Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.1.9Report Generated On : Mon, 26 Jan 2026 13:28:02 +0100Dependencies Scanned : 1488 (621 unique)Vulnerable Dependencies : 74 Vulnerabilities Found : 331Vulnerabilities Suppressed : 0 ... NVD API Last Checked : 2026-01-26T12:24:39ZNVD API Last Modified : 2026-01-25T22:16:00ZNVD Cache Last Checked : 2026-01-26T12:24:39ZNVD Cache Last Modified : 2026-01-25T22:16:00ZSummary Summary of Vulnerable Dependencies (click to show all)
* indicates the dependency has a known exploited vulnerability
accordion.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/accordion/accordion.module.jsMD5: cd9dc460ce0b9a4301c68736b4b09895SHA1: 3e501278557bbc564f22982bd0c805083780f0e7SHA256: 32bcd5ec5cca4bc35f7b8efb90de6ff866709094924f3635d70780500fb2cdf1
Evidence Type Source Name Value Confidence
accordion.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/accordion/accordion.module.min.jsMD5: 9d8b3360f5dfcab3cab1fc14d162b58eSHA1: f6f302e2b04c3c10ceb2e154d4bed8ec3cf03d97SHA256: 7455f8683a795460da575b4d060276ce10e88bc49f02b16216b39ee888ecaef6
Evidence Type Source Name Value Confidence
accordion.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/accordion/accordion.nomodule.jsMD5: a2ba4e1ddf1aded869edb00f0e580964SHA1: 2715fccb41f825f76979d2873c9df6337823f2d9SHA256: f9df85d6e98d056ee5b9966a5cdc3ce0827b512adaaa442e9a472ab751b4f31b
Evidence Type Source Name Value Confidence
accordion.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/accordion/accordion.nomodule.min.jsMD5: a7776a5898396866ed300375f22aa870SHA1: a9cd8c5246df275caa18398a32a34d95c3f6c1bfSHA256: 853e254857d18c135c0eaf060e21f24750cce4a1c2b1cd28a641a95eb2e5f14b
Evidence Type Source Name Value Confidence
aesh-2.8.2.jarDescription:
Æsh (Another Extendable SHell) License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/aesh/aesh/2.8.2/aesh-2.8.2.jar
MD5: 21ea647cd351585c6c633c25dea02983
SHA1: b3da34498cb59529b5e39e4092dc435d1da9d83f
SHA256: 8c1e17fd1ab9d3a736bdee7fbd649e174f7dc26c1ceeac6e9ea596a9d63fcffd
Evidence Type Source Name Value Confidence Vendor file name aesh High Vendor hint analyzer vendor redhat Highest Vendor jar package name aesh Highest Vendor jar package name shell Highest Vendor Manifest automatic-module-name org.aesh.aesh Medium Vendor Manifest implementation-url http://www.jboss.org/aesh-all/aesh Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.aesh Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid aesh Low Vendor pom groupid org.aesh Highest Vendor pom name Æsh High Vendor pom parent-artifactid aesh-all Low Product file name aesh High Product jar package name aesh Highest Product jar package name shell Highest Product Manifest automatic-module-name org.aesh.aesh Medium Product Manifest Implementation-Title Æsh High Product Manifest implementation-url http://www.jboss.org/aesh-all/aesh Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Æsh Medium Product pom artifactid aesh Highest Product pom groupid org.aesh Highest Product pom name Æsh High Product pom parent-artifactid aesh-all Medium Version file version 2.8.2 High Version Manifest Implementation-Version 2.8.2 High Version pom version 2.8.2 Highest
pkg:maven/org.aesh/aesh@2.8.2 (Confidence :High) aether-api-1.0.0.v20140518.jarDescription:
The application programming interface for the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/aether/aether-api/1.0.0.v20140518/aether-api-1.0.0.v20140518.jar
MD5: b05ef5410dad83a4e9ba50e08e0dbbf4
SHA1: be68e917f454dcd841865ad7cf9b7615b26a51f7
SHA256: 84b98521684ab22f9528470fa6d8ab68a230e1b211623c989ba7016c306eb773
Evidence Type Source Name Value Confidence Vendor file name aether-api High Vendor jar package name aether Highest Vendor jar package name eclipse Highest Vendor jar package name repository Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-api/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.eclipse.aether.api Medium Vendor pom artifactid aether-api Low Vendor pom groupid org.eclipse.aether Highest Vendor pom name Aether API High Vendor pom parent-artifactid aether Low Product file name aether-api High Product jar package name aether Highest Product jar package name eclipse Highest Product jar package name repository Highest Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-api/ Low Product Manifest Bundle-Name Aether API Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.eclipse.aether.api Medium Product pom artifactid aether-api Highest Product pom groupid org.eclipse.aether Highest Product pom name Aether API High Product pom parent-artifactid aether Medium Version file version 1.0.0.v20140518 High Version Manifest Bundle-Version 1.0.0.v20140518 High Version pom version 1.0.0.v20140518 Highest
pkg:maven/org.eclipse.aether/aether-api@1.0.0.v20140518 (Confidence :High) aether-util-1.0.0.v20140518.jarDescription:
A collection of utility classes to ease usage of the repository system.
License:
http://www.eclipse.org/legal/epl-v10.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/aether/aether-util/1.0.0.v20140518/aether-util-1.0.0.v20140518.jar
MD5: 08495ee7ecf90f0b528e7d65471532af
SHA1: 7df5ba98ce8b78985d75fdd8c2981fe69234ef85
SHA256: aff0951639837c4e3a4699a421fa79f410032f603f5c6a5bba435e98531f3984
Evidence Type Source Name Value Confidence Vendor file name aether-util High Vendor jar package name aether Highest Vendor jar package name eclipse Highest Vendor jar package name repository Highest Vendor jar package name util Highest Vendor Manifest bundle-docurl http://www.eclipse.org/aether/aether-util/ Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.eclipse.aether.util Medium Vendor pom artifactid aether-util Low Vendor pom groupid org.eclipse.aether Highest Vendor pom name Aether Utilities High Vendor pom parent-artifactid aether Low Product file name aether-util High Product jar package name aether Highest Product jar package name eclipse Highest Product jar package name repository Highest Product jar package name util Highest Product Manifest bundle-docurl http://www.eclipse.org/aether/aether-util/ Low Product Manifest Bundle-Name Aether Utilities Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.eclipse.aether.util Medium Product pom artifactid aether-util Highest Product pom groupid org.eclipse.aether Highest Product pom name Aether Utilities High Product pom parent-artifactid aether Medium Version file version 1.0.0.v20140518 High Version Manifest Bundle-Version 1.0.0.v20140518 High Version pom version 1.0.0.v20140518 Highest
pkg:maven/org.eclipse.aether/aether-util@1.0.0.v20140518 (Confidence :High) analytics.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/analytics/analytics.module.jsMD5: 81317dd36704b0f335d8bdc1c1183fcdSHA1: 144d3b8ea24f38f253ad360bbdff3d9d5c7a59d3SHA256: 1a0708341244e7e5e47fe5786a37226715e35c73e5447dbbabc8a4f972f2e48d
Evidence Type Source Name Value Confidence
analytics.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/analytics/analytics.module.min.jsMD5: e96ff264cd094f8f7885e241959b0eddSHA1: a2f242c130dbebd6d21fd057eeaf13138f920785SHA256: 2227a6199078f6049bd4928caf40d340331a2aa598bf99afb7e1b6d92e2021a8
Evidence Type Source Name Value Confidence
analytics.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/analytics/analytics.nomodule.jsMD5: e4726e6d2e7b05750c1f7e8ac1ce58ccSHA1: 99d43910acf714da21e5ee91d5fa4ebfa7e166a0SHA256: 589a2d56477f2bb7debd104be24548fedf022cd6609f33aa2271ba0280649d5c
Evidence Type Source Name Value Confidence
analytics.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/analytics/analytics.nomodule.min.jsMD5: 19d8562d51e4b7d1c9aab6fac7def375SHA1: 367fdac2f1cebd61dbaade497678b232d1396274SHA256: 461573fb1056cd8a804d77b2a57e4a0a5e78cd21117aeb70ff145a3d2f2ce65d
Evidence Type Source Name Value Confidence
analyzer-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/analyzer-3.0.7.jarMD5: f7c853589a4ed4f7c83946028ff0dd80SHA1: db13787b2136f05b5258e3f690e5f0e8edc07834SHA256: a838c466f1519bb59fe90fe0d6f69605e32569e4293ef3c190bef86dd585ff47
Evidence Type Source Name Value Confidence Vendor file name analyzer High Vendor jar package name analyzer Highest Vendor jar package name fr Highest Vendor jar package name misis Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid analyzer Low Vendor pom groupid fr.gouv.misis Highest Vendor pom parent-artifactid misis-backend-parent Low Product file name analyzer High Product jar package name analyzer Highest Product jar package name fr Highest Product jar package name misis Highest Product Manifest build-jdk-spec 21 Low Product pom artifactid analyzer Highest Product pom groupid fr.gouv.misis Highest Product pom parent-artifactid misis-backend-parent Medium Version file version 3.0.7 High Version pom version 3.0.7 Highest
pkg:maven/fr.gouv.misis/analyzer@3.0.7 (Confidence :High) analyzer-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/app/analyzer-3.0.7.jarMD5: 679981326231a5219338be90312737b7SHA1: d5e1afca671163e2cd296134abf34182a08ecfc2SHA256: 98067b95296c46be1f5d205b03648e36b45fe9ced533442f0413aed6022e1c16
Evidence Type Source Name Value Confidence Vendor file name analyzer High Vendor jar package name fr Low Vendor jar package name misis Low Vendor jar package name numeco Low Product file name analyzer High Product jar package name analyzer Low Product jar package name misis Low Product jar package name numeco Low Version file name analyzer Medium Version file version 3.0.7 High
annotations-26.0.2.jarDescription:
A set of annotations used for code inspection support and code documentation. License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jetbrains/annotations/26.0.2/annotations-26.0.2.jar
MD5: ef0e782af9ee48fac1156485366d7cc9
SHA1: c7ce3cdeda3d18909368dfe5977332dfad326c6d
SHA256: 2037be378980d3ba9333e97955f3b2cde392aa124d04ca73ce2eee6657199297
Evidence Type Source Name Value Confidence Vendor file name annotations High Vendor jar package name annotations Highest Vendor jar package name jetbrains Highest Vendor Manifest multi-release true Low Vendor pom artifactid annotations Low Vendor pom developer id JetBrains Medium Vendor pom developer name JetBrains Team Medium Vendor pom developer org JetBrains Medium Vendor pom developer org URL https://www.jetbrains.com Medium Vendor pom groupid org.jetbrains Highest Vendor pom name JetBrains Java Annotations High Vendor pom url JetBrains/java-annotations Highest Product file name annotations High Product jar package name annotations Highest Product jar package name jetbrains Highest Product Manifest multi-release true Low Product pom artifactid annotations Highest Product pom developer id JetBrains Low Product pom developer name JetBrains Team Low Product pom developer org JetBrains Low Product pom developer org URL https://www.jetbrains.com Low Product pom groupid org.jetbrains Highest Product pom name JetBrains Java Annotations High Product pom url JetBrains/java-annotations High Version file version 26.0.2 High Version pom version 26.0.2 Highest
pkg:maven/org.jetbrains/annotations@26.0.2 (Confidence :High) aopalliance-1.0.jarDescription:
AOP Alliance License:
Public Domain File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/aopalliance/aopalliance/1.0/aopalliance-1.0.jar
MD5: 04177054e180d09e3998808efa0401c7
SHA1: 0235ba8b489512805ac13a8f9ea77a1ca5ebe3e8
SHA256: 0addec670fedcd3f113c5c8091d783280d23f75e3acb841b61a9cdb079376a08
Evidence Type Source Name Value Confidence Vendor file name aopalliance High Vendor jar package name aop Highest Vendor jar package name aopalliance Highest Vendor jar package name aopalliance Low Vendor jar package name intercept Low Vendor pom artifactid aopalliance Low Vendor pom groupid aopalliance Highest Vendor pom name AOP alliance High Vendor pom url http://aopalliance.sourceforge.net Highest Product file name aopalliance High Product jar package name aop Highest Product jar package name aopalliance Highest Product jar package name intercept Low Product pom artifactid aopalliance Highest Product pom groupid aopalliance Highest Product pom name AOP alliance High Product pom url http://aopalliance.sourceforge.net Medium Version file version 1.0 High Version pom version 1.0 Highest
pkg:maven/aopalliance/aopalliance@1.0 (Confidence :High) apiguardian-api-1.1.2.jarDescription:
@API Guardian License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apiguardian/apiguardian-api/1.1.2/apiguardian-api-1.1.2.jar
MD5: 8c7de3f82037fa4a2e8be2a2f13092af
SHA1: a231e0d844d2721b0fa1b238006d15c6ded6842a
SHA256: b509448ac506d607319f182537f0b35d71007582ec741832a1f111e5b5b70b38
Evidence Type Source Name Value Confidence Vendor file name apiguardian-api High Vendor jar package name api Highest Vendor jar package name apiguardian Highest Vendor Manifest build-date 2021-06-27 Low Vendor Manifest build-revision aa952a1b9d5b4e9cc0af853e2c140c2455b397be Low Vendor Manifest build-time 14:53:10.089+0200 Low Vendor Manifest bundle-docurl https://github.com/apiguardian-team/apiguardian Low Vendor Manifest bundle-symbolicname org.apiguardian.api Medium Vendor Manifest Implementation-Vendor apiguardian.org High Vendor Manifest specification-vendor apiguardian.org Low Vendor pom artifactid apiguardian-api Low Vendor pom developer email team@apiguardian.org Low Vendor pom developer id apiguardian Medium Vendor pom developer name @API Guardian Team Medium Vendor pom groupid org.apiguardian Highest Vendor pom name org.apiguardian:apiguardian-api High Vendor pom url apiguardian-team/apiguardian Highest Product file name apiguardian-api High Product jar package name api Highest Product jar package name apiguardian Highest Product Manifest build-date 2021-06-27 Low Product Manifest build-revision aa952a1b9d5b4e9cc0af853e2c140c2455b397be Low Product Manifest build-time 14:53:10.089+0200 Low Product Manifest bundle-docurl https://github.com/apiguardian-team/apiguardian Low Product Manifest Bundle-Name apiguardian-api Medium Product Manifest bundle-symbolicname org.apiguardian.api Medium Product Manifest Implementation-Title apiguardian-api High Product Manifest specification-title apiguardian-api Medium Product pom artifactid apiguardian-api Highest Product pom developer email team@apiguardian.org Low Product pom developer id apiguardian Low Product pom developer name @API Guardian Team Low Product pom groupid org.apiguardian Highest Product pom name org.apiguardian:apiguardian-api High Product pom url apiguardian-team/apiguardian High Version file version 1.1.2 High Version Manifest Bundle-Version 1.1.2 High Version Manifest Implementation-Version 1.1.2 High Version pom version 1.1.2 Highest
pkg:maven/org.apiguardian/apiguardian-api@1.1.2 (Confidence :High) asm-9.6.jarDescription:
ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm/9.6/asm-9.6.jar
MD5: 6f8bccf756f170d4185bb24c8c2d2020
SHA1: aa205cf0a06dbd8e04ece91c0b37c3f5d567546a
SHA256: 3c6fac2424db3d4a853b669f4e3d1d9c3c552235e19a319673f887083c2303a1
Evidence Type Source Name Value Confidence Vendor file name asm High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm Medium Vendor pom artifactid asm Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm High Product jar package name asm Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm Medium Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High Product pom artifactid asm Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.6 High Version Manifest Bundle-Version 9.6 High Version Manifest Implementation-Version 9.6 High Version pom parent-version 9.6 Low Version pom version 9.6 Highest
pkg:maven/org.ow2.asm/asm@9.6 (Confidence :High) asm-9.7.1.jarDescription:
ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm/9.7.1/asm-9.7.1.jar
MD5: e2cdd32d198ad31427d298eee9d39d8d
SHA1: f0ed132a49244b042cd0e15702ab9f2ce3cc8436
SHA256: 8cadd43ac5eb6d09de05faecca38b917a040bb9139c7edeb4cc81c740b713281
Evidence Type Source Name Value Confidence Vendor file name asm High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm Medium Vendor pom artifactid asm Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm High Product jar package name asm Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm Medium Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High Product pom artifactid asm Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.7.1 High Version Manifest Bundle-Version 9.7.1 High Version Manifest Implementation-Version 9.7.1 High Version pom parent-version 9.7.1 Low Version pom version 9.7.1 Highest
pkg:maven/org.ow2.asm/asm@9.7.1 (Confidence :High) asm-9.8.jarDescription:
ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm/9.8/asm-9.8.jar
MD5: f5adf3bfc54fb3d2cd8e3a1f275084bc
SHA1: dc19ecb3f7889b7860697215cae99c0f9b6f6b4b
SHA256: 876eab6a83daecad5ca67eb9fcabb063c97b5aeb8cf1fca7a989ecde17522051
Evidence Type Source Name Value Confidence Vendor file name asm High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm Medium Vendor pom artifactid asm Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm High Product jar package name asm Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm Medium Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High Product pom artifactid asm Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.8 High Version Manifest Bundle-Version 9.8 High Version Manifest Implementation-Version 9.8 High Version pom parent-version 9.8 Low Version pom version 9.8 Highest
pkg:maven/org.ow2.asm/asm@9.8 (Confidence :High) asm-9.9.jarDescription:
ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm/9.9/asm-9.9.jar
MD5: 6d1dd0482c03a6dc1807d9d004456021
SHA1: c29635c8a7afa03d74b33c1884df8abb2b3f3dcc
SHA256: 03d99a74ad1ee5c71334ef67437f4ef4fe3488caa7c96d8645abc73c8e2017d4
Evidence Type Source Name Value Confidence Vendor file name asm High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm Medium Vendor pom artifactid asm Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm High Product jar package name asm Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm Medium Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High Product pom artifactid asm Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.9 High Version Manifest Bundle-Version 9.9 High Version Manifest Implementation-Version 9.9 High Version pom parent-version 9.9 Low Version pom version 9.9 Highest
pkg:maven/org.ow2.asm/asm@9.9 (Confidence :High) asm-analysis-9.9.jarDescription:
Static code analysis API of ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm-analysis/9.9/asm-analysis-9.9.jar
MD5: f07383cfbd50f097558341a03b8871e1
SHA1: 0bf4fa6e66638851c1cd22c2caea0c3ee5d5f437
SHA256: 6a15d28e8bd29ba4fd5bca4baf9b50e8fba2d7b51fbf78cfa0c875a7214c678b
Evidence Type Source Name Value Confidence Vendor file name asm-analysis High Vendor jar package name analysis Highest Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor jar package name tree Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm.tree.analysis Medium Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low Vendor pom artifactid asm-analysis Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm-analysis High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm-analysis High Product jar package name analysis Highest Product jar package name asm Highest Product jar package name objectweb Highest Product jar package name tree Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm.tree.analysis Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm.tree.analysis Medium Product Manifest Implementation-Title Static code analysis API of ASM, a very small and fast Java bytecode manipulation framework High Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low Product pom artifactid asm-analysis Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm-analysis High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.9 High Version Manifest Bundle-Version 9.9 High Version Manifest Implementation-Version 9.9 High Version pom parent-version 9.9 Low Version pom version 9.9 Highest
pkg:maven/org.ow2.asm/asm-analysis@9.9 (Confidence :High) asm-commons-9.8.jarDescription:
Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm-commons/9.8/asm-commons-9.8.jar
MD5: c8c3d9ccf240144e74d94ff658b024c9
SHA1: 36e4d212970388e5bd2c5180292012502df461bb
SHA256: 3301a1c1cb4c59fcc5292648dac1d7c5aed4c0f067dfbe88873b8cdfe77404f4
Evidence Type Source Name Value Confidence Vendor file name asm-commons High Vendor jar package name asm Highest Vendor jar package name commons Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm.commons Medium Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low Vendor pom artifactid asm-commons Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm-commons High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm-commons High Product jar package name asm Highest Product jar package name commons Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm.commons Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm.commons Medium Product Manifest Implementation-Title Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework High Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low Product pom artifactid asm-commons Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm-commons High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.8 High Version Manifest Bundle-Version 9.8 High Version Manifest Implementation-Version 9.8 High Version pom parent-version 9.8 Low Version pom version 9.8 Highest
pkg:maven/org.ow2.asm/asm-commons@9.8 (Confidence :High) asm-commons-9.9.jarDescription:
Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm-commons/9.9/asm-commons-9.9.jar
MD5: 8103b3de8f48fb4c7f97efdaa46ce809
SHA1: db9165a3bf908ded6b08612d583a15d1d0c7bda0
SHA256: db2f6f26150bbe7c126606b4a1151836bcc22a1e05a423b3585698bece995ff8
Evidence Type Source Name Value Confidence Vendor file name asm-commons High Vendor jar package name asm Highest Vendor jar package name commons Highest Vendor jar package name objectweb Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm.commons Medium Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low Vendor pom artifactid asm-commons Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm-commons High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm-commons High Product jar package name asm Highest Product jar package name commons Highest Product jar package name objectweb Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm.commons Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm.commons Medium Product Manifest Implementation-Title Usefull class adapters based on ASM, a very small and fast Java bytecode manipulation framework High Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true Low Product pom artifactid asm-commons Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm-commons High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.9 High Version Manifest Bundle-Version 9.9 High Version Manifest Implementation-Version 9.9 High Version pom parent-version 9.9 Low Version pom version 9.9 Highest
pkg:maven/org.ow2.asm/asm-commons@9.9 (Confidence :High) asm-tree-9.8.jarDescription:
Tree API of ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm-tree/9.8/asm-tree-9.8.jar
MD5: 4ab1aaec43c77a2d9b56e6d6d496f705
SHA1: 018419ca5b77a2f81097c741e7872e6ab8d2f40d
SHA256: 14b7880cb7c85eed101e2710432fc3ffb83275532a6a894dc4c4095d49ad59f1
Evidence Type Source Name Value Confidence Vendor file name asm-tree High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor jar package name tree Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm.tree Medium Vendor Manifest module-requires org.objectweb.asm;transitive=true Low Vendor pom artifactid asm-tree Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm-tree High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm-tree High Product jar package name asm Highest Product jar package name objectweb Highest Product jar package name tree Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm.tree Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm.tree Medium Product Manifest Implementation-Title Tree API of ASM, a very small and fast Java bytecode manipulation framework High Product Manifest module-requires org.objectweb.asm;transitive=true Low Product pom artifactid asm-tree Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm-tree High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.8 High Version Manifest Bundle-Version 9.8 High Version Manifest Implementation-Version 9.8 High Version pom parent-version 9.8 Low Version pom version 9.8 Highest
pkg:maven/org.ow2.asm/asm-tree@9.8 (Confidence :High) asm-tree-9.9.jarDescription:
Tree API of ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm-tree/9.9/asm-tree-9.9.jar
MD5: 912eeaba1a63d574ffc66c651c7c6725
SHA1: f8de6eead6d24dd0f45bd065bbe112b2cda6ea21
SHA256: 42178f3775c9c63f9e5e1446747d29b4eca4d91bd6e75e5c43cfa372a47d38c6
Evidence Type Source Name Value Confidence Vendor file name asm-tree High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor jar package name tree Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm.tree Medium Vendor Manifest module-requires org.objectweb.asm;transitive=true Low Vendor pom artifactid asm-tree Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm-tree High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm-tree High Product jar package name asm Highest Product jar package name objectweb Highest Product jar package name tree Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm.tree Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm.tree Medium Product Manifest Implementation-Title Tree API of ASM, a very small and fast Java bytecode manipulation framework High Product Manifest module-requires org.objectweb.asm;transitive=true Low Product pom artifactid asm-tree Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm-tree High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.9 High Version Manifest Bundle-Version 9.9 High Version Manifest Implementation-Version 9.9 High Version pom parent-version 9.9 Low Version pom version 9.9 Highest
pkg:maven/org.ow2.asm/asm-tree@9.9 (Confidence :High) asm-util-9.9.jarDescription:
Utilities for ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ow2/asm/asm-util/9.9/asm-util-9.9.jar
MD5: ef5e90e736cd09bc407c1d46a3faba0f
SHA1: 42fdfc0508b43807c8078d6e82ecff2ce2112ae8
SHA256: 3842e13cfe324ee9ab7cdc4914be9943541ead397c17e26daf0b8a755bede717
Evidence Type Source Name Value Confidence Vendor file name asm-util High Vendor jar package name asm Highest Vendor jar package name objectweb Highest Vendor jar package name util Highest Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.objectweb.asm.util Medium Vendor Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true,org.objectweb.asm.tree.analysis;transitive=true Low Vendor pom artifactid asm-util Low Vendor pom developer email ebruneton@free.fr Low Vendor pom developer email eu@javatx.org Low Vendor pom developer email forax@univ-mlv.fr Low Vendor pom developer id ebruneton Medium Vendor pom developer id eu Medium Vendor pom developer id forax Medium Vendor pom developer name Eric Bruneton Medium Vendor pom developer name Eugene Kuleshov Medium Vendor pom developer name Remi Forax Medium Vendor pom groupid org.ow2.asm Highest Vendor pom name asm-util High Vendor pom organization name OW2 High Vendor pom organization url http://www.ow2.org/ Medium Vendor pom parent-artifactid ow2 Low Vendor pom parent-groupid org.ow2 Medium Vendor pom url http://asm.ow2.io/ Highest Product file name asm-util High Product jar package name asm Highest Product jar package name objectweb Highest Product jar package name util Highest Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest Bundle-Name org.objectweb.asm.util Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.objectweb.asm.util Medium Product Manifest Implementation-Title Utilities for ASM, a very small and fast Java bytecode manipulation framework High Product Manifest module-requires org.objectweb.asm;transitive=true,org.objectweb.asm.tree;transitive=true,org.objectweb.asm.tree.analysis;transitive=true Low Product pom artifactid asm-util Highest Product pom developer email ebruneton@free.fr Low Product pom developer email eu@javatx.org Low Product pom developer email forax@univ-mlv.fr Low Product pom developer id ebruneton Low Product pom developer id eu Low Product pom developer id forax Low Product pom developer name Eric Bruneton Low Product pom developer name Eugene Kuleshov Low Product pom developer name Remi Forax Low Product pom groupid org.ow2.asm Highest Product pom name asm-util High Product pom organization name OW2 Low Product pom organization url http://www.ow2.org/ Low Product pom parent-artifactid ow2 Medium Product pom parent-groupid org.ow2 Medium Product pom url http://asm.ow2.io/ Medium Version file version 9.9 High Version Manifest Bundle-Version 9.9 High Version Manifest Implementation-Version 9.9 High Version pom parent-version 9.9 Low Version pom version 9.9 Highest
pkg:maven/org.ow2.asm/asm-util@9.9 (Confidence :High) assertj-core-3.25.3.jarDescription:
Rich and fluent assertions for testing in Java License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/assertj/assertj-core/3.25.3/assertj-core-3.25.3.jar
MD5: 88258246abdcbf7298b7c3401273e15b
SHA1: 792b270e73aa1cfc28fa135be0b95e69ea451432
SHA256: 7fbdffa1996d43cc08e2576e01008b07e57bbad2b4741aa6c3ab73ce8511130e
Evidence Type Source Name Value Confidence Vendor file name assertj-core High Vendor jar package name assertions Highest Vendor jar package name assertj Highest Vendor jar package name core Highest Vendor Manifest bundle-developers joel-costigliola;email="joel.costigliola at gmail.com";name="Joel Costigliola";roles="Owner,Developer",scordio;name="Stefano Cordio";roles=Developer,PascalSchumacher;name="Pascal Schumacher";roles=Developer,epeee;name="Erhard Pointl";roles=Developer,croesch;name="Christian Rösch";roles=Developer,VanRoy;name="Julien Roy";roles=Developer,regis1512;name="Régis Pouiller";roles=Developer,fbiville;name="Florent Biville";roles=Developer,Patouche;name="Patrick Allain";roles=Developer Low Vendor Manifest bundle-docurl https://assertj.github.io/doc/#assertj-core Low Vendor Manifest bundle-symbolicname assertj-core Medium Vendor Manifest multi-release true Low Vendor pom artifactid assertj-core Low Vendor pom developer email joel.costigliola at gmail.com Low Vendor pom developer id croesch Medium Vendor pom developer id epeee Medium Vendor pom developer id fbiville Medium Vendor pom developer id joel-costigliola Medium Vendor pom developer id PascalSchumacher Medium Vendor pom developer id Patouche Medium Vendor pom developer id regis1512 Medium Vendor pom developer id scordio Medium Vendor pom developer id VanRoy Medium Vendor pom developer name Christian Rösch Medium Vendor pom developer name Erhard Pointl Medium Vendor pom developer name Florent Biville Medium Vendor pom developer name Joel Costigliola Medium Vendor pom developer name Julien Roy Medium Vendor pom developer name Pascal Schumacher Medium Vendor pom developer name Patrick Allain Medium Vendor pom developer name Régis Pouiller Medium Vendor pom developer name Stefano Cordio Medium Vendor pom groupid org.assertj Highest Vendor pom name AssertJ Core High Vendor pom url https://assertj.github.io/doc/#assertj-core Highest Product file name assertj-core High Product jar package name assertions Highest Product jar package name assertj Highest Product jar package name core Highest Product Manifest bundle-developers joel-costigliola;email="joel.costigliola at gmail.com";name="Joel Costigliola";roles="Owner,Developer",scordio;name="Stefano Cordio";roles=Developer,PascalSchumacher;name="Pascal Schumacher";roles=Developer,epeee;name="Erhard Pointl";roles=Developer,croesch;name="Christian Rösch";roles=Developer,VanRoy;name="Julien Roy";roles=Developer,regis1512;name="Régis Pouiller";roles=Developer,fbiville;name="Florent Biville";roles=Developer,Patouche;name="Patrick Allain";roles=Developer Low Product Manifest bundle-docurl https://assertj.github.io/doc/#assertj-core Low Product Manifest Bundle-Name AssertJ Core Medium Product Manifest bundle-symbolicname assertj-core Medium Product Manifest multi-release true Low Product pom artifactid assertj-core Highest Product pom developer email joel.costigliola at gmail.com Low Product pom developer id croesch Low Product pom developer id epeee Low Product pom developer id fbiville Low Product pom developer id joel-costigliola Low Product pom developer id PascalSchumacher Low Product pom developer id Patouche Low Product pom developer id regis1512 Low Product pom developer id scordio Low Product pom developer id VanRoy Low Product pom developer name Christian Rösch Low Product pom developer name Erhard Pointl Low Product pom developer name Florent Biville Low Product pom developer name Joel Costigliola Low Product pom developer name Julien Roy Low Product pom developer name Pascal Schumacher Low Product pom developer name Patrick Allain Low Product pom developer name Régis Pouiller Low Product pom developer name Stefano Cordio Low Product pom groupid org.assertj Highest Product pom name AssertJ Core High Product pom url https://assertj.github.io/doc/#assertj-core Medium Version file version 3.25.3 High Version Manifest Bundle-Version 3.25.3 High Version pom version 3.25.3 Highest
pkg:maven/org.assertj/assertj-core@3.25.3 (Confidence :High) auto-value-annotations-1.9.jarDescription:
Immutable value-type code generation for Java 1.7+.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/auto/value/auto-value-annotations/1.9/auto-value-annotations-1.9.jarMD5: 86f1f5d71eceea4eb4e3ad0505e8b22cSHA1: 25a0fcef915f663679fcdb447541c5d86a9be4baSHA256: fa5469f4c44ee598a2d8f033ab0a9dcbc6498a0c5e0c998dfa0c2adf51358044
Evidence Type Source Name Value Confidence Vendor file name auto-value-annotations High Vendor jar package name auto Highest Vendor jar package name autovalue Highest Vendor jar package name google Highest Vendor jar package name value Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid auto-value-annotations Low Vendor pom groupid com.google.auto.value Highest Vendor pom name AutoValue Annotations High Vendor pom parent-artifactid auto-value-parent Low Vendor pom url google/auto/tree/master/value Highest Product file name auto-value-annotations High Product jar package name auto Highest Product jar package name autovalue Highest Product jar package name google Highest Product jar package name value Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid auto-value-annotations Highest Product pom groupid com.google.auto.value Highest Product pom name AutoValue Annotations High Product pom parent-artifactid auto-value-parent Medium Product pom url google/auto/tree/master/value High Version file version 1.9 High Version pom version 1.9 Highest
pkg:maven/com.google.auto.value/auto-value-annotations@1.9 (Confidence :High) breadcrumb.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/breadcrumb/breadcrumb.module.jsMD5: 81abd56fd01367d90023d5404429f74dSHA1: 94ca5085adef108725777be33d59ff71b39fbd51SHA256: 97593e77d53ccd014fde3cb1f86a1fafd2bf407de0c919bff58b437af0c72d5c
Evidence Type Source Name Value Confidence
breadcrumb.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/breadcrumb/breadcrumb.module.min.jsMD5: 558df019402f41b7ae4a07c847a925f6SHA1: 1d3fc5aea859324fc28ccf38a4055e2141ca79d3SHA256: a9dcd870582730dd6124fb3df360f1c3182cd626e0577d6375ab7612ab6c35ff
Evidence Type Source Name Value Confidence
breadcrumb.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/breadcrumb/breadcrumb.nomodule.jsMD5: a01dde0bb0a237651c724eea56ca1d80SHA1: 71a303f47a820d2a21dee9eee78c62725097edebSHA256: 27e8b1bc75bdf456bec03539adca0a586dc0841187a5fd3f6f66a5c661825558
Evidence Type Source Name Value Confidence
breadcrumb.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/breadcrumb/breadcrumb.nomodule.min.jsMD5: 8de073c76554863925c9cca277c4d50fSHA1: ea551aa41da081bb1ecde109b99b222e15ecbd7bSHA256: 558600af72146626607abedae9e162e83643cd8a0c9191f5977b33f577f995ee
Evidence Type Source Name Value Confidence
button.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/button/button.module.jsMD5: 6b9ab44370787fbe3d6237e4f55a6c57SHA1: 95d4e8d33e16d5e9924187ed54e575d3858a8e94SHA256: 51b052656842ef3a5f0b92891ac1f7222e950a8652c48cf094c73f2e68049313
