Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 6.1.6Report Generated On : Mon, 6 Dec 2021 15:05:29 GMTDependencies Scanned : 28 (28 unique)Vulnerable Dependencies : 5 Vulnerabilities Found : 7Vulnerabilities Suppressed : 0... NVD CVE Checked : 2021-12-06T15:04:04NVD CVE Modified : 2021-12-06T13:00:01VersionCheckOn : 2021-12-06T15:04:04Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies aether-api-1.13.1.jarDescription:
The application programming interface for the repository system.
File Path: /home/runner/.m2/repository/org/sonatype/aether/aether-api/1.13.1/aether-api-1.13.1.jarMD5: 6438f4b31d3f3220d88edc16abdc3721SHA1: e48292eae5e14ec44978aa53debb1af7ddd6df93SHA256: ae8dc80232771f8913febfa410c5719e9ba8ded81fb99788e214fd676dbbe13fReferenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.sonatype.aether Medium Vendor jar package name repository Highest Vendor jar package name sonatype Highest Vendor pom groupid sonatype.aether Highest Vendor jar package name sonatype Low Vendor pom artifactid aether-api Low Vendor pom parent-artifactid aether Low Vendor file name aether-api High Vendor jar package name aether Highest Vendor pom name Aether :: API High Vendor jar package name aether Low Vendor pom groupid org.sonatype.aether Highest Product pom parent-groupid org.sonatype.aether Medium Product jar package name repository Highest Product jar package name sonatype Highest Product pom parent-artifactid aether Medium Product pom groupid sonatype.aether Highest Product file name aether-api High Product jar package name aether Highest Product pom name Aether :: API High Product jar package name aether Low Product pom artifactid aether-api Highest Version pom version 1.13.1 Highest Version file version 1.13.1 High
aether-impl-1.13.1.jarDescription:
An implementation of the repository system.
File Path: /home/runner/.m2/repository/org/sonatype/aether/aether-impl/1.13.1/aether-impl-1.13.1.jarMD5: 4236e1586cfdd28f032bcf71293f6bb1SHA1: ba2656934fa7c0f20c0c3882873dc705e16ae201SHA256: 865511994805827e88f327944a089142bb7f3d88cde271ba3dceb732cb137a93Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.sonatype.aether Medium Vendor jar package name sonatype Highest Vendor pom groupid sonatype.aether Highest Vendor pom artifactid aether-impl Low Vendor jar package name impl Low Vendor jar package name sonatype Low Vendor pom name Aether :: Implementation High Vendor jar package name impl Highest Vendor pom parent-artifactid aether Low Vendor file name aether-impl High Vendor jar package name aether Highest Vendor jar package name aether Low Vendor pom groupid org.sonatype.aether Highest Product pom parent-groupid org.sonatype.aether Medium Product jar package name sonatype Highest Product pom groupid sonatype.aether Highest Product pom artifactid aether-impl Highest Product jar package name impl Low Product pom name Aether :: Implementation High Product jar package name impl Highest Product pom parent-artifactid aether Medium Product file name aether-impl High Product jar package name aether Highest Product jar package name internal Low Product jar package name aether Low Version pom version 1.13.1 Highest Version file version 1.13.1 High
aether-spi-1.13.1.jarDescription:
The service provider interface for repository system implementations and repository connectors.
File Path: /home/runner/.m2/repository/org/sonatype/aether/aether-spi/1.13.1/aether-spi-1.13.1.jarMD5: 3f1881f890062e779fa27aa9a6789cebSHA1: c62b02d2a5a3939fded72039dd83e5b8ed42d45eSHA256: d5de4e299be5a79feb1dbe8ff3814034c6e44314b4c00b92ffa8d97576ded5b3Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.sonatype.aether Medium Vendor jar package name sonatype Highest Vendor pom groupid sonatype.aether Highest Vendor jar package name spi Low Vendor jar package name sonatype Low Vendor pom name Aether :: SPI High Vendor file name aether-spi High Vendor jar package name spi Highest Vendor pom parent-artifactid aether Low Vendor jar package name aether Highest Vendor jar package name aether Low Vendor pom artifactid aether-spi Low Vendor pom groupid org.sonatype.aether Highest Product pom parent-groupid org.sonatype.aether Medium Product jar package name connector Low Product jar package name sonatype Highest Product pom groupid sonatype.aether Highest Product jar package name spi Low Product pom name Aether :: SPI High Product file name aether-spi High Product jar package name spi Highest Product pom artifactid aether-spi Highest Product pom parent-artifactid aether Medium Product jar package name aether Highest Product jar package name aether Low Version pom version 1.13.1 Highest Version file version 1.13.1 High
aether-util-1.13.1.jarDescription:
A collection of utility classes to ease usage of the repository system.
