Skip to content

Bump org.apache.xmlbeans:xmlbeans from 5.2.1 to 5.2.2 in /plugins/ing…

Mend for GitHub.com / Mend Security Check failed Nov 12, 2024 in 1h 28m 3s

Security Report

The Security Check found 2 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2024-6763

Path to dependency file: /plugins/repository-hdfs/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.55.v20240627/6acd4d3dba5c237cc4315e68f9a602d6d175992a/jetty-server-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.55.v20240627/6acd4d3dba5c237cc4315e68f9a602d6d175992a/jetty-server-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-server/9.4.55.v20240627/6acd4d3dba5c237cc4315e68f9a602d6d175992a/jetty-server-9.4.55.v20240627.jar

Dependency Hierarchy:

-> ❌ jetty-server-9.4.55.v20240627.jar (Vulnerable Library)

Low 3.7 jetty-server-9.4.55.v20240627.jar Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12;org.eclipse.jetty:jetty-server:12.0.12 #16372
CVE-2024-6763

Path to dependency file: /build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.55.v20240627/ef807d867948042293487c025f953fb8e7d77622/jetty-http-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.55.v20240627/ef807d867948042293487c025f953fb8e7d77622/jetty-http-9.4.55.v20240627.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.eclipse.jetty/jetty-http/9.4.55.v20240627/ef807d867948042293487c025f953fb8e7d77622/jetty-http-9.4.55.v20240627.jar

Dependency Hierarchy:

-> hdfs-fixture-3.0.0-SNAPSHOT (Root Library)

   -> javax-websocket-server-impl-9.4.55.v20240627.jar

     -> javax-websocket-client-impl-9.4.55.v20240627.jar

       -> websocket-client-9.4.55.v20240627.jar

         -> jetty-client-9.4.55.v20240627.jar

           -> ❌ jetty-http-9.4.55.v20240627.jar (Vulnerable Library)

Low 3.7 jetty-http-9.4.55.v20240627.jar Upgrade to version: org.eclipse.jetty:jetty-http:12.0.12;org.eclipse.jetty:jetty-server:12.0.12 #14183

Total libraries scanned: 769
Scan token: 08d3e44bb0b24010b30cf37811fc9335