Evidence Type Source Name Value Confidence
button.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/button/button.module.min.jsMD5: 8d96f771898c4ff532224ea61e35b5a6SHA1: 602f5fcc2e8cbb9ef7d87f59d6f48c583c2ff0f5SHA256: 6253f92abfa11553c2a9e0cfc107b6c8f4ef9f6955df67e474ddf964f85e67d7
Evidence Type Source Name Value Confidence
button.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/button/button.nomodule.jsMD5: b0b4a259b71e96245fcde148a2975998SHA1: fca865e6a00045e596d5a478c294cc47accbca95SHA256: 983ce443f4b8d62abf85dfe0d5d3f4e12c86763d6862017362f7b938132c63ac
Evidence Type Source Name Value Confidence
button.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/button/button.nomodule.min.jsMD5: ce5eb555f9026ac0ca6213f7e7f7395aSHA1: 98da99b183eadcfa44acbcb89ad92bb6d8aea723SHA256: a6e5cff90dc9b3236f22104b84fa20972f4c729878fdb8f4e27c7b9af0fa9daa
Evidence Type Source Name Value Confidence
byte-buddy-agent-1.17.7.jarDescription:
The Byte Buddy agent offers convenience for attaching an agent to the local or a remote VM.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/bytebuddy/byte-buddy-agent/1.17.7/byte-buddy-agent-1.17.7.jar
MD5: d805e73391e6fc6d3de5af86e31ae0f7
SHA1: fbf3d6d649ed37fc9e9c59480a05be0a26e3c2da
SHA256: a9ba887dca252ad61b7d5153294f34e6f3bdf4b2736b04373d13615a695fc0ff
Evidence Type Source Name Value Confidence Vendor file name byte-buddy-agent High Vendor jar package name agent Highest Vendor jar package name bytebuddy Highest Vendor jar package name net Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname net.bytebuddy.byte-buddy-agent Medium Vendor Manifest can-redefine-classes true Low Vendor Manifest can-retransform-classes true Low Vendor Manifest can-set-native-method-prefix true Low Vendor Manifest multi-release true Low Vendor pom artifactid byte-buddy-agent Low Vendor pom groupid net.bytebuddy Highest Vendor pom name Byte Buddy agent High Vendor pom parent-artifactid byte-buddy-parent Low Product file name byte-buddy-agent High Product jar package name agent Highest Product jar package name bytebuddy Highest Product jar package name net Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Byte Buddy agent Medium Product Manifest bundle-symbolicname net.bytebuddy.byte-buddy-agent Medium Product Manifest can-redefine-classes true Low Product Manifest can-retransform-classes true Low Product Manifest can-set-native-method-prefix true Low Product Manifest multi-release true Low Product pom artifactid byte-buddy-agent Highest Product pom groupid net.bytebuddy Highest Product pom name Byte Buddy agent High Product pom parent-artifactid byte-buddy-parent Medium Version file version 1.17.7 High Version Manifest Bundle-Version 1.17.7 High Version pom version 1.17.7 Highest
pkg:maven/net.bytebuddy/byte-buddy-agent@1.17.7 (Confidence :High) byte-buddy-agent-1.17.7.jar: attach_hotspot_windows.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/bytebuddy/byte-buddy-agent/1.17.7/byte-buddy-agent-1.17.7.jar/win32-x86-64/attach_hotspot_windows.dllMD5: 053a783e5777c6a9867c27d51af89677SHA1: 5ef4d98ae6a033a5707d0b5466e6138beb337e76SHA256: 16d424423f9b09accf132ad35dbeaa52ac9f6bd45bba1406b89df851f651db20
Evidence Type Source Name Value Confidence Vendor file name attach_hotspot_windows High Product file name attach_hotspot_windows High
byte-buddy-agent-1.17.7.jar: attach_hotspot_windows.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/bytebuddy/byte-buddy-agent/1.17.7/byte-buddy-agent-1.17.7.jar/win32-x86/attach_hotspot_windows.dllMD5: fbca33102ac97be0ed496c0f78e466b3SHA1: c4df05146a86a6d073769bb697d550ef42518ed5SHA256: 810f94c4a2f5ca1a072c19859f7954fed9aa3a1dcb0d601e92d2338793202e72
Evidence Type Source Name Value Confidence Vendor file name attach_hotspot_windows High Product file name attach_hotspot_windows High
camel-quarkus-core-deployment-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jarMD5: 61d4815732be0e379f96203d44368d72SHA1: 87f097c0b269e1e217da619c9b5a08a82f2b0763SHA256: cc612accbb03e5efd7194d5409ea39e8b013d7853ba07986c773da098e688553
Evidence Type Source Name Value Confidence Vendor file name camel-quarkus-core-deployment High Vendor jar package name apache Highest Vendor jar package name camel Highest Vendor jar package name core Highest Vendor jar package name quarkus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid camel-quarkus-core-deployment Low Vendor pom groupid org.apache.camel.quarkus Highest Vendor pom name Camel Quarkus :: Core :: Deployment High Vendor pom parent-artifactid camel-quarkus-core-parent Low Product file name camel-quarkus-core-deployment High Product jar package name apache Highest Product jar package name camel Highest Product jar package name core Highest Product jar package name quarkus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Camel Quarkus :: Core :: Deployment High Product Manifest specification-title Camel Quarkus :: Core :: Deployment Medium Product pom artifactid camel-quarkus-core-deployment Highest Product pom groupid org.apache.camel.quarkus Highest Product pom name Camel Quarkus :: Core :: Deployment High Product pom parent-artifactid camel-quarkus-core-parent Medium Version file version 3.30.0 High Version Manifest Implementation-Version 3.30.0 High Version pom version 3.30.0 Highest
Related Dependencies camel-quarkus-mapstruct-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-mapstruct/3.30.0/camel-quarkus-mapstruct-3.30.0.jar MD5: e18edae76dc98448742539aa8215bc24 SHA1: d44c16ad408779bcaf43e48ff01e427ca13ecfa1 SHA256: 847fbd4fc58a2021c63dd5ddc6381d883d180a03919f184e6731a2c78cdc6080 pkg:maven/org.apache.camel.quarkus/camel-quarkus-mapstruct@3.30.0 camel-quarkus-mapstruct-deployment-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-mapstruct-deployment/3.30.0/camel-quarkus-mapstruct-deployment-3.30.0.jar MD5: 59bc2bc6c9db6c7126f7a832bc2af1f0 SHA1: 9b9588b344f82d2718f76a6da672e9041e70f271 SHA256: 9dee95b384931183bc0a2a6e060efcc15ad4bfd09a946a8db03a272ed73a4508 pkg:maven/org.apache.camel.quarkus/camel-quarkus-mapstruct-deployment@3.30.0 camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-blocked-exchanges.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-blocked-exchanges.jsMD5: 7735987a20cf551108276b98a58641edSHA1: 034265f60de8a9b7e76d06fb4e70821944850dbdSHA256: 9d262a08ada1ceb8ad59ce11d435e058a134e2eeb8ba2f0310c8d83d92c0a227
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-browse.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-browse.jsMD5: f7762a9fb455dcd00e9196027e97b043SHA1: 27a2f757571fb21ad1b0b2d38b806d2178496594SHA256: c8c03c301269ccd3890951821e8fc56397e6b27afd950098d46824e2d5992d39
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-context.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-context.jsMD5: dd03e36a591c654b85d7384e135120feSHA1: b6c4923a793161d2b3e6f443d7c6656195c45897SHA256: 7cee74af02c1d4207242b742ff09c8b834a561d2aabe123615170eaa62fce7d9
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-events.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-events.jsMD5: 5af416800d95b9d71c4b3fc72bafbf9fSHA1: c7b75b8b3a7d4b2ec720bebbb4c75449be74b6ecSHA256: b78e066ef255f858e7f9af5d6d19b4fe440c262867dccfa97a1d7dcb55ae707c
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-inflight-exchanges.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-inflight-exchanges.jsMD5: 36c6865e077e752e3f24e87db3f56a6dSHA1: 7cff185e1d7bdb27eca86af48b39fcfb5b0de329SHA256: 32b7efc104d9b55629b778b4b963fd1e41a16d3e0d8774908380ebbb52b2f950
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-rest.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-rest.jsMD5: 27b23f870f9cbbe38ee2d2e356eb0da5SHA1: ab6d493d8c7e97a3affa95ecc65dcc95cf3132f4SHA256: 06fdbf586c711eae80ce890ddc242c873ef6178a5f58392e7029fb0ed2b7d48a
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-routes.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-routes.jsMD5: 3cbe87042385fee5040af0f88dc588b2SHA1: 592c6f7c306b519d06750487cdcdb93e8c95f55aSHA256: e469bea62383394dbb36f91b34344b65c4971528611a1b475b966512b42e034d
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core-variables.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core-variables.jsMD5: 59cf5346d672d7aa87f5a8158ada279aSHA1: d357d1c72cdb7c1fd841c09521b601cfaba10756SHA256: 8e29d924d8cc979b507b3a88435437fdc0e4136c8969f5f61468043a0e15de2a
Evidence Type Source Name Value Confidence
camel-quarkus-core-deployment-3.30.0.jar: qwc-camel-core.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core-deployment/3.30.0/camel-quarkus-core-deployment-3.30.0.jar/dev-ui/qwc-camel-core.jsMD5: 5fe80dc193b98a399ca4cb40d2d623a0SHA1: 93ed169a8058a54c502846aa9fb2c573c5e47830SHA256: 73b0f0aa97f8eae490d35e2266115437110e34f70cfbd94bcbb7aa0bf84da960
Evidence Type Source Name Value Confidence
card.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/card/card.module.jsMD5: 0f3ce1f30fd59508b37e5fbf5b339154SHA1: 394abdebb735ceb8aecb70c18075d1f0b7b36e13SHA256: 6eaf93371268b9c4836d94d730cc945f51c9e95a22e10c94bf0c73f1778cefad
Evidence Type Source Name Value Confidence
card.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/card/card.module.min.jsMD5: 124a934285dcadfc7cfe7ae20150798fSHA1: aab5a2633491d8e1cc523d5ebcd2b40f898e7980SHA256: f2d01b86afdedd3b696cb28bd04fdd39da9f99e3bada8a5fbb32403e955c6b86
Evidence Type Source Name Value Confidence
card.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/card/card.nomodule.jsMD5: 2ca09e772d5e7dc95cd6fba1330f5b15SHA1: de01e48e50f479a20931ec638dbab09271d20ba2SHA256: 71d9d86acb4ba321cb010485d68043fc0a1dff0ce0bf9564ea7369cd9da8f41c
Evidence Type Source Name Value Confidence
card.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/card/card.nomodule.min.jsMD5: 6ed3e0e0ad1abfa7919970672ad4fe37SHA1: 404d02c2b32c7a841652621f62849e4881230d59SHA256: c541fb9c3de051a9f89b6476a79c11e68ea08b704e030dc1fdf6bb10483d7f03
Evidence Type Source Name Value Confidence
com.aayushatharva.brotli4j.brotli4j-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.brotli4j-1.16.0.jarMD5: 5b8de53b9758ec92871b52f31554cd0fSHA1: 990e983bb462867d036c7c243c6566f65fdca68fSHA256: 285a0b96150649db6fd9d8a0a22ea98fc2b8a558fc924b21836a59550975485e
Evidence Type Source Name Value Confidence Vendor file name com.aayushatharva.brotli4j.brotli4j High Vendor jar package name aayushatharva Low Vendor jar package name brotli4j Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest multi-release true Low Product file name com.aayushatharva.brotli4j.brotli4j High Product jar package name brotli4j Low Product Manifest build-jdk-spec 1.8 Low Product Manifest multi-release true Low Version file name com.aayushatharva.brotli4j.brotli4j Medium Version file version 1.16.0 High Version Manifest build-jdk-spec 1.8 Low
Related Dependencies brotli4j-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/aayushatharva/brotli4j/brotli4j/1.16.0/brotli4j-1.16.0.jar MD5: 5b8de53b9758ec92871b52f31554cd0f SHA1: 990e983bb462867d036c7c243c6566f65fdca68f SHA256: 285a0b96150649db6fd9d8a0a22ea98fc2b8a558fc924b21836a59550975485e pkg:maven/com.aayushatharva.brotli4j/brotli4j@1.16.0 com.aayushatharva.brotli4j.brotli4j-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.brotli4j-1.16.0.jar MD5: 5b8de53b9758ec92871b52f31554cd0f SHA1: 990e983bb462867d036c7c243c6566f65fdca68f SHA256: 285a0b96150649db6fd9d8a0a22ea98fc2b8a558fc924b21836a59550975485e com.aayushatharva.brotli4j.native-linux-x86_64-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.native-linux-x86_64-1.16.0.jarMD5: e302ee0b9c6fb3dc910e24e8b5095ce2SHA1: e72d451319f3b95879f47db7eeea7f720cb84d62SHA256: b6933c389857e1a7f400455096cec01ee76be73d51a9fb1164d2700d3d31054d
Evidence Type Source Name Value Confidence Vendor file name com.aayushatharva.brotli4j.native-linux-x86_64 High Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest multi-release true Low Product file name com.aayushatharva.brotli4j.native-linux-x86_64 High Product Manifest build-jdk-spec 1.8 Low Product Manifest multi-release true Low Version file name com.aayushatharva.brotli4j.native-linux-x86_64 Medium Version file version 1.16.0 High Version Manifest build-jdk-spec 1.8 Low
Related Dependencies com.aayushatharva.brotli4j.native-linux-x86_64-1.16.0.jar (shaded: com.aayushatharva.brotli4j:native-linux-x86_64:1.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.native-linux-x86_64-1.16.0.jar/META-INF/maven/com.aayushatharva.brotli4j/native-linux-x86_64/pom.xml MD5: 96a059db1b5f47c6bd1b55f5ba560a8a SHA1: c32240071000c568a435d2a6022efa970f6fe20f SHA256: 7092265d46ab285d884c970a5a61e72ccd3a30221ae6d5937887feffd6dda6a1 pkg:maven/com.aayushatharva.brotli4j/native-linux-x86_64@1.16.0 com.aayushatharva.brotli4j.native-linux-x86_64-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.native-linux-x86_64-1.16.0.jar MD5: e302ee0b9c6fb3dc910e24e8b5095ce2 SHA1: e72d451319f3b95879f47db7eeea7f720cb84d62 SHA256: b6933c389857e1a7f400455096cec01ee76be73d51a9fb1164d2700d3d31054d native-linux-x86_64-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/aayushatharva/brotli4j/native-linux-x86_64/1.16.0/native-linux-x86_64-1.16.0.jar MD5: e302ee0b9c6fb3dc910e24e8b5095ce2 SHA1: e72d451319f3b95879f47db7eeea7f720cb84d62 SHA256: b6933c389857e1a7f400455096cec01ee76be73d51a9fb1164d2700d3d31054d pkg:maven/com.aayushatharva.brotli4j/native-linux-x86_64@1.16.0 com.aayushatharva.brotli4j.service-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.service-1.16.0.jarMD5: 0a3db781b3b2a0463d1a0c44d7085f19SHA1: bd45e3f5a7165e190ea759abf220ce87d5f59103SHA256: 8e233823936a60d00b9d4434e733bd60aeaaac1c149ae5d9c9e7a49caecafa2d
Evidence Type Source Name Value Confidence Vendor file name com.aayushatharva.brotli4j.service High Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest multi-release true Low Product file name com.aayushatharva.brotli4j.service High Product Manifest build-jdk-spec 1.8 Low Product Manifest multi-release true Low Version file name com.aayushatharva.brotli4j.service Medium Version file version 1.16.0 High Version Manifest build-jdk-spec 1.8 Low
Related Dependencies com.aayushatharva.brotli4j.service-1.16.0.jar (shaded: com.aayushatharva.brotli4j:service:1.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.service-1.16.0.jar/META-INF/maven/com.aayushatharva.brotli4j/service/pom.xml MD5: 8948a399ca1c03a963591b1df49ff785 SHA1: 50c7c8bf836b6c058c9a2c3b487d7256422bf666 SHA256: 5e394cc5dee3cf4c3b4d832b1dedcc70dda7ca6e87f06cb6c9dc327d46110660 pkg:maven/com.aayushatharva.brotli4j/service@1.16.0 com.aayushatharva.brotli4j.service-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.aayushatharva.brotli4j.service-1.16.0.jar MD5: 0a3db781b3b2a0463d1a0c44d7085f19 SHA1: bd45e3f5a7165e190ea759abf220ce87d5f59103 SHA256: 8e233823936a60d00b9d4434e733bd60aeaaac1c149ae5d9c9e7a49caecafa2d service-1.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/aayushatharva/brotli4j/service/1.16.0/service-1.16.0.jar MD5: 0a3db781b3b2a0463d1a0c44d7085f19 SHA1: bd45e3f5a7165e190ea759abf220ce87d5f59103 SHA256: 8e233823936a60d00b9d4434e733bd60aeaaac1c149ae5d9c9e7a49caecafa2d pkg:maven/com.aayushatharva.brotli4j/service@1.16.0 cpe:2.3:a:service_project:service:1.16.0:*:*:*:*:*:*:* (Confidence :Low) suppress com.cronutils.cron-utils-9.2.1.jarDescription:
A Java library to parse, migrate and validate crons as well as describe them in human readable language License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.cronutils.cron-utils-9.2.1.jar
MD5: 4c27537eecc6fa37ed5740b5383643c8
SHA1: 5d3738bc7a2eaa45a94a76c6e87af54a95414637
SHA256: 02af0e8b2fe93c9fa6eecf97b53b39faae14c5b996356edb132e9fe620013744
Evidence Type Source Name Value Confidence Vendor file name com.cronutils.cron-utils High Vendor jar package name cronutils Highest Vendor jar package name cronutils Low Vendor jar package name model Low Vendor Manifest automatic-module-name com.cronutils Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname com.cronutils.cron-utils Medium Product file name com.cronutils.cron-utils High Product jar package name cron Highest Product jar package name cronutils Highest Product jar package name model Low Product jar package name utils Highest Product Manifest automatic-module-name com.cronutils Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name cron-utils Medium Product Manifest bundle-symbolicname com.cronutils.cron-utils Medium Version file name com.cronutils.cron-utils Medium Version file version 9.2.1 High Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 9.2.1 High
Related Dependencies com.cronutils.cron-utils-9.2.1.jar (shaded: com.cronutils:cron-utils:9.2.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.cronutils.cron-utils-9.2.1.jar/META-INF/maven/com.cronutils/cron-utils/pom.xml MD5: 59c81629d25180b6e51ace4757be55bb SHA1: 25ffd6b3b4532cc4fca615df01f6efdd634ee7d8 SHA256: d206c437893df3700ae7c1378e73300758d23858ec4345bbd34ac485391c63b5 pkg:maven/com.cronutils/cron-utils@9.2.1 com.cronutils.cron-utils-9.2.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.cronutils.cron-utils-9.2.1.jar MD5: 4c27537eecc6fa37ed5740b5383643c8 SHA1: 5d3738bc7a2eaa45a94a76c6e87af54a95414637 SHA256: 02af0e8b2fe93c9fa6eecf97b53b39faae14c5b996356edb132e9fe620013744 cron-utils-9.2.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/cronutils/cron-utils/9.2.1/cron-utils-9.2.1.jar MD5: 4c27537eecc6fa37ed5740b5383643c8 SHA1: 5d3738bc7a2eaa45a94a76c6e87af54a95414637 SHA256: 02af0e8b2fe93c9fa6eecf97b53b39faae14c5b996356edb132e9fe620013744 pkg:maven/com.cronutils/cron-utils@9.2.1 cpe:2.3:a:cron-utils_project:cron-utils:9.2.1:*:*:*:*:*:*:* (Confidence :Low) suppress com.fasterxml.classmate-1.7.1.jarDescription:
Library for introspecting types with full generic informationincluding resolving of field and method types. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.classmate-1.7.1.jar
MD5: e64a0680ebc8facde9b4cc431cbc248c
SHA1: e803194e4362a2c0585087c5f315682897d12f00
SHA256: cc3299e5df4fc24180e69477c890d07d38db79dd2decc0ef20e74a986897c0a1
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.classmate High Vendor jar package name classmate Highest Vendor jar package name classmate Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor Manifest specification-vendor fasterxml.com Low Product file name com.fasterxml.classmate High Product jar package name classmate Highest Product jar package name classmate Low Product jar package name fasterxml Highest Product jar package name types Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Product Manifest Bundle-Name ClassMate Medium Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product Manifest Implementation-Title ClassMate High Product Manifest specification-title ClassMate Medium Version file version 1.7.1 High Version Manifest Implementation-Version 1.7.1 High
Related Dependencies classmate-1.7.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/classmate/1.7.1/classmate-1.7.1.jar MD5: e64a0680ebc8facde9b4cc431cbc248c SHA1: e803194e4362a2c0585087c5f315682897d12f00 SHA256: cc3299e5df4fc24180e69477c890d07d38db79dd2decc0ef20e74a986897c0a1 pkg:maven/com.fasterxml/classmate@1.7.1 com.fasterxml.classmate-1.7.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.classmate-1.7.1.jar MD5: e64a0680ebc8facde9b4cc431cbc248c SHA1: e803194e4362a2c0585087c5f315682897d12f00 SHA256: cc3299e5df4fc24180e69477c890d07d38db79dd2decc0ef20e74a986897c0a1 com.fasterxml.jackson.core.jackson-annotations-2.20.jarDescription:
Core annotations used for value types, used by Jackson data binding package. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-annotations-2.20.jar
MD5: b901def3c20752817f27130e4b8d6640
SHA1: 6a5e7291ea3f2b590a7ce400adb7b3aea4d7e12c
SHA256: 959a2ffb2d591436f51f183c6a521fc89347912f711bf0cae008cdf045d95319
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.jackson.core.jackson-annotations High Vendor jar package name annotation Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor jar package name jackson Highest Vendor jar package name jackson Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest specification-vendor FasterXML Low Product file name com.fasterxml.jackson.core.jackson-annotations High Product jar package name annotation Low Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jackson Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name Jackson-annotations Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Product Manifest Implementation-Title Jackson-annotations High Product Manifest specification-title Jackson-annotations Medium Version file version 2.20 High Version Manifest Implementation-Version 2.20 High
Related Dependencies com.fasterxml.jackson.core.jackson-annotations-2.20.jar (shaded: com.fasterxml.jackson.core:jackson-annotations:2.20)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-annotations-2.20.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-annotations/pom.xml MD5: cb4b8730ad5e56f960ceff620a5eff9e SHA1: 046a776ebde36cfa4edd3e396544d8b1e939bef5 SHA256: 4d740c4478dd08d089ecdc6d063228a55a11a7e8e497da4338f872f8115794a4 pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.20 com.fasterxml.jackson.core.jackson-annotations-2.20.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-annotations-2.20.jar MD5: b901def3c20752817f27130e4b8d6640 SHA1: 6a5e7291ea3f2b590a7ce400adb7b3aea4d7e12c SHA256: 959a2ffb2d591436f51f183c6a521fc89347912f711bf0cae008cdf045d95319 jackson-annotations-2.20.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.20/jackson-annotations-2.20.jar MD5: b901def3c20752817f27130e4b8d6640 SHA1: 6a5e7291ea3f2b590a7ce400adb7b3aea4d7e12c SHA256: 959a2ffb2d591436f51f183c6a521fc89347912f711bf0cae008cdf045d95319 pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.20 com.fasterxml.jackson.core.jackson-core-2.20.1.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-core-2.20.1.jar
MD5: 889b2c417b61c9f4f460b06957147234
SHA1: 5734323adfece72111769b0ae38a6cf803e3d178
SHA256: ffab4d957daa2796cf24cb66d0b78a7090f1bcbe17c3a4578f09affaaf137089
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.jackson.core.jackson-core High Vendor jar package name com Highest Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor jar package name jackson Highest Vendor jar package name jackson Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Product file name com.fasterxml.jackson.core.jackson-core High Product jar package name com Highest Product jar package name core Highest Product jar package name core Low Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jackson Low Product jar package name json Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest Implementation-Title Jackson-core High Product Manifest multi-release true Low Product Manifest specification-title Jackson-core Medium Version file version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High
Related Dependencies com.fasterxml.jackson.core.jackson-core-2.20.1.jar (shaded: com.fasterxml.jackson.core:jackson-core:2.20.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-core-2.20.1.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-core/pom.xml MD5: 065f752503e793175bc63ade4a9ff71c SHA1: a295505cd4fdb8da56e6c01f766ec18075e6fa3d SHA256: 44200e47c4cdbde2be5d84304dd6214e8bdbe1d906e44643d40f93055e6bcd43 pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.1 com.fasterxml.jackson.core.jackson-core-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-core-2.20.1.jar MD5: 889b2c417b61c9f4f460b06957147234 SHA1: 5734323adfece72111769b0ae38a6cf803e3d178 SHA256: ffab4d957daa2796cf24cb66d0b78a7090f1bcbe17c3a4578f09affaaf137089 jackson-core-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.20.1/jackson-core-2.20.1.jar MD5: 889b2c417b61c9f4f460b06957147234 SHA1: 5734323adfece72111769b0ae38a6cf803e3d178 SHA256: ffab4d957daa2796cf24cb66d0b78a7090f1bcbe17c3a4578f09affaaf137089 pkg:maven/com.fasterxml.jackson.core/jackson-core@2.20.1 com.fasterxml.jackson.core.jackson-databind-2.20.1.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-databind-2.20.1.jar
MD5: 49d7b7226df5ed4a036e48997a03d066
SHA1: 9586a7fe0e1775de0e54237fa6a2c8455c93ac06
SHA256: 34bbeb4526fff4f8565b12106bf85a6afcbae858966d489b54214ac46b2e26e8
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.jackson.core.jackson-databind High Vendor jar package name databind Highest Vendor jar package name databind Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor jar package name jackson Highest Vendor jar package name jackson Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Product file name com.fasterxml.jackson.core.jackson-databind High Product jar package name databind Highest Product jar package name databind Low Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jackson Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest multi-release true Low Product Manifest specification-title jackson-databind Medium Version file version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High
Related Dependencies com.fasterxml.jackson.core.jackson-databind-2.20.1.jar (shaded: com.fasterxml.jackson.core:jackson-databind:2.20.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-databind-2.20.1.jar/META-INF/maven/com.fasterxml.jackson.core/jackson-databind/pom.xml MD5: b1741ecb7af42931aa5af94297e121a4 SHA1: 88676abff1e9882b4daabf10fb573b9c7de44c53 SHA256: bcfdf278253232b683ab51de2dcbc8f98f20f47738c111ecfd2c85c41b131cec pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1 com.fasterxml.jackson.core.jackson-databind-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.core.jackson-databind-2.20.1.jar MD5: 49d7b7226df5ed4a036e48997a03d066 SHA1: 9586a7fe0e1775de0e54237fa6a2c8455c93ac06 SHA256: 34bbeb4526fff4f8565b12106bf85a6afcbae858966d489b54214ac46b2e26e8 jackson-databind-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.20.1/jackson-databind-2.20.1.jar MD5: 49d7b7226df5ed4a036e48997a03d066 SHA1: 9586a7fe0e1775de0e54237fa6a2c8455c93ac06 SHA256: 34bbeb4526fff4f8565b12106bf85a6afcbae858966d489b54214ac46b2e26e8 pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.20.1 com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.20.1.jarDescription:
Support for reading and writing YAML-encoded data via Jackson abstractions. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.20.1.jar
MD5: 66dc3c5f31150557109b14182ed7ed8a
SHA1: e6da043059c9ec631a3429ded461d5d92f240c3f
SHA256: 030f1d91f7df278e86e1ba3e129fb520871ac16ce53017c735f708823be970db
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.jackson.dataformat.jackson-dataformat-yaml High Vendor jar package name dataformat Highest Vendor jar package name dataformat Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor jar package name jackson Highest Vendor jar package name jackson Low Vendor jar package name yaml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Product file name com.fasterxml.jackson.dataformat.jackson-dataformat-yaml High Product jar package name dataformat Highest Product jar package name dataformat Low Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jackson Low Product jar package name yaml Highest Product jar package name yaml Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Product Manifest Bundle-Name Jackson-dataformat-YAML Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium Product Manifest Implementation-Title Jackson-dataformat-YAML High Product Manifest multi-release true Low Product Manifest specification-title Jackson-dataformat-YAML Medium Version file version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High
Related Dependencies com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.20.1.jar (shaded: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.20.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.20.1.jar/META-INF/maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml/pom.xml MD5: fc4e7881f0809edab977215eab2e1eeb SHA1: c57b3beefd1a6e5e38100a00b53048523996d40e SHA256: 26ba2da0016c2a235b3dc702739c66dceeb18ca054462ae1544dacadf9e0b925 pkg:maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml@2.20.1 com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.dataformat.jackson-dataformat-yaml-2.20.1.jar MD5: 66dc3c5f31150557109b14182ed7ed8a SHA1: e6da043059c9ec631a3429ded461d5d92f240c3f SHA256: 030f1d91f7df278e86e1ba3e129fb520871ac16ce53017c735f708823be970db jackson-dataformat-yaml-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-yaml/2.20.1/jackson-dataformat-yaml-2.20.1.jar MD5: 66dc3c5f31150557109b14182ed7ed8a SHA1: e6da043059c9ec631a3429ded461d5d92f240c3f SHA256: 030f1d91f7df278e86e1ba3e129fb520871ac16ce53017c735f708823be970db pkg:maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml@2.20.1 com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.20.1.jarDescription:
Add-on module for Jackson (https://github.com/FasterXML/jackson) to supportJDK 8 data types. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.20.1.jar
MD5: 9360afe5a78d29ce5510f670b3286e77
SHA1: 6a8bbc260ba834f67220117d9f08510d69c4a3f0
SHA256: 6821cdd695e95c4e6853ec855a7432c71f2f4be318b3ca190fbbf8a2e5f981f2
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.jackson.datatype.jackson-datatype-jdk8 High Vendor jar package name datatype Highest Vendor jar package name datatype Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor jar package name jackson Highest Vendor jar package name jackson Low Vendor jar package name jdk8 Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Product file name com.fasterxml.jackson.datatype.jackson-datatype-jdk8 High Product jar package name datatype Highest Product jar package name datatype Low Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jackson Low Product jar package name jdk8 Highest Product jar package name jdk8 Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low Product Manifest Bundle-Name Jackson datatype: jdk8 Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium Product Manifest Implementation-Title Jackson datatype: jdk8 High Product Manifest multi-release true Low Product Manifest specification-title Jackson datatype: jdk8 Medium Version file version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High
Related Dependencies com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.20.1.jar (shaded: com.fasterxml.jackson.datatype:jackson-datatype-jdk8:2.20.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.20.1.jar/META-INF/maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8/pom.xml MD5: 9b65ba2c64cad4d0ba95a021eb7d18ea SHA1: 4fc9611d16a9138438d997ee4d6d13efab67cfc1 SHA256: f300fd100cc47beda0c1d133518064ec95314eba341b1fd9178c021580b91c9e pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.20.1 com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.datatype.jackson-datatype-jdk8-2.20.1.jar MD5: 9360afe5a78d29ce5510f670b3286e77 SHA1: 6a8bbc260ba834f67220117d9f08510d69c4a3f0 SHA256: 6821cdd695e95c4e6853ec855a7432c71f2f4be318b3ca190fbbf8a2e5f981f2 com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.20.1.jar MD5: 1ebd4e254f641f0cadf0ffdc1f662fea SHA1: 7ad06a455afc4a38412d5dab127191bdc3d90faf SHA256: 692be83c7e2eebb53b995c11d813c603a7d716d60c9d2d4fb9486ecb105f9291 com.fasterxml.jackson.module.jackson-module-parameter-names-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.fasterxml.jackson.module.jackson-module-parameter-names-2.20.1.jar MD5: 4670f258db373db07ab0c552696c4aa2 SHA1: 4214b732f1bd4e640e8e51ab6c5a73f6a418aaeb SHA256: 3b7e3702fce28ff4819bc5d3f18ff513c3cd32eda46e74cf3328142dea882aa9 jackson-datatype-jdk8-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jdk8/2.20.1/jackson-datatype-jdk8-2.20.1.jar MD5: 9360afe5a78d29ce5510f670b3286e77 SHA1: 6a8bbc260ba834f67220117d9f08510d69c4a3f0 SHA256: 6821cdd695e95c4e6853ec855a7432c71f2f4be318b3ca190fbbf8a2e5f981f2 pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.20.1 com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.20.1.jarDescription:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.20.1.jar
MD5: 1ebd4e254f641f0cadf0ffdc1f662fea
SHA1: 7ad06a455afc4a38412d5dab127191bdc3d90faf
SHA256: 692be83c7e2eebb53b995c11d813c603a7d716d60c9d2d4fb9486ecb105f9291
Evidence Type Source Name Value Confidence Vendor file name com.fasterxml.jackson.datatype.jackson-datatype-jsr310 High Vendor jar package name datatype Highest Vendor jar package name datatype Low Vendor jar package name fasterxml Highest Vendor jar package name fasterxml Low Vendor jar package name jackson Highest Vendor jar package name jackson Low Vendor jar package name jsr310 Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Product file name com.fasterxml.jackson.datatype.jackson-datatype-jsr310 High Product jar package name datatype Highest Product jar package name datatype Low Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jackson Low Product jar package name jsr310 Highest Product jar package name jsr310 Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low Product Manifest Bundle-Name Jackson datatype: JSR310 Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium Product Manifest Implementation-Title Jackson datatype: JSR310 High Product Manifest multi-release true Low Product Manifest specification-title Jackson datatype: JSR310 Medium Version file version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High
Related Dependencies com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.20.1.jar (shaded: com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.20.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.datatype.jackson-datatype-jsr310-2.20.1.jar/META-INF/maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310/pom.xml MD5: 4cae0b49912ac669925df3d245f48b5d SHA1: f2c31b84ae7f19b5fa1167a19ad0b0e6766538fe SHA256: f15fd62eb24476b00ab1ff7720f00b166b6973e6286d14708bb86612ebf923d4 pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.20.1 com.fasterxml.jackson.module.jackson-module-parameter-names-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.module.jackson-module-parameter-names-2.20.1.jar MD5: 4670f258db373db07ab0c552696c4aa2 SHA1: 4214b732f1bd4e640e8e51ab6c5a73f6a418aaeb SHA256: 3b7e3702fce28ff4819bc5d3f18ff513c3cd32eda46e74cf3328142dea882aa9 jackson-datatype-jsr310-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jsr310/2.20.1/jackson-datatype-jsr310-2.20.1.jar MD5: 1ebd4e254f641f0cadf0ffdc1f662fea SHA1: 7ad06a455afc4a38412d5dab127191bdc3d90faf SHA256: 692be83c7e2eebb53b995c11d813c603a7d716d60c9d2d4fb9486ecb105f9291 pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.20.1 com.github.ben-manes.caffeine.caffeine-3.2.3.jarDescription:
A high performance caching library License:
https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.github.ben-manes.caffeine.caffeine-3.2.3.jar
MD5: 0258f45d43968523cc11beeb01b240f2
SHA1: c097f0f6d21a0e6db88ea55836e26419b30dfe19
SHA256: ca70c90a5d1ce1511880ce9c93d4ad22108f61111d3daf91eb52762b571bd179
Evidence Type Source Name Value Confidence Vendor file name com.github.ben-manes.caffeine.caffeine High Vendor jar package name benmanes Low Vendor jar package name caffeine Highest Vendor jar package name caffeine Low Vendor jar package name github Highest Vendor jar package name github Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium Product file name com.github.ben-manes.caffeine.caffeine High Product jar package name benmanes Low Product jar package name cache Low Product jar package name caffeine Highest Product jar package name caffeine Low Product jar package name github Highest Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name com.github.ben-manes.caffeine Medium Product Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium Product Manifest Implementation-Title A high performance caching library High Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High
Related Dependencies caffeine-3.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/ben-manes/caffeine/caffeine/3.2.3/caffeine-3.2.3.jar MD5: 0258f45d43968523cc11beeb01b240f2 SHA1: c097f0f6d21a0e6db88ea55836e26419b30dfe19 SHA256: ca70c90a5d1ce1511880ce9c93d4ad22108f61111d3daf91eb52762b571bd179 pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3 com.github.ben-manes.caffeine.caffeine-3.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.github.ben-manes.caffeine.caffeine-3.2.3.jar MD5: 0258f45d43968523cc11beeb01b240f2 SHA1: c097f0f6d21a0e6db88ea55836e26419b30dfe19 SHA256: ca70c90a5d1ce1511880ce9c93d4ad22108f61111d3daf91eb52762b571bd179 com.google.auto.service.auto-service-annotations-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.google.auto.service.auto-service-annotations-1.1.1.jarMD5: 418feb19f713c38641702c09b9033436SHA1: da12a15cd058ba90a0ff55357fb521161af4736dSHA256: 16a76dd00a2650568447f5d6e3a9e2c809d9a42367d56b45215cfb89731f4d24