File Path: /home/runner/.m2/repository/org/sonatype/aether/aether-util/1.13.1/aether-util-1.13.1.jarMD5: 119757ef761de4a43c763622dcb1f56eSHA1: c8487ceb499b9ced96694731810acd1a70e13acaSHA256: 687799a0ce988bee9e8eb9ae0ba870300adc0114248ad4a4327bdb625d27e010Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name util Highest Vendor pom parent-groupid org.sonatype.aether Medium Vendor jar package name repository Highest Vendor jar package name sonatype Highest Vendor pom groupid sonatype.aether Highest Vendor jar package name sonatype Low Vendor pom name Aether :: Utilities High Vendor file name aether-util High Vendor jar package name util Low Vendor pom artifactid aether-util Low Vendor pom parent-artifactid aether Low Vendor jar package name aether Highest Vendor jar package name aether Low Vendor pom groupid org.sonatype.aether Highest Product pom artifactid aether-util Highest Product jar package name util Highest Product pom parent-groupid org.sonatype.aether Medium Product jar package name repository Highest Product jar package name sonatype Highest Product pom groupid sonatype.aether Highest Product pom name Aether :: Utilities High Product file name aether-util High Product jar package name util Low Product pom parent-artifactid aether Medium Product jar package name aether Highest Product jar package name aether Low Version pom version 1.13.1 Highest Version file version 1.13.1 High
commons-io-2.5.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/commons-io/commons-io/2.5/commons-io-2.5.jar
MD5: e2d74794fba570ec2115fb9d5b05dc9b
SHA1: 2852e6e05fbb95076fc091f6d1780f1f8fe35e0f
SHA256: a10418348d234968600ccb1d988efcbbd08716e1d96936ccc1880e7d22513474
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom groupid commons-io Highest Vendor jar package name apache Highest Vendor file name commons-io High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest implementation-build tags/commons-io-2.5@r1739098; 2016-04-14 09:19:54-0400 Low Vendor pom name Apache Commons IO High Vendor jar package name commons Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid commons-io Low Vendor pom parent-groupid org.apache.commons Medium Vendor jar package name io Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Vendor pom url http://commons.apache.org/proper/commons-io/ Highest Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product jar package name apache Highest Product pom groupid commons-io Highest Product file name commons-io High Product pom url http://commons.apache.org/proper/commons-io/ Medium Product Manifest implementation-build tags/commons-io-2.5@r1739098; 2016-04-14 09:19:54-0400 Low Product pom name Apache Commons IO High Product jar package name commons Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom parent-groupid org.apache.commons Medium Product jar package name io Highest Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Product Manifest Implementation-Title Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product Manifest bundle-symbolicname org.apache.commons.io Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Version file version 2.5 High Version pom parent-version 2.5 Low Version pom version 2.5 Highest Version Manifest Implementation-Version 2.5 High
Published Vulnerabilities CVE-2021-29425 suppress
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
commons-lang3-3.6.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.6/commons-lang3-3.6.jar
MD5: 5d18f68b5122fd398c118df53ab4cf55
SHA1: 9d28a6b23650e8a7e9063c04588ace6cf7012c17
SHA256: 89c27f03fff18d0b06e7afd7ef25e209766df95b6c1269d6c3ebbdea48d5f284
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest Vendor jar package name commons Highest Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid commons-lang3 Low Vendor jar package name lang3 Highest Vendor pom parent-artifactid commons-parent Low Vendor pom groupid org.apache.commons Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor file name commons-lang3 High Vendor pom name Apache Commons Lang High Vendor pom groupid apache.commons Highest Product jar package name apache Highest Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Product jar package name commons Highest Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product pom artifactid commons-lang3 Highest Product pom parent-groupid org.apache.commons Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Apache Commons Lang Medium Product jar package name lang3 Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-lang/ Medium Product file name commons-lang3 High Product pom name Apache Commons Lang High Product pom groupid apache.commons Highest Version pom parent-version 3.6 Low Version file version 3.6 High Version Manifest Implementation-Version 3.6 High Version pom version 3.6 Highest
jdom2-2.0.5.jarDescription:
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
License:
Similar to Apache License but with the acknowledgment clause removed: https://raw.github.com/hunterhacker/jdom/master/LICENSE.txt File Path: /home/runner/.m2/repository/org/jdom/jdom2/2.0.5/jdom2-2.0.5.jar
MD5: 302db3c65c38d3c10ef31bca76bd76b4
SHA1: 2001db51c131e555bafdb77fc52af6a9408c505e
SHA256: 32ed093f39c46a8d99f801240069478eac93b35f07351c001f2cef4330e97b4a
