Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 6.1.6Report Generated On : Mon, 6 Dec 2021 15:06:47 GMTDependencies Scanned : 43 (40 unique)Vulnerable Dependencies : 5 Vulnerabilities Found : 8Vulnerabilities Suppressed : 0... NVD CVE Checked : 2021-12-06T15:04:04NVD CVE Modified : 2021-12-06T13:00:01VersionCheckOn : 2021-12-06T15:04:04Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies aether-api-0.9.0.M2.jarDescription:
The application programming interface for the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/eclipse/aether/aether-api/0.9.0.M2/aether-api-0.9.0.M2.jar
MD5: 4f45381e19be0eb964f3be5df6351b95
SHA1: 97662c999c6b2fbf2ee50e814a34639c1c1d22de
SHA256: e220097cffad96c2963ab12652ff8833ec6f40143d509f0a2ea59d22209b6ecd
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.eclipse.aether.api Medium Vendor jar package name eclipse Highest Vendor jar package name repository Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-api/ Low Vendor pom artifactid aether-api Low Vendor pom groupid org.eclipse.aether Highest Vendor pom groupid eclipse.aether Highest Vendor pom parent-artifactid aether Low Vendor file name aether-api High Vendor pom parent-groupid org.eclipse.aether Medium Vendor jar package name aether Highest Vendor pom name Aether API High Product Manifest bundle-symbolicname org.eclipse.aether.api Medium Product jar package name eclipse Highest Product jar package name repository Highest Product Manifest Bundle-Name Aether API (Incubation) Medium Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-api/ Low Product pom artifactid aether-api Highest Product pom groupid eclipse.aether Highest Product pom parent-artifactid aether Medium Product file name aether-api High Product pom parent-groupid org.eclipse.aether Medium Product jar package name aether Highest Product pom name Aether API High Version pom version 0.9.0.M2 Highest Version Manifest Bundle-Version 0.9.0.M2 High
aether-impl-0.9.0.M2.jarDescription:
An implementation of the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/eclipse/aether/aether-impl/0.9.0.M2/aether-impl-0.9.0.M2.jar
MD5: ffc94e83df65abdc44580b4046ee3b8f
SHA1: eab9a4baae8de96a24c04219236363d0ca73e8a9
SHA256: 637f5fb07d9b03957bc5f1a57b77a8202ba0a44f52a0d2c30e5d59b65e89ce48
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-impl/ Low Vendor pom name Aether Implementation High Vendor pom artifactid aether-impl Low Vendor pom groupid org.eclipse.aether Highest Vendor Manifest bundle-symbolicname org.eclipse.aether.impl Medium Vendor jar package name impl Highest Vendor pom groupid eclipse.aether Highest Vendor pom parent-artifactid aether Low Vendor pom parent-groupid org.eclipse.aether Medium Vendor file name aether-impl High Vendor jar package name aether Highest Product jar package name eclipse Highest Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-impl/ Low Product pom artifactid aether-impl Highest Product pom name Aether Implementation High Product Manifest bundle-symbolicname org.eclipse.aether.impl Medium Product jar package name impl Highest Product pom groupid eclipse.aether Highest Product pom parent-artifactid aether Medium Product pom parent-groupid org.eclipse.aether Medium Product file name aether-impl High Product jar package name aether Highest Product Manifest Bundle-Name Aether Implementation (Incubation) Medium Version pom version 0.9.0.M2 Highest Version Manifest Bundle-Version 0.9.0.M2 High
aether-spi-0.9.0.M2.jarDescription:
The service provider interface for repository system implementations and repository connectors.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/eclipse/aether/aether-spi/0.9.0.M2/aether-spi-0.9.0.M2.jar
MD5: 552d54d8bb3691eedd831b50bb87c309
SHA1: 3647d00620a91360990c9680f29fbcc22d69c2ee
SHA256: b7b78090d4e708ccbc42b039c8c36c8efb19296146584a14d5bb3e66935ddfe4
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name eclipse Highest Vendor file name aether-spi High Vendor pom name Aether SPI High Vendor Manifest bundle-symbolicname org.eclipse.aether.spi Medium Vendor jar package name spi Highest Vendor pom groupid org.eclipse.aether Highest Vendor pom groupid eclipse.aether Highest Vendor pom parent-artifactid aether Low Vendor pom parent-groupid org.eclipse.aether Medium Vendor jar package name aether Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-spi/ Low Vendor pom artifactid aether-spi Low Product jar package name eclipse Highest Product file name aether-spi High Product Manifest Bundle-Name Aether SPI (Incubation) Medium Product pom name Aether SPI High Product Manifest bundle-symbolicname org.eclipse.aether.spi Medium Product jar package name spi Highest Product pom artifactid aether-spi Highest Product pom groupid eclipse.aether Highest Product pom parent-artifactid aether Medium Product pom parent-groupid org.eclipse.aether Medium Product jar package name aether Highest Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-spi/ Low Version pom version 0.9.0.M2 Highest Version Manifest Bundle-Version 0.9.0.M2 High
aether-util-0.9.0.M2.jarDescription:
A collection of utility classes to ease usage of the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/eclipse/aether/aether-util/0.9.0.M2/aether-util-0.9.0.M2.jar
MD5: fc6315129d2e2063e2f2725e6337587f
SHA1: b957089deb654647da320ad7507b0a4b5ce23813
SHA256: 7d62b0fdef90196ec4b2947f5973d750bfd3935785244e77cc06780131c404e9
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name eclipse Highest Vendor jar package name util Highest Vendor jar package name repository Highest Vendor pom name Aether Utilities High Vendor pom groupid org.eclipse.aether Highest Vendor file name aether-util High Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-util/ Low Vendor pom groupid eclipse.aether Highest Vendor pom artifactid aether-util Low Vendor pom parent-artifactid aether Low Vendor pom parent-groupid org.eclipse.aether Medium Vendor jar package name aether Highest Vendor Manifest bundle-symbolicname org.eclipse.aether.util Medium Product pom artifactid aether-util Highest Product jar package name eclipse Highest Product jar package name util Highest Product jar package name repository Highest Product pom name Aether Utilities High Product file name aether-util High Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-util/ Low Product Manifest Bundle-Name Aether Utilities (Incubation) Medium Product pom groupid eclipse.aether Highest Product pom parent-artifactid aether Medium Product pom parent-groupid org.eclipse.aether Medium Product jar package name aether Highest Product Manifest bundle-symbolicname org.eclipse.aether.util Medium Version pom version 0.9.0.M2 Highest Version Manifest Bundle-Version 0.9.0.M2 High
aopalliance-1.0.jarDescription:
AOP Alliance License:
Public Domain File Path: /home/runner/.m2/repository/aopalliance/aopalliance/1.0/aopalliance-1.0.jar
MD5: 04177054e180d09e3998808efa0401c7
SHA1: 0235ba8b489512805ac13a8f9ea77a1ca5ebe3e8
SHA256: 0addec670fedcd3f113c5c8091d783280d23f75e3acb841b61a9cdb079376a08
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name aopalliance Highest Vendor jar package name aopalliance Low Vendor file name aopalliance High Vendor pom url http://aopalliance.sourceforge.net Highest Vendor pom groupid aopalliance Highest Vendor pom artifactid aopalliance Low Vendor jar package name aop Highest Vendor jar package name intercept Low Vendor pom name AOP alliance High Product jar package name aopalliance Highest Product pom artifactid aopalliance Highest Product file name aopalliance High Product pom url http://aopalliance.sourceforge.net Medium Product pom groupid aopalliance Highest Product jar package name aop Highest Product jar package name intercept Low Product pom name AOP alliance High Version file version 1.0 High Version pom version 1.0 Highest
asm-3.3.1.jarFile Path: /home/runner/.m2/repository/asm/asm/3.3.1/asm-3.3.1.jarMD5: 1ad1e8959324b0f680b8e62406955642SHA1: 1d5f20b4ea675e6fab6ab79f1cd60ec268ddc015SHA256: c2b39275f8e951bc74750080a1266cdabc39399bc5e13d642bf2d346449df7f3Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor France Telecom R&D High Vendor pom parent-artifactid asm-parent Low Vendor pom groupid asm Highest Vendor pom name ASM Core High Vendor jar package name asm Highest Vendor pom artifactid asm Low Vendor file name asm High Product Manifest Implementation-Title ASM High Product pom parent-artifactid asm-parent Medium Product pom groupid asm Highest Product pom name ASM Core High Product pom artifactid asm Highest Product jar package name asm Highest Product file name asm High Version pom version 3.3.1 Highest Version Manifest Implementation-Version 3.3.1 High Version file version 3.3.1 High
cdi-api-1.0.jarDescription:
APIs for JSR-299: Contexts and Dependency Injection for Java EE File Path: /home/runner/.m2/repository/javax/enterprise/cdi-api/1.0/cdi-api-1.0.jarMD5: 462c0959f0322016495f4598243bc0f2SHA1: 44c453f60909dfc223552ace63e05c694215156bSHA256: 1f10b2204cc77c919301f20ff90461c3df1b6e6cb148be1c2d22107f4851d423Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name javax Highest Vendor pom groupid javax.enterprise Highest Vendor pom parent-artifactid weld-api-parent Low Vendor Manifest implementation-url http://www.seamframework.org/Weld/cdi-api Low Vendor pom name CDI APIs High Vendor Manifest Implementation-Vendor Seam Framework High Vendor pom parent-groupid org.jboss.weld Medium Vendor Manifest specification-vendor Seam Framework Low Vendor pom artifactid cdi-api Low Vendor file name cdi-api High Vendor jar package name enterprise Highest Product Manifest specification-title CDI APIs Medium Product pom artifactid cdi-api Highest Product jar package name javax Highest Product pom parent-artifactid weld-api-parent Medium Product pom groupid javax.enterprise Highest Product Manifest implementation-url http://www.seamframework.org/Weld/cdi-api Low Product pom name CDI APIs High Product pom parent-groupid org.jboss.weld Medium Product file name cdi-api High Product Manifest Implementation-Title CDI APIs High Product jar package name enterprise Highest Version file version 1.0 High Version pom version 1.0 Highest
commons-io-2.5.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/commons-io/commons-io/2.5/commons-io-2.5.jar
MD5: e2d74794fba570ec2115fb9d5b05dc9b
SHA1: 2852e6e05fbb95076fc091f6d1780f1f8fe35e0f
SHA256: a10418348d234968600ccb1d988efcbbd08716e1d96936ccc1880e7d22513474
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom groupid commons-io Highest Vendor jar package name apache Highest Vendor file name commons-io High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest implementation-build tags/commons-io-2.5@r1739098; 2016-04-14 09:19:54-0400 Low Vendor pom name Apache Commons IO High Vendor jar package name commons Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom artifactid commons-io Low Vendor pom parent-groupid org.apache.commons Medium Vendor jar package name io Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Vendor pom url http://commons.apache.org/proper/commons-io/ Highest Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product jar package name apache Highest Product pom groupid commons-io Highest Product file name commons-io High Product pom url http://commons.apache.org/proper/commons-io/ Medium Product Manifest implementation-build tags/commons-io-2.5@r1739098; 2016-04-14 09:19:54-0400 Low Product pom name Apache Commons IO High Product jar package name commons Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom parent-groupid org.apache.commons Medium Product jar package name io Highest Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Product Manifest Implementation-Title Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product Manifest bundle-symbolicname org.apache.commons.io Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Version file version 2.5 High Version pom parent-version 2.5 Low Version pom version 2.5 Highest Version Manifest Implementation-Version 2.5 High
Published Vulnerabilities CVE-2021-29425 suppress
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N References:
Vulnerable Software & Versions: (show all )
commons-lang3-3.6.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.6/commons-lang3-3.6.jar
MD5: 5d18f68b5122fd398c118df53ab4cf55
SHA1: 9d28a6b23650e8a7e9063c04588ace6cf7012c17
SHA256: 89c27f03fff18d0b06e7afd7ef25e209766df95b6c1269d6c3ebbdea48d5f284
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Vendor pom url http://commons.apache.org/proper/commons-lang/ Highest Vendor jar package name commons Highest Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid commons-lang3 Low Vendor jar package name lang3 Highest Vendor pom parent-artifactid commons-parent Low Vendor pom groupid org.apache.commons Highest Vendor Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor file name commons-lang3 High Vendor pom name Apache Commons Lang High Vendor pom groupid apache.commons Highest Product jar package name apache Highest Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-lang/ Low Product jar package name commons Highest Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product pom artifactid commons-lang3 Highest Product pom parent-groupid org.apache.commons Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Apache Commons Lang Medium Product jar package name lang3 Highest Product Manifest implementation-url http://commons.apache.org/proper/commons-lang/ Low Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-lang/ Medium Product file name commons-lang3 High Product pom name Apache Commons Lang High Product pom groupid apache.commons Highest Version pom parent-version 3.6 Low Version file version 3.6 High Version Manifest Implementation-Version 3.6 High Version pom version 3.6 Highest
geronimo-json_1.1_spec-1.0.jarDescription:
Apache Geronimo implementation of the JSR-374 License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/geronimo/specs/geronimo-json_1.1_spec/1.0/geronimo-json_1.1_spec-1.0.jar
MD5: cebdac023b86830a21a119ce73a6eb76
SHA1: 9949887a93a1336e78cf424336a2008377f37851
SHA256: 9277e9b259b62d9942cdfc39780d540459372aa5d4a50ae9ecff9e408b9814f2
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.apache.geronimo.specs Highest Vendor jar package name json Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom groupid apache.geronimo.specs Highest Vendor pom parent-groupid org.apache.geronimo.genesis Medium Vendor pom artifactid geronimo-json_1.1_spec Low Vendor pom name Apache Geronimo JSON Spec 1.1 High Vendor pom url http://geronimo.apache.org/maven/${siteId}/${project.version} Highest Vendor Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-json_1.1_spec/1.0 Low Vendor pom parent-artifactid genesis-java8-flava Low Vendor file name geronimo-json_1.1_spec-1.0 High Vendor Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-json_1.1_spec Medium Product jar package name json Highest Product pom url http://geronimo.apache.org/maven/${siteId}/${project.version} Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom parent-artifactid genesis-java8-flava Medium Product pom groupid apache.geronimo.specs Highest Product Manifest Bundle-Name Apache Geronimo JSON Spec 1.1 Medium Product pom parent-groupid org.apache.geronimo.genesis Medium Product pom name Apache Geronimo JSON Spec 1.1 High Product Manifest Implementation-Title Apache Geronimo JSON Spec 1.1 High Product Manifest bundle-docurl http://geronimo.apache.org/maven/specs/geronimo-json_1.1_spec/1.0 Low Product pom artifactid geronimo-json_1.1_spec Highest Product file name geronimo-json_1.1_spec-1.0 High Product Manifest bundle-symbolicname org.apache.geronimo.specs.geronimo-json_1.1_spec Medium Version pom parent-version 1.0 Low Version pom version 1.0 Highest Version Manifest Implementation-Version 1.0 High
guava-15.0.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has two code dependencies - javax.annotation
per the JSR-305 spec and javax.inject per the JSR-330 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/com/google/guava/guava/15.0/guava-15.0.jar
MD5: 2c10bb2ca3ac8b55b0e77e54a7eb3744
SHA1: ed727a8d9f247e2050281cb083f1c77b09dcb5cd
SHA256: 7a34575770eebc60a5476616e3676a6cb6f2975c78c415e2a6014ac724ba5783
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.google.guava Highest Vendor pom groupid google.guava Highest Vendor pom artifactid guava Low Vendor file name guava High Vendor jar package name google Highest Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor pom parent-groupid com.google.guava Medium Vendor pom name Guava: Google Core Libraries for Java High Vendor pom parent-artifactid guava-parent Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product pom groupid google.guava Highest Product file name guava High Product jar package name google Highest Product Manifest bundle-symbolicname com.google.guava Medium Product pom parent-groupid com.google.guava Medium Product pom parent-artifactid guava-parent Medium Product pom name Guava: Google Core Libraries for Java High Product pom artifactid guava Highest Version pom version 15.0 Highest Version file version 15.0 High
Published Vulnerabilities CVE-2018-10237 suppress
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with GWT serialization) perform eager allocation without appropriate checks on what a client has sent and whether the data size is reasonable. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H References:
CONFIRM - https://groups.google.com/d/topic/guava-announce/xqWALw4W1vs/discussion MISC - https://www.oracle.com/security-alerts/cpujan2021.html MISC - https://www.oracle.com/security-alerts/cpujul2020.html MISC - https://www.oracle.com/security-alerts/cpuoct2021.html MLIST - [activemq-gitbox] 20190530 [GitHub] [activemq-artemis] brusdev opened a new pull request #2687: ARTEMIS-2359 Upgrade to Guava 24.1 MLIST - [activemq-issues] 20190516 [jira] [Created] (AMQ-7208) Security Issue related to Guava 18.0 MLIST - [activemq-issues] 20190820 [jira] [Created] (AMQ-7279) Security Vulnerabilities in Libraries - jackson-databind-2.9.8.jar, tomcat-servlet-api-8.0.53.jar, tomcat-websocket-api-8.0.53.jar, zookeeper-3.4.6.jar, guava-18.0.jar, jetty-all-9.2.26.v20180806.jar, scala-library-2.11.0.jar MLIST - [arrow-github] 20210610 [GitHub] [arrow] projjal opened a new pull request #10501: ARROW-13032: Update guava version MLIST - [cassandra-commits] 20190612 [jira] [Assigned] (CASSANDRA-14760) CVE-2018-10237 Security vulnerability in 3.11.3 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] davidkarlsen opened a new pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200206 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200211 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] andrei-ivanov commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] coheigea commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [cxf-dev] 20200420 [GitHub] [cxf] reta commented on a change in pull request #638: upgrade guava, CVE-2018-10237 MLIST - [drill-dev] 20191017 Dependencies used by Drill contain known vulnerabilities MLIST - [drill-dev] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [drill-issues] 20191021 [jira] [Created] (DRILL-7416) Updates required to dependencies to resolve potential security vulnerabilities MLIST - [flink-dev] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [flink-dev] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200806 [jira] [Created] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20200814 [jira] [Commented] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-issues] 20210212 [jira] [Closed] (FLINK-18841) CVE-2018-10237 and CWE-400 occurred in flink dependency MLIST - [flink-user] 20200806 Dependency vulnerabilities with Apache Flink 1.10.1 version MLIST - [hadoop-common-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [hadoop-common-dev] 20200623 Update guava to 27.0-jre in hadoop branch-2.10 MLIST - [hadoop-hdfs-dev] 20190401 Update guava to 27.0-jre in hadoop-project MLIST - [kafka-users] 20200413 CVEs for the dependency software guava and rocksdbjni of Kafka MLIST - [lucene-issues] 20201022 [jira] [Created] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Resolved] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [lucene-issues] 20201022 [jira] [Updated] (SOLR-14960) Solr-clustering is bringing in CVE-2018-10237 vulnerable guava MLIST - [maven-issues] 20210122 [GitHub] [maven-indexer] akurtakov opened a new pull request #75: Remove guava dependency from indexer-core MLIST - [pulsar-commits] 20190416 [GitHub] [pulsar] one70six opened a new issue #4057: Security Vulnerabilities - Black Duck Scan - Pulsar v.2.3.1 MLIST - [pulsar-commits] 20210406 [GitHub] [pulsar] lhotari opened a new pull request #10149: Upgrade jclouds to 2.3.0 to fix security vulnerabilities MLIST - [samza-commits] 20210310 [GitHub] [samza] Telesia opened a new pull request #1471: SAMZA-2630: Upgrade dependencies for security fixes MLIST - [storm-issues] 20210315 [jira] [Created] (STORM-3754) Upgrade Guava version because of security vulnerability MLIST - [syncope-dev] 20200423 Re: Time to cut 2.1.6 / 2.0.15? N/A - N/A OSSINDEX - [CVE-2018-10237] Deserialization of Untrusted Data REDHAT - RHSA-2018:2423 REDHAT - RHSA-2018:2424 REDHAT - RHSA-2018:2425 REDHAT - RHSA-2018:2428 REDHAT - RHSA-2018:2598 REDHAT - RHSA-2018:2643 REDHAT - RHSA-2018:2740 REDHAT - RHSA-2018:2741 REDHAT - RHSA-2018:2742 REDHAT - RHSA-2018:2743 REDHAT - RHSA-2018:2927 REDHAT - RHSA-2019:2858 REDHAT - RHSA-2019:3149 SECTRACK - 1041707 Vulnerable Software & Versions: (show all )
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N References:
Vulnerable Software & Versions: (show all )
io.wcm.tooling.commons.content-package-builder-1.6.2.jarDescription:
Java Library for building AEM Content Packages with content pages and binary files. License:
"The Apache Software License, Version 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /home/runner/.m2/repository/io/wcm/tooling/commons/io.wcm.tooling.commons.content-package-builder/1.6.2/io.wcm.tooling.commons.content-package-builder-1.6.2.jar
MD5: 06d8c580e8d1131bdf11c92f0356f63d
SHA1: 084e94c8cbf8cb66cffa93cf37adbf56de2cbc85
SHA256: 56b05b612eafadabacadb0fd0cd94cbc276401b6966153e8d51c524160adc0c7
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom groupid io.wcm.tooling.commons Highest Vendor Manifest bundle-docurl https://wcm.io/tooling/commons/content-package-builder/ Low Vendor jar package name wcm Highest Vendor Manifest bundle-symbolicname io.wcm.tooling.commons.content-package-builder Medium Vendor jar package name commons Highest Vendor jar package name tooling Highest Vendor jar package name io Highest Vendor pom artifactid io.wcm.tooling.commons.content-package-builder Low Vendor pom name AEM Content Package Builder High Vendor pom parent-artifactid io.wcm.tooling.commons.parent Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest build-jdk-spec 11 Low Vendor pom url ${site.url}/${site.url.module.prefix}/ Highest Vendor file name io.wcm.tooling.commons.content-package-builder High Product Manifest bundle-docurl https://wcm.io/tooling/commons/content-package-builder/ Low Product pom groupid io.wcm.tooling.commons Highest Product jar package name wcm Highest Product pom url ${site.url}/${site.url.module.prefix}/ Medium Product Manifest bundle-symbolicname io.wcm.tooling.commons.content-package-builder Medium Product jar package name commons Highest Product jar package name tooling Highest Product jar package name io Highest Product pom name AEM Content Package Builder High Product pom artifactid io.wcm.tooling.commons.content-package-builder Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name wcm.io AEM Content Package Builder Medium Product file name io.wcm.tooling.commons.content-package-builder High Product pom parent-artifactid io.wcm.tooling.commons.parent Medium Version file version 1.6.2 High Version pom parent-version 1.6.2 Low Version pom version 1.6.2 Highest Version Manifest Bundle-Version 1.6.2 High
jackrabbit-api-2.16.0.jarDescription:
Jackrabbit-specific extensions to the JCR API License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/jackrabbit/jackrabbit-api/2.16.0/jackrabbit-api-2.16.0.jar
MD5: 4f66766e7153e75726867e49781346c4
SHA1: 0bda9c9da2ca4d6fc14918ebf7b5ab1f72e5a089
SHA256: 51e881d990efef071ea6f201fce7e6c660f359faa10873106017098a506e0953
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name jackrabbit Highest Vendor jar package name apache Highest Vendor pom groupid org.apache.jackrabbit Highest Vendor pom artifactid jackrabbit-api Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest bundle-docurl http://jackrabbit.apache.org Low Vendor pom parent-groupid org.apache.jackrabbit Medium Vendor pom name Apache Jackrabbit API High Vendor pom groupid apache.jackrabbit Highest Vendor Manifest bundle-symbolicname org.apache.jackrabbit.jackrabbit-api Medium Vendor jar package name api Highest Vendor file name jackrabbit-api High Vendor pom parent-artifactid jackrabbit-parent Low Product jar package name jackrabbit Highest Product jar package name apache Highest Product Manifest Bundle-Name Apache Jackrabbit API Medium Product pom artifactid jackrabbit-api Highest Product pom parent-artifactid jackrabbit-parent Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-docurl http://jackrabbit.apache.org Low Product pom parent-groupid org.apache.jackrabbit Medium Product pom name Apache Jackrabbit API High Product pom groupid apache.jackrabbit Highest Product Manifest bundle-symbolicname org.apache.jackrabbit.jackrabbit-api Medium Product jar package name api Highest Product file name jackrabbit-api High Version file version 2.16.0 High Version pom version 2.16.0 Highest Version Manifest Bundle-Version 2.16.0 High
Related Dependencies jackrabbit-jcr-commons-2.16.0.jarFile Path: /home/runner/.m2/repository/org/apache/jackrabbit/jackrabbit-jcr-commons/2.16.0/jackrabbit-jcr-commons-2.16.0.jar MD5: 0c5f517ca6b857dc51a497d31b5b4549 SHA1: d38f9bc34aadd014de31b401b5aa6244e6ced665 SHA256: 35082c387d6903ab0a1726d8a70b659864b68ed83aa347fb6bc2803ee1c53f06 pkg:maven/org.apache.jackrabbit/jackrabbit-jcr-commons@2.16.0 javax.inject-1.jarDescription:
The javax.inject API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256: 91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom groupid javax.inject Highest Vendor jar package name javax Highest Vendor pom name javax.inject High Vendor pom artifactid javax.inject Low Vendor jar package name javax Low Vendor file name javax.inject-1 High Vendor pom url http://code.google.com/p/atinject/ Highest Vendor jar package name inject Low Vendor jar package name inject Highest Product pom groupid javax.inject Highest Product jar package name javax Highest Product pom name javax.inject High Product pom artifactid javax.inject Highest Product file name javax.inject-1 High Product jar package name inject Low Product jar package name inject Highest Product pom url http://code.google.com/p/atinject/ Medium Version pom version 1 Highest Version file version 1 Medium
jcr-2.0.jarDescription:
The Content Repository API for JavaTM Technology Version 2.0 is specified by JSR-283.
This module contains the complete API as specified.