Evidence Type Source Name Value Confidence Vendor file name com.google.auto.service.auto-service-annotations High Vendor jar package name auto Highest Vendor jar package name auto Low Vendor jar package name google Highest Vendor jar package name google Low Vendor jar package name service Highest Vendor jar package name service Low Vendor Manifest automatic-module-name com.google.auto.service Medium Vendor Manifest build-jdk-spec 11 Low Product file name com.google.auto.service.auto-service-annotations High Product jar package name auto Highest Product jar package name auto Low Product jar package name autoservice Low Product jar package name google Highest Product jar package name service Highest Product jar package name service Low Product Manifest automatic-module-name com.google.auto.service Medium Product Manifest build-jdk-spec 11 Low Version file name com.google.auto.service.auto-service-annotations Medium Version file version 1.1.1 High Version Manifest build-jdk-spec 11 Low
Related Dependencies auto-service-annotations-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/auto/service/auto-service-annotations/1.1.1/auto-service-annotations-1.1.1.jar MD5: 418feb19f713c38641702c09b9033436 SHA1: da12a15cd058ba90a0ff55357fb521161af4736d SHA256: 16a76dd00a2650568447f5d6e3a9e2c809d9a42367d56b45215cfb89731f4d24 pkg:maven/com.google.auto.service/auto-service-annotations@1.1.1 cpe:2.3:a:service_project:service:1.1.1:*:*:*:*:*:*:* (Confidence :Low) suppress com.google.errorprone.error_prone_annotations-2.44.0.jarDescription:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time. License:
"Apache 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.google.errorprone.error_prone_annotations-2.44.0.jar
MD5: 11d0ff18fb88d4e4c48a4347e9e4a1e0
SHA1: bbbf88e1d12da9c6f7f204ca78a55446654ce7e1
SHA256: bcf738a525e546c926a233d0a169cf7eafcf703fe81ac9d6994f7244eda29052
Evidence Type Source Name Value Confidence Vendor file name com.google.errorprone.error_prone_annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name errorprone Highest Vendor jar package name errorprone Low Vendor jar package name google Highest Vendor jar package name google Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium Vendor Manifest multi-release true Low Product file name com.google.errorprone.error_prone_annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name errorprone Highest Product jar package name errorprone Low Product jar package name google Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low Product Manifest Bundle-Name error-prone annotations Medium Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium Product Manifest multi-release true Low Version file name com.google.errorprone.error_prone_annotations Medium Version file version 2.44.0 High Version jar package name annotations Highest Version jar package name errorprone Highest Version Manifest build-jdk-spec 21 Low Version Manifest Bundle-Version 2.44.0 High
Related Dependencies com.google.errorprone.error_prone_annotations-2.44.0.jar (shaded: com.google.errorprone:error_prone_annotations:2.44.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.google.errorprone.error_prone_annotations-2.44.0.jar/META-INF/maven/com.google.errorprone/error_prone_annotations/pom.xml MD5: 76b1e5397d756b92e32a50d3a87b7bd6 SHA1: 81fa3850562bcd428578a76061e4d7ee28b6227b SHA256: 7e619590512e84a28e02358adeabe7de4bab790af614e840b404139516de1657 pkg:maven/com.google.errorprone/error_prone_annotations@2.44.0 com.google.errorprone.error_prone_annotations-2.44.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.google.errorprone.error_prone_annotations-2.44.0.jar MD5: 11d0ff18fb88d4e4c48a4347e9e4a1e0 SHA1: bbbf88e1d12da9c6f7f204ca78a55446654ce7e1 SHA256: bcf738a525e546c926a233d0a169cf7eafcf703fe81ac9d6994f7244eda29052 error_prone_annotations-2.44.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/errorprone/error_prone_annotations/2.44.0/error_prone_annotations-2.44.0.jar MD5: 11d0ff18fb88d4e4c48a4347e9e4a1e0 SHA1: bbbf88e1d12da9c6f7f204ca78a55446654ce7e1 SHA256: bcf738a525e546c926a233d0a169cf7eafcf703fe81ac9d6994f7244eda29052 pkg:maven/com.google.errorprone/error_prone_annotations@2.44.0 com.google.guava.failureaccess-1.0.1.jarDescription:
Contains com.google.common.util.concurrent.internal.InternalFutureFailureAccess and InternalFutures. Most users will never need to use this artifact. Its classes is conceptually a part of Guava, but they're in this separate artifact so that Android libraries can use them without pulling in all of Guava (just as they can use ListenableFuture by depending on the listenablefuture artifact). License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.google.guava.failureaccess-1.0.1.jar
MD5: 091883993ef5bfa91da01dcc8fc52236
SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9
SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26
Evidence Type Source Name Value Confidence Vendor file name com.google.guava.failureaccess High Vendor jar package name common Low Vendor jar package name google Highest Vendor jar package name google Low Vendor jar package name util Low Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium Product file name com.google.guava.failureaccess High Product jar package name common Highest Product jar package name common Low Product jar package name concurrent Highest Product jar package name concurrent Low Product jar package name google Highest Product jar package name util Highest Product jar package name util Low Product Manifest bundle-docurl https://github.com/google/guava/ Low Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium Version file name com.google.guava.failureaccess Medium Version file version 1.0.1 High Version jar package name google Highest Version Manifest Bundle-Version 1.0.1 High
Related Dependencies failureaccess-1.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/guava/failureaccess/1.0.1/failureaccess-1.0.1.jar MD5: 091883993ef5bfa91da01dcc8fc52236 SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9 SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26 pkg:maven/com.google.guava/failureaccess@1.0.1 cpe:2.3:a:google:guava:1.0.1:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2023-2976 suppress
Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.
Even though the security vulnerability is fixed in version 32.0.0, we recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows. CWE-552 Files or Directories Accessible to External Parties
CVSSv3:
Base Score: HIGH (7.1) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve-coordination@google.com - EXPLOIT,PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
com.google.guava.guava-33.5.0-jre.jarDescription:
Guava is a suite of core and expanded libraries that include utility classes, Google's collections, I/O classes, and much more. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.google.guava.guava-33.5.0-jre.jar
MD5: d9fbf39a41a5bab891348f07668e18c5
SHA1: 8699de25f2f979108d6c1b804a7ba38cda1116bc
SHA256: 1e301f0c52ac248b0b14fdc3d12283c77252d4d6f48521d572e7d8c4c2cc4ac7
Evidence Type Source Name Value Confidence Vendor file name com.google.guava.guava High Vendor jar package name common Low Vendor jar package name google Highest Vendor jar package name google Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor Manifest multi-release true Low Product file name com.google.guava.guava High Product jar package name common Low Product jar package name google Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/google/guava/ Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product Manifest bundle-symbolicname com.google.guava Medium Product Manifest multi-release true Low Version file name com.google.guava.guava Medium Version file version 33.5.0 High Version jar package name google Highest Version Manifest build-jdk-spec 11 Low Version Manifest Bundle-Version 33.5.0.jre High
Related Dependencies guava-33.5.0-jre.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/guava/guava/33.5.0-jre/guava-33.5.0-jre.jar MD5: d9fbf39a41a5bab891348f07668e18c5 SHA1: 8699de25f2f979108d6c1b804a7ba38cda1116bc SHA256: 1e301f0c52ac248b0b14fdc3d12283c77252d4d6f48521d572e7d8c4c2cc4ac7 pkg:maven/com.google.guava/guava@33.5.0-jre cpe:2.3:a:google:guava:33.5.0:*:*:*:*:*:*:* (Confidence :Low) suppress com.google.j2objc.j2objc-annotations-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.google.j2objc.j2objc-annotations-2.8.jarMD5: c50af69b704dc91050efb98e0dff66d1SHA1: c85270e307e7b822f1086b93689124b89768e273SHA256: f02a95fa1a5e95edb3ed859fd0fb7df709d121a35290eff8b74dce2ab7f4d6ed
Evidence Type Source Name Value Confidence Vendor file name com.google.j2objc.j2objc-annotations High Vendor jar package name annotations Low Vendor jar package name google Low Vendor jar package name j2objc Low Product file name com.google.j2objc.j2objc-annotations High Product jar package name annotations Low Product jar package name j2objc Low Version file name com.google.j2objc.j2objc-annotations Medium Version file version 2.8 High
Related Dependencies j2objc-annotations-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/j2objc/j2objc-annotations/2.8/j2objc-annotations-2.8.jar MD5: c50af69b704dc91050efb98e0dff66d1 SHA1: c85270e307e7b822f1086b93689124b89768e273 SHA256: f02a95fa1a5e95edb3ed859fd0fb7df709d121a35290eff8b74dce2ab7f4d6ed pkg:maven/com.google.j2objc/j2objc-annotations@2.8 com.opencsv.opencsv-5.11.2.jarDescription:
A simple library for reading and writing CSV in Java License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.opencsv.opencsv-5.11.2.jar
MD5: 5773da53f17d87117a11df60f4328983
SHA1: 40b776b96a8f81cf675d5384ca6440c20e6e258a
SHA256: 690daad9014f23afd3ab6f1b0c45a5e0b738ac37a8d2e810e196193aab521245
Evidence Type Source Name Value Confidence Vendor file name com.opencsv.opencsv High Vendor jar package name bean Low Vendor jar package name opencsv Highest Vendor jar package name opencsv Low Vendor Manifest automatic-module-name com.opencsv Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname com.opencsv Medium Product file name com.opencsv.opencsv High Product jar package name bean Low Product jar package name opencsv Highest Product Manifest automatic-module-name com.opencsv Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name opencsv Medium Product Manifest bundle-symbolicname com.opencsv Medium Version file name com.opencsv.opencsv Medium Version file version 5.11.2 High Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 5.11.2 High
Related Dependencies opencsv-5.11.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/opencsv/opencsv/5.11.2/opencsv-5.11.2.jar MD5: 5773da53f17d87117a11df60f4328983 SHA1: 40b776b96a8f81cf675d5384ca6440c20e6e258a SHA256: 690daad9014f23afd3ab6f1b0c45a5e0b738ac37a8d2e810e196193aab521245 pkg:maven/com.opencsv/opencsv@5.11.2 com.rabbitmq.amqp-client-5.20.0.jarDescription:
The RabbitMQ Java client library allows Java applications to interface with RabbitMQ. License:
https://www.apache.org/licenses/LICENSE-2.0.html, https://www.gnu.org/licenses/gpl-2.0.txt, https://www.mozilla.org/en-US/MPL/2.0/ File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.rabbitmq.amqp-client-5.20.0.jar
MD5: c03b89b9df5ce7c5a43090ce6146a04c
SHA1: e8b2cbfe10d9cdcdc29961943b1c6c40f42e2f32
SHA256: 420e085cad65b0b4889def4a5704ae7dfe467b1bedb9fee709b17c154207843b
Evidence Type Source Name Value Confidence Vendor file name com.rabbitmq.amqp-client High Vendor jar package name client Highest Vendor jar package name client Low Vendor jar package name rabbitmq Highest Vendor jar package name rabbitmq Low Vendor Manifest automatic-module-name com.rabbitmq.client Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://www.rabbitmq.com Low Vendor Manifest bundle-symbolicname com.rabbitmq.client Medium Vendor Manifest implementation-url https://www.rabbitmq.com Low Vendor Manifest Implementation-Vendor VMware, Inc. or its affiliates. High Vendor Manifest specification-vendor AMQP Working Group (www.amqp.org) Low Product file name com.rabbitmq.amqp-client High Product jar package name amqp Highest Product jar package name client Highest Product jar package name client Low Product jar package name rabbitmq Highest Product Manifest automatic-module-name com.rabbitmq.client Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://www.rabbitmq.com Low Product Manifest Bundle-Name RabbitMQ Java Client Medium Product Manifest bundle-symbolicname com.rabbitmq.client Medium Product Manifest Implementation-Title RabbitMQ Java Client High Product Manifest implementation-url https://www.rabbitmq.com Low Product Manifest specification-title AMQP Medium Version file version 5.20.0 High Version Manifest Implementation-Version 5.20.0 High
Related Dependencies amqp-client-5.20.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/rabbitmq/amqp-client/5.20.0/amqp-client-5.20.0.jar MD5: c03b89b9df5ce7c5a43090ce6146a04c SHA1: e8b2cbfe10d9cdcdc29961943b1c6c40f42e2f32 SHA256: 420e085cad65b0b4889def4a5704ae7dfe467b1bedb9fee709b17c154207843b pkg:maven/com.rabbitmq/amqp-client@5.20.0 com.rabbitmq.amqp-client-5.20.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.rabbitmq.amqp-client-5.20.0.jar MD5: c03b89b9df5ce7c5a43090ce6146a04c SHA1: e8b2cbfe10d9cdcdc29961943b1c6c40f42e2f32 SHA256: 420e085cad65b0b4889def4a5704ae7dfe467b1bedb9fee709b17c154207843b com.sun.istack.istack-commons-runtime-4.1.2.jarDescription:
istack common utility code License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/com.sun.istack.istack-commons-runtime-4.1.2.jar
MD5: 535154ef647af2a52478c4debec93659
SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739
SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee
Evidence Type Source Name Value Confidence Vendor file name com.sun.istack.istack-commons-runtime High Vendor jar package name istack Highest Vendor jar package name istack Low Vendor jar package name sun Highest Vendor jar package name sun Low Vendor jar (hint) package name oracle Highest Vendor jar (hint) package name oracle Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Vendor Manifest implementation-build-id 4.1.2 - 343a28e Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Product file name com.sun.istack.istack-commons-runtime High Product jar package name istack Highest Product jar package name istack Low Product jar package name sun Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name istack common utility code runtime Medium Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Product Manifest implementation-build-id 4.1.2 - 343a28e Low Version file name com.sun.istack.istack-commons-runtime Medium Version file version 4.1.2 High Version Manifest Bundle-Version 4.1.2 High Version Manifest implementation-build-id 4.1.2 Low
Related Dependencies com.sun.istack.istack-commons-runtime-4.1.2.jar (shaded: com.sun.istack:istack-commons-runtime:4.1.2)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.sun.istack.istack-commons-runtime-4.1.2.jar/META-INF/maven/com.sun.istack/istack-commons-runtime/pom.xml MD5: 15bd8ed7117a57d709407e03d24196fe SHA1: 791e64803f294eafcf0f401c399d626ad0721500 SHA256: 1222a290beddb6f6e92bc999bcebc3696fcd6d72215856d224727a7bc2dc3aca pkg:maven/com.sun.istack/istack-commons-runtime@4.1.2 com.sun.istack.istack-commons-runtime-4.1.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.sun.istack.istack-commons-runtime-4.1.2.jar MD5: 535154ef647af2a52478c4debec93659 SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739 SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee istack-commons-runtime-4.1.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/sun/istack/istack-commons-runtime/4.1.2/istack-commons-runtime-4.1.2.jar MD5: 535154ef647af2a52478c4debec93659 SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739 SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee pkg:maven/com.sun.istack/istack-commons-runtime@4.1.2 common-java5-3.2.2.jarDescription:
Shared Java 5 code for all providers. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/common-java5/3.2.2/common-java5-3.2.2.jarMD5: 62ce140ee0cb1d7c6d392729e619c34bSHA1: c43a047cf985b82b3ff9b765183d8a52cfa5794fSHA256: 97ad4c16be3dbc34d0f5658c690eeadce27bf177518a46ee0fe8452ed7d6836e
Evidence Type Source Name Value Confidence Vendor file name common-java5 High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid common-java5 Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Shared Java 5 Provider Base High Vendor pom parent-artifactid surefire-providers Low Product file name common-java5 High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Shared Java 5 Provider Base High Product Manifest specification-title Shared Java 5 Provider Base Medium Product pom artifactid common-java5 Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Shared Java 5 Provider Base High Product pom parent-artifactid surefire-providers Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/common-java5@3.2.2 (Confidence :High) common-java5-3.2.3.jarDescription:
Shared Java 5 code for all providers. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/common-java5/3.2.3/common-java5-3.2.3.jarMD5: e93bbea13dcefd6781dc22cfccdd6735SHA1: dd489494cee969cb1ca49d0adcde8108d35c6b6fSHA256: ef1b816fce727e2cca7e712cca42db16c23691dd25176e9239da67d8193ba44a
Evidence Type Source Name Value Confidence Vendor file name common-java5 High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid common-java5 Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Shared Java 5 Provider Base High Vendor pom parent-artifactid surefire-providers Low Product file name common-java5 High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Shared Java 5 Provider Base High Product Manifest specification-title Shared Java 5 Provider Base Medium Product pom artifactid common-java5 Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Shared Java 5 Provider Base High Product pom parent-artifactid surefire-providers Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/common-java5@3.2.3 (Confidence :High) commonmark-0.27.0.jarDescription:
Core of commonmark-java (a library for parsing Markdown to an AST, modifying the AST and rendering it to HTML or Markdown) License:
BSD-2-Clause: https://opensource.org/licenses/BSD-2-Clause File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/commonmark/commonmark/0.27.0/commonmark-0.27.0.jar
MD5: c2435aad1f45b476322b324707e7f58a
SHA1: e1a4f968d70eefba0db19bcb534742b33812c96a
SHA256: 7a5a1a6e848e729fd7f85309f39e777af949848a914e559caeb7f64baef6e63e
Evidence Type Source Name Value Confidence Vendor file name commonmark High Vendor jar package name commonmark Highest Vendor jar package name html Highest Vendor jar package name markdown Highest Vendor jar package name parsing Highest Vendor Manifest build-jdk-spec 24 Low Vendor Manifest bundle-symbolicname org.commonmark Medium Vendor pom artifactid commonmark Low Vendor pom groupid org.commonmark Highest Vendor pom name commonmark-java core High Vendor pom parent-artifactid commonmark-parent Low Product file name commonmark High Product jar package name commonmark Highest Product jar package name html Highest Product jar package name markdown Highest Product jar package name parsing Highest Product Manifest build-jdk-spec 24 Low Product Manifest Bundle-Name commonmark-java core Medium Product Manifest bundle-symbolicname org.commonmark Medium Product pom artifactid commonmark Highest Product pom groupid org.commonmark Highest Product pom name commonmark-java core High Product pom parent-artifactid commonmark-parent Medium Version file version 0.27.0 High Version Manifest Bundle-Version 0.27.0 High Version pom version 0.27.0 Highest
pkg:maven/org.commonmark/commonmark@0.27.0 (Confidence :High) commons-cli-1.11.0.jarDescription:
Apache Commons CLI provides a simple API for presenting, processing, and validating a Command Line Interface.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-cli/commons-cli/1.11.0/commons-cli-1.11.0.jar
MD5: e689f5e4947368dd0233fc28f613f561
SHA1: a461452d3e31bebf2706323f8738ec44b19c96e1
SHA256: 8f7f8605d68e15bf32db61ec94eac6fdafc51b1bdbe1e0e0802b57d23f387792
Evidence Type Source Name Value Confidence Vendor file name commons-cli High Vendor jar package name apache Highest Vendor jar package name cli Highest Vendor jar package name commons Highest Vendor Manifest build-jdk-spec 25 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-cli/ Low Vendor Manifest bundle-symbolicname org.apache.commons.cli Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-cli Low Vendor pom developer email bob@werken.com Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email ebourg@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jbjk@mac.com Low Vendor pom developer email jstrachan@apache.org Low Vendor pom developer email roxspring@imapmail.org Low Vendor pom developer email tn@apache.org Low Vendor pom developer id bob Medium Vendor pom developer id chtompki Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id jkeyes Medium Vendor pom developer id jstrachan Medium Vendor pom developer id roxspring Medium Vendor pom developer id tn Medium Vendor pom developer name Bob McWhirter Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name James Strachan Medium Vendor pom developer name John Keyes Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer org Ariane Software Medium Vendor pom developer org Indigo Stone Medium Vendor pom developer org integral Source Medium Vendor pom developer org SpiritSoft, Inc. Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org Werken Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-cli Highest Vendor pom name Apache Commons CLI High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-cli/ Highest Product file name commons-cli High Product jar package name apache Highest Product jar package name cli Highest Product jar package name commons Highest Product Manifest build-jdk-spec 25 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-cli/ Low Product Manifest Bundle-Name Apache Commons CLI Medium Product Manifest bundle-symbolicname org.apache.commons.cli Medium Product Manifest Implementation-Title Apache Commons CLI High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons CLI Medium Product pom artifactid commons-cli Highest Product pom developer email bob@werken.com Low Product pom developer email chtompki@apache.org Low Product pom developer email ebourg@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jbjk@mac.com Low Product pom developer email jstrachan@apache.org Low Product pom developer email roxspring@imapmail.org Low Product pom developer email tn@apache.org Low Product pom developer id bob Low Product pom developer id chtompki Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id jkeyes Low Product pom developer id jstrachan Low Product pom developer id roxspring Low Product pom developer id tn Low Product pom developer name Bob McWhirter Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name James Strachan Low Product pom developer name John Keyes Low Product pom developer name Rob Oxspring Low Product pom developer name Rob Tompkins Low Product pom developer name Thomas Neidhart Low Product pom developer org Ariane Software Low Product pom developer org Indigo Stone Low Product pom developer org integral Source Low Product pom developer org SpiritSoft, Inc. Low Product pom developer org The Apache Software Foundation Low Product pom developer org Werken Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-cli Highest Product pom name Apache Commons CLI High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-cli/ Medium Version file version 1.11.0 High Version Manifest Bundle-Version 1.11.0 High Version Manifest Implementation-Version 1.11.0 High Version pom parent-version 1.11.0 Low Version pom version 1.11.0 Highest
pkg:maven/commons-cli/commons-cli@1.11.0 (Confidence :High) commons-codec-1.20.0.jarDescription:
The Apache Commons Codec component contains encoders and decoders for
formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-codec/commons-codec/1.20.0/commons-codec-1.20.0.jar
MD5: 3fb10a4c7cc664241cc4ca8a0e10b0b8
SHA1: 6a671d1c456a875ff61abec63216f754078bb0ed
SHA256: 6af66595f9f6a7bb58ce66518d6888d40b547c366d2262f06676eee19528ff66
Evidence Type Source Name Value Confidence Vendor file name commons-codec High Vendor jar package name apache Highest Vendor jar package name codec Highest Vendor jar package name commons Highest Vendor jar package name digest Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest build-jdk-spec 25 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email mattsicker@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id mattsicker Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Matt Sicker Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://juliusdavies.ca/ Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product file name commons-codec High Product jar package name apache Highest Product jar package name codec Highest Product jar package name commons Highest Product jar package name digest Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product Manifest build-jdk-spec 25 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Codec Medium Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email mattsicker@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id mattsicker Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Matt Sicker Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://juliusdavies.ca/ Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version file version 1.20.0 High Version Manifest Bundle-Version 1.20.0 High Version Manifest Implementation-Version 1.20.0 High Version pom parent-version 1.20.0 Low Version pom version 1.20.0 Highest
pkg:maven/commons-codec/commons-codec@1.20.0 (Confidence :High) commons-compress-1.21.jarDescription:
Apache Commons Compress software defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
lzma, xz, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-compress/1.21/commons-compress-1.21.jar
MD5: 2a713d10331bc4e13459a3dc0463f16f
SHA1: 4ec95b60d4e86b5c95a0e919cb172a0af98011ef
SHA256: 6aecfd5459728a595601cfa07258d131972ffc39b492eb48bdd596577a2f244a
Evidence Type Source Name Value Confidence Vendor file name commons-compress High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name compress Highest Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest implementation-build UNKNOWN@r60e3d9f6bef1e431f8738e881c051d706f81e6cf; 2021-07-09 16:56:00+0000 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email peterlee at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id peterlee Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Peter Alfred Lee Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product file name commons-compress High Product jar package name apache Highest Product jar package name commons Highest Product jar package name compress Highest Product Manifest automatic-module-name org.apache.commons.compress Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest implementation-build UNKNOWN@r60e3d9f6bef1e431f8738e881c051d706f81e6cf; 2021-07-09 16:56:00+0000 Low Product Manifest Implementation-Title Apache Commons Compress High Product Manifest specification-title Apache Commons Compress Medium Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email peterlee at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id peterlee Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Peter Alfred Lee Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version file version 1.21 High Version Manifest Implementation-Version 1.21 High Version pom parent-version 1.21 Low Version pom version 1.21 Highest
CVE-2024-25710 suppress
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-26308 suppress
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommended to upgrade to version 1.26, which fixes the issue. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
commons-compress-1.27.1.jarDescription:
Apache Commons Compress defines an API for working with
compression and archive formats. These include bzip2, gzip, pack200,
LZMA, XZ, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-compress/1.27.1/commons-compress-1.27.1.jar
MD5: 1db4bd87b0082044c6e7a6af0b977a3e
SHA1: a19151084758e2fbb6b41eddaa88e7b8ff4e6599
SHA256: 293d80f54b536b74095dcd7ea3cf0a29bbfc3402519281332495f4420d370d16
Evidence Type Source Name Value Confidence Vendor file name commons-compress High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name compress Highest Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email peterlee at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id peterlee Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Peter Alfred Lee Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product file name commons-compress High Product jar package name 9 Highest Product jar package name apache Highest Product jar package name commons Highest Product jar package name compress Highest Product Manifest automatic-module-name org.apache.commons.compress Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest Implementation-Title Apache Commons Compress High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest specification-title Apache Commons Compress Medium Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email peterlee at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id peterlee Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Peter Alfred Lee Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version file version 1.27.1 High Version Manifest Bundle-Version 1.27.1 High Version Manifest Implementation-Version 1.27.1 High Version pom parent-version 1.27.1 Low Version pom version 1.27.1 Highest
commons-compress-1.28.0.jarDescription:
Apache Commons Compress defines an API for working with
compression and archive formats. These include bzip2, gzip, pack200,
LZMA, XZ, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-compress/1.28.0/commons-compress-1.28.0.jar
MD5: f33efe616d561f8281ef7bf9f2576ad0
SHA1: e482f2c7a88dac3c497e96aa420b6a769f59c8d7
SHA256: e1522945218456f3649a39bc4afd70ce4bd466221519dba7d378f2141a4642ca
Evidence Type Source Name Value Confidence Vendor file name commons-compress High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name compress Highest Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 6.0.0 Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email peterlee at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id peterlee Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Peter Alfred Lee Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product file name commons-compress High Product jar package name apache Highest Product jar package name commons Highest Product jar package name compress Highest Product Manifest automatic-module-name org.apache.commons.compress Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest Implementation-Title Apache Commons Compress High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 6.0.0 Low Product Manifest specification-title Apache Commons Compress Medium Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email peterlee at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id peterlee Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Peter Alfred Lee Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version file version 1.28.0 High Version Manifest Bundle-Version 1.28.0 High Version Manifest Implementation-Version 1.28.0 High Version pom parent-version 1.28.0 Low Version pom version 1.28.0 Highest
commons-io-2.11.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-io/commons-io/2.11.0/commons-io-2.11.0.jar
MD5: 3b4b7ccfaeceeac240b804839ee1a1ca
SHA1: a2503f302b11ebde7ebc3df41daebe0e4eea3689
SHA256: 961b2f6d87dbacc5d54abf45ab7a6e2495f89b75598962d8c723cea9bc210908
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.11.0 High Version Manifest Bundle-Version 2.11.0 High Version Manifest Implementation-Version 2.11.0 High Version pom parent-version 2.11.0 Low Version pom version 2.11.0 Highest
CVE-2024-47554 suppress
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
commons-io-2.12.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-io/commons-io/2.12.0/commons-io-2.12.0.jar
MD5: 7abdf3e1c7bb44ae120be4b7dc1995f0
SHA1: e5e3eb2ff05b494287f51476bc715161412c525f
SHA256: 74bd60c8eebd3d43f77a66c69c86540c257a3a098172f8b1d7fcdc9ed3e139ea
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.12.0 High Version Manifest Bundle-Version 2.12.0 High Version Manifest Implementation-Version 2.12.0 High Version pom parent-version 2.12.0 Low Version pom version 2.12.0 Highest
CVE-2024-47554 suppress
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
commons-io-2.15.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-io/commons-io/2.15.0/commons-io-2.15.0.jar
MD5: 125a9d3dc2477b10cc6fa6e89c699e81
SHA1: 5c3c2db10f6f797430a7f9c696b4d1273768c924
SHA256: a328dad730921d197b6a9b195dffa00e41c974c2dac8fe37e84d31706bca7792
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.15.0 High Version Manifest Bundle-Version 2.15.0 High Version Manifest Implementation-Version 2.15.0 High Version pom parent-version 2.15.0 Low Version pom version 2.15.0 Highest
commons-io-2.18.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-io/commons-io/2.18.0/commons-io-2.18.0.jar
MD5: 8cce74ccf461cd6502ae04c908eca917
SHA1: 44084ef756763795b31c578403dd028ff4a22950
SHA256: f3ca0f8d63c40e23a56d54101c60d5edee136b42d84bfb85bc7963093109cf8b
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.18.0 High Version Manifest Bundle-Version 2.18.0 High Version Manifest Implementation-Version 2.18.0 High Version pom parent-version 2.18.0 Low Version pom version 2.18.0 Highest
Related Dependencies commons-io.commons-io-2.18.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/commons-io.commons-io-2.18.0.jar MD5: 8cce74ccf461cd6502ae04c908eca917 SHA1: 44084ef756763795b31c578403dd028ff4a22950 SHA256: f3ca0f8d63c40e23a56d54101c60d5edee136b42d84bfb85bc7963093109cf8b commons-io-2.21.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-io/commons-io/2.21.0/commons-io-2.21.0.jar
MD5: bc7e020873f086ede85f97bd9f013215
SHA1: 52a6f68fe5afe335cde95461dd5c3412f04996f7
SHA256: 7d643a2afea8b058b762aa6fb90e5b256f6c729739f8b3784c3370ddc609e88d
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest enabledynamicagentloading -XX:+EnableDynamicAgentLoading Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest enabledynamicagentloading -XX:+EnableDynamicAgentLoading Low Product Manifest Implementation-Title Apache Commons IO High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.21.0 High Version Manifest Bundle-Version 2.21.0 High Version Manifest Implementation-Version 2.21.0 High Version pom parent-version 2.21.0 Low Version pom version 2.21.0 Highest
commons-io-2.6.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/commons-io/commons-io/2.6/commons-io-2.6.jar
MD5: 467c2a1f64319c99b5faf03fc78572af
SHA1: 815893df5f31da2ece4040fe0a12fd44b577afaf
SHA256: f877d304660ac2a142f3865badfc971dec7ed73c747c7f8d5d2f5139ca736513
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.io Medium Vendor Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id commons-io Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest implementation-url http://commons.apache.org/proper/commons-io/ Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory@apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-io/ Medium Version file version 2.6 High Version Manifest Implementation-Version 2.6 High Version pom parent-version 2.6 Low Version pom version 2.6 Highest
CVE-2021-29425 suppress
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - EXPLOIT,ISSUE_TRACKING,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2024-47554 suppress
Uncontrolled Resource Consumption vulnerability in Apache Commons IO.