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid jdom2 Low Vendor manifest: org/jdom2/filter/ Implementation-Vendor jdom.org Medium Vendor pom url http://www.jdom.org Highest Vendor file name jdom2 High Vendor manifest: org/jdom2/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/xpath/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/adapters/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/input/ Implementation-Vendor jdom.org Medium Vendor pom groupid jdom Highest Vendor pom organization name JDOM High Vendor manifest: org/jdom2/transform/ Implementation-Vendor jdom.org Medium Vendor pom organization url http://www.jdom.org Medium Vendor pom name JDOM High Vendor manifest: org/jdom2/output/ Implementation-Vendor jdom.org Medium Vendor pom groupid org.jdom Highest Vendor jar package name jdom2 Highest Product file name jdom2 High Product manifest: org/jdom2/output/ Specification-Title JDOM Output Classes Medium Product manifest: org/jdom2/transform/ Specification-Title JDOM Transformation Classes Medium Product jar package name transform Highest Product jar package name output Highest Product manifest: org/jdom2/filter/ Specification-Title JDOM Filter Classes Medium Product pom groupid jdom Highest Product manifest: org/jdom2/ Implementation-Title org.jdom2 Medium Product pom url http://www.jdom.org Medium Product manifest: org/jdom2/adapters/ Implementation-Title org.jdom2.adapters Medium Product manifest: org/jdom2/ Specification-Title JDOM Classes Medium Product pom name JDOM High Product jar package name adapters Highest Product manifest: org/jdom2/adapters/ Specification-Title JDOM Adapter Classes Medium Product jar package name jdom2 Highest Product pom organization name JDOM Low Product manifest: org/jdom2/xpath/ Specification-Title JDOM XPath Classes Medium Product manifest: org/jdom2/output/ Implementation-Title org.jdom2.output Medium Product jar package name input Highest Product jar package name xpath Highest Product manifest: org/jdom2/transform/ Implementation-Title org.jdom2.transform Medium Product pom artifactid jdom2 Highest Product manifest: org/jdom2/input/ Specification-Title JDOM Input Classes Medium Product manifest: org/jdom2/input/ Implementation-Title org.jdom2.input Medium Product pom organization url http://www.jdom.org Low Product manifest: org/jdom2/xpath/ Implementation-Title org.jdom2.xpath Medium Product jar package name filter Highest Product manifest: org/jdom2/filter/ Implementation-Title org.jdom2.filter Medium Version manifest: org/jdom2/input/ Implementation-Version 2.0.5 Medium Version manifest: org/jdom2/xpath/ Implementation-Version 2.0.5 Medium Version pom version 2.0.5 Highest Version manifest: org/jdom2/filter/ Implementation-Version 2.0.5 Medium Version manifest: org/jdom2/adapters/ Implementation-Version 2.0.5 Medium Version manifest: org/jdom2/ Implementation-Version 2.0.5 Medium Version manifest: org/jdom2/transform/ Implementation-Version 2.0.5 Medium Version manifest: org/jdom2/output/ Implementation-Version 2.0.5 Medium Version file version 2.0.5 High
Published Vulnerabilities CVE-2021-33813 suppress
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
maven-aether-provider-3.0.5.jarDescription:
This module provides extensions to Aether for utilizing the Maven POM and Maven repository metadata for artifacts resolution
and download.
File Path: /home/runner/.m2/repository/org/apache/maven/maven-aether-provider/3.0.5/maven-aether-provider-3.0.5.jarMD5: aad430d4111400e0d78c4e79eb0f9797SHA1: e0716af7536efeb1da5d90b12464fea2a6fb40efSHA256: c74327cd5d7b137c8be3591c766271ac8ace1a617518f0410b8a95579f9839b0Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name repository Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom artifactid maven-aether-provider Low Vendor pom groupid org.apache.maven Highest Vendor file name maven-aether-provider High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Vendor pom name Maven Aether Provider High Product jar package name apache Highest Product file name maven-aether-provider High Product Manifest specification-title Maven Aether Provider Medium Product pom artifactid maven-aether-provider Highest Product Manifest Implementation-Title Maven Aether Provider High Product jar package name repository Highest Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom name Maven Aether Provider High Product pom parent-artifactid maven Medium Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-artifact-3.0.5.jarFile Path: /home/runner/.m2/repository/org/apache/maven/maven-artifact/3.0.5/maven-artifact-3.0.5.jarMD5: 37818c6f0ef84b6338fdd1520e9831dbSHA1: 7cd9aa7425c4a967bd39c2f6f61ab9535570fcb4SHA256: c6d5e244dd2329971f91b8df666ffe9e0b00a7dd014d6ee073b6f6cb82877f5cReferenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Maven Artifact High Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor jar package name artifact Highest Vendor pom groupid org.apache.maven Highest Vendor pom artifactid maven-artifact Low Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor file name maven-artifact High Vendor pom parent-groupid org.apache.maven Medium Product Manifest Implementation-Title Maven Artifact High Product jar package name apache Highest Product pom name Maven Artifact High Product file name maven-artifact High Product jar package name maven Highest Product Manifest specification-title Maven Artifact Medium Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom artifactid maven-artifact Highest Product pom parent-artifactid maven Medium Product jar package name artifact Highest Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-core-3.0.5.jarDescription:
Maven Core classes. File Path: /home/runner/.m2/repository/org/apache/maven/maven-core/3.0.5/maven-core-3.0.5.jarMD5: ee0bd82403231f5e268fd85044027221SHA1: 27659b27346aff66d36e8ab16c7050220d875bcaSHA256: ac8e617f951ecde3c4f6bca4922fdd7861500fe7d58289f26ad5adac443075bcReferenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name maven-core High Vendor pom artifactid maven-core Low Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Core High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Product jar package name apache Highest Product pom artifactid maven-core Highest Product file name maven-core High Product pom name Maven Core High Product Manifest Implementation-Title Maven Core High Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product Manifest specification-title Maven Core Medium Product pom parent-artifactid maven Medium Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