License:
Day Specification License: http://www.day.com/dam/day/downloads/jsr283/day-spec-license.htm
Day Specification License addendum: http://www.day.com/content/dam/day/downloads/jsr283/LICENSE.txt File Path: /home/runner/.m2/repository/javax/jcr/jcr/2.0/jcr-2.0.jar
MD5: ede5e78b16c8ed298ce0b6d296584ebd
SHA1: 08297216bcfe4aea369ed6ee0d1718133f752e97
SHA256: cbf083bc58cb88a0c19112187a4c52d3115f525b5bb7f2913635f5679e6e9743
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor file name jcr High Vendor jar package name javax Highest Vendor pom groupid javax.jcr Highest Vendor pom artifactid jcr Low Vendor jar package name repository Highest Vendor jar package name version Highest Vendor Manifest bundle-category jcr Low Vendor Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=283 Low Vendor pom organization name Day Software High Vendor pom organization url http://www.day.com Medium Vendor pom name Content Repository for JavaTM Technology API High Vendor pom url http://www.jcp.org/en/jsr/detail?id=283 Highest Vendor Manifest bundle-symbolicname javax.jcr Medium Vendor jar package name jcr Highest Product file name jcr High Product jar package name javax Highest Product pom groupid javax.jcr Highest Product jar package name repository Highest Product jar package name version Highest Product Manifest bundle-category jcr Low Product Manifest bundle-docurl http://www.jcp.org/en/jsr/detail?id=283 Low Product pom url http://www.jcp.org/en/jsr/detail?id=283 Medium Product pom artifactid jcr Highest Product pom organization url http://www.day.com Low Product pom organization name Day Software Low Product pom name Content Repository for JavaTM Technology API High Product Manifest bundle-symbolicname javax.jcr Medium Product jar package name jcr Highest Product Manifest Bundle-Name Content Repository for JavaTM Technology API Medium Version pom version 2.0 Highest Version Manifest Bundle-Version 2.0 High Version file version 2.0 High
johnzon-core-1.1.1.jarDescription:
Apache Johnzon is an implementation of JSR-353 (JavaTM API for JSON Processing). License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/johnzon/johnzon-core/1.1.1/johnzon-core-1.1.1.jar
MD5: 382db6f05ae30248c43ad2c5ace1f527
SHA1: 72a57f53f160a6cbadef1ea25fe3843206bc8aa4
SHA256: bf0d0785e942b57071bf3f68e635ce6a38189bd382a6ef14a190d2f859532318
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache.johnzon Medium Vendor Manifest require-capability osgi.extender;filter:="(osgi.extender=osgi.serviceloader.registrar)",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom groupid org.apache.johnzon Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom parent-groupid org.apache.johnzon Medium Vendor jar package name johnzon Highest Vendor file name johnzon-core High Vendor pom artifactid johnzon-core Low Vendor pom parent-artifactid johnzon Low Vendor pom name Johnzon :: Core High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="javax.json.spi.JsonProvider" Low Vendor jar package name core Highest Vendor pom groupid apache.johnzon Highest Vendor Manifest bundle-docurl http://johnzon.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.johnzon.core Medium Product jar package name apache Highest Product Manifest require-capability osgi.extender;filter:="(osgi.extender=osgi.serviceloader.registrar)",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom parent-groupid org.apache.johnzon Medium Product Manifest Bundle-Name Johnzon :: Core Medium Product jar package name johnzon Highest Product pom parent-artifactid johnzon Medium Product file name johnzon-core High Product pom name Johnzon :: Core High Product Manifest specification-title Johnzon :: Core Medium Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="javax.json.spi.JsonProvider" Low Product jar package name core Highest Product Manifest Implementation-Title Johnzon :: Core High Product pom groupid apache.johnzon Highest Product pom artifactid johnzon-core Highest Product Manifest bundle-docurl http://johnzon.apache.org/ Low Product Manifest bundle-symbolicname org.apache.johnzon.core Medium Version file version 1.1.1 High Version Manifest Implementation-Version 1.1.1 High Version Manifest Bundle-Version 1.1.1 High Version pom version 1.1.1 Highest
jsr250-api-1.0.jarDescription:
JSR-250 Reference Implementation by Glassfish License:
COMMON DEVELOPMENT AND DISTRIBUTION LICENSE (CDDL) Version 1.0: https://glassfish.dev.java.net/public/CDDLv1.0.html File Path: /home/runner/.m2/repository/javax/annotation/jsr250-api/1.0/jsr250-api-1.0.jar
MD5: 4cd56b2e4977e541186de69f5126b4a6
SHA1: 5025422767732a1ab45d93abfea846513d742dcf
SHA256: a1a922d0d9b6d183ed3800dfac01d1e1eb159f0e8c6f94736931c1def54a941f
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name javax Highest Vendor pom artifactid jsr250-api Low Vendor jar package name annotation Low Vendor jar package name javax Low Vendor pom groupid javax.annotation Highest Vendor pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Highest Vendor pom name JSR-250 Common Annotations for the JavaTM Platform High Vendor file name jsr250-api High Vendor jar package name annotation Highest Product jar package name javax Highest Product pom url http://jcp.org/aboutJava/communityprocess/final/jsr250/index.html Medium Product pom artifactid jsr250-api Highest Product jar package name annotation Low Product pom groupid javax.annotation Highest Product pom name JSR-250 Common Annotations for the JavaTM Platform High Product file name jsr250-api High Product jar package name annotation Highest Version file version 1.0 High Version pom version 1.0 Highest
maven-aether-provider-3.1.0.jarDescription:
Extensions to Aether for utilizing Maven POM and repository metadata. File Path: /home/runner/.m2/repository/org/apache/maven/maven-aether-provider/3.1.0/maven-aether-provider-3.1.0.jarMD5: 223a5fac960a7398aa3c6607f8da4558SHA1: dda2231a2be2768109d474805c702b76a8e794e6SHA256: ec5edc09f3cc4d4e23c7f8a1105b520d63498f5a18bd00b8d3833aa38d3f136eReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name repository Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom artifactid maven-aether-provider Low Vendor pom groupid org.apache.maven Highest Vendor file name maven-aether-provider High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Vendor pom name Maven Aether Provider High Product jar package name apache Highest Product file name maven-aether-provider High Product Manifest specification-title Maven Aether Provider Medium Product pom artifactid maven-aether-provider Highest Product Manifest Implementation-Title Maven Aether Provider High Product jar package name repository Highest Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom name Maven Aether Provider High Product pom parent-artifactid maven Medium Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-artifact-3.1.0.jarFile Path: /home/runner/.m2/repository/org/apache/maven/maven-artifact/3.1.0/maven-artifact-3.1.0.jarMD5: d8facb86c908e0977b21b1e83746e342SHA1: 446e6a69fee5b7f2b0f498c0e4dfbd38f740a8f9SHA256: 7f8a8ca4b2df5f81918fab2b9231a008f470d88ec54ddcbe38474bbf21b7571eReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Maven Artifact High Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor jar package name artifact Highest Vendor pom groupid org.apache.maven Highest Vendor pom artifactid maven-artifact Low Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor file name maven-artifact High Vendor pom parent-groupid org.apache.maven Medium Product Manifest Implementation-Title Maven Artifact High Product jar package name apache Highest Product pom name Maven Artifact High Product file name maven-artifact High Product jar package name maven Highest Product Manifest specification-title Maven Artifact Medium Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom artifactid maven-artifact Highest Product pom parent-artifactid maven Medium Product jar package name artifact Highest Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-core-3.1.0.jarDescription:
Maven Core classes. File Path: /home/runner/.m2/repository/org/apache/maven/maven-core/3.1.0/maven-core-3.1.0.jarMD5: 67c1cd4fa81ff39826826f46e88f420fSHA1: 3aca07a1e496f1fb9c0d2d950b6aac7779c67b98SHA256: 603cea35d0812036f68c48d02a20af674db2235ce9d251ecb96fe72df07be8feReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name maven-core High Vendor pom artifactid maven-core Low Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Core High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Product jar package name apache Highest Product pom artifactid maven-core Highest Product file name maven-core High Product pom name Maven Core High Product Manifest Implementation-Title Maven Core High Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product Manifest specification-title Maven Core Medium Product pom parent-artifactid maven Medium Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
Published Vulnerabilities CVE-2021-26291 suppress