The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.
This issue affects Apache Commons IO: from 2.0 before 2.14.0.
Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
commons-lang3-3.12.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-lang3/3.12.0/commons-lang3-3.12.0.jar
MD5: 19fe50567358922bdad277959ea69545
SHA1: c6842c86792ff03b9f1d1fe2aab8dc23aa6c6f0e
SHA256: d919d904486c037f8d193412da0c92e22a9fa24230b9d67a57855c5c31c7e94e
Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary D. Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary D. Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version file version 3.12.0 High Version Manifest Bundle-Version 3.12.0 High Version Manifest Implementation-Version 3.12.0 High Version pom parent-version 3.12.0 Low Version pom version 3.12.0 Highest
CVE-2025-48924 suppress
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue. CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
commons-lang3-3.19.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17 and 21 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-lang3/3.19.0/commons-lang3-3.19.0.jar
MD5: 2ac2db154e365d55d167ec1215125a3a
SHA1: d6524b169a6574cd253760c472d419b47bfd37e6
SHA256: 32733ab4bc90b45b63eb72677d886961003fd4ed113e07b1028f9877cb2ac735
Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version file version 3.19.0 High Version Manifest Bundle-Version 3.19.0 High Version Manifest Implementation-Version 3.19.0 High Version pom parent-version 3.19.0 Low Version pom version 3.19.0 Highest
component.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/component.module.jsMD5: 1c5af2930fb40cdd6240ad53c2b4d7a0SHA1: d8e78d92618739ba682806312be1ae669092770cSHA256: 433d065544036de36c88aff714bf12740fe1fa991eea66584fa6281433abfe74
Evidence Type Source Name Value Confidence
component.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/component.module.min.jsMD5: 24ba171a94af062cc6daa20da3af60bbSHA1: 035b0215d5e9481f9bbfd30b1001360b839e9735SHA256: c3510209013cf4d0e96a008aedfcee262addcf7b4cd07941211452633cbb35a4
Evidence Type Source Name Value Confidence
component.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/component.nomodule.jsMD5: 0ad2529bd9e3aec48bec141648993e0eSHA1: dc909eaaa9af1a2d898e5984cf45a34fc6eb5645SHA256: eedb70631d3fb7d5ca1fdd4538bed96977efef93fe7da5978a1f3a73e5071be0
Evidence Type Source Name Value Confidence
component.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/component.nomodule.min.jsMD5: 6b9595aed1d4a293cbb4a5365f8c8796SHA1: bc8ba652e2c0d03957f270315d76e7bd955d78a1SHA256: 39d179c9bad6c165a1e78bc358e72ecc8c196ae680c744801d65d6dc0f469490
Evidence Type Source Name Value Confidence
core-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/core/target/core-3.0.7.jarMD5: 62455d7c00a89537ab05c8f3440e569bSHA1: d7266e1d17503c59a7d744f12a0be25fed5542afSHA256: c8d1cbca6c85fbed6077997f766bf2f02b4a2be8e77a0fa7660290debdb969af
Evidence Type Source Name Value Confidence Vendor file name core High Vendor jar package name core Highest Vendor jar package name fr Highest Vendor jar package name misis Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid core Low Vendor pom groupid fr.gouv.misis Highest Vendor pom parent-artifactid misis-backend-parent Low Product file name core High Product jar package name core Highest Product jar package name fr Highest Product jar package name misis Highest Product Manifest build-jdk-spec 21 Low Product pom artifactid core Highest Product pom groupid fr.gouv.misis Highest Product pom parent-artifactid misis-backend-parent Medium Version file version 3.0.7 High Version pom version 3.0.7 Highest
Related Dependencies fr.gouv.misis.core-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/fr.gouv.misis.core-3.0.7.jar MD5: 62455d7c00a89537ab05c8f3440e569b SHA1: d7266e1d17503c59a7d744f12a0be25fed5542af SHA256: c8d1cbca6c85fbed6077997f766bf2f02b4a2be8e77a0fa7660290debdb969af fr.gouv.misis.core-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/fr.gouv.misis.core-3.0.7.jar MD5: 62455d7c00a89537ab05c8f3440e569b SHA1: d7266e1d17503c59a7d744f12a0be25fed5542af SHA256: c8d1cbca6c85fbed6077997f766bf2f02b4a2be8e77a0fa7660290debdb969af pkg:maven/fr.gouv.misis/core@3.0.7 (Confidence :High) core.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/core/core.module.jsMD5: ad2cb38d7acb6a5e46ed6f2a8b164901SHA1: 31f71c2d104bea5dfd4b929ff1871689f0626393SHA256: eda94a60818ede7b9ec708e12ff86830a6ac7404703b226e4c2ddc8d585040ef
Evidence Type Source Name Value Confidence
core.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/core/core.module.min.jsMD5: af1c1f6b68313df3f7f3bae406c966beSHA1: 4fa7807733a6c4b5b3f60761816760bcb2a181d9SHA256: 087cccc2ed8f813c06c595140bd3e5dae5f961652240738e35b26005dff475ea
Evidence Type Source Name Value Confidence
core.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/core/core.nomodule.jsMD5: 231f33a5e803cd2b1ff2f28965c17a7eSHA1: d104cdcc4c0034e9eb23fd6c8ee16d8e495af48fSHA256: 10e056aea891cc0d817563fc3bbba014b6a9de7319b94f07cbdb5b4aa002343e
Evidence Type Source Name Value Confidence
core.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/core/core.nomodule.min.jsMD5: 4ce0ae3e18cdf9997c74ec8c5c0ed089SHA1: 12b735e98ed5997b4713e151fbf233f21acb84a8SHA256: cb5182e9d18ede040c3ea0570b6c52acaa79dca33f3563ed45ebf0375a09223b
Evidence Type Source Name Value Confidence
cyclonedx-core-java-11.0.1.jarDescription:
The CycloneDX core module provides a model representation of the BOM along with utilities to assist in creating, parsing, and validating BOMs. License:
Apache-2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/cyclonedx/cyclonedx-core-java/11.0.1/cyclonedx-core-java-11.0.1.jar
MD5: 2939896ee374a5f6d45ca70157e58113
SHA1: c5e6a5bdd203c23063db37d5db69bfd5e037d5d2
SHA256: 989348cc6d385629a3ccb735d450b0f0f022167cb702c2fcb0e6f2bdd989dde7
Evidence Type Source Name Value Confidence Vendor file name cyclonedx-core-java High Vendor jar package name bom Highest Vendor jar package name cyclonedx Highest Vendor jar package name model Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid cyclonedx-core-java Low Vendor pom developer name Alex Alzate Medium Vendor pom developer name Jeffry Hesse Medium Vendor pom developer name Steve Springett Medium Vendor pom developer org OWASP Medium Vendor pom developer org Sonatype Medium Vendor pom developer org URL https://www.owasp.org/ Medium Vendor pom developer org URL https://www.sonatype.org/ Medium Vendor pom groupid org.cyclonedx Highest Vendor pom name CycloneDX Core (Java) High Vendor pom organization name OWASP Foundation High Vendor pom organization url https://owasp.org/ Medium Vendor pom url CycloneDX/cyclonedx-core-java Highest Product file name cyclonedx-core-java High Product jar package name bom Highest Product jar package name cyclonedx Highest Product jar package name model Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid cyclonedx-core-java Highest Product pom developer name Alex Alzate Low Product pom developer name Jeffry Hesse Low Product pom developer name Steve Springett Low Product pom developer org OWASP Low Product pom developer org Sonatype Low Product pom developer org URL https://www.owasp.org/ Low Product pom developer org URL https://www.sonatype.org/ Low Product pom groupid org.cyclonedx Highest Product pom name CycloneDX Core (Java) High Product pom organization name OWASP Foundation Low Product pom organization url https://owasp.org/ Low Product pom url CycloneDX/cyclonedx-core-java High Version file version 11.0.1 High Version pom version 11.0.1 Highest
pkg:maven/org.cyclonedx/cyclonedx-core-java@11.0.1 (Confidence :High) cpe:2.3:a:alex_project:alex:11.0.1:*:*:*:*:*:*:* (Confidence :Low) suppress database-commons-1.21.3.jarDescription:
Isolated container management for Java code testing License:
MIT: http://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/testcontainers/database-commons/1.21.3/database-commons-1.21.3.jar
MD5: 697b592202716f05fd3db6ab5000313c
SHA1: 5c5a96de87527f78e1c5d9b82e9f265c89075883
SHA256: 61ad1b495dafa49b71f8de36082bc5baceb92dd00c62b941f467de419ac7548d
Evidence Type Source Name Value Confidence Vendor file name database-commons High Vendor jar package name ext Low Vendor jar package name testcontainers Highest Vendor jar package name testcontainers Low Vendor pom artifactid database-commons Low Vendor pom developer email rich.north@gmail.com Low Vendor pom developer id rnorth Medium Vendor pom developer name Richard North Medium Vendor pom groupid org.testcontainers Highest Vendor pom name Testcontainers :: Database-Commons High Vendor pom url https://java.testcontainers.org Highest Product file name database-commons High Product jar package name ext Low Product jar package name testcontainers Highest Product pom artifactid database-commons Highest Product pom developer email rich.north@gmail.com Low Product pom developer id rnorth Low Product pom developer name Richard North Low Product pom groupid org.testcontainers Highest Product pom name Testcontainers :: Database-Commons High Product pom url https://java.testcontainers.org Medium Version file version 1.21.3 High Version pom version 1.21.3 Highest
pkg:maven/org.testcontainers/database-commons@1.21.3 (Confidence :High) display.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/display/display.module.jsMD5: a1b933248db77a72363d2a88403d68d5SHA1: 79dbb5b8abbff4ed0a7984687e7ae9b7bf3463fbSHA256: 3f25c62b51b6df1e6a1cf8fac02f9eeaa67467b6efb1a1b8a22b383c52afef7f
Evidence Type Source Name Value Confidence
display.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/display/display.module.min.jsMD5: 34225197c6c9bd2d30448709ac7e6748SHA1: a315d7ff90339de06d5ae2294f2447cb7104e260SHA256: b7619623571a883cd4a04780643b247290a8246c0e2406ad7cef488c259690fd
Evidence Type Source Name Value Confidence
display.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/display/display.nomodule.jsMD5: fdf772346a22f6abcaa267b906c3dc2bSHA1: 855e5af3afe4223399f76fe25a033ec918e5202fSHA256: 84538c40b9f6985939fbeede8c9dbd87e81a37bdc501aa28a0d893d3ca569d5f
Evidence Type Source Name Value Confidence
display.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/display/display.nomodule.min.jsMD5: 7ac03fc1fe35e4d048f458046d64a08cSHA1: adfaded4f635283733b9e06cb6f8ea66276f18a5SHA256: 756236836e867e5c2422455379560405927a1b159632360ef48c72dc092a85ce
Evidence Type Source Name Value Confidence
docker-java-api-3.4.2.jarDescription:
Java API Client for Docker File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-api/3.4.2/docker-java-api-3.4.2.jarMD5: c68fca0735d2481b0fafc3dae09ab21bSHA1: 90aef34aa23575de51923c83771fbe378b2eb4e5SHA256: 6789d68f95904cf274a6410fdfcc5530976bc94197c856909459bb8c64db557b
Evidence Type Source Name Value Confidence Vendor file name docker-java-api High Vendor jar package name api Highest Vendor jar package name dockerjava Highest Vendor jar package name github Highest Vendor Manifest automatic-module-name com.github.dockerjava.api Medium Vendor pom artifactid docker-java-api Low Vendor pom groupid com.github.docker-java Highest Vendor pom name docker-java-api High Vendor pom parent-artifactid docker-java-parent Low Vendor pom url docker-java/docker-java Highest Product file name docker-java-api High Product jar package name api Highest Product jar package name dockerjava Highest Product jar package name github Highest Product Manifest automatic-module-name com.github.dockerjava.api Medium Product pom artifactid docker-java-api Highest Product pom groupid com.github.docker-java Highest Product pom name docker-java-api High Product pom parent-artifactid docker-java-parent Medium Product pom url docker-java/docker-java High Version file version 3.4.2 High Version pom version 3.4.2 Highest
pkg:maven/com.github.docker-java/docker-java-api@3.4.2 (Confidence :High) docker-java-transport-3.4.2.jarDescription:
Java API Client for Docker File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport/3.4.2/docker-java-transport-3.4.2.jarMD5: d56715a3bfdd8cf854809d369742e467SHA1: e70abb944ff1fe7c25fbcdecd31c732772a07a6eSHA256: bc9981224fdc2d4726566fc723470601ceb14378265c865b4c203146a4e39765
Evidence Type Source Name Value Confidence Vendor file name docker-java-transport High Vendor jar package name dockerjava Highest Vendor jar package name github Highest Vendor jar package name transport Highest Vendor Manifest automatic-module-name com.github.dockerjava.transport Medium Vendor pom artifactid docker-java-transport Low Vendor pom groupid com.github.docker-java Highest Vendor pom name docker-java-transport High Vendor pom parent-artifactid docker-java-parent Low Vendor pom url docker-java/docker-java Highest Product file name docker-java-transport High Product jar package name dockerjava Highest Product jar package name github Highest Product jar package name transport Highest Product Manifest automatic-module-name com.github.dockerjava.transport Medium Product pom artifactid docker-java-transport Highest Product pom groupid com.github.docker-java Highest Product pom name docker-java-transport High Product pom parent-artifactid docker-java-parent Medium Product pom url docker-java/docker-java High Version file version 3.4.2 High Version pom version 3.4.2 Highest
pkg:maven/com.github.docker-java/docker-java-transport@3.4.2 (Confidence :High) docker-java-transport-zerodep-3.4.2.jar (shaded: com.github.docker-java:docker-java-transport-httpclient5:3.4.2)Description:
Java API Client for Docker File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport-zerodep/3.4.2/docker-java-transport-zerodep-3.4.2.jar/META-INF/maven/com.github.docker-java/docker-java-transport-httpclient5/pom.xmlMD5: e78f5ecc64e3a6cb30e029a384f28c90SHA1: c6dc09835e90a45eb03aa7a9af355bcedb2713c6SHA256: 773bf7f5b0d6fe0464c8c4daf68745efbfb2bedbd187b6af7169e411ca10cdcd
Evidence Type Source Name Value Confidence Vendor pom artifactid docker-java-transport-httpclient5 Low Vendor pom groupid com.github.docker-java Highest Vendor pom name docker-java-transport-httpclient5 High Vendor pom parent-artifactid docker-java-parent Low Vendor pom url docker-java/docker-java Highest Product pom artifactid docker-java-transport-httpclient5 Highest Product pom groupid com.github.docker-java Highest Product pom name docker-java-transport-httpclient5 High Product pom parent-artifactid docker-java-parent Medium Product pom url docker-java/docker-java High Version pom version 3.4.2 Highest
pkg:maven/com.github.docker-java/docker-java-transport-httpclient5@3.4.2 (Confidence :High) docker-java-transport-zerodep-3.4.2.jar (shaded: commons-codec:commons-codec:1.13)Description:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport-zerodep/3.4.2/docker-java-transport-zerodep-3.4.2.jar/META-INF/maven/commons-codec/commons-codec/pom.xmlMD5: 2c1614eab362ed2249c8f4fdeee086a1SHA1: d3c2c675df030573f0d8b0e475e00d3a0f5235a4SHA256: c2e2a902d38230cf3031d0b434d5de2614fa0ff26d384b6d282aab56c7d3fc69
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version pom parent-version 1.13 Low Version pom version 1.13 Highest
pkg:maven/commons-codec/commons-codec@1.13 (Confidence :High) docker-java-transport-zerodep-3.4.2.jar (shaded: org.apache.httpcomponents.client5:httpclient5:5.0.3)Description:
Apache HttpComponents Client File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport-zerodep/3.4.2/docker-java-transport-zerodep-3.4.2.jar/META-INF/maven/org.apache.httpcomponents.client5/httpclient5/pom.xmlMD5: c94b77faf91a9f7f024f9a6a967be728SHA1: a12213238a7ca3964cb5cd99b5281759f0ba131eSHA256: d5fbcfdb6ce40a1978cbc58882aa68de19003d60a392582c9bf1ede53a91dd9d
Evidence Type Source Name Value Confidence Vendor pom artifactid httpclient5 Low Vendor pom groupid org.apache.httpcomponents.client5 Highest Vendor pom name Apache HttpClient High Vendor pom parent-artifactid httpclient5-parent Low Vendor pom url https://hc.apache.org/httpcomponents-client-5.0.x/ Highest Product pom artifactid httpclient5 Highest Product pom groupid org.apache.httpcomponents.client5 Highest Product pom name Apache HttpClient High Product pom parent-artifactid httpclient5-parent Medium Product pom url https://hc.apache.org/httpcomponents-client-5.0.x/ Medium Version pom version 5.0.3 Highest
docker-java-transport-zerodep-3.4.2.jar (shaded: org.apache.httpcomponents.core5:httpcore5-h2:5.0.2)Description:
Apache HttpComponents HTTP/2 Core Components File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport-zerodep/3.4.2/docker-java-transport-zerodep-3.4.2.jar/META-INF/maven/org.apache.httpcomponents.core5/httpcore5-h2/pom.xmlMD5: d4c87e7b260bcbec7ef2f1a2db63a7faSHA1: 5386c5d3b3084e16dde704f62cb1c9bf01abab0dSHA256: f2707a828006f8970fc07d80247bbaa0059e8d8c1b8d0c57be44db8ed51c9766
Evidence Type Source Name Value Confidence Vendor pom artifactid httpcore5-h2 Low Vendor pom groupid org.apache.httpcomponents.core5 Highest Vendor pom name Apache HttpComponents Core HTTP/2 High Vendor pom parent-artifactid httpcore5-parent Low Vendor pom url https://hc.apache.org/httpcomponents-core-5.0.x/ Highest Product pom artifactid httpcore5-h2 Highest Product pom groupid org.apache.httpcomponents.core5 Highest Product pom name Apache HttpComponents Core HTTP/2 High Product pom parent-artifactid httpcore5-parent Medium Product pom url https://hc.apache.org/httpcomponents-core-5.0.x/ Medium Version pom version 5.0.2 Highest
pkg:maven/org.apache.httpcomponents.core5/httpcore5-h2@5.0.2 (Confidence :High) docker-java-transport-zerodep-3.4.2.jar (shaded: org.apache.httpcomponents.core5:httpcore5:5.0.2)Description:
Apache HttpComponents HTTP/1.1 core components File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport-zerodep/3.4.2/docker-java-transport-zerodep-3.4.2.jar/META-INF/maven/org.apache.httpcomponents.core5/httpcore5/pom.xmlMD5: f43777cdf47a449ea3affab520e15896SHA1: 95e749187b7b3a50390fa239185b50cf8669d743SHA256: 8da9695a3afcef528f3dc79fc9a34f4a72c870e7c702a9a42ac7dc8beb912f2f
Evidence Type Source Name Value Confidence Vendor pom artifactid httpcore5 Low Vendor pom groupid org.apache.httpcomponents.core5 Highest Vendor pom name Apache HttpComponents Core HTTP/1.1 High Vendor pom parent-artifactid httpcore5-parent Low Vendor pom url https://hc.apache.org/httpcomponents-core-5.0.x/ Highest Product pom artifactid httpcore5 Highest Product pom groupid org.apache.httpcomponents.core5 Highest Product pom name Apache HttpComponents Core HTTP/1.1 High Product pom parent-artifactid httpcore5-parent Medium Product pom url https://hc.apache.org/httpcomponents-core-5.0.x/ Medium Version pom version 5.0.2 Highest
pkg:maven/org.apache.httpcomponents.core5/httpcore5@5.0.2 (Confidence :High) docker-java-transport-zerodep-3.4.2.jarDescription:
Java API Client for Docker File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/docker-java/docker-java-transport-zerodep/3.4.2/docker-java-transport-zerodep-3.4.2.jarMD5: 1e5e8b565518b6544fe62aecbbcf580eSHA1: 784b535b8e294e699032abead0687b6773761e34SHA256: 582b772e0c52fa9d24710617ef610655465edd9a2930b0db75fc8667d6a8d02b
Evidence Type Source Name Value Confidence Vendor file name docker-java-transport-zerodep High Vendor jar package name dockerjava Highest Vendor jar package name github Highest Vendor jar package name zerodep Highest Vendor Manifest automatic-module-name com.github.dockerjava.transport.zerodep Medium Vendor pom artifactid docker-java-transport-zerodep Low Vendor pom groupid com.github.docker-java Highest Vendor pom name docker-java-transport-zerodep High Vendor pom parent-artifactid docker-java-parent Low Vendor pom url docker-java/docker-java Highest Product file name docker-java-transport-zerodep High Product jar package name dockerjava Highest Product jar package name github Highest Product jar package name zerodep Highest Product Manifest automatic-module-name com.github.dockerjava.transport.zerodep Medium Product pom artifactid docker-java-transport-zerodep Highest Product pom groupid com.github.docker-java Highest Product pom name docker-java-transport-zerodep High Product pom parent-artifactid docker-java-parent Medium Product pom url docker-java/docker-java High Version file version 3.4.2 High Version pom version 3.4.2 Highest
pkg:maven/com.github.docker-java/docker-java-transport-zerodep@3.4.2 (Confidence :High) doxia-sink-api-1.0.jarDescription:
Doxia Sink API. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/doxia/doxia-sink-api/1.0/doxia-sink-api-1.0.jarMD5: 04067d1b5c9ac4447fd376632b13fba0SHA1: 13f502f2fb1d4e2db6f19352c85b83277084bb98SHA256: 1cd68e9b4cf427a2b6b9a943a9bef6da879d25702334ea5addb0d153bb8f8911
Evidence Type Source Name Value Confidence Vendor file name doxia-sink-api High Vendor jar package name apache Highest Vendor jar package name doxia Highest Vendor jar package name maven Highest Vendor jar package name sink Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.doxia Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid doxia-sink-api Low Vendor pom groupid org.apache.maven.doxia Highest Vendor pom name Doxia :: Sink API High Vendor pom parent-artifactid doxia Low Product file name doxia-sink-api High Product jar package name apache Highest Product jar package name doxia Highest Product jar package name maven Highest Product jar package name sink Highest Product Manifest Implementation-Title Doxia :: Sink API High Product Manifest specification-title Doxia :: Sink API Medium Product pom artifactid doxia-sink-api Highest Product pom groupid org.apache.maven.doxia Highest Product pom name Doxia :: Sink API High Product pom parent-artifactid doxia Medium Version file version 1.0 High Version Manifest Implementation-Version 1.0 High Version pom version 1.0 Highest
pkg:maven/org.apache.maven.doxia/doxia-sink-api@1.0 (Confidence :High) dsfr.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/dsfr.module.jsMD5: a09259695e47bd2d64ec218c319648dfSHA1: 06f68f0f5afd43aab7b92fd0f57254ecb79b798bSHA256: 13ec028be35b98d46f4f15413070340a6a999331e2fe3dfe29e7ce19f01107a6
Evidence Type Source Name Value Confidence
Related Dependencies dsfr.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/dsfr/dsfr.module.js MD5: a09259695e47bd2d64ec218c319648df SHA1: 06f68f0f5afd43aab7b92fd0f57254ecb79b798b SHA256: 13ec028be35b98d46f4f15413070340a6a999331e2fe3dfe29e7ce19f01107a6 dsfr.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/dsfr/dsfr.module.min.jsMD5: c39f3bbf2f0ba94255f3af82f192a8d7SHA1: df99ebb14023cf310e8fc7846eee66aba6e6a76fSHA256: ee6948420b883371725d6b424e1cd3fddc7524643ff6d6f9919ab5e58797d058
Evidence Type Source Name Value Confidence
dsfr.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/dsfr.nomodule.jsMD5: 29f3cad3c418c5eac097e79568323601SHA1: 01262d8d58acd6e71a29c228f1bade712ded2b7bSHA256: 586164e3a862fd1a94618e10441fa76d7ee187a2e462c44809eb4a00a4fe3cde
Evidence Type Source Name Value Confidence
Related Dependencies dsfr.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/dsfr/dsfr.nomodule.js MD5: 29f3cad3c418c5eac097e79568323601 SHA1: 01262d8d58acd6e71a29c228f1bade712ded2b7b SHA256: 586164e3a862fd1a94618e10441fa76d7ee187a2e462c44809eb4a00a4fe3cde dsfr.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/dsfr/dsfr.nomodule.min.jsMD5: a77da9a6186851e378a7cdfe5a5b07fcSHA1: 508906aa8f581926cf95fb0a4d136bd64a1f043eSHA256: 1b52d96bc7c831ea333f9adb43dd80a37596da42a74af1b0d56f1afd0a985446
Evidence Type Source Name Value Confidence
duct-tape-1.0.8.jarDescription:
General purpose resilience utilities for Java 8 (circuit breakers, timeouts, rate limiters, and handlers for unreliable or inconsistent results)
License:
MIT: http://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/rnorth/duct-tape/duct-tape/1.0.8/duct-tape-1.0.8.jar
MD5: af347a22d19d632616d7a3fb63024218
SHA1: 92edc22a9ab2f3e17c9bf700aaee377d50e8b530
SHA256: 31cef12ddec979d1f86d7cf708c41a17da523d05c685fd6642e9d0b2addb7240
Evidence Type Source Name Value Confidence Vendor file name duct-tape High Vendor jar package name ducttape Low Vendor jar package name rnorth Highest Vendor jar package name rnorth Low Vendor jar package name timeouts Highest Vendor pom artifactid duct-tape Low Vendor pom developer email rich.north@gmail.com Low Vendor pom developer id rnorth Medium Vendor pom developer name Richard North Medium Vendor pom groupid org.rnorth.duct-tape Highest Vendor pom name Duct Tape High Vendor pom url rnorth/ Highest Vendor pom url rnorth/${project.artifactId} Highest Product file name duct-tape High Product jar package name ducttape Low Product jar package name rnorth Highest Product jar package name timeouts Highest Product pom artifactid duct-tape Highest Product pom developer email rich.north@gmail.com Low Product pom developer id rnorth Low Product pom developer name Richard North Low Product pom groupid org.rnorth.duct-tape Highest Product pom name Duct Tape High Product pom url rnorth/ High Product pom url rnorth/${project.artifactId} High Version file version 1.0.8 High Version pom version 1.0.8 Highest
pkg:maven/org.rnorth.duct-tape/duct-tape@1.0.8 (Confidence :High) file-management-3.1.0.jarDescription:
API to collect files from a given directory using several include/exclude rules. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/shared/file-management/3.1.0/file-management-3.1.0.jarMD5: 94be12af3d234da86b130cb297234befSHA1: f87a3a54c856714e4157b9ce7a5ff6ffc310d447SHA256: 2e8cb2d546a01c2259cb17f1e06732db3d14b079d19622bf8400c82cb1ee6b96
Evidence Type Source Name Value Confidence Vendor file name file-management High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid file-management Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven File Management API High Vendor pom parent-artifactid maven-shared-components Low Product file name file-management High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven File Management API High Product Manifest specification-title Apache Maven File Management API Medium Product pom artifactid file-management Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven File Management API High Product pom parent-artifactid maven-shared-components Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
pkg:maven/org.apache.maven.shared/file-management@3.1.0 (Confidence :High) freemarker-2.3.34.jarDescription:
FreeMarker is a "template engine"; a generic tool to generate text output based on templates.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/freemarker/freemarker/2.3.34/freemarker-2.3.34.jar
MD5: 1704fd3c579385ca5fd0ebcdf50df73c
SHA1: c2fa47a1c3b6dcdfca90e952e51211967a4baa54
SHA256: 9a9fb91cd64199232eb1ca9766148a5d30ef8944be5fac051018f96c70c8f6a3
Evidence Type Source Name Value Confidence Vendor file name freemarker High Vendor jar package name freemarker Highest Vendor jar package name on Highest Vendor jar package name template Highest Vendor Manifest automatic-module-name freemarker Medium Vendor Manifest bundle-requiredexecutionenvironment JavaSE-16, JavaSE-15, JavaSE-14, JavaSE-13, JavaSE-12, JavaSE-11, JavaSE-10, JavaSE-9, JavaSE-1.8 Low Vendor Manifest bundle-symbolicname org.freemarker.freemarker Medium Vendor Manifest extension-name FreeMarker Medium Vendor Manifest Implementation-Vendor freemarker.org High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor freemarker.org Low Vendor pom artifactid freemarker Low Vendor pom groupid org.freemarker Highest Vendor pom name Apache FreeMarker High Vendor pom organization name Apache Software Foundation High Vendor pom organization url http://apache.org Medium Vendor pom url https://freemarker.apache.org/ Highest Product file name freemarker High Product jar package name 16 Highest Product jar package name 9 Highest Product jar package name freemarker Highest Product jar package name on Highest Product jar package name template Highest Product Manifest automatic-module-name freemarker Medium Product Manifest Bundle-Name org.freemarker.freemarker Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-16, JavaSE-15, JavaSE-14, JavaSE-13, JavaSE-12, JavaSE-11, JavaSE-10, JavaSE-9, JavaSE-1.8 Low Product Manifest bundle-symbolicname org.freemarker.freemarker Medium Product Manifest extension-name FreeMarker Medium Product Manifest Implementation-Title FreeMarker High Product Manifest multi-release true Low Product Manifest specification-title FreeMarker Medium Product pom artifactid freemarker Highest Product pom groupid org.freemarker Highest Product pom name Apache FreeMarker High Product pom organization name Apache Software Foundation Low Product pom organization url http://apache.org Low Product pom url https://freemarker.apache.org/ Medium Version file version 2.3.34 High Version Manifest Implementation-Version 2.3.34 High Version pom version 2.3.34 Highest
pkg:maven/org.freemarker/freemarker@2.3.34 (Confidence :High) generated-bytecode.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/quarkus/generated-bytecode.jarMD5: b6c4d3a122a5060307932327b4658074SHA1: c66021e0a09be46f95207b624cfe1ef523b6ae9cSHA256: 3413663ad02af42f0ceda0eb8f0786b85f9019b3f44a241dc60d4f68d68f1a7e
Evidence Type Source Name Value Confidence Vendor file name generated-bytecode High Vendor jar package name io Low Vendor jar package name quarkus Low Product file name generated-bytecode High Product jar package name quarkus Low
generated-bytecode.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/quarkus/generated-bytecode.jarMD5: c9b6b945f874b635b14a35c494e4168cSHA1: 6eb6fa1d18f5441d6edaf949ee0f8205b20fb773SHA256: c5f3e5850f0cf4b2d3e0d3a01a93c0cf33ca582178a43e56c2068f9161dfd1c8
Evidence Type Source Name Value Confidence Vendor file name generated-bytecode High Vendor jar package name io Low Vendor jar package name quarkus Low Product file name generated-bytecode High Product jar package name quarkus Low
gizmo-1.9.0.jarDescription:
A bytecode generation library.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/gizmo/gizmo/1.9.0/gizmo-1.9.0.jar
MD5: 2babcc5a125fabca13d5d698792a3e52
SHA1: aee1682be59ead4282ef547839d05b855175f0c2
SHA256: 6d463d670ea45cb9a8241e99dd02c7e422d9982a2ff6e8623d338ac2a6c892b1
Evidence Type Source Name Value Confidence Vendor file name gizmo High Vendor hint analyzer vendor redhat Highest Vendor jar package name gizmo Highest Vendor jar package name io Highest Vendor jar package name quarkus Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid gizmo Low Vendor pom groupid io.quarkus.gizmo Highest Vendor pom name Gizmo High Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Product file name gizmo High Product jar package name gizmo Highest Product jar package name io Highest Product jar package name quarkus Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Gizmo High Product Manifest implementation-url http://www.jboss.org Low Product Manifest specification-title Gizmo Medium Product pom artifactid gizmo Highest Product pom groupid io.quarkus.gizmo Highest Product pom name Gizmo High Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Version file version 1.9.0 High Version Manifest Implementation-Version 1.9.0 High Version pom parent-version 1.9.0 Low Version pom version 1.9.0 Highest
pkg:maven/io.quarkus.gizmo/gizmo@1.9.0 (Confidence :High) gizmo2-2.0.0.Beta10.jarDescription:
A bytecode generation convenience library License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/gizmo/gizmo2/2.0.0.Beta10/gizmo2-2.0.0.Beta10.jar
MD5: c5935f1cd67508a5a3f4fe7df3cf0bf3
SHA1: 2430d5034a1d59b12f66e80df782a5ceee90c664
SHA256: 288c4c2255268d9ac374fe582fd840a8361fd1c4414b2bd266cc9fb60b0a1538
