http://github.com/wmeissner/jnr-netdb Medium
Product pom artifactid jnr-netdb Highest
Version pom version 0.4 Highest
maven: org.jruby.extras:jnr-netdb:0.4
Confidence :High