Published Vulnerabilities CVE-2021-26291 suppress
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html CWE-346 Origin Validation Error
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N References:
Vulnerable Software & Versions: (show all )
maven-model-3.0.5.jarDescription:
Model for Maven POM (Project Object Model) File Path: /home/runner/.m2/repository/org/apache/maven/maven-model/3.0.5/maven-model-3.0.5.jarMD5: 40a2c5b201caf14b90faa27fd55f9515SHA1: 490d7489dd73137f6afef52c5a3e465201c533bfSHA256: 876a76b663db6c7326ad234afe430c473d3261a06b3284f31d5eb4889d1c3084Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Maven Model High Vendor jar package name model Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom artifactid maven-model Low Vendor pom groupid org.apache.maven Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor file name maven-model High Vendor pom parent-groupid org.apache.maven Medium Product jar package name apache Highest Product pom name Maven Model High Product jar package name model Highest Product file name maven-model High Product Manifest Implementation-Title Maven Model High Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product Manifest specification-title Maven Model Medium Product pom parent-artifactid maven Medium Product pom artifactid maven-model Highest Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-model-builder-3.0.5.jarDescription:
The effective model builder, with inheritance, profile activation, interpolation, ... File Path: /home/runner/.m2/repository/org/apache/maven/maven-model-builder/3.0.5/maven-model-builder-3.0.5.jarMD5: 98198ff5698781c9bf48b081bad49e62SHA1: f1e0b49ebe74335c11c93eec7549c65291053bc9SHA256: 45a2c6ff76e12678eaf576bd7a68d028c5a5ba85fdc216a381ea86e9187e1b51Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid maven-model-builder Low Vendor file name maven-model-builder High Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Maven Model Builder High Vendor jar package name model Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor jar package name interpolation Highest Vendor pom groupid org.apache.maven Highest Vendor jar package name profile Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Vendor jar package name inheritance Highest Product file name maven-model-builder High Product jar package name apache Highest Product pom name Maven Model Builder High Product jar package name model Highest Product jar package name maven Highest Product Manifest specification-title Maven Model Builder Medium Product pom groupid apache.maven Highest Product jar package name interpolation Highest Product Manifest Implementation-Title Maven Model Builder High Product jar package name profile Highest Product pom parent-groupid org.apache.maven Medium Product jar package name inheritance Highest Product pom parent-artifactid maven Medium Product pom artifactid maven-model-builder Highest Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-plugin-api-3.0.5.jarDescription:
The API for plugins - Mojos - development. File Path: /home/runner/.m2/repository/org/apache/maven/maven-plugin-api/3.0.5/maven-plugin-api-3.0.5.jarMD5: cbe2f575d378fc6163c157a0e6af42a3SHA1: 958b87b581d46e7958b39733b0cc600927e8521eSHA256: 469505f75b8526a338cfd7e0ec841655ae52ddbcc1b36482e97d72f52ce7d890Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-plugin-api Low Vendor file name maven-plugin-api High Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor jar package name plugin Highest Vendor pom parent-groupid org.apache.maven Medium Vendor pom name Maven Plugin API High Product Manifest Implementation-Title Maven Plugin API High Product jar package name apache Highest Product Manifest specification-title Maven Plugin API Medium Product file name maven-plugin-api High Product jar package name maven Highest Product jar package name plugin Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom parent-artifactid maven Medium Product pom name Maven Plugin API High Product pom artifactid maven-plugin-api Highest Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-repository-metadata-3.0.5.jarDescription:
Per-directory local and remote repository metadata. File Path: /home/runner/.m2/repository/org/apache/maven/maven-repository-metadata/3.0.5/maven-repository-metadata-3.0.5.jarMD5: 2b5e8628b7d1d32829437dd1dc66f97aSHA1: 94475fff77103ae46a1b02284a0950ed74497fc3SHA256: c867b4e075a4548bf27422542f96b159f94c4e7ffaaf6427b10433afd6a3a38cReferenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name repository Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor file name maven-repository-metadata High Vendor pom name Maven Repository Metadata Model High Vendor pom artifactid maven-repository-metadata Low Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Product jar package name apache Highest Product Manifest specification-title Maven Repository Metadata Model Medium Product pom artifactid maven-repository-metadata Highest Product file name maven-repository-metadata High Product pom name Maven Repository Metadata Model High Product jar package name repository Highest Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom parent-artifactid maven Medium Product Manifest Implementation-Title Maven Repository Metadata Model High Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-settings-3.0.5.jarDescription:
Maven Settings model. File Path: /home/runner/.m2/repository/org/apache/maven/maven-settings/3.0.5/maven-settings-3.0.5.jarMD5: a608e0ce2bffaf9f89418e657746c894SHA1: 8e98d918ba2b41175d72307853f792e3bded4fc7SHA256: d8f9f237afc21d8202eedffa29cbf6e9d46c78b3c22b217d16267216988221b9Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name settings Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name maven-settings High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom artifactid maven-settings Low Vendor pom parent-groupid org.apache.maven Medium Vendor pom name Maven Settings High Product jar package name apache Highest Product Manifest specification-title Maven Settings Medium Product jar package name settings Highest Product Manifest Implementation-Title Maven Settings High Product jar package name maven Highest Product file name maven-settings High Product pom groupid apache.maven Highest Product pom artifactid maven-settings Highest Product pom parent-groupid org.apache.maven Medium Product pom name Maven Settings High Product pom parent-artifactid maven Medium Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
maven-settings-builder-3.0.5.jarDescription:
The effective settings builder, with inheritance and password decryption. File Path: /home/runner/.m2/repository/org/apache/maven/maven-settings-builder/3.0.5/maven-settings-builder-3.0.5.jarMD5: 9446d7885d57cd95170f1c2cccd89564SHA1: 7b87eb83abd6efa77e51882bbebc1b316739c681SHA256: ac0e62e26b7f690e265ba75667531973b8a2da12b3b0ff102a612f05b42b6fafReferenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name settings Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom name Maven Settings Builder High Vendor pom groupid org.apache.maven Highest Vendor file name maven-settings-builder High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom artifactid maven-settings-builder Low Vendor pom parent-groupid org.apache.maven Medium Product Manifest specification-title Maven Settings Builder Medium Product jar package name apache Highest Product file name maven-settings-builder High Product Manifest Implementation-Title Maven Settings Builder High Product jar package name settings Highest Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom artifactid maven-settings-builder Highest Product pom parent-artifactid maven Medium Product pom name Maven Settings Builder High Version pom version 3.0.5 Highest Version Manifest Implementation-Version 3.0.5 High Version file version 3.0.5 High
org.apache.sling.commons.json-2.0.8.jarDescription:
Apache Sling JSON Library License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/sling/org.apache.sling.commons.json/2.0.8/org.apache.sling.commons.json-2.0.8.jar
MD5: 307a20494e8f52f6d049bdd253bcb5f2
SHA1: bae2d2fc9e42ee0942caa8523c3027f0024091b3
SHA256: b508999e86064cd71086acec7b64ff163874a5c695b9fb037d2ff9c99d6bca96
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest bundle-docurl http://sling.apache.org Low Vendor jar package name commons Highest Vendor jar package name sling Highest Vendor jar package name json Highest Vendor pom name Apache Sling JSON Library High Vendor pom groupid apache.sling Highest Vendor pom parent-artifactid sling Low Vendor Manifest bundle-category sling Low Vendor pom artifactid apache.sling.commons.json Low Vendor file name org.apache.sling.commons.json High Vendor Manifest bundle-symbolicname org.apache.sling.commons.json Medium Vendor pom parent-groupid org.apache.sling Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom groupid org.apache.sling Highest Product jar package name apache Highest Product pom artifactid org.apache.sling.commons.json Highest Product Manifest bundle-docurl http://sling.apache.org Low Product jar package name commons Highest Product jar package name sling Highest Product jar package name json Highest Product pom name Apache Sling JSON Library High Product pom groupid apache.sling Highest Product Manifest Bundle-Name Apache Sling JSON Library Medium Product pom artifactid apache.sling.commons.json Highest Product Manifest bundle-category sling Low Product file name org.apache.sling.commons.json High Product Manifest bundle-symbolicname org.apache.sling.commons.json Medium Product pom parent-groupid org.apache.sling Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom parent-artifactid sling Medium Version pom version 2.0.8 Highest Version Manifest Bundle-Version 2.0.8 High Version pom parent-version 2.0.8 Low Version file version 2.0.8 High
plexus-build-api-0.0.7.jarFile Path: /home/runner/.m2/repository/org/sonatype/plexus/plexus-build-api/0.0.7/plexus-build-api-0.0.7.jarMD5: 49f0f8c6bdf2687e358870a4fc1559c6SHA1: e6ba5cd4bfd8de00235af936e7f63eb24ed436e6SHA256: 934171640fbd3d2495c50b79b0d9adb11e2c83e65bad157df8fe34bcac0ff798Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name plexus Low Vendor pom parent-artifactid spice-parent Low Vendor file name plexus-build-api High Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor pom artifactid plexus-build-api Low Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom groupid org.sonatype.plexus Highest Vendor jar package name plexus Highest Vendor jar package name build Low Vendor pom groupid sonatype.plexus Highest Vendor jar package name build Highest Product jar package name incremental Low Product jar package name plexus Low Product pom artifactid plexus-build-api Highest Product jar package name plexus Highest Product file name plexus-build-api High Product pom parent-artifactid spice-parent Medium Product jar package name sonatype Highest Product jar package name build Low Product pom groupid sonatype.plexus Highest Product pom parent-groupid org.sonatype.spice Medium Product jar package name build Highest Version file version 0.0.7 High Version pom parent-version 0.0.7 Low Version pom version 0.0.7 Highest