Evidence Type Source Name Value Confidence Vendor file name gizmo2 High Vendor hint analyzer vendor redhat Highest Vendor jar package name gizmo Highest Vendor jar package name gizmo2 Highest Vendor jar package name io Highest Vendor jar package name quarkus Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid gizmo2 Low Vendor pom groupid io.quarkus.gizmo Highest Vendor pom name Gizmo High Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Product file name gizmo2 High Product jar package name gizmo Highest Product jar package name gizmo2 Highest Product jar package name io Highest Product jar package name quarkus Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Gizmo High Product Manifest implementation-url http://www.jboss.org Low Product Manifest specification-title Gizmo Medium Product pom artifactid gizmo2 Highest Product pom groupid io.quarkus.gizmo Highest Product pom name Gizmo High Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Version Manifest Implementation-Version 2.0.0.Beta10 High Version pom parent-version 2.0.0.Beta10 Low Version pom version 2.0.0.Beta10 Highest
pkg:maven/io.quarkus.gizmo/gizmo2@2.0.0.Beta10 (Confidence :High) google-auth-library-credentials-1.10.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/auth/google-auth-library-credentials/1.10.0/google-auth-library-credentials-1.10.0.jarMD5: c41dbaccb8d4c155ae8e2961ad22f26aSHA1: ca4b2f754fa3abfcb57a3f8e56b153a2277d00b2SHA256: 7ba26f607ab1b2dffb0d4d8b2c7efe1ab6cb3ff5d5a7991cee6e6e484d0c7b9c
Evidence Type Source Name Value Confidence Vendor file name google-auth-library-credentials High Vendor jar package name auth Highest Vendor jar package name credentials Highest Vendor jar package name google Highest Vendor Manifest automatic-module-name com.google.auth Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid google-auth-library-credentials Low Vendor pom groupid com.google.auth Highest Vendor pom name Google Auth Library for Java - Credentials High Vendor pom parent-artifactid google-auth-library-parent Low Product file name google-auth-library-credentials High Product jar package name auth Highest Product jar package name credentials Highest Product jar package name google Highest Product Manifest automatic-module-name com.google.auth Medium Product Manifest build-jdk-spec 1.8 Low Product pom artifactid google-auth-library-credentials Highest Product pom groupid com.google.auth Highest Product pom name Google Auth Library for Java - Credentials High Product pom parent-artifactid google-auth-library-parent Medium Version file version 1.10.0 High Version pom version 1.10.0 Highest
pkg:maven/com.google.auth/google-auth-library-credentials@1.10.0 (Confidence :High) google-auth-library-oauth2-http-1.10.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/auth/google-auth-library-oauth2-http/1.10.0/google-auth-library-oauth2-http-1.10.0.jarMD5: 3059c63004e1344eb648bb8fc0d5e1f0SHA1: 4eb85f801b8424f9ba440a8520023e390135658cSHA256: 99463bcfee2925c9198d2788d9e639511db95640ad7335f3f760af3fba617e28
Evidence Type Source Name Value Confidence Vendor file name google-auth-library-oauth2-http High Vendor jar package name auth Highest Vendor jar package name google Highest Vendor jar package name http Highest Vendor jar package name oauth2 Highest Vendor Manifest automatic-module-name com.google.auth.oauth2 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid google-auth-library-oauth2-http Low Vendor pom groupid com.google.auth Highest Vendor pom name Google Auth Library for Java - OAuth2 HTTP High Vendor pom parent-artifactid google-auth-library-parent Low Product file name google-auth-library-oauth2-http High Product jar package name auth Highest Product jar package name google Highest Product jar package name http Highest Product jar package name oauth2 Highest Product Manifest automatic-module-name com.google.auth.oauth2 Medium Product Manifest build-jdk-spec 1.8 Low Product pom artifactid google-auth-library-oauth2-http Highest Product pom groupid com.google.auth Highest Product pom name Google Auth Library for Java - OAuth2 HTTP High Product pom parent-artifactid google-auth-library-parent Medium Version file version 1.10.0 High Version pom version 1.10.0 Highest
pkg:maven/com.google.auth/google-auth-library-oauth2-http@1.10.0 (Confidence :High) google-http-client-1.47.1.jarDescription:
Google HTTP Client Library for Java. Functionality that works on all supported Java platforms,
including Java 7 (or higher) desktop (SE) and web (EE), Android, and Google App Engine.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/http-client/google-http-client/1.47.1/google-http-client-1.47.1.jar
MD5: 9e817392d5af0068fc9d95af610dfdea
SHA1: eabad78d440226732a453d6a300663a9770f5b7e
SHA256: 22447fde9f2e33e27a23a25953b1c622ead6c055c761fde6ca50573c9473457a
Evidence Type Source Name Value Confidence Vendor file name google-http-client High Vendor jar package name api Highest Vendor jar package name client Highest Vendor jar package name google Highest Vendor jar package name http Highest Vendor Manifest automatic-module-name com.google.api.client Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://www.google.com/ Low Vendor Manifest bundle-symbolicname com.google.http-client.google-http-client Medium Vendor Manifest Implementation-Vendor Google High Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor pom artifactid google-http-client Low Vendor pom groupid com.google.http-client Highest Vendor pom name Google HTTP Client Library for Java High Vendor pom parent-artifactid google-http-client-parent Low Product file name google-http-client High Product jar package name api Highest Product jar package name client Highest Product jar package name google Highest Product jar package name http Highest Product Manifest automatic-module-name com.google.api.client Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://www.google.com/ Low Product Manifest Bundle-Name Google HTTP Client Library for Java Medium Product Manifest bundle-symbolicname com.google.http-client.google-http-client Medium Product Manifest Implementation-Title Google HTTP Client Library for Java High Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product pom artifactid google-http-client Highest Product pom groupid com.google.http-client Highest Product pom name Google HTTP Client Library for Java High Product pom parent-artifactid google-http-client-parent Medium Version file version 1.47.1 High Version Manifest Bundle-Version 1.47.1 High Version Manifest Implementation-Version 1.47.1 High Version pom version 1.47.1 Highest
pkg:maven/com.google.http-client/google-http-client@1.47.1 (Confidence :High) google-http-client-apache-v2-1.47.1.jarDescription:
Google HTTP Client Library for Java License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/http-client/google-http-client-apache-v2/1.47.1/google-http-client-apache-v2-1.47.1.jar
MD5: a4aeac848b1f21a2c22349114b31916f
SHA1: c2d3b75281146585f984b338bd81ce2b1ec8be32
SHA256: e6a8be28ce3b8dd4296ac05770d9e532727272f2666a4a3d25639cc8e11157d5
Evidence Type Source Name Value Confidence Vendor file name google-http-client-apache-v2 High Vendor jar package name api Highest Vendor jar package name client Highest Vendor jar package name google Highest Vendor jar package name http Highest Vendor Manifest automatic-module-name com.google.api.client.http.apache.v2 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://www.google.com/ Low Vendor Manifest bundle-symbolicname com.google.http-client.google-http-client-apache-v2 Medium Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor pom artifactid google-http-client-apache-v2 Low Vendor pom groupid com.google.http-client Highest Vendor pom name Apache HTTP transport v2 for the Google HTTP Client Library for Java. High Vendor pom parent-artifactid google-http-client-parent Low Product file name google-http-client-apache-v2 High Product jar package name api Highest Product jar package name client Highest Product jar package name google Highest Product jar package name http Highest Product Manifest automatic-module-name com.google.api.client.http.apache.v2 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://www.google.com/ Low Product Manifest Bundle-Name Apache HTTP transport v2 for the Google HTTP Client Library for Java. Medium Product Manifest bundle-symbolicname com.google.http-client.google-http-client-apache-v2 Medium Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product pom artifactid google-http-client-apache-v2 Highest Product pom groupid com.google.http-client Highest Product pom name Apache HTTP transport v2 for the Google HTTP Client Library for Java. High Product pom parent-artifactid google-http-client-parent Medium Version file version 1.47.1 High Version Manifest Bundle-Version 1.47.1 High Version pom version 1.47.1 Highest
pkg:maven/com.google.http-client/google-http-client-apache-v2@1.47.1 (Confidence :High) google-http-client-gson-1.47.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/http-client/google-http-client-gson/1.47.1/google-http-client-gson-1.47.1.jarMD5: 4f8c574f2c7d9ae7ddd8873febf1ff79SHA1: 04331c43544544d60df28055c295949e22ba60a4SHA256: 64ac2b1313dca6b6fc9bd14128ab186528fe992b094f5371fa7f828eed8903bd
Evidence Type Source Name Value Confidence Vendor file name google-http-client-gson High Vendor jar package name api Highest Vendor jar package name client Highest Vendor jar package name google Highest Vendor jar package name json Highest Vendor Manifest automatic-module-name com.google.api.client.json.gson Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid google-http-client-gson Low Vendor pom groupid com.google.http-client Highest Vendor pom name GSON extensions to the Google HTTP Client Library for Java. High Vendor pom parent-artifactid google-http-client-parent Low Product file name google-http-client-gson High Product jar package name api Highest Product jar package name client Highest Product jar package name google Highest Product jar package name json Highest Product Manifest automatic-module-name com.google.api.client.json.gson Medium Product Manifest build-jdk-spec 1.8 Low Product pom artifactid google-http-client-gson Highest Product pom groupid com.google.http-client Highest Product pom name GSON extensions to the Google HTTP Client Library for Java. High Product pom parent-artifactid google-http-client-parent Medium Version file version 1.47.1 High Version pom version 1.47.1 Highest
pkg:maven/com.google.http-client/google-http-client-gson@1.47.1 (Confidence :High) groovy-4.0.22.jarDescription:
Groovy: A powerful multi-faceted language for the JVM License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/groovy/groovy/4.0.22/groovy-4.0.22.jar
MD5: b527c6bfa1af469f1a4374e9fc6de4bf
SHA1: a04df669ad2778678072315bc92f10f03362e7d7
SHA256: f9d8bd4d65852c18194e353c77f3d2c23e0013856951c5430ba56972d2f67a1e
Evidence Type Source Name Value Confidence Vendor file name groovy High Vendor jar package name apache Highest Vendor jar package name groovy Highest Vendor Manifest automatic-module-name org.apache.groovy Medium Vendor Manifest bundle-symbolicname groovy Medium Vendor Manifest eclipse-buddypolicy dependent Low Vendor Manifest eclipse-extensibleapi true Low Vendor Manifest extension-name groovy Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid groovy Low Vendor pom developer email aalmiray@users.sourceforge.net Low Vendor pom developer email b55r@sina.com Low Vendor pom developer email blackdrag@gmx.org Low Vendor pom developer email bob@werken.com Low Vendor pom developer email cedric.champeau@gmail.com Low Vendor pom developer email ckl@dacelo.nl Low Vendor pom developer email cpoirier@dreaming.org Low Vendor pom developer email goetze@dovetail.com Low Vendor pom developer email guillaume.alleon@gmail.com Low Vendor pom developer email hamletdrc@gmail.com Low Vendor pom developer email james@coredevelopers.com Low Vendor pom developer email jason@planet57.com Low Vendor pom developer email jeremy.rayner@gmail.com Low Vendor pom developer email jim@pagesmiths.com Low Vendor pom developer email johnstump2@yahoo.com Low Vendor pom developer email mguillemot@yahoo.fr Low Vendor pom developer email paulk@asert.com.au Low Vendor pom developer email phkim@cluecom.co.kr Low Vendor pom developer email pniederw@gmail.com Low Vendor pom developer email russel@winder.org.uk Low Vendor pom developer email sam@sampullara.com Low Vendor pom developer email sormuras@gmx.de Low Vendor pom developer email tug@wilson.co.uk Low Vendor pom developer id aalmiray Medium Vendor pom developer id alextkachman Medium Vendor pom developer id andresteingress Medium Vendor pom developer id blackdrag Medium Vendor pom developer id bob Medium Vendor pom developer id bran Medium Vendor pom developer id ckl Medium Vendor pom developer id cpoirier Medium Vendor pom developer id cstein Medium Vendor pom developer id emilles Medium Vendor pom developer id galleon Medium Vendor pom developer id glaforge Medium Vendor pom developer id goetze Medium Vendor pom developer id grocher Medium Vendor pom developer id hamletdrc Medium Vendor pom developer id jamiemc Medium Vendor pom developer id jez Medium Vendor pom developer id jimwhite Medium Vendor pom developer id joe Medium Vendor pom developer id jstrachan Medium Vendor pom developer id jstump Medium Vendor pom developer id jwill Medium Vendor pom developer id jwilson Medium Vendor pom developer id kasper Medium Vendor pom developer id mattf Medium Vendor pom developer id melix Medium Vendor pom developer id mguillem Medium Vendor pom developer id mittie Medium Vendor pom developer id pascalschumacher Medium Vendor pom developer id paulk Medium Vendor pom developer id phk Medium Vendor pom developer id pniederw Medium Vendor pom developer id roshandawrani Medium Vendor pom developer id rpopma Medium Vendor pom developer id russel Medium Vendor pom developer id shemnon Medium Vendor pom developer id skizz Medium Vendor pom developer id spullara Medium Vendor pom developer id sunlan Medium Vendor pom developer id timyates Medium Vendor pom developer id travis Medium Vendor pom developer id user57 Medium Vendor pom developer id zohar Medium Vendor pom developer name Alex Tkachman Medium Vendor pom developer name Andre Steingress Medium Vendor pom developer name Andres Almiray Medium Vendor pom developer name Bing Ran Medium Vendor pom developer name bob mcwhirter Medium Vendor pom developer name Cedric Champeau Medium Vendor pom developer name Chris Poirier Medium Vendor pom developer name Chris Stevenson Medium Vendor pom developer name Christiaan ten Klooster Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Daniel Sun Medium Vendor pom developer name Danno Ferrin Medium Vendor pom developer name Dierk Koenig Medium Vendor pom developer name Eric Milles Medium Vendor pom developer name Graeme Rocher Medium Vendor pom developer name Guillaume Alleon Medium Vendor pom developer name Guillaume Laforge Medium Vendor pom developer name Hamlet D'Arcy Medium Vendor pom developer name James Strachan Medium Vendor pom developer name James Williams Medium Vendor pom developer name Jamie McCrindle Medium Vendor pom developer name Jason Dillon Medium Vendor pom developer name Jeremy Rayner Medium Vendor pom developer name Jim White Medium Vendor pom developer name Jochen Theodorou Medium Vendor pom developer name Joe Walnes Medium Vendor pom developer name John Stump Medium Vendor pom developer name John Wilson Medium Vendor pom developer name Kasper Nielsen Medium Vendor pom developer name Marc Guillemot Medium Vendor pom developer name Matt Foemmel Medium Vendor pom developer name Pascal Schumacher Medium Vendor pom developer name Paul King Medium Vendor pom developer name Peter Niederwieser Medium Vendor pom developer name Pilho Kim Medium Vendor pom developer name Remko Popma Medium Vendor pom developer name Roshan Dawrani Medium Vendor pom developer name Russel Winder Medium Vendor pom developer name Sam Pullara Medium Vendor pom developer name Steve Goetze Medium Vendor pom developer name Tim Yates Medium Vendor pom developer name Travis Kay Medium Vendor pom developer name Zohar Melamed Medium Vendor pom developer org Concertant LLP & It'z Interactive Ltd Medium Vendor pom developer org Core Developers Network Medium Vendor pom developer org CTSR.de Medium Vendor pom developer org Dacelo WebDevelopment Medium Vendor pom developer org Dovetailed Technologies, LLC Medium Vendor pom developer org Google Medium Vendor pom developer org IFCX.org Medium Vendor pom developer org javanicus Medium Vendor pom developer org Karakun AG Medium Vendor pom developer org Leadingcare Medium Vendor pom developer org OCI, Australia Medium Vendor pom developer org The Werken Company Medium Vendor pom developer org The Wilson Partnership Medium Vendor pom developer org Thomson Reuters Medium Vendor pom developer org ThoughtWorks Medium Vendor pom developer org Three Medium Vendor pom groupid org.apache.groovy Highest Vendor pom name Apache Groovy High Vendor pom organization name Apache Software Foundation High Vendor pom organization url https://apache.org Medium Vendor pom url https://groovy-lang.org Highest Product file name groovy High Product jar package name apache Highest Product jar package name groovy Highest Product jar package name runtime Highest Product Manifest automatic-module-name org.apache.groovy Medium Product Manifest Bundle-Name Groovy module: groovy Medium Product Manifest bundle-symbolicname groovy Medium Product Manifest eclipse-buddypolicy dependent Low Product Manifest eclipse-extensibleapi true Low Product Manifest extension-name groovy Medium Product Manifest Implementation-Title Groovy: a powerful, multi-faceted language for the JVM High Product Manifest specification-title Groovy: a powerful, multi-faceted language for the JVM Medium Product pom artifactid groovy Highest Product pom developer email aalmiray@users.sourceforge.net Low Product pom developer email b55r@sina.com Low Product pom developer email blackdrag@gmx.org Low Product pom developer email bob@werken.com Low Product pom developer email cedric.champeau@gmail.com Low Product pom developer email ckl@dacelo.nl Low Product pom developer email cpoirier@dreaming.org Low Product pom developer email goetze@dovetail.com Low Product pom developer email guillaume.alleon@gmail.com Low Product pom developer email hamletdrc@gmail.com Low Product pom developer email james@coredevelopers.com Low Product pom developer email jason@planet57.com Low Product pom developer email jeremy.rayner@gmail.com Low Product pom developer email jim@pagesmiths.com Low Product pom developer email johnstump2@yahoo.com Low Product pom developer email mguillemot@yahoo.fr Low Product pom developer email paulk@asert.com.au Low Product pom developer email phkim@cluecom.co.kr Low Product pom developer email pniederw@gmail.com Low Product pom developer email russel@winder.org.uk Low Product pom developer email sam@sampullara.com Low Product pom developer email sormuras@gmx.de Low Product pom developer email tug@wilson.co.uk Low Product pom developer id aalmiray Low Product pom developer id alextkachman Low Product pom developer id andresteingress Low Product pom developer id blackdrag Low Product pom developer id bob Low Product pom developer id bran Low Product pom developer id ckl Low Product pom developer id cpoirier Low Product pom developer id cstein Low Product pom developer id emilles Low Product pom developer id galleon Low Product pom developer id glaforge Low Product pom developer id goetze Low Product pom developer id grocher Low Product pom developer id hamletdrc Low Product pom developer id jamiemc Low Product pom developer id jez Low Product pom developer id jimwhite Low Product pom developer id joe Low Product pom developer id jstrachan Low Product pom developer id jstump Low Product pom developer id jwill Low Product pom developer id jwilson Low Product pom developer id kasper Low Product pom developer id mattf Low Product pom developer id melix Low Product pom developer id mguillem Low Product pom developer id mittie Low Product pom developer id pascalschumacher Low Product pom developer id paulk Low Product pom developer id phk Low Product pom developer id pniederw Low Product pom developer id roshandawrani Low Product pom developer id rpopma Low Product pom developer id russel Low Product pom developer id shemnon Low Product pom developer id skizz Low Product pom developer id spullara Low Product pom developer id sunlan Low Product pom developer id timyates Low Product pom developer id travis Low Product pom developer id user57 Low Product pom developer id zohar Low Product pom developer name Alex Tkachman Low Product pom developer name Andre Steingress Low Product pom developer name Andres Almiray Low Product pom developer name Bing Ran Low Product pom developer name bob mcwhirter Low Product pom developer name Cedric Champeau Low Product pom developer name Chris Poirier Low Product pom developer name Chris Stevenson Low Product pom developer name Christiaan ten Klooster Low Product pom developer name Christian Stein Low Product pom developer name Daniel Sun Low Product pom developer name Danno Ferrin Low Product pom developer name Dierk Koenig Low Product pom developer name Eric Milles Low Product pom developer name Graeme Rocher Low Product pom developer name Guillaume Alleon Low Product pom developer name Guillaume Laforge Low Product pom developer name Hamlet D'Arcy Low Product pom developer name James Strachan Low Product pom developer name James Williams Low Product pom developer name Jamie McCrindle Low Product pom developer name Jason Dillon Low Product pom developer name Jeremy Rayner Low Product pom developer name Jim White Low Product pom developer name Jochen Theodorou Low Product pom developer name Joe Walnes Low Product pom developer name John Stump Low Product pom developer name John Wilson Low Product pom developer name Kasper Nielsen Low Product pom developer name Marc Guillemot Low Product pom developer name Matt Foemmel Low Product pom developer name Pascal Schumacher Low Product pom developer name Paul King Low Product pom developer name Peter Niederwieser Low Product pom developer name Pilho Kim Low Product pom developer name Remko Popma Low Product pom developer name Roshan Dawrani Low Product pom developer name Russel Winder Low Product pom developer name Sam Pullara Low Product pom developer name Steve Goetze Low Product pom developer name Tim Yates Low Product pom developer name Travis Kay Low Product pom developer name Zohar Melamed Low Product pom developer org Concertant LLP & It'z Interactive Ltd Low Product pom developer org Core Developers Network Low Product pom developer org CTSR.de Low Product pom developer org Dacelo WebDevelopment Low Product pom developer org Dovetailed Technologies, LLC Low Product pom developer org Google Low Product pom developer org IFCX.org Low Product pom developer org javanicus Low Product pom developer org Karakun AG Low Product pom developer org Leadingcare Low Product pom developer org OCI, Australia Low Product pom developer org The Werken Company Low Product pom developer org The Wilson Partnership Low Product pom developer org Thomson Reuters Low Product pom developer org ThoughtWorks Low Product pom developer org Three Low Product pom groupid org.apache.groovy Highest Product pom name Apache Groovy High Product pom organization name Apache Software Foundation Low Product pom organization url https://apache.org Low Product pom url https://groovy-lang.org Medium Version file version 4.0.22 High Version Manifest Bundle-Version 4.0.22 High Version Manifest Implementation-Version 4.0.22 High Version pom version 4.0.22 Highest
Related Dependencies groovy-xml-4.0.22.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/groovy/groovy-xml/4.0.22/groovy-xml-4.0.22.jar MD5: 26134c83f393438bfc52402651803252 SHA1: 951b9a1f3891981aa152fd02076a8ba6c20857e7 SHA256: a8c6c845ed22feaaed8f0fd79798b8abea3e090afd5a9adaab96dbda152169cb pkg:maven/org.apache.groovy/groovy-xml@4.0.22 groovy-json-4.0.22.jarDescription:
Groovy: A powerful multi-faceted language for the JVM License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/groovy/groovy-json/4.0.22/groovy-json-4.0.22.jar
MD5: 86f2d4325465f5b747d6c2cd159b36c0
SHA1: 5c8edac1ee596375a3d28fc2c0e844ee067f6b6b
SHA256: aba93254d9293881282bd639b7b3db8bdcb5bf6cca4cac0df7a0bd193743f652
Evidence Type Source Name Value Confidence Vendor file name groovy-json High Vendor jar package name apache Highest Vendor jar package name groovy Highest Vendor jar package name json Highest Vendor Manifest automatic-module-name org.apache.groovy.json Medium Vendor Manifest bundle-symbolicname groovy-json Medium Vendor Manifest eclipse-buddypolicy dependent Low Vendor Manifest extension-name groovy Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.apache.groovy.json.FastStringServiceFactory" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid groovy-json Low Vendor pom developer email aalmiray@users.sourceforge.net Low Vendor pom developer email b55r@sina.com Low Vendor pom developer email blackdrag@gmx.org Low Vendor pom developer email bob@werken.com Low Vendor pom developer email cedric.champeau@gmail.com Low Vendor pom developer email ckl@dacelo.nl Low Vendor pom developer email cpoirier@dreaming.org Low Vendor pom developer email goetze@dovetail.com Low Vendor pom developer email guillaume.alleon@gmail.com Low Vendor pom developer email hamletdrc@gmail.com Low Vendor pom developer email james@coredevelopers.com Low Vendor pom developer email jason@planet57.com Low Vendor pom developer email jeremy.rayner@gmail.com Low Vendor pom developer email jim@pagesmiths.com Low Vendor pom developer email johnstump2@yahoo.com Low Vendor pom developer email mguillemot@yahoo.fr Low Vendor pom developer email paulk@asert.com.au Low Vendor pom developer email phkim@cluecom.co.kr Low Vendor pom developer email pniederw@gmail.com Low Vendor pom developer email russel@winder.org.uk Low Vendor pom developer email sam@sampullara.com Low Vendor pom developer email sormuras@gmx.de Low Vendor pom developer email tug@wilson.co.uk Low Vendor pom developer id aalmiray Medium Vendor pom developer id alextkachman Medium Vendor pom developer id andresteingress Medium Vendor pom developer id blackdrag Medium Vendor pom developer id bob Medium Vendor pom developer id bran Medium Vendor pom developer id ckl Medium Vendor pom developer id cpoirier Medium Vendor pom developer id cstein Medium Vendor pom developer id emilles Medium Vendor pom developer id galleon Medium Vendor pom developer id glaforge Medium Vendor pom developer id goetze Medium Vendor pom developer id grocher Medium Vendor pom developer id hamletdrc Medium Vendor pom developer id jamiemc Medium Vendor pom developer id jez Medium Vendor pom developer id jimwhite Medium Vendor pom developer id joe Medium Vendor pom developer id jstrachan Medium Vendor pom developer id jstump Medium Vendor pom developer id jwill Medium Vendor pom developer id jwilson Medium Vendor pom developer id kasper Medium Vendor pom developer id mattf Medium Vendor pom developer id melix Medium Vendor pom developer id mguillem Medium Vendor pom developer id mittie Medium Vendor pom developer id pascalschumacher Medium Vendor pom developer id paulk Medium Vendor pom developer id phk Medium Vendor pom developer id pniederw Medium Vendor pom developer id roshandawrani Medium Vendor pom developer id rpopma Medium Vendor pom developer id russel Medium Vendor pom developer id shemnon Medium Vendor pom developer id skizz Medium Vendor pom developer id spullara Medium Vendor pom developer id sunlan Medium Vendor pom developer id timyates Medium Vendor pom developer id travis Medium Vendor pom developer id user57 Medium Vendor pom developer id zohar Medium Vendor pom developer name Alex Tkachman Medium Vendor pom developer name Andre Steingress Medium Vendor pom developer name Andres Almiray Medium Vendor pom developer name Bing Ran Medium Vendor pom developer name bob mcwhirter Medium Vendor pom developer name Cedric Champeau Medium Vendor pom developer name Chris Poirier Medium Vendor pom developer name Chris Stevenson Medium Vendor pom developer name Christiaan ten Klooster Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Daniel Sun Medium Vendor pom developer name Danno Ferrin Medium Vendor pom developer name Dierk Koenig Medium Vendor pom developer name Eric Milles Medium Vendor pom developer name Graeme Rocher Medium Vendor pom developer name Guillaume Alleon Medium Vendor pom developer name Guillaume Laforge Medium Vendor pom developer name Hamlet D'Arcy Medium Vendor pom developer name James Strachan Medium Vendor pom developer name James Williams Medium Vendor pom developer name Jamie McCrindle Medium Vendor pom developer name Jason Dillon Medium Vendor pom developer name Jeremy Rayner Medium Vendor pom developer name Jim White Medium Vendor pom developer name Jochen Theodorou Medium Vendor pom developer name Joe Walnes Medium Vendor pom developer name John Stump Medium Vendor pom developer name John Wilson Medium Vendor pom developer name Kasper Nielsen Medium Vendor pom developer name Marc Guillemot Medium Vendor pom developer name Matt Foemmel Medium Vendor pom developer name Pascal Schumacher Medium Vendor pom developer name Paul King Medium Vendor pom developer name Peter Niederwieser Medium Vendor pom developer name Pilho Kim Medium Vendor pom developer name Remko Popma Medium Vendor pom developer name Roshan Dawrani Medium Vendor pom developer name Russel Winder Medium Vendor pom developer name Sam Pullara Medium Vendor pom developer name Steve Goetze Medium Vendor pom developer name Tim Yates Medium Vendor pom developer name Travis Kay Medium Vendor pom developer name Zohar Melamed Medium Vendor pom developer org Concertant LLP & It'z Interactive Ltd Medium Vendor pom developer org Core Developers Network Medium Vendor pom developer org CTSR.de Medium Vendor pom developer org Dacelo WebDevelopment Medium Vendor pom developer org Dovetailed Technologies, LLC Medium Vendor pom developer org Google Medium Vendor pom developer org IFCX.org Medium Vendor pom developer org javanicus Medium Vendor pom developer org Karakun AG Medium Vendor pom developer org Leadingcare Medium Vendor pom developer org OCI, Australia Medium Vendor pom developer org The Werken Company Medium Vendor pom developer org The Wilson Partnership Medium Vendor pom developer org Thomson Reuters Medium Vendor pom developer org ThoughtWorks Medium Vendor pom developer org Three Medium Vendor pom groupid org.apache.groovy Highest Vendor pom name Apache Groovy High Vendor pom organization name Apache Software Foundation High Vendor pom organization url https://apache.org Medium Vendor pom url https://groovy-lang.org Highest Product file name groovy-json High Product jar package name apache Highest Product jar package name faststringservicefactory Highest Product jar package name groovy Highest Product jar package name json Highest Product Manifest automatic-module-name org.apache.groovy.json Medium Product Manifest Bundle-Name Groovy module: groovy-json Medium Product Manifest bundle-symbolicname groovy-json Medium Product Manifest eclipse-buddypolicy dependent Low Product Manifest extension-name groovy Medium Product