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html CWE-346 Origin Validation Error
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N References:
Vulnerable Software & Versions: (show all )
maven-model-3.1.0.jarDescription:
Model for Maven POM (Project Object Model) File Path: /home/runner/.m2/repository/org/apache/maven/maven-model/3.1.0/maven-model-3.1.0.jarMD5: f632d28a057446fa533d08e877100b3bSHA1: 82b2f097c1cc9a8d0e6b99af5e56327d5002c30fSHA256: f9f7ad6301942d385fc79ed0615a7d5f06dbda60dee70b709e679624313e642aReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Maven Model High Vendor jar package name model Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom artifactid maven-model Low Vendor pom groupid org.apache.maven Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor file name maven-model High Vendor pom parent-groupid org.apache.maven Medium Product jar package name apache Highest Product pom name Maven Model High Product jar package name model Highest Product file name maven-model High Product Manifest Implementation-Title Maven Model High Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product Manifest specification-title Maven Model Medium Product pom parent-artifactid maven Medium Product pom artifactid maven-model Highest Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-model-builder-3.1.0.jarDescription:
The effective model builder, with inheritance, profile activation, interpolation, ... File Path: /home/runner/.m2/repository/org/apache/maven/maven-model-builder/3.1.0/maven-model-builder-3.1.0.jarMD5: 0affc5812b09809c99ddb077f615dc21SHA1: 13ba294cedb659c3851f0c2980af7f44bcc6a8e0SHA256: 45f437ef89851578e7d230c873b7aa766147e807100a044e7d17213f0a8ac2e5Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid maven-model-builder Low Vendor file name maven-model-builder High Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom name Maven Model Builder High Vendor jar package name model Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor jar package name interpolation Highest Vendor pom groupid org.apache.maven Highest Vendor jar package name profile Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Vendor jar package name inheritance Highest Product file name maven-model-builder High Product jar package name apache Highest Product pom name Maven Model Builder High Product jar package name model Highest Product jar package name maven Highest Product Manifest specification-title Maven Model Builder Medium Product pom groupid apache.maven Highest Product jar package name interpolation Highest Product Manifest Implementation-Title Maven Model Builder High Product jar package name profile Highest Product pom parent-groupid org.apache.maven Medium Product jar package name inheritance Highest Product pom parent-artifactid maven Medium Product pom artifactid maven-model-builder Highest Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-plugin-api-3.1.0.jarDescription:
The API for plugins - Mojos - development. File Path: /home/runner/.m2/repository/org/apache/maven/maven-plugin-api/3.1.0/maven-plugin-api-3.1.0.jarMD5: 3a2af8945d7b2ae38ca33a97f60a9611SHA1: 8821fd1b81c6b960f7ce39f5dde612c665146fd8SHA256: c6e743680d5ca55a39652f14777181fadf98b6cfef870c3985996f2a5cd0bf6dReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-plugin-api Low Vendor file name maven-plugin-api High Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor jar package name plugin Highest Vendor pom parent-groupid org.apache.maven Medium Vendor pom name Maven Plugin API High Product Manifest Implementation-Title Maven Plugin API High Product jar package name apache Highest Product Manifest specification-title Maven Plugin API Medium Product file name maven-plugin-api High Product jar package name maven Highest Product jar package name plugin Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom parent-artifactid maven Medium Product pom name Maven Plugin API High Product pom artifactid maven-plugin-api Highest Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-repository-metadata-3.1.0.jarDescription:
Per-directory local and remote repository metadata. File Path: /home/runner/.m2/repository/org/apache/maven/maven-repository-metadata/3.1.0/maven-repository-metadata-3.1.0.jarMD5: ae0f6b92d5a03661cd47df621c4eee6cSHA1: 77bb2c383b1654b158cf9f905f4105d9d522fc7eSHA256: 1f98b8b101fea1167d3d5dfd6439757bd96f79e62388323af258fddc1e60382eReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name repository Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor file name maven-repository-metadata High Vendor pom name Maven Repository Metadata Model High Vendor pom artifactid maven-repository-metadata Low Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom parent-groupid org.apache.maven Medium Product jar package name apache Highest Product Manifest specification-title Maven Repository Metadata Model Medium Product pom artifactid maven-repository-metadata Highest Product file name maven-repository-metadata High Product pom name Maven Repository Metadata Model High Product jar package name repository Highest Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom parent-artifactid maven Medium Product Manifest Implementation-Title Maven Repository Metadata Model High Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-settings-3.1.0.jarDescription:
Maven Settings model. File Path: /home/runner/.m2/repository/org/apache/maven/maven-settings/3.1.0/maven-settings-3.1.0.jarMD5: b18f33545dacd6f3860930934c3dd30dSHA1: 032c65d957271cb15ae3c93c883ab7e6aca39138SHA256: a44bb2a6c8571269a06ab8efba046fd319af34c4985deda66512dc1e648f301aReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name settings Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor file name maven-settings High Vendor pom groupid apache.maven Highest Vendor pom groupid org.apache.maven Highest Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom artifactid maven-settings Low Vendor pom parent-groupid org.apache.maven Medium Vendor pom name Maven Settings High Product jar package name apache Highest Product Manifest specification-title Maven Settings Medium Product jar package name settings Highest Product Manifest Implementation-Title Maven Settings High Product jar package name maven Highest Product file name maven-settings High Product pom groupid apache.maven Highest Product pom artifactid maven-settings Highest Product pom parent-groupid org.apache.maven Medium Product pom name Maven Settings High Product pom parent-artifactid maven Medium Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
maven-settings-builder-3.1.0.jarDescription:
The effective settings builder, with inheritance and password decryption. File Path: /home/runner/.m2/repository/org/apache/maven/maven-settings-builder/3.1.0/maven-settings-builder-3.1.0.jarMD5: eb9de409fb60d13e107b094a1764d3c3SHA1: ab0e825308fb8862d6d2b6fecea80c0d06c48407SHA256: d73d0740f1ae3f903eaac1e9f69229068d8ffd60e6afe84e64cc6bad42de2ff2Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor pom parent-artifactid maven Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name settings Highest Vendor jar package name maven Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.maven Highest Vendor pom name Maven Settings Builder High Vendor pom groupid org.apache.maven Highest Vendor file name maven-settings-builder High Vendor Manifest Implementation-Vendor-Id org.apache.maven Medium Vendor pom artifactid maven-settings-builder Low Vendor pom parent-groupid org.apache.maven Medium Product Manifest specification-title Maven Settings Builder Medium Product jar package name apache Highest Product file name maven-settings-builder High Product Manifest Implementation-Title Maven Settings Builder High Product jar package name settings Highest Product jar package name maven Highest Product pom groupid apache.maven Highest Product pom parent-groupid org.apache.maven Medium Product pom artifactid maven-settings-builder Highest Product pom parent-artifactid maven Medium Product pom name Maven Settings Builder High Version Manifest Implementation-Version 3.1.0 High Version file version 3.1.0 High Version pom version 3.1.0 Highest
org.apache.jackrabbit.vault-3.1.44.jarDescription:
Builds an OSGi bundle for the file vault parts
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/jackrabbit/vault/org.apache.jackrabbit.vault/3.1.44/org.apache.jackrabbit.vault-3.1.44.jar
MD5: 6fcbf022b81ce371d7c31d06d1a147ba
SHA1: 10b5306bf2432bfd8a4ec3b18007eff383985808
SHA256: 42d903a39f2b8c4003f9c58510abb049655399157cfc760540a58daf35273735