plexus-cipher-1.4.jarFile Path: /home/runner/.m2/repository/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.jarMD5: 7b2d6fcf0d5800d5b1ce09d98d98dcafSHA1: 50ade46f23bb38cd984b4ec560c46223432aac38SHA256: 5a15fdba22669e0fdd06e10dcce6320879e1f7398fbc910cd0677b50672a78c4Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name plexus Low Vendor pom parent-artifactid spice-parent Low Vendor jar package name sonatype Highest Vendor jar package name cipher Highest Vendor jar package name components Low Vendor jar package name sonatype Low Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom groupid org.sonatype.plexus Highest Vendor pom artifactid plexus-cipher Low Vendor pom url http://spice.sonatype.org/${project.artifactId} Highest Vendor jar package name plexus Highest Vendor file name plexus-cipher High Vendor pom groupid sonatype.plexus Highest Vendor pom name Plexus Cipher: encryption/decryption Component High Product jar package name plexus Low Product pom parent-artifactid spice-parent Medium Product jar package name sonatype Highest Product pom url http://spice.sonatype.org/${project.artifactId} Medium Product jar package name cipher Highest Product jar package name components Low Product pom parent-groupid org.sonatype.spice Medium Product jar package name plexus Highest Product jar package name cipher Low Product file name plexus-cipher High Product pom groupid sonatype.plexus Highest Product pom name Plexus Cipher: encryption/decryption Component High Product pom artifactid plexus-cipher Highest Version file version 1.4 High Version pom version 1.4 Highest Version pom parent-version 1.4 Low
plexus-classworlds-2.4.jarDescription:
A class loader framework File Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-classworlds/2.4/plexus-classworlds-2.4.jarMD5: 4b6ec19d96af7d901c1aad7d2415d498SHA1: ef38ff5c25f83a4a02fcd9843d85f3e47012873eSHA256: 259d528a29722cab6349d7e7d432e3fd4877c087ffcb04985a6612e97023bba8Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-classworlds High Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor pom artifactid plexus-classworlds Low Vendor pom parent-groupid org.codehaus.plexus Medium Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Classworlds High Vendor jar package name classworlds Highest Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor jar package name classworlds Low Vendor pom parent-artifactid plexus Low Product file name plexus-classworlds High Product jar package name plexus Low Product pom artifactid plexus-classworlds Highest Product pom name Plexus Classworlds High Product jar package name classworlds Highest Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product jar package name codehaus Highest Product pom parent-artifactid plexus Medium Product pom parent-groupid org.codehaus.plexus Medium Product jar package name classworlds Low Version pom parent-version 2.4 Low Version file version 2.4 High Version pom version 2.4 Highest
plexus-component-annotations-1.5.5.jarDescription:
Plexus Component "Java 5" Annotations, to describe plexus components properties in java sources with
standard annotations instead of javadoc annotations.
File Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-component-annotations/1.5.5/plexus-component-annotations-1.5.5.jarMD5: ef37dcdb84030422db428b63c4354e5bSHA1: c72f2660d0cbed24246ddb55d7fdc4f7374d2078SHA256: 4df7a6a7be64b35bbccf60b5c115697f9ea3421d22674ae67135dde375fcca1fReferenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor file name plexus-component-annotations High Vendor pom parent-groupid org.codehaus.plexus Medium Vendor jar package name annotations Highest Vendor pom name Plexus :: Component Annotations High Vendor pom groupid org.codehaus.plexus Highest Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor jar package name component Highest Vendor pom artifactid plexus-component-annotations Low Vendor pom parent-artifactid plexus-containers Low Vendor jar package name component Low Product jar package name plexus Low Product pom parent-artifactid plexus-containers Medium Product file name plexus-component-annotations High Product pom parent-groupid org.codehaus.plexus Medium Product jar package name annotations Highest Product pom name Plexus :: Component Annotations High Product jar package name annotations Low Product pom artifactid plexus-component-annotations Highest Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product jar package name codehaus Highest Product jar package name component Highest Product jar package name component Low Version file version 1.5.5 High Version pom version 1.5.5 Highest
plexus-interpolation-1.14.jarFile Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-interpolation/1.14/plexus-interpolation-1.14.jarMD5: f92db8b194fc417d72cc74c428afacf8SHA1: c88dd864fe8b8256c25558ce7cd63be66ba07693SHA256: 7fc63378d3e84663619b9bedace9f9fe78b276c2be3c62ca2245449294c84176Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor jar package name interpolation Highest Vendor pom name Plexus Interpolation API High Vendor pom parent-groupid org.codehaus.plexus Medium Vendor jar package name interpolation Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor file name plexus-interpolation High Vendor pom artifactid plexus-interpolation Low Vendor pom parent-artifactid plexus-components Low Product jar package name plexus Low Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product jar package name codehaus Highest Product file name plexus-interpolation High Product pom parent-artifactid plexus-components Medium Product jar package name interpolation Highest Product pom name Plexus Interpolation API High Product pom parent-groupid org.codehaus.plexus Medium Product pom artifactid plexus-interpolation Highest Product jar package name interpolation Low Version file version 1.14 High Version pom parent-version 1.14 Low Version pom version 1.14 Highest