Manifest Implementation-Title Groovy: a powerful, multi-faceted language for the JVM High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.apache.groovy.json.FastStringServiceFactory" Low Product Manifest specification-title Groovy: a powerful, multi-faceted language for the JVM Medium Product pom artifactid groovy-json Highest Product pom developer email aalmiray@users.sourceforge.net Low Product pom developer email b55r@sina.com Low Product pom developer email blackdrag@gmx.org Low Product pom developer email bob@werken.com Low Product pom developer email cedric.champeau@gmail.com Low Product pom developer email ckl@dacelo.nl Low Product pom developer email cpoirier@dreaming.org Low Product pom developer email goetze@dovetail.com Low Product pom developer email guillaume.alleon@gmail.com Low Product pom developer email hamletdrc@gmail.com Low Product pom developer email james@coredevelopers.com Low Product pom developer email jason@planet57.com Low Product pom developer email jeremy.rayner@gmail.com Low Product pom developer email jim@pagesmiths.com Low Product pom developer email johnstump2@yahoo.com Low Product pom developer email mguillemot@yahoo.fr Low Product pom developer email paulk@asert.com.au Low Product pom developer email phkim@cluecom.co.kr Low Product pom developer email pniederw@gmail.com Low Product pom developer email russel@winder.org.uk Low Product pom developer email sam@sampullara.com Low Product pom developer email sormuras@gmx.de Low Product pom developer email tug@wilson.co.uk Low Product pom developer id aalmiray Low Product pom developer id alextkachman Low Product pom developer id andresteingress Low Product pom developer id blackdrag Low Product pom developer id bob Low Product pom developer id bran Low Product pom developer id ckl Low Product pom developer id cpoirier Low Product pom developer id cstein Low Product pom developer id emilles Low Product pom developer id galleon Low Product pom developer id glaforge Low Product pom developer id goetze Low Product pom developer id grocher Low Product pom developer id hamletdrc Low Product pom developer id jamiemc Low Product pom developer id jez Low Product pom developer id jimwhite Low Product pom developer id joe Low Product pom developer id jstrachan Low Product pom developer id jstump Low Product pom developer id jwill Low Product pom developer id jwilson Low Product pom developer id kasper Low Product pom developer id mattf Low Product pom developer id melix Low Product pom developer id mguillem Low Product pom developer id mittie Low Product pom developer id pascalschumacher Low Product pom developer id paulk Low Product pom developer id phk Low Product pom developer id pniederw Low Product pom developer id roshandawrani Low Product pom developer id rpopma Low Product pom developer id russel Low Product pom developer id shemnon Low Product pom developer id skizz Low Product pom developer id spullara Low Product pom developer id sunlan Low Product pom developer id timyates Low Product pom developer id travis Low Product pom developer id user57 Low Product pom developer id zohar Low Product pom developer name Alex Tkachman Low Product pom developer name Andre Steingress Low Product pom developer name Andres Almiray Low Product pom developer name Bing Ran Low Product pom developer name bob mcwhirter Low Product pom developer name Cedric Champeau Low Product pom developer name Chris Poirier Low Product pom developer name Chris Stevenson Low Product pom developer name Christiaan ten Klooster Low Product pom developer name Christian Stein Low Product pom developer name Daniel Sun Low Product pom developer name Danno Ferrin Low Product pom developer name Dierk Koenig Low Product pom developer name Eric Milles Low Product pom developer name Graeme Rocher Low Product pom developer name Guillaume Alleon Low Product pom developer name Guillaume Laforge Low Product pom developer name Hamlet D'Arcy Low Product pom developer name James Strachan Low Product pom developer name James Williams Low Product pom developer name Jamie McCrindle Low Product pom developer name Jason Dillon Low Product pom developer name Jeremy Rayner Low Product pom developer name Jim White Low Product pom developer name Jochen Theodorou Low Product pom developer name Joe Walnes Low Product pom developer name John Stump Low Product pom developer name John Wilson Low Product pom developer name Kasper Nielsen Low Product pom developer name Marc Guillemot Low Product pom developer name Matt Foemmel Low Product pom developer name Pascal Schumacher Low Product pom developer name Paul King Low Product pom developer name Peter Niederwieser Low Product pom developer name Pilho Kim Low Product pom developer name Remko Popma Low Product pom developer name Roshan Dawrani Low Product pom developer name Russel Winder Low Product pom developer name Sam Pullara Low Product pom developer name Steve Goetze Low Product pom developer name Tim Yates Low Product pom developer name Travis Kay Low Product pom developer name Zohar Melamed Low Product pom developer org Concertant LLP & It'z Interactive Ltd Low Product pom developer org Core Developers Network Low Product pom developer org CTSR.de Low Product pom developer org Dacelo WebDevelopment Low Product pom developer org Dovetailed Technologies, LLC Low Product pom developer org Google Low Product pom developer org IFCX.org Low Product pom developer org javanicus Low Product pom developer org Karakun AG Low Product pom developer org Leadingcare Low Product pom developer org OCI, Australia Low Product pom developer org The Werken Company Low Product pom developer org The Wilson Partnership Low Product pom developer org Thomson Reuters Low Product pom developer org ThoughtWorks Low Product pom developer org Three Low Product pom groupid org.apache.groovy Highest Product pom name Apache Groovy High Product pom organization name Apache Software Foundation Low Product pom organization url https://apache.org Low Product pom url https://groovy-lang.org Medium Version file version 4.0.22 High Version Manifest Bundle-Version 4.0.22 High Version Manifest Implementation-Version 4.0.22 High Version pom version 4.0.22 Highest
pkg:maven/org.apache.groovy/groovy-json@4.0.22 (Confidence :High) cpe:2.3:a:google:gmail:4.0.22:*:*:*:*:*:*:* (Confidence :Low) suppress grpc-api-1.76.0.jarDescription:
gRPC: API License:
Apache 2.0: https://opensource.org/licenses/Apache-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/grpc/grpc-api/1.76.0/grpc-api-1.76.0.jar
MD5: fcf50d9eecdc3c7c9916288bace923eb
SHA1: f213e3ee49b82497dfc0f5eb30bac62d917f1a52
SHA256: 13ce42c59871a04a7340f01e1dbd879fefa04811878cfd68864596321f555ed3
Evidence Type Source Name Value Confidence Vendor file name grpc-api High Vendor jar package name grpc Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name io.grpc Medium Vendor pom artifactid grpc-api Low Vendor pom developer email grpc-io@googlegroups.com Low Vendor pom developer id grpc.io Medium Vendor pom developer name gRPC Contributors Medium Vendor pom developer org gRPC Authors Medium Vendor pom developer org URL https://www.google.com Medium Vendor pom groupid io.grpc Highest Vendor pom name io.grpc:grpc-api High Vendor pom url grpc/grpc-java Highest Product file name grpc-api High Product jar package name grpc Highest Product jar package name io Highest Product Manifest automatic-module-name io.grpc Medium Product Manifest Implementation-Title jar High Product pom artifactid grpc-api Highest Product pom developer email grpc-io@googlegroups.com Low Product pom developer id grpc.io Low Product pom developer name gRPC Contributors Low Product pom developer org gRPC Authors Low Product pom developer org URL https://www.google.com Low Product pom groupid io.grpc Highest Product pom name io.grpc:grpc-api High Product pom url grpc/grpc-java High Version file version 1.76.0 High Version Manifest Implementation-Version 1.76.0 High Version pom version 1.76.0 Highest
Related Dependencies grpc-context-1.76.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/grpc/grpc-context/1.76.0/grpc-context-1.76.0.jar MD5: f02035eabbbcececc30327f7706661ab SHA1: 529d9887c6ec08ac5c6ff32699eb314a724f63b4 SHA256: 3b4eb9ca65fe5cd98b2665f9b355158fac5a048708626b5b68dc66c43fb820d3 pkg:maven/io.grpc/grpc-context@1.76.0 gson-2.13.2.jarDescription:
Gson JSON library License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/code/gson/gson/2.13.2/gson-2.13.2.jar
MD5: a2c47e14ce5e956105458fe455f5d542
SHA1: 48b8230771e573b54ce6e867a9001e75977fe78e
SHA256: dd0ce1b55a3ed2080cb70f9c655850cda86c206862310009dcb5e5c95265a5e0
Evidence Type Source Name Value Confidence Vendor file name gson High Vendor jar package name google Highest Vendor jar package name gson Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-contactaddress https://github.com/google/gson Low Vendor Manifest bundle-developers google;organization=Google;organizationUrl="https://www.google.com" Low Vendor Manifest bundle-docurl https://github.com/google/gson Low Vendor Manifest bundle-symbolicname com.google.gson Medium Vendor Manifest multi-release true Low Vendor pom artifactid gson Low Vendor pom groupid com.google.code.gson Highest Vendor pom name Gson High Vendor pom parent-artifactid gson-parent Low Product file name gson High Product jar package name google Highest Product jar package name gson Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-contactaddress https://github.com/google/gson Low Product Manifest bundle-developers google;organization=Google;organizationUrl="https://www.google.com" Low Product Manifest bundle-docurl https://github.com/google/gson Low Product Manifest Bundle-Name Gson Medium Product Manifest bundle-symbolicname com.google.gson Medium Product Manifest multi-release true Low Product pom artifactid gson Highest Product pom groupid com.google.code.gson Highest Product pom name Gson High Product pom parent-artifactid gson-parent Medium Version file version 2.13.2 High Version Manifest Bundle-Version 2.13.2 High Version pom version 2.13.2 Highest
guice-5.1.0-classes.jarDescription:
Guice is a lightweight dependency injection framework for Java 6 and above License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/inject/guice/5.1.0/guice-5.1.0-classes.jar
MD5: d4d4d9bf878b98862116e8ccc0a5c34e
SHA1: e7ba4c25bec3761840f67c73f166c0d509d01d1d
SHA256: 142ad4475e19524d2fe3ac995b3f7cbc962fc726f2edb9dbdccc61feab9b2bf9
Evidence Type Source Name Value Confidence Vendor file name guice High Vendor jar package name google Highest Vendor jar package name google Low Vendor jar package name guice Highest Vendor jar package name inject Highest Vendor jar package name inject Low Vendor jar package name internal Low Vendor Manifest automatic-module-name com.google.guice Medium Vendor Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Vendor Manifest bundle-docurl https://github.com/google/guice Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor Manifest bundle-symbolicname com.google.inject Medium Vendor Manifest eclipse-extensibleapi true Low Product file name guice High Product jar package name dependency Highest Product jar package name google Highest Product jar package name guice Highest Product jar package name inject Highest Product jar package name inject Low Product jar package name internal Low Product Manifest automatic-module-name com.google.guice Medium Product Manifest bundle-copyright Copyright (C) 2006 Google Inc. Low Product Manifest bundle-docurl https://github.com/google/guice Low Product Manifest Bundle-Name guice Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product Manifest bundle-symbolicname com.google.inject Medium Product Manifest eclipse-extensibleapi true Low Version file name guice Medium Version file version 5.1.0 High Version jar package name google Highest Version jar package name guice Highest Version Manifest bundle-copyright 2006 Low Version Manifest Bundle-Version 5.1.0 High
h2-2.4.240.jarDescription:
H2 Database Engine License:
MPL 2.0: https://www.mozilla.org/en-US/MPL/2.0/
EPL 1.0: https://opensource.org/licenses/eclipse-1.0.php File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/h2database/h2/2.4.240/h2-2.4.240.jar
MD5: fb14a47b07dfd4381a608d3adb89dc25
SHA1: 686180ad33981ad943fdc0ab381e619b2c2fdfe5
SHA256: 29b70e427cc1c40cdc376283adbb0cc62853073797bb5fe5761f81fe73d57ce0
Evidence Type Source Name Value Confidence Vendor file name h2 High Vendor jar package name database Highest Vendor jar package name engine Highest Vendor jar package name h2 Highest Vendor Manifest automatic-module-name com.h2database Medium Vendor Manifest bundle-category jdbc Low Vendor Manifest bundle-symbolicname com.h2database Medium Vendor Manifest implementation-url https://h2database.com Low Vendor Manifest multi-release true Low Vendor Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Vendor pom artifactid h2 Low Vendor pom developer email thomas.tom.mueller at gmail dot com Low Vendor pom developer id thomas.tom.mueller Medium Vendor pom developer name Thomas Mueller Medium Vendor pom groupid com.h2database Highest Vendor pom name H2 Database Engine High Vendor pom url https://h2database.com Highest Product file name h2 High Product jar package name database Highest Product jar package name engine Highest Product jar package name h2 Highest Product jar package name jdbc Highest Product jar package name org Highest Product jar package name service Highest Product Manifest automatic-module-name com.h2database Medium Product Manifest bundle-category jdbc Low Product Manifest Bundle-Name H2 Database Engine Medium Product Manifest bundle-symbolicname com.h2database Medium Product Manifest Implementation-Title H2 Database Engine High Product Manifest implementation-url https://h2database.com Low Product Manifest multi-release true Low Product Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Product pom artifactid h2 Highest Product pom developer email thomas.tom.mueller at gmail dot com Low Product pom developer id thomas.tom.mueller Low Product pom developer name Thomas Mueller Low Product pom groupid com.h2database Highest Product pom name H2 Database Engine High Product pom url https://h2database.com Medium Version file version 2.4.240 High Version Manifest Bundle-Version 2.4.240 High Version Manifest Implementation-Version 2.4.240 High Version pom version 2.4.240 Highest
h2-2.4.240.jar: data.zip: table.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/h2database/h2/2.4.240/h2-2.4.240.jar/org/h2/util/data.zip/org/h2/server/web/res/table.jsMD5: ca07fc6140e278428c7704453d30bed5SHA1: 8044d5d7aecfa0cd1cbb897af398492ac5c8af7eSHA256: 968e1c570a30b2383db9fc67150ac924df171fe587c44996bdd08f2f14b7a017
Evidence Type Source Name Value Confidence
h2-2.4.240.jar: data.zip: tree.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/h2database/h2/2.4.240/h2-2.4.240.jar/org/h2/util/data.zip/org/h2/server/web/res/tree.jsMD5: c2620dfa674439d78be770a2588a3e56SHA1: 0c6bc6d3eb88131d071938de4e5514e1f182e1f9SHA256: 9f933afa133f72bd51e7904e54792418ed1595e35005e48b72af1f7fbccd8963
Evidence Type Source Name Value Confidence
hamcrest-2.2.jarDescription:
Core API and libraries of hamcrest matcher framework. License:
BSD License 3: http://opensource.org/licenses/BSD-3-Clause File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hamcrest/hamcrest/2.2/hamcrest-2.2.jar
MD5: 10b47e837f271d0662f28780e60388e8
SHA1: 1820c0968dba3a11a1b30669bb1f01978a91dedc
SHA256: 5e62846a89f05cd78cd9c1a553f340d002458380c320455dd1f8fc5497a8a1c1
Evidence Type Source Name Value Confidence Vendor file name hamcrest High Vendor jar package name core Highest Vendor jar package name hamcrest Highest Vendor jar package name matcher Highest Vendor Manifest automatic-module-name org.hamcrest Medium Vendor Manifest bundle-symbolicname org.hamcrest Medium Vendor Manifest Implementation-Vendor hamcrest.org High Vendor pom artifactid hamcrest Low Vendor pom developer id joewalnes Medium Vendor pom developer id npryce Medium Vendor pom developer id sf105 Medium Vendor pom developer name Joe Walnes Medium Vendor pom developer name Nat Pryce Medium Vendor pom developer name Steve Freeman Medium Vendor pom groupid org.hamcrest Highest Vendor pom name Hamcrest High Vendor pom url http://hamcrest.org/JavaHamcrest/ Highest Product file name hamcrest High Product jar package name core Highest Product jar package name hamcrest Highest Product jar package name matcher Highest Product Manifest automatic-module-name org.hamcrest Medium Product Manifest Bundle-Name hamcrest Medium Product Manifest bundle-symbolicname org.hamcrest Medium Product Manifest Implementation-Title hamcrest High Product pom artifactid hamcrest Highest Product pom developer id joewalnes Low Product pom developer id npryce Low Product pom developer id sf105 Low Product pom developer name Joe Walnes Low Product pom developer name Nat Pryce Low Product pom developer name Steve Freeman Low Product pom groupid org.hamcrest Highest Product pom name Hamcrest High Product pom url http://hamcrest.org/JavaHamcrest/ Medium Version file version 2.2 High Version Manifest Bundle-Version 2.2 High Version Manifest Implementation-Version 2.2 High Version pom version 2.2 Highest
pkg:maven/org.hamcrest/hamcrest@2.2 (Confidence :High) header.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/header/header.module.jsMD5: 5e9489a41e0b79619ae72f50357e3ae2SHA1: cf72159214fe605c19a4165ecbe5885501830c07SHA256: b9a9d3803448b78145f6ca5eac84acebc21b77390f1ab0336112983a8eeec2c3
Evidence Type Source Name Value Confidence
header.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/header/header.module.min.jsMD5: aa88d45c5a84929f7b1fe933066061b8SHA1: aba5c6f9719c590891f640d61c7af347d3cdce86SHA256: 78012f5ac77137d41e9a409fbce3812732a5e6b5aa849f2571eee3e1bb7e2fc0
Evidence Type Source Name Value Confidence
header.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/header/header.nomodule.jsMD5: 4ff79a609bdb2ade06d7dbab7d6034cdSHA1: 0e0ac1af1a6f9a72fd6dabfb5ea7bc1148ee5be7SHA256: f8fe70d88052f130b949066f58ddac727439dd301968e78519d007e9efd35228
Evidence Type Source Name Value Confidence
header.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/header/header.nomodule.min.jsMD5: 5a000208c7118d1c68098a8b7df8bf0cSHA1: 55216448204b4d5c97cc62f1067bbee9609166e5SHA256: 4a5643c34911d5be09b655f03c0930e7f8b6f7e256f5ff5d6aa55aba9776195d
Evidence Type Source Name Value Confidence
hibernate-tools-language-7.1.11.Final.jarDescription:
Tools to aid Hibernate developers through natural language,
leveraging LLMs and generative AI functionalities. License:
Apache License, version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hibernate/tool/hibernate-tools-language/7.1.11.Final/hibernate-tools-language-7.1.11.Final.jar
MD5: dd0f421351b87511a1c2318f5457ef1b
SHA1: 4b5ef05b17da896385d066198bccbd4381048f8d
SHA256: 5d5e946148c4a2c7a8eca06e653ab2fd1452f627d5c9a22fcc5c65b2418be5b3
Evidence Type Source Name Value Confidence Vendor file name hibernate-tools-language High Vendor hint analyzer vendor redhat Highest Vendor jar package name hibernate Highest Vendor jar package name language Highest Vendor jar package name tool Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url http://hibernate.org/tools/ Low Vendor Manifest Implementation-Vendor Hibernate High Vendor Manifest specification-vendor Hibernate Low Vendor pom artifactid hibernate-tools-language Low Vendor pom developer email jacques.stadler+github@gmail.com Low Vendor pom developer email koen@hibernate.org Low Vendor pom developer email marko@hibernate.org Low Vendor pom developer email max@hibernate.org Low Vendor pom developer id koentsje Medium Vendor pom developer id marko.bekhta Medium Vendor pom developer id maxandersen Medium Vendor pom developer id stadler Medium Vendor pom developer name Jacques Stadler Medium Vendor pom developer name Koen Aers Medium Vendor pom developer name Marko Bekhta Medium Vendor pom developer name Max Andersen Medium Vendor pom groupid org.hibernate.tool Highest Vendor pom name Hibernate Tools Natural Language High Vendor pom url http://hibernate.org/tools/ Highest Product file name hibernate-tools-language High Product jar package name hibernate Highest Product jar package name language Highest Product jar package name tool Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Hibernate Tools Natural Language High Product Manifest implementation-url http://hibernate.org/tools/ Low Product Manifest specification-title Hibernate Tools Natural Language Medium Product pom artifactid hibernate-tools-language Highest Product pom developer email jacques.stadler+github@gmail.com Low Product pom developer email koen@hibernate.org Low Product pom developer email marko@hibernate.org Low Product pom developer email max@hibernate.org Low Product pom developer id koentsje Low Product pom developer id marko.bekhta Low Product pom developer id maxandersen Low Product pom developer id stadler Low Product pom developer name Jacques Stadler Low Product pom developer name Koen Aers Low Product pom developer name Marko Bekhta Low Product pom developer name Max Andersen Low Product pom groupid org.hibernate.tool Highest Product pom name Hibernate Tools Natural Language High Product pom url http://hibernate.org/tools/ Medium Version Manifest Implementation-Version 7.1.11.Final High Version pom version 7.1.11.Final Highest
pkg:maven/org.hibernate.tool/hibernate-tools-language@7.1.11.Final (Confidence :High) httpclient-4.5.14.jarDescription:
Apache HttpComponents Client
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jarMD5: 2cb357c4b763f47e58af6cad47df6ba3SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98SHA256: c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6
Evidence Type Source Name Value Confidence Vendor file name httpclient High Vendor jar package name apache Highest Vendor jar package name client Highest Vendor jar package name httpclient Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpclient Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client-ga Highest Product file name httpclient High Product jar package name apache Highest Product jar package name client Highest Product jar package name http Highest Product jar package name httpclient Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Product Manifest Implementation-Title Apache HttpClient High Product Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Product Manifest specification-title Apache HttpClient Medium Product pom artifactid httpclient Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client-ga Medium Version file version 4.5.14 High Version Manifest Implementation-Version 4.5.14 High Version pom version 4.5.14 Highest
httpcore-4.4.16.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jarMD5: 28d2cd9bf8789fd2ec774fb88436ebd1SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850SHA256: 6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464f
Evidence Type Source Name Value Confidence Vendor file name httpcore High Vendor jar package name apache Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor pom artifactid httpcore Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpCore High Vendor pom parent-artifactid httpcomponents-core Low Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product file name httpcore High Product jar package name apache Highest Product jar package name http Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product pom artifactid httpcore Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpCore High Product pom parent-artifactid httpcomponents-core Medium Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Version file version 4.4.16 High Version Manifest Implementation-Version 4.4.16 High Version pom version 4.4.16 Highest
pkg:maven/org.apache.httpcomponents/httpcore@4.4.16 (Confidence :High) httpmime-4.5.14.jarDescription:
Apache HttpComponents HttpClient - MIME coded entities
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/httpcomponents/httpmime/4.5.14/httpmime-4.5.14.jarMD5: 714c4ae31c40e6633c0bcaa4e6264153SHA1: 6662758a1f1cb1149cf916bdac28332e0902ec44SHA256: d401243d5c6eae928a37121b6e819158c8c32ea0584793e7285bb489ab2a3d17
Evidence Type Source Name Value Confidence Vendor file name httpmime High Vendor jar package name apache Highest Vendor jar package name mime Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpmime Medium Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpmime Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient Mime High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client-ga Highest Product file name httpmime High Product jar package name apache Highest Product jar package name http Highest Product jar package name mime Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpmime Medium Product Manifest Implementation-Title Apache HttpClient Mime High Product Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Product Manifest specification-title Apache HttpClient Mime Medium Product pom artifactid httpmime Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient Mime High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client-ga Medium Version file version 4.5.14 High Version Manifest Implementation-Version 4.5.14 High Version pom version 4.5.14 Highest
pkg:maven/org.apache.httpcomponents/httpmime@4.5.14 (Confidence :High) io.agroal.agroal-api-2.8.jarDescription:
The natural database connection pool License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.agroal.agroal-api-2.8.jar
MD5: cb4604e9d4935a3b54ed0b085c6f4c46
SHA1: 772047422d66760beaf8d95cfc9657855b1809e2
SHA256: e5500e8fd736e749ec0373e8af3f2d2af8c37cf0d9eb73a35290b2dd2156421a
Evidence Type Source Name Value Confidence Vendor file name io.agroal.agroal-api High Vendor hint analyzer vendor redhat Highest Vendor jar package name agroal Highest Vendor jar package name agroal Low Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name io Highest Vendor jar package name io Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname io.agroal.api Medium Vendor Manifest implementation-url https://github.com/agroal Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name io.agroal.agroal-api High Product jar package name agroal Highest Product jar package name agroal Low Product jar package name api Highest Product jar package name api Low Product jar package name io Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Agroal API Medium Product Manifest bundle-symbolicname io.agroal.api Medium Product Manifest Implementation-Title Agroal API High Product Manifest implementation-url https://github.com/agroal Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Agroal API Medium Version file version 2.8 High Version Manifest Implementation-Version 2.8 High
Related Dependencies agroal-api-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/agroal/agroal-api/2.8/agroal-api-2.8.jar MD5: cb4604e9d4935a3b54ed0b085c6f4c46 SHA1: 772047422d66760beaf8d95cfc9657855b1809e2 SHA256: e5500e8fd736e749ec0373e8af3f2d2af8c37cf0d9eb73a35290b2dd2156421a pkg:maven/io.agroal/agroal-api@2.8 io.agroal.agroal-api-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.agroal.agroal-api-2.8.jar MD5: cb4604e9d4935a3b54ed0b085c6f4c46 SHA1: 772047422d66760beaf8d95cfc9657855b1809e2 SHA256: e5500e8fd736e749ec0373e8af3f2d2af8c37cf0d9eb73a35290b2dd2156421a io.agroal.agroal-narayana-2.8.jarDescription:
The natural database connection pool License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.agroal.agroal-narayana-2.8.jar
MD5: 12a438414e751b3bf1c6d96ba51e6041
SHA1: c89aa19b6436fec7d1b6d8545d3629b2800a3470
SHA256: 0e7e658707a9bc3f857defc1005f649abbf010d54697ec7c66d7d43f39c3fe23
Evidence Type Source Name Value Confidence Vendor file name io.agroal.agroal-narayana High Vendor hint analyzer vendor redhat Highest Vendor jar package name agroal Highest Vendor jar package name agroal Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name narayana Highest Vendor jar package name narayana Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname io.agroal.narayana Medium Vendor Manifest implementation-url https://github.com/agroal Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name io.agroal.agroal-narayana High Product jar package name agroal Highest Product jar package name agroal Low Product jar package name io Highest Product jar package name narayana Highest Product jar package name narayana Low Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Agroal Narayana Integration Medium Product Manifest bundle-symbolicname io.agroal.narayana Medium Product Manifest Implementation-Title Agroal Narayana Integration High Product Manifest implementation-url https://github.com/agroal Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Agroal Narayana Integration Medium Version file version 2.8 High Version Manifest Implementation-Version 2.8 High
Related Dependencies agroal-narayana-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/agroal/agroal-narayana/2.8/agroal-narayana-2.8.jar MD5: 12a438414e751b3bf1c6d96ba51e6041 SHA1: c89aa19b6436fec7d1b6d8545d3629b2800a3470 SHA256: 0e7e658707a9bc3f857defc1005f649abbf010d54697ec7c66d7d43f39c3fe23 pkg:maven/io.agroal/agroal-narayana@2.8 io.agroal.agroal-narayana-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.agroal.agroal-narayana-2.8.jar MD5: 12a438414e751b3bf1c6d96ba51e6041 SHA1: c89aa19b6436fec7d1b6d8545d3629b2800a3470 SHA256: 0e7e658707a9bc3f857defc1005f649abbf010d54697ec7c66d7d43f39c3fe23 io.agroal.agroal-pool-2.8.jarDescription:
The natural database connection pool License:
http://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.agroal.agroal-pool-2.8.jar
MD5: 15c8d88ab71718e5258e62cb0f91e48a
SHA1: 1a04e038f13cc0fc6c64941721e81b6983625af0
SHA256: 2964854555dab2c32b745b383ac13400396f827f35b2f12a2c984afacfe7523e
Evidence Type Source Name Value Confidence Vendor file name io.agroal.agroal-pool High Vendor hint analyzer vendor redhat Highest Vendor jar package name agroal Highest Vendor jar package name agroal Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name pool Highest Vendor jar package name pool Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname io.agroal.pool Medium Vendor Manifest implementation-url https://github.com/agroal Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="io.agroal.api.AgroalDataSourceProvider";uses:="io.agroal.api" Low Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name io.agroal.agroal-pool High Product jar package name agroal Highest Product jar package name agroal Low Product jar package name io Highest Product jar package name pool Highest Product jar package name pool Low Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Agroal Connection Pool Medium Product Manifest bundle-symbolicname io.agroal.pool Medium Product Manifest Implementation-Title Agroal Connection Pool High Product Manifest implementation-url https://github.com/agroal Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="io.agroal.api.AgroalDataSourceProvider";uses:="io.agroal.api" Low Product Manifest specification-title Agroal Connection Pool Medium Version file version 2.8 High Version Manifest Implementation-Version 2.8 High