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name jackrabbit Highest Vendor Manifest provide-capability osgi.service;objectClass:List="javax.management.DynamicMBean",osgi.service;objectClass:List="org.apache.jackrabbit.vault.packaging.Packaging",osgi.service;objectClass:List="org.apache.jackrabbit.vault.packaging.events.PackageEventListener",osgi.service;objectClass:List="org.apache.jackrabbit.vault.packaging.events.impl.PackageEventDispatcher" Low Vendor jar package name apache Highest Vendor Manifest bundle-symbolicname org.apache.jackrabbit.vault Medium Vendor pom parent-groupid org.apache.jackrabbit.vault Medium Vendor pom groupid org.apache.jackrabbit.vault Highest Vendor pom groupid apache.jackrabbit.vault Highest Vendor pom parent-artifactid parent Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.component)(version>=1.3.0)(!(version>=2.0.0)))",osgi.service;filter:="(objectClass=org.apache.jackrabbit.vault.packaging.events.PackageEventListener)";effective:=active;resolution:=optional;cardinality:=multiple,osgi.service;filter:="(objectClass=org.apache.jackrabbit.vault.packaging.events.impl.PackageEventDispatcher)";effective:=active,osgi.service;filter:="(objectClass=org.apache.sling.jcr.api.SlingRepository)";effective:=active;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest embedded-artifacts jackrabbit-spi-commons-2.16.1.jar;g="org.apache.jackrabbit";a="jackrabbit-spi-commons";v="2.16.1",jackrabbit-spi-2.16.1.jar;g="org.apache.jackrabbit";a="jackrabbit-spi";v="2.16.1" Low Vendor Manifest bundle-docurl http://jackrabbit.apache.org/filevault/ Low Vendor pom name Apache Jackrabbit FileVault Core Bundle High Vendor Manifest bundle-category jackrabbit Low Vendor file name org.apache.jackrabbit.vault High Vendor jar package name vault Highest Vendor pom artifactid apache.jackrabbit.vault Low Vendor Manifest service-component OSGI-INF/org.apache.jackrabbit.vault.packaging.events.impl.PackageEventDispatcherImpl.xml,OSGI-INF/org.apache.jackrabbit.vault.packaging.impl.ActivityLog.xml,OSGI-INF/org.apache.jackrabbit.vault.packaging.impl.PackageManagerMBeanImpl.xml,OSGI-INF/org.apache.jackrabbit.vault.packaging.impl.PackagingImpl.xml Low Product jar package name jackrabbit Highest Product Manifest provide-capability osgi.service;objectClass:List="javax.management.DynamicMBean",osgi.service;objectClass:List="org.apache.jackrabbit.vault.packaging.Packaging",osgi.service;objectClass:List="org.apache.jackrabbit.vault.packaging.events.PackageEventListener",osgi.service;objectClass:List="org.apache.jackrabbit.vault.packaging.events.impl.PackageEventDispatcher" Low Product jar package name apache Highest Product pom parent-artifactid parent Medium Product Manifest bundle-symbolicname org.apache.jackrabbit.vault Medium Product pom parent-groupid org.apache.jackrabbit.vault Medium Product pom artifactid apache.jackrabbit.vault Highest Product pom groupid apache.jackrabbit.vault Highest Product jar package name packaging Highest Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.component)(version>=1.3.0)(!(version>=2.0.0)))",osgi.service;filter:="(objectClass=org.apache.jackrabbit.vault.packaging.events.PackageEventListener)";effective:=active;resolution:=optional;cardinality:=multiple,osgi.service;filter:="(objectClass=org.apache.jackrabbit.vault.packaging.events.impl.PackageEventDispatcher)";effective:=active,osgi.service;filter:="(objectClass=org.apache.sling.jcr.api.SlingRepository)";effective:=active;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest embedded-artifacts jackrabbit-spi-commons-2.16.1.jar;g="org.apache.jackrabbit";a="jackrabbit-spi-commons";v="2.16.1",jackrabbit-spi-2.16.1.jar;g="org.apache.jackrabbit";a="jackrabbit-spi";v="2.16.1" Low Product pom artifactid org.apache.jackrabbit.vault Highest Product Manifest bundle-docurl http://jackrabbit.apache.org/filevault/ Low Product pom name Apache Jackrabbit FileVault Core Bundle High Product Manifest bundle-category jackrabbit Low Product file name org.apache.jackrabbit.vault High Product jar package name vault Highest Product Manifest Bundle-Name Apache Jackrabbit FileVault Core Bundle Medium Product Manifest service-component OSGI-INF/org.apache.jackrabbit.vault.packaging.events.impl.PackageEventDispatcherImpl.xml,OSGI-INF/org.apache.jackrabbit.vault.packaging.impl.ActivityLog.xml,OSGI-INF/org.apache.jackrabbit.vault.packaging.impl.PackageManagerMBeanImpl.xml,OSGI-INF/org.apache.jackrabbit.vault.packaging.impl.PackagingImpl.xml Low Version Manifest Bundle-Version 3.1.44 High Version pom version 3.1.44 Highest Version file version 3.1.44 High
org.apache.jackrabbit.vault-3.1.44.jar: jackrabbit-spi-2.16.1.jarDescription:
The Apache Jackrabbit™ content repository is a fully conforming implementation of the Content Repository for Java Technology API (JCR, specified in JSR 170 and 283). A content repository is a hierarchical content store with support for structured and unstructured content, full text search, versioning, transactions, observation, and more. Apache Jackrabbit is a project of the Apache Software Foundation. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/jackrabbit/vault/org.apache.jackrabbit.vault/3.1.44/org.apache.jackrabbit.vault-3.1.44.jar/jackrabbit-spi-2.16.1.jar
MD5: 34af186319cfc56397ae5374275b7255
SHA1: d8fa398bc1ef0d943a94c0b93bf000705fd5c13d
SHA256: 4b09b47b7fe69f12c2d9f61d9bc97a3881b140d79c22453e32e84b95edf8b006
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor file name jackrabbit-spi High Vendor jar package name jackrabbit Highest Vendor jar package name apache Highest Vendor pom artifactid jackrabbit-spi Low Vendor Manifest bundle-symbolicname org.apache.jackrabbit.jackrabbit-spi Medium Vendor jar package name spi Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest bundle-docurl http://jackrabbit.apache.org Low Vendor pom name Jackrabbit SPI High Vendor pom parent-groupid org.apache.jackrabbit Medium Vendor pom groupid apache.jackrabbit Highest Vendor pom parent-artifactid jackrabbit-parent Low Product file name jackrabbit-spi High Product jar package name jackrabbit Highest Product jar package name apache Highest Product pom parent-artifactid jackrabbit-parent Medium Product Manifest bundle-symbolicname org.apache.jackrabbit.jackrabbit-spi Medium Product jar package name spi Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-docurl http://jackrabbit.apache.org Low Product pom name Jackrabbit SPI High Product pom parent-groupid org.apache.jackrabbit Medium Product pom artifactid jackrabbit-spi Highest Product Manifest Bundle-Name Jackrabbit SPI Medium Product pom groupid apache.jackrabbit Highest Version file version 2.16.1 High Version Manifest Bundle-Version 2.16.1 High Version pom version 2.16.1 Highest
Related Dependencies org.apache.jackrabbit.vault-3.1.44.jar: jackrabbit-spi-commons-2.16.1.jarFile Path: /home/runner/.m2/repository/org/apache/jackrabbit/vault/org.apache.jackrabbit.vault/3.1.44/org.apache.jackrabbit.vault-3.1.44.jar/jackrabbit-spi-commons-2.16.1.jar MD5: df7d4cc751459924e6afabd6449db6f8 SHA1: 36891f581abfa7e33b81593e0863ab47e03a3f66 SHA256: 04242b0755db906cc9ed1836167a09501e083482a74f29b208fe5c451310ce3a pkg:maven/org.apache.jackrabbit/jackrabbit-spi-commons@2.16.1 org.apache.sling.commons.osgi-2.4.0.jarDescription:
Commons OSGi License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/apache/sling/org.apache.sling.commons.osgi/2.4.0/org.apache.sling.commons.osgi-2.4.0.jar
MD5: eee508e63a7721b33b9a9f5a402f02fd
SHA1: 8a7f6ebd0694eb4f1f44620e3615f483194d51c8
SHA256: 4a97362b8eb38ac23b423d5fd91e0eb9ad34cb44135ecd0fb3fbb57094fa5072
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor Manifest bundle-docurl http://sling.apache.org Low Vendor jar package name commons Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name sling Highest Vendor pom name Apache Sling Commons OSGi support High Vendor jar package name osgi Highest Vendor pom groupid apache.sling Highest Vendor pom parent-artifactid sling Low Vendor Manifest bundle-category sling Low Vendor pom artifactid apache.sling.commons.osgi Low Vendor Manifest bundle-symbolicname org.apache.sling.commons.osgi Medium Vendor pom parent-groupid org.apache.sling Medium Vendor file name org.apache.sling.commons.osgi High Vendor pom groupid org.apache.sling Highest Product pom artifactid org.apache.sling.commons.osgi Highest Product pom artifactid apache.sling.commons.osgi Highest Product jar package name apache Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product Manifest bundle-docurl http://sling.apache.org Low Product jar package name commons Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product jar package name sling Highest Product pom name Apache Sling Commons OSGi support High Product jar package name osgi Highest Product pom groupid apache.sling Highest Product Manifest bundle-category sling Low Product Manifest Bundle-Name Apache Sling Commons OSGi support Medium Product Manifest bundle-symbolicname org.apache.sling.commons.osgi Medium Product pom parent-groupid org.apache.sling Medium Product file name org.apache.sling.commons.osgi High Product pom parent-artifactid sling Medium Version Manifest Bundle-Version 2.4.0 High Version pom version 2.4.0 Highest Version file version 2.4.0 High Version pom parent-version 2.4.0 Low
org.apache.sling.contentparser.api-2.0.0.jarDescription:
API for parsing Apache Sling Resource trees stored in files (e.g. JSON, FileVault XML, etc.)