plexus-sec-dispatcher-1.3.jarFile Path: /home/runner/.m2/repository/org/sonatype/plexus/plexus-sec-dispatcher/1.3/plexus-sec-dispatcher-1.3.jarMD5: 53160199f5667de3fca69b723173639bSHA1: dedc02034fb8fcd7615d66593228cb71709134b4SHA256: 3b0559bb8432f28937efe6ca193ef54a8506d0075d73fd7406b9b116c6a11063Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name plexus Low Vendor pom parent-artifactid spice-parent Low Vendor jar package name sec Highest Vendor jar package name sonatype Highest Vendor jar package name components Low Vendor jar package name sonatype Low Vendor file name plexus-sec-dispatcher High Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom groupid org.sonatype.plexus Highest Vendor pom url http://spice.sonatype.org/${project.artifactId} Highest Vendor jar package name plexus Highest Vendor pom name Plexus Security Dispatcher Component High Vendor pom artifactid plexus-sec-dispatcher Low Vendor pom groupid sonatype.plexus Highest Product jar package name plexus Low Product jar package name sec Highest Product pom parent-artifactid spice-parent Medium Product jar package name sonatype Highest Product pom url http://spice.sonatype.org/${project.artifactId} Medium Product jar package name components Low Product file name plexus-sec-dispatcher High Product pom parent-groupid org.sonatype.spice Medium Product jar package name plexus Highest Product pom name Plexus Security Dispatcher Component High Product pom artifactid plexus-sec-dispatcher Highest Product jar package name sec Low Product pom groupid sonatype.plexus Highest Version file version 1.3 High Version pom parent-version 1.3 Low Version pom version 1.3 Highest
plexus-utils-2.0.6.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines, XML and more. File Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-utils/2.0.6/plexus-utils-2.0.6.jarMD5: 64523c08c852c1ffb7650f207baca314SHA1: 3a20c424a712a7c02b02af61dcad5f001b29a9fdSHA256: 8b909f4ca9788647942f883d4e559bcc642123f7c6bcd3846983a2e465469c33Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor pom url http://plexus.codehaus.org/plexus-utils Highest Vendor pom parent-groupid org.codehaus.plexus Medium Vendor pom artifactid plexus-utils Low Vendor jar package name xml Highest Vendor pom groupid org.codehaus.plexus Highest Vendor jar package name util Low Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Vendor file name plexus-utils High Product jar package name plexus Low Product pom parent-artifactid plexus Medium Product pom parent-groupid org.codehaus.plexus Medium Product jar package name xml Highest Product jar package name util Low Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product pom url http://plexus.codehaus.org/plexus-utils Medium Product jar package name codehaus Highest Product pom name Plexus Common Utilities High Product pom artifactid plexus-utils Highest Product file name plexus-utils High Version pom version 2.0.6 Highest Version pom parent-version 2.0.6 Low Version file version 2.0.6 High
Published Vulnerabilities CVE-2017-1000487 suppress
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
Directory traversal in org.codehaus.plexus.util.Expand (OSSINDEX) suppress
> org.codehaus.plexus.util.Expand does not guard against directory traversal, but such protection is generally expected from unarchiving tools.> > -- [github.com](https://github.com/codehaus-plexus/plexus-utils/issues/4) Unscored:
References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.codehaus.plexus:plexus-utils:2.0.6:*:*:*:*:*:*:* Possible XML Injection (OSSINDEX) suppress
> `org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment(XMLWriter, String, int, int, int)` does not check if the comment includes a `"-->"` sequence. This means that text contained in the command string could be interpreted as XML, possibly leading to XML injection issues, depending on how this method is being called.> > -- [github.com](https://github.com/codehaus-plexus/plexus-utils/issues/3) Unscored:
References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.codehaus.plexus:plexus-utils:2.0.6:*:*:*:*:*:*:* sisu-guava-0.9.9.jarDescription:
Patched build of Guava: Google Core Libraries for Java 1.5+ License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/sonatype/sisu/sisu-guava/0.9.9/sisu-guava-0.9.9.jar
MD5: 36484b30beda10de99c56801db4657e0
SHA1: 91395a7816ad64c5ef68e1a1b5b861463f0eb3e2
SHA256: 9897e80ff6c08fc45b5b5ebd81d9e943a1087bdf0ad50cda457d616abbdaacd9
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-copyright Copyright (C) 2009 Google Inc. Low Vendor pom groupid sonatype.sisu Highest Vendor pom parent-groupid org.sonatype.sisu.inject Medium Vendor pom name Sisu Guava - Core Library High Vendor pom artifactid sisu-guava Low Vendor file name sisu-guava High Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor Manifest bundle-docurl http://code.google.com/p/guava-libraries/ Low Vendor Manifest bundle-symbolicname org.sonatype.sisu.guava;singleton:=true Medium Vendor pom groupid org.sonatype.sisu Highest Vendor pom parent-artifactid guava-parent Low Product Manifest Bundle-Name sisu-guava Medium Product Manifest bundle-copyright Copyright (C) 2009 Google Inc. Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product pom artifactid sisu-guava Highest Product pom parent-artifactid guava-parent Medium Product pom groupid sonatype.sisu Highest Product pom parent-groupid org.sonatype.sisu.inject Medium Product pom name Sisu Guava - Core Library High Product jar package name google Highest Product file name sisu-guava High Product Manifest bundle-docurl http://code.google.com/p/guava-libraries/ Low Product Manifest bundle-symbolicname org.sonatype.sisu.guava;singleton:=true Medium Version Manifest Bundle-Version 0.9.9 High Version pom version 0.9.9 Highest Version file version 0.9.9 High
Published Vulnerabilities CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
sisu-guice-3.1.0-no_aop.jarDescription:
Patched build of Guice: a lightweight dependency injection framework for Java 5 and above License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/sonatype/sisu/sisu-guice/3.1.0/sisu-guice-3.1.0-no_aop.jar
MD5: 19f877ae736fa153a545d0cf801dcec9
SHA1: 97c87d15d749c86b2be1b9809b28321a1d926c7f
SHA256: 4b76079f35407e5682aac1ecbe67afd5f430ae619044a9d6a413666a45750c25
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.sonatype.sisu.guice;singleton:=true Medium Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor jar package name singleton Highest Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Vendor pom groupid org.sonatype.sisu Highest Vendor file name sisu-guice High Vendor jar package name inject Low Vendor jar package name google Low Vendor jar package name internal Low Vendor jar package name guice Highest Vendor Manifest eclipse-extensibleapi true Low Product Manifest bundle-symbolicname org.sonatype.sisu.guice;singleton:=true Medium Product pom artifactid sisu-guice Highest Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Product Manifest Bundle-Name sisu-guice (no_aop) Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product jar package name singleton Highest Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Product file name sisu-guice High Product jar package name google Highest Product jar package name inject Low Product jar package name dependency Highest Product jar package name internal Low Product jar package name guice Highest Product Manifest eclipse-extensibleapi true Low Version file version 3.1.0 High Version pom version 3.1.0 Highest
sisu-inject-bean-2.3.0.jarLicense:
http://www.apache.org/licenses/LICENSE-2.0.txt, http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/sonatype/sisu/sisu-inject-bean/2.3.0/sisu-inject-bean-2.3.0.jar
MD5: 27a128e32326472ebfec3a7b8cb2cdf9
SHA1: 4767ee22f0b84fc0fe3af2095c30bfbdafba9459
SHA256: 75819b29737c2bee1bfbda1011d455c7036738e0ef32ffbf85ba1d8fa157ceb2
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-activationpolicy lazy Low Vendor jar package name bean Highest Vendor pom name Sisu-Inject-Bean : Aggregate OSGi bundle High Vendor jar package name sonatype Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor jar package name singleton Highest Vendor pom groupid org.sonatype.sisu Highest Vendor pom artifactid sisu-inject-bean Low Vendor file name sisu-inject-bean High Vendor pom parent-artifactid guice-bean Low Vendor Manifest bundle-symbolicname org.sonatype.inject;singleton:=true Medium Vendor pom groupid sonatype.sisu Highest Vendor pom parent-groupid org.sonatype.sisu.inject Medium Vendor Manifest bundle-copyright Copyright (C) 2010 Sonatype Inc. Low Vendor Manifest bundle-docurl https://github.com/sonatype/sisu/ Low Vendor jar package name inject Highest Vendor jar package name guice Highest Vendor jar package name sisu Highest Product pom artifactid sisu-inject-bean Highest Product Manifest bundle-activationpolicy lazy Low Product jar package name bean Highest Product pom name Sisu-Inject-Bean : Aggregate OSGi bundle High Product jar package name sonatype Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product jar package name singleton Highest Product Manifest Bundle-Name sisu-inject-bean Medium Product file name sisu-inject-bean High Product pom parent-artifactid guice-bean Medium Product Manifest bundle-symbolicname org.sonatype.inject;singleton:=true Medium Product pom groupid sonatype.sisu Highest Product pom parent-groupid org.sonatype.sisu.inject Medium Product Manifest bundle-copyright Copyright (C) 2010 Sonatype Inc. Low Product Manifest bundle-docurl https://github.com/sonatype/sisu/ Low Product jar package name inject Highest Product jar package name guice Highest Product jar package name sisu Highest Version file version 2.3.0 High Version Manifest Bundle-Version 2.3.0 High Version pom version 2.3.0 Highest
sisu-inject-plexus-2.3.0.jarLicense:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/sonatype/sisu/sisu-inject-plexus/2.3.0/sisu-inject-plexus-2.3.0.jar
MD5: 5c35e512b479cc0d1c830c0cc9452504
SHA1: 7d8ecdce497bf361b83cfbc890670ca50d6ec299
SHA256: bf9083fb846993689409b2bdbc735048e53bac6cc32707cde7ef84817b6e9365
Referenced In Project/Scope: i18n Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name sonatype Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor file name sisu-inject-plexus High Vendor pom groupid org.sonatype.sisu Highest Vendor jar package name plexus Highest Vendor pom groupid sonatype.sisu Highest Vendor pom parent-groupid org.sonatype.sisu.inject Medium Vendor pom artifactid sisu-inject-plexus Low Vendor Manifest bundle-symbolicname org.sonatype.inject.plexus;singleton:=true Medium Vendor Manifest bundle-copyright Copyright (C) 2010 Sonatype Inc. Low Vendor Manifest bundle-docurl https://github.com/sonatype/sisu/ Low Vendor pom parent-artifactid guice-plexus Low Vendor pom name Sisu-Inject-Plexus : Aggregate OSGi bundle High Vendor jar package name guice Highest Product pom parent-artifactid guice-plexus Medium Product jar package name sonatype Highest Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product pom artifactid sisu-inject-plexus Highest Product file name sisu-inject-plexus High Product jar package name plexus Highest Product pom groupid sonatype.sisu Highest Product pom parent-groupid org.sonatype.sisu.inject Medium Product Manifest bundle-symbolicname org.sonatype.inject.plexus;singleton:=true Medium Product Manifest bundle-copyright Copyright (C) 2010 Sonatype Inc. Low Product Manifest bundle-docurl https://github.com/sonatype/sisu/ Low Product Manifest Bundle-Name sisu-inject-plexus Medium Product pom name Sisu-Inject-Plexus : Aggregate OSGi bundle High Product jar package name guice Highest Version file version 2.3.0 High Version Manifest Bundle-Version 2.3.0 High Version pom version 2.3.0 Highest