Related Dependencies agroal-pool-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/agroal/agroal-pool/2.8/agroal-pool-2.8.jar MD5: 15c8d88ab71718e5258e62cb0f91e48a SHA1: 1a04e038f13cc0fc6c64941721e81b6983625af0 SHA256: 2964854555dab2c32b745b383ac13400396f827f35b2f12a2c984afacfe7523e pkg:maven/io.agroal/agroal-pool@2.8 io.agroal.agroal-pool-2.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.agroal.agroal-pool-2.8.jar MD5: 15c8d88ab71718e5258e62cb0f91e48a SHA1: 1a04e038f13cc0fc6c64941721e81b6983625af0 SHA256: 2964854555dab2c32b745b383ac13400396f827f35b2f12a2c984afacfe7523e io.netty.netty-transport-4.1.130.Final.jarDescription:
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers and clients. License:
https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.netty.netty-transport-4.1.130.Final.jar
MD5: 0a9e8d9d92e5f8ed9e3b008f06db40d7
SHA1: 3a25cd7a1c057ed9a1606caa4b693f9c8b5c4b53
SHA256: 1bf573266d271f856705a9984d25449c56a1d73c02a16af12033ceccfe555dbb
Evidence Type Source Name Value Confidence Vendor file name io.netty.netty-transport High Vendor jar package name channel Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name netty Highest Vendor jar package name netty Low Vendor Manifest automatic-module-name io.netty.transport Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://netty.io/ Low Vendor Manifest bundle-symbolicname io.netty.transport Medium Vendor Manifest implementation-url https://netty.io/netty-transport/ Low Vendor Manifest Implementation-Vendor The Netty Project High Vendor Manifest Implementation-Vendor-Id io.netty Medium Vendor Manifest specification-vendor The Netty Project Low Product file name io.netty.netty-transport High Product jar package name channel Low Product jar package name io Highest Product jar package name netty Highest Product jar package name netty Low Product Manifest automatic-module-name io.netty.transport Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://netty.io/ Low Product Manifest Bundle-Name Netty/Transport Medium Product Manifest bundle-symbolicname io.netty.transport Medium Product Manifest Implementation-Title Netty/Transport High Product Manifest implementation-url https://netty.io/netty-transport/ Low Product Manifest specification-title Netty/Transport Medium Version file version 4.1.130 High Version Manifest Implementation-Version 4.1.130.Final High
Related Dependencies io.netty.netty-transport-native-unix-common-4.1.130.Final.jarDescription:
Static library which contains common unix utilities. License:
https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.netty.netty-transport-native-unix-common-4.1.130.Final.jar
MD5: 388abb78bf16bcf6f1bb1a3731b13703
SHA1: a29adec03f7dbefdab3b21523a15c35e794f3154
SHA256: cf5efc4168597d7cd14695b469418cac2a1134533f9a0c82ef0538d796fd39e1
Evidence Type Source Name Value Confidence Vendor file name io.netty.netty-transport-native-unix-common High Vendor jar package name channel Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name netty Highest Vendor jar package name netty Low Vendor jar package name unix Highest Vendor Manifest automatic-module-name io.netty.transport.unix.common Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://netty.io/ Low Vendor Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium Vendor Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low Vendor Manifest Implementation-Vendor The Netty Project High Vendor Manifest Implementation-Vendor-Id io.netty Medium Vendor Manifest specification-vendor The Netty Project Low Product file name io.netty.netty-transport-native-unix-common High Product jar package name channel Low Product jar package name io Highest Product jar package name netty Highest Product jar package name netty Low Product jar package name unix Highest Product jar package name unix Low Product Manifest automatic-module-name io.netty.transport.unix.common Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://netty.io/ Low Product Manifest Bundle-Name Netty/Transport/Native/Unix/Common Medium Product Manifest bundle-symbolicname io.netty.transport-native-unix-common Medium Product Manifest Implementation-Title Netty/Transport/Native/Unix/Common High Product Manifest implementation-url https://netty.io/netty-transport-native-unix-common/ Low Product Manifest specification-title Netty/Transport/Native/Unix/Common Medium Version file version 4.1.130 High Version Manifest Implementation-Version 4.1.130.Final High
Related Dependencies io.netty.netty-transport-native-unix-common-4.1.130.Final.jar (shaded: io.netty:netty-transport-native-unix-common:4.1.130.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.netty.netty-transport-native-unix-common-4.1.130.Final.jar/META-INF/maven/io.netty/netty-transport-native-unix-common/pom.xml MD5: 3c16ab8c549e8b5e35e0a78fc421c303 SHA1: db4bf41bf34664dffd9405e42b726d539e75eb91 SHA256: 5f02bee3da578fec4f59f0125143e3497e890135c7acc01c5cdaba23608f88cb pkg:maven/io.netty/netty-transport-native-unix-common@4.1.130.Final netty-transport-native-unix-common-4.1.130.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/netty/netty-transport-native-unix-common/4.1.130.Final/netty-transport-native-unix-common-4.1.130.Final.jar MD5: 388abb78bf16bcf6f1bb1a3731b13703 SHA1: a29adec03f7dbefdab3b21523a15c35e794f3154 SHA256: cf5efc4168597d7cd14695b469418cac2a1134533f9a0c82ef0538d796fd39e1 pkg:maven/io.netty/netty-transport-native-unix-common@4.1.130.Final io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-2.21.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-2.21.0.jarMD5: 3c3fb5472064c8bcd96db0ba1a4d7d96SHA1: 095c1dd19f9cb95e2ea5fafa00ceec362f19cd3aSHA256: 2e07a33e29ebf63a4f2f25e46fe73d531beb552230b299888f9970c33b816a8f
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.instrumentation.opentelemetry-instrumentation-api High Vendor jar package name api Highest Vendor jar package name instrumentation Highest Vendor jar package name instrumentation Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor Manifest automatic-module-name io.opentelemetry.instrumentation_api Medium Vendor Manifest implementation-url https://github.com/open-telemetry/opentelemetry-java-instrumentation Low Vendor Manifest Implementation-Vendor OpenTelemetry High Product file name io.opentelemetry.instrumentation.opentelemetry-instrumentation-api High Product jar package name api Highest Product jar package name api Low Product jar package name instrumentation Highest Product jar package name instrumentation Low Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product Manifest automatic-module-name io.opentelemetry.instrumentation_api Medium Product Manifest Implementation-Title instrumentation-api High Product Manifest implementation-url https://github.com/open-telemetry/opentelemetry-java-instrumentation Low Version file version 2.21.0 High Version Manifest Implementation-Version 2.21.0 High
Related Dependencies io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-2.21.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-2.21.0.jar MD5: 3c3fb5472064c8bcd96db0ba1a4d7d96 SHA1: 095c1dd19f9cb95e2ea5fafa00ceec362f19cd3a SHA256: 2e07a33e29ebf63a4f2f25e46fe73d531beb552230b299888f9970c33b816a8f opentelemetry-instrumentation-api-2.21.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/instrumentation/opentelemetry-instrumentation-api/2.21.0/opentelemetry-instrumentation-api-2.21.0.jar MD5: 3c3fb5472064c8bcd96db0ba1a4d7d96 SHA1: 095c1dd19f9cb95e2ea5fafa00ceec362f19cd3a SHA256: 2e07a33e29ebf63a4f2f25e46fe73d531beb552230b299888f9970c33b816a8f pkg:maven/io.opentelemetry.instrumentation/opentelemetry-instrumentation-api@2.21.0 io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-incubator-2.21.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-incubator-2.21.0-alpha.jarMD5: ff6e136fcf85cb1ffc12202b96127127SHA1: 4e9011f1c6387c20b49f23cb4b075d1484f64d03SHA256: 29a21d5a5be749907de3e2202d6028e4722be18a85e434862085bf5dd1884f27
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-incubator High Vendor jar package name api Highest Vendor jar package name instrumentation Highest Vendor jar package name instrumentation Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor Manifest automatic-module-name io.opentelemetry.instrumentation_api_incubator Medium Vendor Manifest implementation-url https://github.com/open-telemetry/opentelemetry-java-instrumentation Low Vendor Manifest Implementation-Vendor OpenTelemetry High Product file name io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-incubator High Product jar package name api Highest Product jar package name api Low Product jar package name instrumentation Highest Product jar package name instrumentation Low Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product Manifest automatic-module-name io.opentelemetry.instrumentation_api_incubator Medium Product Manifest Implementation-Title instrumentation-api-incubator High Product Manifest implementation-url https://github.com/open-telemetry/opentelemetry-java-instrumentation Low Version file version 2.21.0.alpha High Version Manifest Implementation-Version 2.21.0-alpha High
Related Dependencies io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-incubator-2.21.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.instrumentation.opentelemetry-instrumentation-api-incubator-2.21.0-alpha.jar MD5: ff6e136fcf85cb1ffc12202b96127127 SHA1: 4e9011f1c6387c20b49f23cb4b075d1484f64d03 SHA256: 29a21d5a5be749907de3e2202d6028e4722be18a85e434862085bf5dd1884f27 opentelemetry-instrumentation-api-incubator-2.21.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/instrumentation/opentelemetry-instrumentation-api-incubator/2.21.0-alpha/opentelemetry-instrumentation-api-incubator-2.21.0-alpha.jar MD5: ff6e136fcf85cb1ffc12202b96127127 SHA1: 4e9011f1c6387c20b49f23cb4b075d1484f64d03 SHA256: 29a21d5a5be749907de3e2202d6028e4722be18a85e434862085bf5dd1884f27 pkg:maven/io.opentelemetry.instrumentation/opentelemetry-instrumentation-api-incubator@2.21.0-alpha io.opentelemetry.opentelemetry-api-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-api-1.55.0.jarMD5: 49d78a9675d767d602fd6ef1e2ad45cdSHA1: a71c43562e4d55c75997ccaa0c0513e5f881b703SHA256: 387b4bf98631fc2ede9470879a8ff28dd8c5cb2d3dcf5b6ef77f5ee2bdb7b4f1
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.opentelemetry-api High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor Manifest automatic-module-name io.opentelemetry.api Medium Product file name io.opentelemetry.opentelemetry-api High Product jar package name api Highest Product jar package name api Low Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product Manifest automatic-module-name io.opentelemetry.api Medium Product Manifest Implementation-Title all High Version file version 1.55.0 High Version Manifest Implementation-Version 1.55.0 High
Related Dependencies io.opentelemetry.opentelemetry-api-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-api-1.55.0.jar MD5: 49d78a9675d767d602fd6ef1e2ad45cd SHA1: a71c43562e4d55c75997ccaa0c0513e5f881b703 SHA256: 387b4bf98631fc2ede9470879a8ff28dd8c5cb2d3dcf5b6ef77f5ee2bdb7b4f1 io.opentelemetry.opentelemetry-common-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-common-1.55.0.jar MD5: 0176d68f570c526d6257bb57603fc777 SHA1: a979f45396c5332f43b9198ebf3eb52f5451e83f SHA256: fca14bb87309d1193347d179b91c63045fa05a856f1fbeec6ef61c4a7f81b227 io.opentelemetry.opentelemetry-context-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-context-1.55.0.jar MD5: f1e3c1cdfad72db43ca23f02c7b442da SHA1: a3e7c14152b6b6c62e0c64f991791fa0c5cbf02d SHA256: f34a4718b70446ec462703ced5cc2c9ad4c9b7c69dcb41d0f032ba51c625a3dd io.opentelemetry.opentelemetry-exporter-logging-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-exporter-logging-1.55.0.jar MD5: db368c1dd575972e8685cafb06f7c02c SHA1: e15ff02ddc81aa8e07438b40c8aa9eb8297275eb SHA256: 068ce0d75097e6ac655e179aa007d816204e8ac8892f193e15a7fa8d9b1c3ef8 io.opentelemetry.opentelemetry-sdk-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-1.55.0.jar MD5: 1c5e0a162ef1b99da83cc1a0324c8127 SHA1: 457309ce1ed276bd9b1f4029c97c22721f58f346 SHA256: d63231ea6fd33e0457c776a9aa8ae7ba778379b03119228ec56a5c8c16f9480e io.opentelemetry.opentelemetry-sdk-common-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-common-1.55.0.jar MD5: d2b6d07f9a62cc3011ab97d903e68acc SHA1: c43e69b259fe060b67520e4f011fa776a2dcca58 SHA256: e28bb83d0ae5a760ba95952daf820180ee7defb0c5783c9d21f9c00ada80020e io.opentelemetry.opentelemetry-sdk-extension-autoconfigure-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-extension-autoconfigure-1.55.0.jar MD5: e1ee40b0fa7f827b1f883e620c8af5cd SHA1: c513f20e376a495dc24fd28793632736660a705c SHA256: 88c32085a6f9cdd7725514ed1bbec3b196ecbd97d9375ca9b7f84c6163a48f1e io.opentelemetry.opentelemetry-sdk-extension-autoconfigure-spi-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-extension-autoconfigure-spi-1.55.0.jar MD5: b3d1b801b1ea32432690e43742e652c6 SHA1: f20fc03f7ea80cd062520f6cda3b1a61a107860f SHA256: 3ee1f647238bb77df7b7bde47bc87a35a7807b3c5bb389ca81b0ba16c77824ff io.opentelemetry.opentelemetry-sdk-logs-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-logs-1.55.0.jar MD5: 029da7104d349af7cb68f33f545d4747 SHA1: 0b4c62673fb2f2385b691d6600a194f98fbc8625 SHA256: d917bb833899057c7cbdbcc30290e816071b90e52c965693aaad4cc1b32ecc11 io.opentelemetry.opentelemetry-sdk-metrics-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-metrics-1.55.0.jar MD5: 3a1985ee03d33b6251bf10dbd5174d98 SHA1: 2db32c617c5d37c9ee69d58009edcc9a12ba6a24 SHA256: 6219d69c3abdd6113bee35df94826f48e84b742041f5124b5857a2b801f74573 io.opentelemetry.opentelemetry-sdk-trace-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-trace-1.55.0.jar MD5: b8b03a9eee54376a6874dfc8cb4714a6 SHA1: b0334b4edb3d14e181f9f4fdc40a0dd5a6bcbffd SHA256: e593660b9fad8bfdb5e981ccd392aa030f788d577c55f8bac3b6c4c6dae509bb opentelemetry-api-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-api/1.55.0/opentelemetry-api-1.55.0.jar MD5: 49d78a9675d767d602fd6ef1e2ad45cd SHA1: a71c43562e4d55c75997ccaa0c0513e5f881b703 SHA256: 387b4bf98631fc2ede9470879a8ff28dd8c5cb2d3dcf5b6ef77f5ee2bdb7b4f1 pkg:maven/io.opentelemetry/opentelemetry-api@1.55.0 io.opentelemetry.opentelemetry-api-incubator-1.55.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-api-incubator-1.55.0-alpha.jarMD5: ec570ebde29cda09d9833706bbdf17b4SHA1: 11a0532d53e3d2cb44d1ce1cf9c61a15986526f9SHA256: f7e8a9985491b3b5adf2ec198cdcd3fc9f51940f0f16baa25802c2d03ca51668
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.opentelemetry-api-incubator High Vendor jar package name api Highest Vendor jar package name api Low Vendor jar package name incubator Highest Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor Manifest automatic-module-name io.opentelemetry.api.incubator Medium Product file name io.opentelemetry.opentelemetry-api-incubator High Product jar package name api Highest Product jar package name api Low Product jar package name incubator Highest Product jar package name incubator Low Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product Manifest automatic-module-name io.opentelemetry.api.incubator Medium Product Manifest Implementation-Title incubator High Version file version 1.55.0.alpha High Version Manifest Implementation-Version 1.55.0-alpha High
Related Dependencies io.opentelemetry.opentelemetry-api-incubator-1.55.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-api-incubator-1.55.0-alpha.jar MD5: ec570ebde29cda09d9833706bbdf17b4 SHA1: 11a0532d53e3d2cb44d1ce1cf9c61a15986526f9 SHA256: f7e8a9985491b3b5adf2ec198cdcd3fc9f51940f0f16baa25802c2d03ca51668 opentelemetry-api-incubator-1.55.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-api-incubator/1.55.0-alpha/opentelemetry-api-incubator-1.55.0-alpha.jar MD5: ec570ebde29cda09d9833706bbdf17b4 SHA1: 11a0532d53e3d2cb44d1ce1cf9c61a15986526f9 SHA256: f7e8a9985491b3b5adf2ec198cdcd3fc9f51940f0f16baa25802c2d03ca51668 pkg:maven/io.opentelemetry/opentelemetry-api-incubator@1.55.0-alpha io.opentelemetry.opentelemetry-common-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-common-1.55.0.jarMD5: 0176d68f570c526d6257bb57603fc777SHA1: a979f45396c5332f43b9198ebf3eb52f5451e83fSHA256: fca14bb87309d1193347d179b91c63045fa05a856f1fbeec6ef61c4a7f81b227
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.opentelemetry-common High Vendor jar package name common Highest Vendor jar package name common Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor Manifest automatic-module-name io.opentelemetry.common Medium Product file name io.opentelemetry.opentelemetry-common High Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product Manifest automatic-module-name io.opentelemetry.common Medium Product Manifest Implementation-Title common High Version file version 1.55.0 High Version Manifest Implementation-Version 1.55.0 High
Related Dependencies io.opentelemetry.opentelemetry-context-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-context-1.55.0.jar MD5: f1e3c1cdfad72db43ca23f02c7b442da SHA1: a3e7c14152b6b6c62e0c64f991791fa0c5cbf02d SHA256: f34a4718b70446ec462703ced5cc2c9ad4c9b7c69dcb41d0f032ba51c625a3dd opentelemetry-common-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-common/1.55.0/opentelemetry-common-1.55.0.jar MD5: 0176d68f570c526d6257bb57603fc777 SHA1: a979f45396c5332f43b9198ebf3eb52f5451e83f SHA256: fca14bb87309d1193347d179b91c63045fa05a856f1fbeec6ef61c4a7f81b227 pkg:maven/io.opentelemetry/opentelemetry-common@1.55.0 io.opentelemetry.semconv.opentelemetry-semconv-1.37.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.semconv.opentelemetry-semconv-1.37.0.jarMD5: cf5af7a7b155e0322071a76209aec9c6SHA1: c6f9a930842c93c08fd87349db3defcbc228e925SHA256: 693ad6f04f29b4b593a04adef5f575d28b3a91ea3449ab5b1e1e2e5c6efc6cdc
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.semconv.opentelemetry-semconv High Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor jar package name semconv Highest Vendor jar package name semconv Low Vendor Manifest automatic-module-name io.opentelemetry.semconv Medium Product file name io.opentelemetry.semconv.opentelemetry-semconv High Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product jar package name semconv Highest Product jar package name semconv Low Product Manifest automatic-module-name io.opentelemetry.semconv Medium Product Manifest Implementation-Title opentelemetry-semconv High Version file version 1.37.0 High Version Manifest Implementation-Version 1.37.0 High
Related Dependencies io.opentelemetry.semconv.opentelemetry-semconv-1.37.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.semconv.opentelemetry-semconv-1.37.0.jar MD5: cf5af7a7b155e0322071a76209aec9c6 SHA1: c6f9a930842c93c08fd87349db3defcbc228e925 SHA256: 693ad6f04f29b4b593a04adef5f575d28b3a91ea3449ab5b1e1e2e5c6efc6cdc opentelemetry-semconv-1.37.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/semconv/opentelemetry-semconv/1.37.0/opentelemetry-semconv-1.37.0.jar MD5: cf5af7a7b155e0322071a76209aec9c6 SHA1: c6f9a930842c93c08fd87349db3defcbc228e925 SHA256: 693ad6f04f29b4b593a04adef5f575d28b3a91ea3449ab5b1e1e2e5c6efc6cdc pkg:maven/io.opentelemetry.semconv/opentelemetry-semconv@1.37.0 io.opentelemetry.semconv.opentelemetry-semconv-incubating-1.37.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.semconv.opentelemetry-semconv-incubating-1.37.0-alpha.jarMD5: 3fb5625f6cb38a2ccb7ef43e6c850e77SHA1: 3ac6c12a55b25cea4cb9ddab3f8187bd8175c5dbSHA256: 0ce785cab9b23fd3d64bab3c86d7c60572325df85184b759d6069ca9f316fc09
Evidence Type Source Name Value Confidence Vendor file name io.opentelemetry.semconv.opentelemetry-semconv-incubating High Vendor jar package name incubating Highest Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name opentelemetry Highest Vendor jar package name opentelemetry Low Vendor jar package name semconv Highest Vendor jar package name semconv Low Vendor Manifest automatic-module-name io.opentelemetry.semconv.incubating Medium Product file name io.opentelemetry.semconv.opentelemetry-semconv-incubating High Product jar package name incubating Highest Product jar package name incubating Low Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name opentelemetry Low Product jar package name semconv Highest Product jar package name semconv Low Product Manifest automatic-module-name io.opentelemetry.semconv.incubating Medium Product Manifest Implementation-Title opentelemetry-semconv-incubating High Version file version 1.37.0.alpha High Version Manifest Implementation-Version 1.37.0-alpha High
Related Dependencies io.opentelemetry.semconv.opentelemetry-semconv-incubating-1.37.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.opentelemetry.semconv.opentelemetry-semconv-incubating-1.37.0-alpha.jar MD5: 3fb5625f6cb38a2ccb7ef43e6c850e77 SHA1: 3ac6c12a55b25cea4cb9ddab3f8187bd8175c5db SHA256: 0ce785cab9b23fd3d64bab3c86d7c60572325df85184b759d6069ca9f316fc09 opentelemetry-semconv-incubating-1.37.0-alpha.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/semconv/opentelemetry-semconv-incubating/1.37.0-alpha/opentelemetry-semconv-incubating-1.37.0-alpha.jar MD5: 3fb5625f6cb38a2ccb7ef43e6c850e77 SHA1: 3ac6c12a55b25cea4cb9ddab3f8187bd8175c5db SHA256: 0ce785cab9b23fd3d64bab3c86d7c60572325df85184b759d6069ca9f316fc09 pkg:maven/io.opentelemetry.semconv/opentelemetry-semconv-incubating@1.37.0-alpha io.quarkus.arc.arc-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.arc.arc-3.30.6.jar
MD5: 7d2bb1947201e639b513cfc7e5fca644
SHA1: b644118078600efca5b22108e290ed6e20a95059
SHA256: 0bf95869f29d1a8920a0e1f162b7019941c1154904cb44b6e60b530560292177
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.arc.arc High Vendor jar package name arc Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.arc.arc High Product jar package name arc Highest Product jar package name arc Low Product jar package name impl Low Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title ArC - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title ArC - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies arc-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/arc/arc/3.30.6/arc-3.30.6.jar MD5: 7d2bb1947201e639b513cfc7e5fca644 SHA1: b644118078600efca5b22108e290ed6e20a95059 SHA256: 0bf95869f29d1a8920a0e1f162b7019941c1154904cb44b6e60b530560292177 pkg:maven/io.quarkus.arc/arc@3.30.6 arc-processor-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/arc/arc-processor/3.30.6/arc-processor-3.30.6.jar MD5: a49bacee60c3247deb4466411b7b961b SHA1: df4aaf5664b6c20ecc22652ffa58f029c489191a SHA256: f4845c9cf0b9d513f28a282dbc06aa2fcdbcae8dafb05e137963231e85a991ad pkg:maven/io.quarkus.arc/arc-processor@3.30.6 io.quarkus.arc.arc-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.arc.arc-3.30.6.jar MD5: 7d2bb1947201e639b513cfc7e5fca644 SHA1: b644118078600efca5b22108e290ed6e20a95059 SHA256: 0bf95869f29d1a8920a0e1f162b7019941c1154904cb44b6e60b530560292177 io.quarkus.quarkus-arc-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-arc-3.30.6.jar MD5: 1a86d01b638e20641471b59618970d02 SHA1: fd21d510f788c22bbc9758c85eba41f990d5c9bc SHA256: 4c4520041d7f0676f43084d84f0b8cb3d7d094bb4a6fcca9cf626456a01f56aa io.quarkus.quarkus-arc-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-arc-3.30.6.jar
MD5: 1a86d01b638e20641471b59618970d02
SHA1: fd21d510f788c22bbc9758c85eba41f990d5c9bc
SHA256: 4c4520041d7f0676f43084d84f0b8cb3d7d094bb4a6fcca9cf626456a01f56aa
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-arc High Vendor jar package name arc Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-arc High Product jar package name arc Highest Product jar package name arc Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - ArC - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - ArC - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-arc-3.30.6.jar (shaded: io.quarkus:quarkus-arc:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-arc-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-arc/pom.xml MD5: 3f3497a65c973d1219fbcf45ce85e783 SHA1: d6885d53b9266abe868e46eb34796499329968dd SHA256: 483bad816416b453c85492501d52d4e5c6e1eb362063edc6dc461b89afd45c20 pkg:maven/io.quarkus/quarkus-arc@3.30.6 quarkus-arc-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc/3.30.6/quarkus-arc-3.30.6.jar MD5: 1a86d01b638e20641471b59618970d02 SHA1: fd21d510f788c22bbc9758c85eba41f990d5c9bc SHA256: 4c4520041d7f0676f43084d84f0b8cb3d7d094bb4a6fcca9cf626456a01f56aa pkg:maven/io.quarkus/quarkus-arc@3.30.6 io.quarkus.quarkus-bootstrap-runner-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.quarkus.quarkus-bootstrap-runner-3.30.6.jar
MD5: 0ee3ae3f2d8d42ce12bd952306d6c757
SHA1: f09f83be756656aaf86badb78d6cbe5b3d710d85
SHA256: a762c1c83bb9d21ab967b89d581ec5cd5bbddda0529ef97ac76b37f10b741d36
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-bootstrap-runner High Vendor jar package name bootstrap Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-bootstrap-runner High Product jar package name bootstrap Highest Product jar package name bootstrap Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runner Highest Product jar package name runner Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Bootstrap - Runner High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Bootstrap - Runner Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-bootstrap-runner-3.30.6.jar (shaded: io.quarkus:quarkus-bootstrap-runner:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.quarkus.quarkus-bootstrap-runner-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-bootstrap-runner/pom.xml MD5: 61aaca8582e9b82b5c512e9045c5491f SHA1: 6da38d20f9fa67e945fba3504703f8a89fc52155 SHA256: f7a9b18b3eb8fb5acb0fb0a33e68e32c02ccc2afc7790b0cab882acbbc81803f pkg:maven/io.quarkus/quarkus-bootstrap-runner@3.30.6 io.quarkus.quarkus-bootstrap-runner-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.quarkus.quarkus-bootstrap-runner-3.30.6.jar MD5: 0ee3ae3f2d8d42ce12bd952306d6c757 SHA1: f09f83be756656aaf86badb78d6cbe5b3d710d85 SHA256: a762c1c83bb9d21ab967b89d581ec5cd5bbddda0529ef97ac76b37f10b741d36 io.quarkus.quarkus-classloader-commons-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.quarkus.quarkus-classloader-commons-3.30.6.jar MD5: 87c70d85bf8d1533d03fc1a507ec8b3c SHA1: 1d0a94683ee209584b49abdbbfb3be0dcc411607 SHA256: 847fa06fccc8443075c9bb223ac474253260bb06c173d90e629bbd3361b00c55 io.quarkus.quarkus-development-mode-spi-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.quarkus.quarkus-development-mode-spi-3.30.6.jar MD5: d7d1c00ca45afbcb452c28fbba726124 SHA1: 6014731c19ccec7efa9f063b616a51157866866f SHA256: 9736fc687b020929fdcc9bda7d38ad28540188aae8f5039e612e71c3f8c1080f io.quarkus.quarkus-vertx-latebound-mdc-provider-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.quarkus.quarkus-vertx-latebound-mdc-provider-3.30.6.jar MD5: 7e89bac39cbeb2ccc893c448ba800f27 SHA1: 46e2aeff2c5719f55149520b7d9813491cb34948 SHA256: 837f8e791ba43a90283cd96aca1e34c989385780332ec48e9099a8a1a89f8f74 quarkus-bootstrap-runner-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-bootstrap-runner/3.30.6/quarkus-bootstrap-runner-3.30.6.jar MD5: 0ee3ae3f2d8d42ce12bd952306d6c757 SHA1: f09f83be756656aaf86badb78d6cbe5b3d710d85 SHA256: a762c1c83bb9d21ab967b89d581ec5cd5bbddda0529ef97ac76b37f10b741d36 pkg:maven/io.quarkus/quarkus-bootstrap-runner@3.30.6 io.quarkus.quarkus-classloader-commons-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.quarkus.quarkus-classloader-commons-3.30.6.jar
MD5: 87c70d85bf8d1533d03fc1a507ec8b3c
SHA1: 1d0a94683ee209584b49abdbbfb3be0dcc411607
SHA256: 847fa06fccc8443075c9bb223ac474253260bb06c173d90e629bbd3361b00c55
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-classloader-commons High Vendor jar package name commons Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-classloader-commons High Product jar package name classloading Low Product jar package name commons Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Bootstrap - Classloader common utilities High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Bootstrap - Classloader common utilities Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-classloader-commons-3.30.6.jar (shaded: io.quarkus:quarkus-classloader-commons:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.quarkus.quarkus-classloader-commons-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-classloader-commons/pom.xml MD5: d810725f161dac6b41623bd4481acbee SHA1: 77c3dbaf97e2d79de251906b54c5b6c27f32a5fb SHA256: 480cf9cb851d3f2e018e79d14a0f88002926410d9761a192c43db3eebc8630ae pkg:maven/io.quarkus/quarkus-classloader-commons@3.30.6 io.quarkus.quarkus-development-mode-spi-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.quarkus.quarkus-development-mode-spi-3.30.6.jar MD5: d7d1c00ca45afbcb452c28fbba726124 SHA1: 6014731c19ccec7efa9f063b616a51157866866f SHA256: 9736fc687b020929fdcc9bda7d38ad28540188aae8f5039e612e71c3f8c1080f io.quarkus.quarkus-vertx-latebound-mdc-provider-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.quarkus.quarkus-vertx-latebound-mdc-provider-3.30.6.jar MD5: 7e89bac39cbeb2ccc893c448ba800f27 SHA1: 46e2aeff2c5719f55149520b7d9813491cb34948 SHA256: 837f8e791ba43a90283cd96aca1e34c989385780332ec48e9099a8a1a89f8f74 quarkus-classloader-commons-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-classloader-commons/3.30.6/quarkus-classloader-commons-3.30.6.jar MD5: 87c70d85bf8d1533d03fc1a507ec8b3c SHA1: 1d0a94683ee209584b49abdbbfb3be0dcc411607 SHA256: 847fa06fccc8443075c9bb223ac474253260bb06c173d90e629bbd3361b00c55 pkg:maven/io.quarkus/quarkus-classloader-commons@3.30.6 io.quarkus.quarkus-container-image-jib-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-container-image-jib-3.30.6.jar
MD5: a97b9a0cd25c536ac3b95f377240bd3f
SHA1: ef9bc72af1ebc42e78169a96465aefb361b00d1d
SHA256: 0010757c8c86d6e6bb31bedc1793ea13f9b8e1ba168cb44b248cb35a4fee17ec
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-container-image-jib High Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-container-image-jib High Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Container Image - Jib High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Container Image - Jib Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-container-image-jib-3.30.6.jar (shaded: io.quarkus:quarkus-container-image-jib:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-container-image-jib-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-container-image-jib/pom.xml MD5: eca28ce87fb0fcc2660293c9036fdbb3 SHA1: 9e7907878a9ab19787b497a43fa83cfa42411987 SHA256: 8df176f6a350d4133619d6fc398f550ed59e736cc93d94bfca606e300b152b87 pkg:maven/io.quarkus/quarkus-container-image-jib@3.30.6 io.quarkus.quarkus-container-image-jib-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-container-image-jib-3.30.6.jar MD5: a97b9a0cd25c536ac3b95f377240bd3f SHA1: ef9bc72af1ebc42e78169a96465aefb361b00d1d SHA256: 0010757c8c86d6e6bb31bedc1793ea13f9b8e1ba168cb44b248cb35a4fee17ec quarkus-container-image-jib-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-container-image-jib/3.30.6/quarkus-container-image-jib-3.30.6.jar MD5: a97b9a0cd25c536ac3b95f377240bd3f SHA1: ef9bc72af1ebc42e78169a96465aefb361b00d1d SHA256: 0010757c8c86d6e6bb31bedc1793ea13f9b8e1ba168cb44b248cb35a4fee17ec pkg:maven/io.quarkus/quarkus-container-image-jib@3.30.6 io.quarkus.quarkus-core-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-core-3.30.6.jar
MD5: 36e4013f1439c7e0ff77b3f1e5a0d6e7
SHA1: f74c846903fe65b034b4d20a986ce81dbca8ff7d
SHA256: 1fe86dc63702be41fcfdf53262495fbf30aa00b46f0b3f7cd288671578e418c9