License:
"Apache License, Version 2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /home/runner/.m2/repository/org/apache/sling/org.apache.sling.contentparser.api/2.0.0/org.apache.sling.contentparser.api-2.0.0.jar
MD5: 3eb906352a0f03504e360574db4df6be
SHA1: be6dca46a31df6abe3836fbba7b9d21681aa495d
SHA256: 4dbbe0d338c13d2152fce5a31ce3b138b202746b0dcbdea4dd76c6c46ed6a46c
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name org.apache.sling.contentparser.api High Vendor jar package name sling Highest Vendor pom name Apache Sling Content Parser API High Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-developers sling;name="Apache Sling Project" Low Vendor Manifest bundle-docurl http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.api Low Vendor pom groupid apache.sling Highest Vendor Manifest Implementation-Vendor-Id org.apache.sling Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest bundle-category sling Low Vendor pom parent-artifactid sling-bundle-parent Low Vendor Manifest bundle-symbolicname org.apache.sling.contentparser.api Medium Vendor jar package name contentparser Highest Vendor Manifest implementation-url http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.api Low Vendor pom parent-groupid org.apache.sling Medium Vendor pom artifactid apache.sling.contentparser.api Low Vendor jar package name api Highest Vendor pom groupid org.apache.sling Highest Product Manifest specification-title Apache Sling Content Parser API Medium Product jar package name apache Highest Product file name org.apache.sling.contentparser.api High Product jar package name sling Highest Product pom name Apache Sling Content Parser API High Product Manifest bundle-developers sling;name="Apache Sling Project" Low Product Manifest bundle-docurl http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.api Low Product pom artifactid org.apache.sling.contentparser.api Highest Product pom groupid apache.sling Highest Product Manifest Bundle-Name Apache Sling Content Parser API Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-category sling Low Product Manifest bundle-symbolicname org.apache.sling.contentparser.api Medium Product jar package name contentparser Highest Product pom parent-artifactid sling-bundle-parent Medium Product pom artifactid apache.sling.contentparser.api Highest Product Manifest implementation-url http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.api Low Product pom parent-groupid org.apache.sling Medium Product Manifest Implementation-Title Apache Sling Content Parser API High Product jar package name api Highest Version file version 2.0.0 High Version pom version 2.0.0 Highest Version Manifest Implementation-Version 2.0.0 High Version Manifest Bundle-Version 2.0.0 High Version pom parent-version 2.0.0 Low
Published Vulnerabilities CVE-2015-2944 suppress
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the URI, related to (1) org/apache/sling/api/servlets/HtmlResponse and (2) org/apache/sling/servlets/post/HtmlResponse. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
org.apache.sling.contentparser.xml-2.0.0.jarDescription:
Apache Sling Content Parser for resource trees stored in XML files
License:
"Apache License, Version 2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /home/runner/.m2/repository/org/apache/sling/org.apache.sling.contentparser.xml/2.0.0/org.apache.sling.contentparser.xml-2.0.0.jar
MD5: 25060bc2347d0af12fca0d3b0c2cf535
SHA1: 26ec54dd8adcc1b7fd2ec20d19c3da007d897e69
SHA256: 579de30af29953b457134f926be8d155fc86abeb083ff9e0b2470f8b726c9c26
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name apache Highest Vendor Manifest implementation-url http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.xml Low Vendor file name org.apache.sling.contentparser.xml High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name sling Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-developers sling;name="Apache Sling Project" Low Vendor Manifest bundle-symbolicname org.apache.sling.contentparser.xml Medium Vendor pom groupid apache.sling Highest Vendor pom name Apache Sling Content Parser for XML High Vendor jar package name xml Highest Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.component)(version>=1.4.0)(!(version>=2.0.0)))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid apache.sling.contentparser.xml Low Vendor Manifest Implementation-Vendor-Id org.apache.sling Medium Vendor Manifest bundle-category sling Low Vendor pom parent-artifactid sling-bundle-parent Low Vendor Manifest bundle-docurl http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.xml Low Vendor jar package name contentparser Highest Vendor Manifest service-component OSGI-INF/org.apache.sling.contentparser.xml.internal.XMLContentParser.xml Low Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.sling.contentparser.api.ContentParser" Low Vendor pom parent-groupid org.apache.sling Medium Vendor pom groupid org.apache.sling Highest Product jar package name apache Highest Product Manifest implementation-url http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.xml Low Product file name org.apache.sling.contentparser.xml High Product jar package name sling Highest Product Manifest bundle-developers sling;name="Apache Sling Project" Low Product Manifest bundle-symbolicname org.apache.sling.contentparser.xml Medium Product pom groupid apache.sling Highest Product Manifest Bundle-Name Apache Sling Content Parser for XML Medium Product pom name Apache Sling Content Parser for XML High Product jar package name xml Highest Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.component)(version>=1.4.0)(!(version>=2.0.0)))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-category sling Low Product Manifest bundle-docurl http://sling.apache.org/sling-bundle-parent/org.apache.sling.contentparser.xml Low Product pom artifactid apache.sling.contentparser.xml Highest Product jar package name contentparser Highest Product pom parent-artifactid sling-bundle-parent Medium Product Manifest service-component OSGI-INF/org.apache.sling.contentparser.xml.internal.XMLContentParser.xml Low Product Manifest specification-title Apache Sling Content Parser for XML Medium Product Manifest provide-capability osgi.service;objectClass:List="org.apache.sling.contentparser.api.ContentParser" Low Product pom parent-groupid org.apache.sling Medium Product pom artifactid org.apache.sling.contentparser.xml Highest Product Manifest Implementation-Title Apache Sling Content Parser for XML High Version file version 2.0.0 High Version pom version 2.0.0 Highest Version Manifest Implementation-Version 2.0.0 High Version Manifest Bundle-Version 2.0.0 High Version pom parent-version 2.0.0 Low
Related Dependencies org.apache.sling.contentparser.json-2.0.0.jarFile Path: /home/runner/.m2/repository/org/apache/sling/org.apache.sling.contentparser.json/2.0.0/org.apache.sling.contentparser.json-2.0.0.jar MD5: b4f99566dd81e4e01013fea375e1e86c SHA1: f07f7db921f3d607422a5cdbf0edd520d7ce124a SHA256: 18ed3f2cb3ee51ce086d77a3861403462c8e614917572f6b096c8a31ee1065d3 pkg:maven/org.apache.sling/org.apache.sling.contentparser.json@2.0.0 org.eclipse.sisu.inject-0.0.0.M2a.jarLicense:
http://www.eclipse.org/legal/epl-v10.html File Path: /home/runner/.m2/repository/org/eclipse/sisu/org.eclipse.sisu.inject/0.0.0.M2a/org.eclipse.sisu.inject-0.0.0.M2a.jar
MD5: 6112d58a332b93e86b63aacc66200477
SHA1: 17941e32c751179a9628b25f54ce5641edafb9be
SHA256: 3e745c61748a4780839cbc6c0b10854abae3be26f3cf283a00bc002d2ed98bd1
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name eclipse Highest Vendor file name org.eclipse.sisu.inject High Vendor Manifest bundle-activationpolicy lazy Low Vendor pom groupid eclipse.sisu Highest Vendor Manifest bundle-symbolicname org.eclipse.sisu.inject;singleton:=true Medium Vendor Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Vendor pom groupid org.eclipse.sisu Highest Vendor Manifest bundle-copyright Copyright (c) 2010, 2012 Sonatype, Inc. and others Low Vendor pom parent-artifactid sisu-inject Low Vendor pom parent-groupid org.eclipse.sisu Medium Vendor pom artifactid eclipse.sisu.inject Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6,J2SE-1.5 Low Vendor jar package name inject Highest Vendor jar package name sisu Highest Product jar package name eclipse Highest Product file name org.eclipse.sisu.inject High Product Manifest bundle-activationpolicy lazy Low Product pom groupid eclipse.sisu Highest Product Manifest bundle-symbolicname org.eclipse.sisu.inject;singleton:=true Medium Product Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Product pom artifactid eclipse.sisu.inject Highest Product Manifest bundle-copyright Copyright (c) 2010, 2012 Sonatype, Inc. and others Low Product pom parent-groupid org.eclipse.sisu Medium Product pom artifactid org.eclipse.sisu.inject Highest Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6,J2SE-1.5 Low Product pom parent-artifactid sisu-inject Medium Product jar package name inject Highest Product Manifest Bundle-Name Sisu-Inject Medium Product jar package name sisu Highest Version pom version 0.0.0.M2a Highest Version Manifest Bundle-Version 0.0.0.M2a High
org.eclipse.sisu.plexus-0.0.0.M2a.jarFile Path: /home/runner/.m2/repository/org/eclipse/sisu/org.eclipse.sisu.plexus/0.0.0.M2a/org.eclipse.sisu.plexus-0.0.0.M2a.jarMD5: ad12584ce30edeacab4a6c32f4afd9b9SHA1: 07510dc8dfe27a0b57c17601bc760b7b0c8f95faSHA256: 03df90434ddf1851924dd9ba4d5f22aff7b134265fe9c7ecdb59d9b1dc3c1987Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor jar package name eclipse Highest Vendor pom parent-artifactid sisu-plexus Low Vendor pom groupid eclipse.sisu Highest Vendor jar package name plexus Highest Vendor file name org.eclipse.sisu.plexus High Vendor pom groupid org.eclipse.sisu Highest Vendor pom artifactid eclipse.sisu.plexus Low Vendor jar package name sisu Highest Vendor pom parent-groupid org.eclipse.sisu Medium Product jar package name plexus Low Product pom artifactid org.eclipse.sisu.plexus Highest Product jar package name eclipse Highest Product pom artifactid eclipse.sisu.plexus Highest Product pom groupid eclipse.sisu Highest Product jar package name plexus Highest Product file name org.eclipse.sisu.plexus High Product pom parent-artifactid sisu-plexus Medium Product jar package name sisu Highest Product pom parent-groupid org.eclipse.sisu Medium Version pom version 0.0.0.M2a Highest
plexus-cipher-1.4.jarFile Path: /home/runner/.m2/repository/org/sonatype/plexus/plexus-cipher/1.4/plexus-cipher-1.4.jarMD5: 7b2d6fcf0d5800d5b1ce09d98d98dcafSHA1: 50ade46f23bb38cd984b4ec560c46223432aac38SHA256: 5a15fdba22669e0fdd06e10dcce6320879e1f7398fbc910cd0677b50672a78c4Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name plexus Low Vendor pom parent-artifactid spice-parent Low Vendor jar package name sonatype Highest Vendor jar package name cipher Highest Vendor jar package name components Low Vendor jar package name sonatype Low Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom groupid org.sonatype.plexus Highest Vendor pom artifactid plexus-cipher Low Vendor pom url http://spice.sonatype.org/${project.artifactId} Highest Vendor jar package name plexus Highest Vendor file name plexus-cipher High Vendor pom groupid sonatype.plexus Highest Vendor pom name Plexus Cipher: encryption/decryption Component High Product jar package name plexus Low Product pom parent-artifactid spice-parent Medium Product jar package name sonatype Highest Product pom url http://spice.sonatype.org/${project.artifactId} Medium Product jar package name cipher Highest Product jar package name components Low Product pom parent-groupid org.sonatype.spice Medium Product jar package name plexus Highest Product jar package name cipher Low Product file name plexus-cipher High Product pom groupid sonatype.plexus Highest Product pom name Plexus Cipher: encryption/decryption Component High Product pom artifactid plexus-cipher Highest Version file version 1.4 High Version pom version 1.4 Highest Version pom parent-version 1.4 Low
plexus-classworlds-2.4.2.jarDescription:
A class loader framework File Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-classworlds/2.4.2/plexus-classworlds-2.4.2.jarMD5: e5e410378fb6c1c355c279d5e9b87f56SHA1: e006f28662eba33d91d1c5e342e0bd66f8e9da18SHA256: c7cf8ef0b2d82fe1bb6e3fbcc2bab993118220f289548ce9b61a07ac47ec9826Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor file name plexus-classworlds High Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor pom artifactid plexus-classworlds Low Vendor pom parent-groupid org.codehaus.plexus Medium Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Classworlds High Vendor jar package name classworlds Highest Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor jar package name classworlds Low Vendor pom parent-artifactid plexus Low Product file name plexus-classworlds High Product jar package name plexus Low Product pom artifactid plexus-classworlds Highest Product pom name Plexus Classworlds High Product jar package name classworlds Highest Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product jar package name codehaus Highest Product pom parent-artifactid plexus Medium Product pom parent-groupid org.codehaus.plexus Medium Product jar package name classworlds Low Version pom version 2.4.2 Highest Version file version 2.4.2 High Version pom parent-version 2.4.2 Low
plexus-component-annotations-1.5.5.jarDescription:
Plexus Component "Java 5" Annotations, to describe plexus components properties in java sources with
standard annotations instead of javadoc annotations.
File Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-component-annotations/1.5.5/plexus-component-annotations-1.5.5.jarMD5: ef37dcdb84030422db428b63c4354e5bSHA1: c72f2660d0cbed24246ddb55d7fdc4f7374d2078SHA256: 4df7a6a7be64b35bbccf60b5c115697f9ea3421d22674ae67135dde375fcca1fReferenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor file name plexus-component-annotations High Vendor pom parent-groupid org.codehaus.plexus Medium Vendor jar package name annotations Highest Vendor pom name Plexus :: Component Annotations High Vendor pom groupid org.codehaus.plexus Highest Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor jar package name component Highest Vendor pom artifactid plexus-component-annotations Low Vendor pom parent-artifactid plexus-containers Low Vendor jar package name component Low Product jar package name plexus Low Product pom parent-artifactid plexus-containers Medium Product file name plexus-component-annotations High Product pom parent-groupid org.codehaus.plexus Medium Product jar package name annotations Highest Product pom name Plexus :: Component Annotations High Product jar package name annotations Low Product pom artifactid plexus-component-annotations Highest Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product jar package name codehaus Highest Product jar package name component Highest Product jar package name component Low Version file version 1.5.5 High Version pom version 1.5.5 Highest
plexus-interpolation-1.16.jarFile Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-interpolation/1.16/plexus-interpolation-1.16.jarMD5: 17124c31e7f9b739688b31ef47fee6c0SHA1: a868d4a603bd42c9dee67890c4e60e360a11838cSHA256: bc4053a078ec83523a010c321c0d6852b43ddc4e076a6500b8bc133b6c69e561Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor jar package name interpolation Highest Vendor pom name Plexus Interpolation API High Vendor pom parent-groupid org.codehaus.plexus Medium Vendor jar package name interpolation Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor file name plexus-interpolation High Vendor pom artifactid plexus-interpolation Low Vendor pom parent-artifactid plexus-components Low Product jar package name plexus Low Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product jar package name codehaus Highest Product file name plexus-interpolation High Product pom parent-artifactid plexus-components Medium Product jar package name interpolation Highest Product pom name Plexus Interpolation API High Product pom parent-groupid org.codehaus.plexus Medium Product pom artifactid plexus-interpolation Highest Product jar package name interpolation Low Version file version 1.16 High Version pom parent-version 1.16 Low Version pom version 1.16 Highest
plexus-sec-dispatcher-1.3.jarFile Path: /home/runner/.m2/repository/org/sonatype/plexus/plexus-sec-dispatcher/1.3/plexus-sec-dispatcher-1.3.jarMD5: 53160199f5667de3fca69b723173639bSHA1: dedc02034fb8fcd7615d66593228cb71709134b4SHA256: 3b0559bb8432f28937efe6ca193ef54a8506d0075d73fd7406b9b116c6a11063Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name plexus Low Vendor pom parent-artifactid spice-parent Low Vendor jar package name sec Highest Vendor jar package name sonatype Highest Vendor jar package name components Low Vendor jar package name sonatype Low Vendor file name plexus-sec-dispatcher High Vendor pom parent-groupid org.sonatype.spice Medium Vendor pom groupid org.sonatype.plexus Highest Vendor pom url http://spice.sonatype.org/${project.artifactId} Highest Vendor jar package name plexus Highest Vendor pom name Plexus Security Dispatcher Component High Vendor pom artifactid plexus-sec-dispatcher Low Vendor pom groupid sonatype.plexus Highest Product jar package name plexus Low Product jar package name sec Highest Product pom parent-artifactid spice-parent Medium Product jar package name sonatype Highest Product pom url http://spice.sonatype.org/${project.artifactId} Medium Product jar package name components Low Product file name plexus-sec-dispatcher High Product pom parent-groupid org.sonatype.spice Medium Product jar package name plexus Highest Product pom name Plexus Security Dispatcher Component High Product pom artifactid plexus-sec-dispatcher Highest Product jar package name sec Low Product pom groupid sonatype.plexus Highest Version file version 1.3 High Version pom parent-version 1.3 Low Version pom version 1.3 Highest
plexus-utils-3.0.10.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines, XML and
more.
File Path: /home/runner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.10/plexus-utils-3.0.10.jarMD5: b8e14dd6e93c8f34888846dcac492160SHA1: 65e6460a49460d2ca038f8644ff9ae6d878733b8SHA256: 9fc0794062be85c3606000b326ea0339e8620d15949cb96a254b85a8f958e955Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor jar package name codehaus Low Vendor jar package name plexus Low Vendor pom url http://plexus.codehaus.org/plexus-utils Highest Vendor pom parent-groupid org.codehaus.plexus Medium Vendor pom artifactid plexus-utils Low Vendor jar package name xml Highest Vendor pom groupid org.codehaus.plexus Highest Vendor jar package name util Low Vendor pom groupid codehaus.plexus Highest Vendor jar package name plexus Highest Vendor jar package name codehaus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Vendor file name plexus-utils High Product jar package name plexus Low Product pom parent-artifactid plexus Medium Product pom parent-groupid org.codehaus.plexus Medium Product jar package name xml Highest Product jar package name util Low Product pom groupid codehaus.plexus Highest Product jar package name plexus Highest Product pom url http://plexus.codehaus.org/plexus-utils Medium Product jar package name codehaus Highest Product pom name Plexus Common Utilities High Product pom artifactid plexus-utils Highest Product file name plexus-utils High Version pom version 3.0.10 Highest Version file version 3.0.10 High Version pom parent-version 3.0.10 Low
Published Vulnerabilities CVE-2017-1000487 suppress
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
Directory traversal in org.codehaus.plexus.util.Expand (OSSINDEX) suppress
> org.codehaus.plexus.util.Expand does not guard against directory traversal, but such protection is generally expected from unarchiving tools.> > -- [github.com](https://github.com/codehaus-plexus/plexus-utils/issues/4) Unscored:
References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.codehaus.plexus:plexus-utils:3.0.10:*:*:*:*:*:*:* Possible XML Injection (OSSINDEX) suppress
> `org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment(XMLWriter, String, int, int, int)` does not check if the comment includes a `"-->"` sequence. This means that text contained in the command string could be interpreted as XML, possibly leading to XML injection issues, depending on how this method is being called.> > -- [github.com](https://github.com/codehaus-plexus/plexus-utils/issues/3) Unscored:
References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.codehaus.plexus:plexus-utils:3.0.10:*:*:*:*:*:*:* sisu-guice-3.1.0-no_aop.jarDescription:
Patched build of Guice: a lightweight dependency injection framework for Java 5 and above License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/runner/.m2/repository/org/sonatype/sisu/sisu-guice/3.1.0/sisu-guice-3.1.0-no_aop.jar
MD5: 19f877ae736fa153a545d0cf801dcec9
SHA1: 97c87d15d749c86b2be1b9809b28321a1d926c7f
SHA256: 4b76079f35407e5682aac1ecbe67afd5f430ae619044a9d6a413666a45750c25
Referenced In Project/Scope: Sling-Initial-Content Transformation Maven Plugin:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.sonatype.sisu.guice;singleton:=true Medium Vendor Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Vendor jar package name singleton Highest Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Vendor pom groupid org.sonatype.sisu Highest Vendor file name sisu-guice High Vendor jar package name inject Low Vendor jar package name google Low Vendor jar package name internal Low Vendor jar package name guice Highest Vendor Manifest eclipse-extensibleapi true Low Product Manifest bundle-symbolicname org.sonatype.sisu.guice;singleton:=true Medium Product pom artifactid sisu-guice Highest Product Manifest bundle-docurl http://code.google.com/p/google-guice/ Low Product Manifest Bundle-Name sisu-guice (no_aop) Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5,JavaSE-1.6 Low Product jar package name singleton Highest Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Product file name sisu-guice High Product jar package name google Highest Product jar package name inject Low Product jar package name dependency Highest Product jar package name internal Low Product jar package name guice Highest Product Manifest eclipse-extensibleapi true Low Version file version 3.1.0 High Version pom version 3.1.0 Highest