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-core High Vendor jar package name io Low Vendor jar package name quarkus Low Vendor jar package name runtime Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-core High Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Core - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Core - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-fs-util-1.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-fs-util-1.2.0.jarMD5: 22005094fe4e648430b36888b9283e80SHA1: 9d80184036981d6c6174e18a416a295ed0be8b09SHA256: 2237355335bb23abfcb0750bd34a1ba2d66fa95a28c6c0cde39f7145664b83e0
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-fs-util High Vendor hint analyzer vendor redhat Highest Vendor jar package name fs Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url https://quarkus.io/ Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name io.quarkus.quarkus-fs-util High Product jar package name fs Highest Product jar package name fs Low Product jar package name io Highest Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name util Highest Product jar package name util Low Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Quarkus - FS Util High Product Manifest implementation-url https://quarkus.io/ Low Product Manifest specification-title Quarkus - FS Util Medium Version file version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High
Related Dependencies io.quarkus.quarkus-fs-util-1.2.0.jar (shaded: io.quarkus:quarkus-fs-util:1.2.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-fs-util-1.2.0.jar/META-INF/maven/io.quarkus/quarkus-fs-util/pom.xml MD5: 65c9dd4cad304691641a90b9b62a9837 SHA1: 656d823ed02049ea0f232cc8374d43094a50f42d SHA256: 7fb394a72b0452fa64cc4ee5b57bca7e99aaa86c7237dc229e469e79ba60e61f pkg:maven/io.quarkus/quarkus-fs-util@1.2.0 io.quarkus.quarkus-fs-util-1.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-fs-util-1.2.0.jar MD5: 22005094fe4e648430b36888b9283e80 SHA1: 9d80184036981d6c6174e18a416a295ed0be8b09 SHA256: 2237355335bb23abfcb0750bd34a1ba2d66fa95a28c6c0cde39f7145664b83e0 quarkus-fs-util-1.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-fs-util/1.2.0/quarkus-fs-util-1.2.0.jar MD5: 22005094fe4e648430b36888b9283e80 SHA1: 9d80184036981d6c6174e18a416a295ed0be8b09 SHA256: 2237355335bb23abfcb0750bd34a1ba2d66fa95a28c6c0cde39f7145664b83e0 pkg:maven/io.quarkus/quarkus-fs-util@1.2.0 CVE-2022-21724 suppress
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue. CWE-665 Improper Initialization
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-4116 suppress
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution. NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-6267 suppress
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security. CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-26291 suppress
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html CWE-346 Origin Validation Error
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2020-1714 suppress
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution. CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-0981 suppress
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended. CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2023-4853 suppress
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. CWE-148 Improper Neutralization of Input Leaders, CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,TECHNICAL_DESCRIPTION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - EXPLOIT,MITIGATION,TECHNICAL_DESCRIPTION,VENDOR_ADVISORY secalert@redhat.com - ISSUE_TRACKING,VENDOR_ADVISORY secalert@redhat.com - MITIGATION,VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29428 suppress
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. This vulnerability impacted builds using precompiled script plugins written in Kotlin DSL and tests for Gradle plugins written using ProjectBuilder or TestKit. If you are on Windows or modern versions of macOS, you are not vulnerable. If you are on a Unix-like operating system with the "sticky" bit set on your system temporary directory, you are not vulnerable. The problem has been patched and released with Gradle 7.0. As a workaround, on Unix-like operating systems, ensure that the "sticky" bit is set. This only allows the original user (or root) to delete a file. If you are unable to change the permissions of the system temporary directory, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. For additional details refer to the referenced GitHub Security Advisory. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions
CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.4) Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2020-13692 suppress
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: HIGH (7.7) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2017-18640 suppress
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564. CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-25649 suppress
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-28491 suppress
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY report@snyk.io - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY report@snyk.io - PATCH,THIRD_PARTY_ADVISORY report@snyk.io - PATCH,THIRD_PARTY_ADVISORY report@snyk.io - PATCH,THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-37136 suppress
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37137 suppress
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37714 suppress
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes. CWE-248 Uncaught Exception, CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - RELEASE_NOTES,VENDOR_ADVISORY security-advisories@github.com - RELEASE_NOTES,VENDOR_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-42003 suppress
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-42004 suppress
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2023-1584 suppress
A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens. NVD-CWE-noinfo, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2020-25638 suppress
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (7.4) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert@redhat.com - MAILING_LIST,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29427 suppress
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was introduced in the wake of the "A Confusing Dependency" blog post. In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file. This may change how dependencies are resolved for Gradle plugins and build scripts. For builds that are vulnerable, there are two risks: 1) Information disclosure: Gradle could make dependency requests to repositories outside your organization and leak internal package identifiers. 2) Dependency poisoning/Dependency confusion: Gradle could download a malicious binary from a repository outside your organization due to name squatting. For a full example and more details refer to the referenced GitHub Security Advisory. The problem has been patched and released with Gradle 7.0. Users relying on this feature should upgrade their build as soon as possible. As a workaround, users may use a company repository which has the right rules for fetching packages from public repositories, or use project level repository content filtering, inside `buildscript.repositories`. This option is available since Gradle 5.1 when the feature was introduced. CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:1.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-20328 suppress
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption. CWE-295 Improper Certificate Validation
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:1.6/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:A/AC:M/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-21363 suppress
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.6) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2019-14900 suppress
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43797 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-0044 suppress
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-21295 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has meaning and needs to be checked. An attacker can smuggle requests inside the body as it gets downgraded from HTTP/2 to HTTP/1.1. For an example attack refer to the linked GitHub Advisory. Users are only affected if all of this is true: `HTTP2MultiplexCodec` or `Http2FrameCodec` is used, `Http2StreamFrameToHttpObjectCodec` is used to convert to HTTP/1.1 objects, and these HTTP/1.1 objects are forwarded to another remote peer. This has been patched in 4.1.60.Final As a workaround, the user can do the validation by themselves by implementing a custom `ChannelInboundHandler` that is put in the `ChannelPipeline` behind `Http2StreamFrameToHttpObjectCodec`. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-21409 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-2471 suppress
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H). NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.9) Vector: /AV:N/AC:M/Au:S/C:C/I:N/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2021-38153 suppress
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0. CWE-203 Observable Discrepancy
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-21290 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - EXPLOIT,THIRD_PARTY_ADVISORY security-advisories@github.com - MAILING_LIST,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29429 suppress
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system temporary directory first. Sensitive information contained in these files can be exposed to other local users on the same system. If you do not use the `TextResourceFactory` API, you are not vulnerable. As of Gradle 7.0, uses of the system temporary directory have been moved to the Gradle User Home directory. By default, this directory is restricted to the user running the build. As a workaround, set a more restrictive umask that removes read access to other users. When files are created in the system temporary directory, they will not be accessible to other users. If you are unable to change your system's umask, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. CWE-377 Insecure Temporary File
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-1728 suppress
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors. CWE-358 Improperly Implemented Security Check for Standard, CWE-1021 Improper Restriction of Rendered UI Layers or Frames
CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-10693 suppress
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages. CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-25633 suppress
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-20289 suppress
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-28170 suppress
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. CWE-20 Improper Input Validation, CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-3642 suppress
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. CWE-203 Observable Discrepancy
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.6/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-25724 suppress
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected. CWE-567 Unsynchronized Access to Shared Data in a Multithreaded Context
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve-coordination@google.com - EXPLOIT,PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2023-0481 suppress
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
io.quarkus.quarkus-hibernate-orm-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-3.30.6.jar
MD5: cceca7e1228581bdb9313b52541b9561
SHA1: 16fefa2f60687f3c2eed3565cedcce5839a21aec
SHA256: ac9de9795ebac95348cb4d06a6c3e1515f44c8bd131bdcf90a1500d15fcc27f0
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-hibernate-orm High Vendor jar package name hibernate Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-hibernate-orm High Product jar package name hibernate Highest Product jar package name hibernate Low Product jar package name orm Highest Product jar package name orm Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Hibernate ORM - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Hibernate ORM - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-hibernate-orm-3.30.6.jar (shaded: io.quarkus:quarkus-hibernate-orm:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-hibernate-orm/pom.xml MD5: 199141bf54a15bc441f8e77fc609fa39 SHA1: cce0561bf2bdcd01f420950f87b1a1bf3a25cca6 SHA256: da9f042a085c8e27f3d92aadf2557798674b65f52de8b87da5c9f500353fe1e5 pkg:maven/io.quarkus/quarkus-hibernate-orm@3.30.6 io.quarkus.quarkus-hibernate-orm-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-3.30.6.jar MD5: cceca7e1228581bdb9313b52541b9561 SHA1: 16fefa2f60687f3c2eed3565cedcce5839a21aec SHA256: ac9de9795ebac95348cb4d06a6c3e1515f44c8bd131bdcf90a1500d15fcc27f0 io.quarkus.quarkus-hibernate-orm-panache-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-panache-3.30.6.jar MD5: 2c73b0cd67e9e766b88c178054a2bdc4 SHA1: f85012539e3bbe821945123f1b88c0c23246eca6 SHA256: f3b0990ad3fe9f1735fe004fc66998c0fcdc3ebdd1ab11a2554fb7ca8dbce175 io.quarkus.quarkus-hibernate-orm-panache-common-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-panache-common-3.30.6.jar MD5: 4cc83466ff487f284cdda59b967238dc SHA1: 1456eccda5d17c0e5ffb9a7de17e3a087b0762d3 SHA256: 656f475a8739d925f0dea566397e2c6ea1cf49f5f95e246391a55012cb49e686 quarkus-hibernate-orm-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-orm/3.30.6/quarkus-hibernate-orm-3.30.6.jar MD5: cceca7e1228581bdb9313b52541b9561 SHA1: 16fefa2f60687f3c2eed3565cedcce5839a21aec SHA256: ac9de9795ebac95348cb4d06a6c3e1515f44c8bd131bdcf90a1500d15fcc27f0 pkg:maven/io.quarkus/quarkus-hibernate-orm@3.30.6 CVE-2020-25638 suppress
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (7.4) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert@redhat.com - MAILING_LIST,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-14900 suppress
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-hibernate-orm-panache-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-panache-3.30.6.jar
MD5: 2c73b0cd67e9e766b88c178054a2bdc4
SHA1: f85012539e3bbe821945123f1b88c0c23246eca6
SHA256: f3b0990ad3fe9f1735fe004fc66998c0fcdc3ebdd1ab11a2554fb7ca8dbce175
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-hibernate-orm-panache High Vendor jar package name hibernate Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-hibernate-orm-panache High Product jar package name hibernate Highest Product jar package name hibernate Low Product jar package name orm Highest Product jar package name orm Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Hibernate ORM with Panache - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Hibernate ORM with Panache - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-hibernate-orm-panache-3.30.6.jar (shaded: io.quarkus:quarkus-hibernate-orm-panache:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-panache-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-hibernate-orm-panache/pom.xml MD5: 3bed599186cc431319c8672e5d62b230 SHA1: a5b7cd8760ab220ea852508cf3aea9b1b16defc0 SHA256: 9f607bf00d9221e9acfeb79dc2611edd77dfd3c914dc01f7a01ec003abf35786 pkg:maven/io.quarkus/quarkus-hibernate-orm-panache@3.30.6 io.quarkus.quarkus-hibernate-orm-panache-common-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-orm-panache-common-3.30.6.jar MD5: 4cc83466ff487f284cdda59b967238dc SHA1: 1456eccda5d17c0e5ffb9a7de17e3a087b0762d3 SHA256: 656f475a8739d925f0dea566397e2c6ea1cf49f5f95e246391a55012cb49e686 quarkus-hibernate-orm-panache-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-orm-panache/3.30.6/quarkus-hibernate-orm-panache-3.30.6.jar MD5: 2c73b0cd67e9e766b88c178054a2bdc4 SHA1: f85012539e3bbe821945123f1b88c0c23246eca6 SHA256: f3b0990ad3fe9f1735fe004fc66998c0fcdc3ebdd1ab11a2554fb7ca8dbce175 pkg:maven/io.quarkus/quarkus-hibernate-orm-panache@3.30.6 CVE-2020-25638 suppress
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (7.4) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert@redhat.com - MAILING_LIST,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-14900 suppress
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-hibernate-validator-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-validator-3.30.6.jar
MD5: 0fe0ce7b9bae21f8671b7640228d7eda
SHA1: c2e9cc4d6ff8c4a37120741b2d4c4bff45ad63ff
SHA256: b9b641579c84be47a1cef39051ba0fe98cedfae969f868e989f64e8c96211ca1
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-hibernate-validator High Vendor jar package name hibernate Low Vendor jar package name io Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-hibernate-validator High Product jar package name hibernate Highest Product jar package name hibernate Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name validator Highest Product jar package name validator Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Hibernate Validator - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Hibernate Validator - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-hibernate-validator-3.30.6.jar (shaded: io.quarkus:quarkus-hibernate-validator:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-validator-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-hibernate-validator/pom.xml MD5: 517bfcfb9f96c43911e8fe798844b940 SHA1: 91d3e122214f6f11afc1ed2daf09c361a9b52bff SHA256: 46adf111dcdaade5f77c2b8d6c51d571f63204760be24e9810a2a953fab399f7 pkg:maven/io.quarkus/quarkus-hibernate-validator@3.30.6 io.quarkus.quarkus-hibernate-validator-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-hibernate-validator-3.30.6.jar MD5: 0fe0ce7b9bae21f8671b7640228d7eda SHA1: c2e9cc4d6ff8c4a37120741b2d4c4bff45ad63ff SHA256: b9b641579c84be47a1cef39051ba0fe98cedfae969f868e989f64e8c96211ca1 quarkus-hibernate-validator-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-validator/3.30.6/quarkus-hibernate-validator-3.30.6.jar MD5: 0fe0ce7b9bae21f8671b7640228d7eda SHA1: c2e9cc4d6ff8c4a37120741b2d4c4bff45ad63ff SHA256: b9b641579c84be47a1cef39051ba0fe98cedfae969f868e989f64e8c96211ca1 pkg:maven/io.quarkus/quarkus-hibernate-validator@3.30.6 CVE-2025-15104 suppress
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd). CWE-918 Server-Side Request Forgery (SSRF)
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2023-1932 suppress
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-jaxb-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-jaxb-3.30.6.jar
MD5: fcbfed55a660a6fdb2acb6156f3c6858
SHA1: c1ed5de66c9d5b1fd2eba1cd7b9bed72e809f6bc
SHA256: cbb59d173be0598b84fdb8a2b07f069acee5e832bb0f041ce7b10ae2ba70fa54
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-jaxb High Vendor jar package name io Low Vendor jar package name jaxb Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-jaxb High Product jar package name jaxb Highest Product jar package name jaxb Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - JAXB - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - JAXB - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-jdbc-postgresql-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-jdbc-postgresql-3.30.6.jar
MD5: cbbdcdc8abb9fe432a665831f3244322
SHA1: 39d2c606b913f1cc292906d259d11c5dc8d8f1ca
SHA256: 52ddb2c5a7f17c7f0f6b58fc554af4c077665cf7281dba3bd0be2507ee5c3882
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-jdbc-postgresql High Vendor jar package name io Low Vendor jar package name jdbc Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-jdbc-postgresql High Product jar package name jdbc Highest Product jar package name jdbc Low Product jar package name postgresql Highest Product jar package name postgresql Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - JDBC - PostgreSQL - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - JDBC - PostgreSQL - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-jdbc-postgresql-3.30.6.jar (shaded: io.quarkus:quarkus-jdbc-postgresql:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-jdbc-postgresql-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-jdbc-postgresql/pom.xml MD5: 4672ad39306b4e8df64be5d3281c8f9a SHA1: fba954b833ee49fe10c92f704d02f73f4896930d SHA256: cf990866f1f7e18f8b1e66b7920f15f067f5d972ebfcb760607661e2c4c1ec04 pkg:maven/io.quarkus/quarkus-jdbc-postgresql@3.30.6 io.quarkus.quarkus-jdbc-postgresql-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-jdbc-postgresql-3.30.6.jar MD5: cbbdcdc8abb9fe432a665831f3244322 SHA1: 39d2c606b913f1cc292906d259d11c5dc8d8f1ca SHA256: 52ddb2c5a7f17c7f0f6b58fc554af4c077665cf7281dba3bd0be2507ee5c3882 quarkus-jdbc-postgresql-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-jdbc-postgresql/3.30.6/quarkus-jdbc-postgresql-3.30.6.jar MD5: cbbdcdc8abb9fe432a665831f3244322 SHA1: 39d2c606b913f1cc292906d259d11c5dc8d8f1ca SHA256: 52ddb2c5a7f17c7f0f6b58fc554af4c077665cf7281dba3bd0be2507ee5c3882 pkg:maven/io.quarkus/quarkus-jdbc-postgresql@3.30.6 CVE-2015-0244 suppress
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-3166 suppress
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-10211 suppress
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. CWE-94 Improper Control of Generation of Code ('Code Injection'), NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2018-1115 suppress
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-0241 suppress
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read, or (2) crafted timestamp formatting template, which triggers a buffer overflow. CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-0242 suppress
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-0243 suppress
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-10127 suppress
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:2.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:L/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2020-25695 suppress
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2016-5423 suppress
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types. CWE-476 NULL Pointer Dereference
CVSSv3:
Base Score: HIGH (8.3) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - PATCH,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2016-7048 suppress
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2020-25694 suppress
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CWE-327 Use of a Broken or Risky Cryptographic Algorithm
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-23214 suppress
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.1) Vector: /AV:N/AC:H/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2019-10128 suppress
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.1) Vector: /AV:L/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-3167 suppress
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack. CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2016-0768 suppress
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2016-0773 suppress
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2017-7484 suppress
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access. CWE-285 Improper Authorization, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2016-5424 suppress
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv3:
Base Score: HIGH (7.1) Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:1.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2017-14798 suppress
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. CWE-61 UNIX Symbolic Link (Symlink) Following, CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.9) Vector: /AV:L/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions:
CVE-2019-10210 suppress
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. CWE-522 Insufficiently Protected Credentials
CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0061 suppress
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0063 suppress
Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0064 suppress
Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector. CWE-189 Numeric Errors
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0065 suppress
Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, a different vulnerability than CVE-2014-0063. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-5288 suppress
The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt. CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2007-2138 suppress
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings." CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - BROKEN_LINK cve@mitre.org - BROKEN_LINK cve@mitre.org - BROKEN_LINK cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2014-0062 suppress
Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window. CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv2:
Base Score: MEDIUM (4.9) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0067 suppress
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-8161 suppress
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-3165 suppress
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-3393 suppress
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0060 suppress
PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0066 suppress
The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2010-0733 suppress
Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations. CWE-189 Numeric Errors
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH secalert@redhat.com - PATCH Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-liquibase-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-liquibase-3.30.6.jar
MD5: 3ea4ce87175a63a83d539e6e8bbec868
SHA1: d3b799ef4639cdda4ceacc9b611d1c0c16140806
SHA256: cb65b6c419ae31b33533474e26d4033431c84f2fcd6c44a01602cfa41bee3fb3
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-liquibase High Vendor jar package name io Low Vendor jar package name liquibase Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-liquibase High Product jar package name liquibase Highest Product jar package name liquibase Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Liquibase - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Liquibase - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-liquibase-common-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-liquibase-common-3.30.6.jar MD5: 1f3bdd3abd24e440941da8859b26ed90 SHA1: 2527ed4f5222982b8f1ee297b0d97bb25e4f46b5 SHA256: 5dd7bd2ac85f828d2d33119e20a149b51f83182b67d385cf98137bc20f45b8a1 quarkus-liquibase-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-liquibase/3.30.6/quarkus-liquibase-3.30.6.jar MD5: 3ea4ce87175a63a83d539e6e8bbec868 SHA1: d3b799ef4639cdda4ceacc9b611d1c0c16140806 SHA256: cb65b6c419ae31b33533474e26d4033431c84f2fcd6c44a01602cfa41bee3fb3 pkg:maven/io.quarkus/quarkus-liquibase@3.30.6 CVE-2022-0839 suppress
Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-mutiny-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-mutiny-3.30.6.jar
MD5: c74c53390dd8237a4b46711f6f8f439d
SHA1: 7ad923f9d5a1f9a8cd32fc88b2c27e4708e2ba86
SHA256: f97153ec08c818b7307ec33d16cf4d92df76364228c78fe0365b29d6ea999fb3
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-mutiny High Vendor jar package name io Low Vendor jar package name mutiny Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-mutiny High Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Mutiny - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Mutiny - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-mutiny-3.30.6.jar (shaded: io.quarkus:quarkus-mutiny:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-mutiny-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-mutiny/pom.xml MD5: 35b60d74db916eab381b62296fdb9213 SHA1: cca24b8f2143bf5146f8c6860c0c1272c1e6182d SHA256: 2c8ed5dba8a3c859817b8b70d86dc9ccf9d8bc66acc2ccd4a002f98ce3800468 pkg:maven/io.quarkus/quarkus-mutiny@3.30.6 io.quarkus.quarkus-mutiny-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-mutiny-3.30.6.jar MD5: c74c53390dd8237a4b46711f6f8f439d SHA1: 7ad923f9d5a1f9a8cd32fc88b2c27e4708e2ba86 SHA256: f97153ec08c818b7307ec33d16cf4d92df76364228c78fe0365b29d6ea999fb3 io.quarkus.quarkus-mutiny-reactive-streams-operators-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-mutiny-reactive-streams-operators-3.30.6.jar MD5: aa1ec3e405fd22a2ee124c97a9794eb0 SHA1: 69340b5aca2e12660d07e1881d290f0f776776c6 SHA256: 1f5fcfe8db3ca487835c03bc7b812c2c52b0f935648826b985dfda4b7cd86459 quarkus-mutiny-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-mutiny/3.30.6/quarkus-mutiny-3.30.6.jar MD5: c74c53390dd8237a4b46711f6f8f439d SHA1: 7ad923f9d5a1f9a8cd32fc88b2c27e4708e2ba86 SHA256: f97153ec08c818b7307ec33d16cf4d92df76364228c78fe0365b29d6ea999fb3 pkg:maven/io.quarkus/quarkus-mutiny@3.30.6 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-mutiny-reactive-streams-operators-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-mutiny-reactive-streams-operators-3.30.6.jar
MD5: aa1ec3e405fd22a2ee124c97a9794eb0
SHA1: 69340b5aca2e12660d07e1881d290f0f776776c6
SHA256: 1f5fcfe8db3ca487835c03bc7b812c2c52b0f935648826b985dfda4b7cd86459
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-mutiny-reactive-streams-operators High Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-mutiny-reactive-streams-operators High Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - SmallRye Mutiny Reactive Streams Operators - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - SmallRye Mutiny Reactive Streams Operators - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-mutiny-reactive-streams-operators-3.30.6.jar (shaded: io.quarkus:quarkus-mutiny-reactive-streams-operators:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-mutiny-reactive-streams-operators-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-mutiny-reactive-streams-operators/pom.xml MD5: 21b2475291aa4df436599f4c3d2f3cf7 SHA1: 8fc2a46702e84a548dbdd0d80f3f4dd895fd076f SHA256: fc802bbf44454df4c3b5cfb3fb199acdbfc407ad04408a67ecafe435f1142ff7 pkg:maven/io.quarkus/quarkus-mutiny-reactive-streams-operators@3.30.6 quarkus-mutiny-reactive-streams-operators-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-mutiny-reactive-streams-operators/3.30.6/quarkus-mutiny-reactive-streams-operators-3.30.6.jar MD5: aa1ec3e405fd22a2ee124c97a9794eb0 SHA1: 69340b5aca2e12660d07e1881d290f0f776776c6 SHA256: 1f5fcfe8db3ca487835c03bc7b812c2c52b0f935648826b985dfda4b7cd86459 pkg:maven/io.quarkus/quarkus-mutiny-reactive-streams-operators@3.30.6 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-netty-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-netty-3.30.6.jar
MD5: be5f795a5dc49219012ebe4167ed38e5
SHA1: 1475255e8f4573361d1b9aa4cf93bd9a57a4570a
SHA256: 4731eb231441a79371aec695eb42c758cc2b16291314402454bc43b766919abb
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-netty High Vendor jar package name io Low Vendor jar package name netty Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-netty High Product jar package name netty Highest Product jar package name netty Low Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Netty - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Netty - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-netty-3.30.6.jar (shaded: io.quarkus:quarkus-netty:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-netty-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-netty/pom.xml MD5: 4e007fbc51b9bbe8f8af14cda10bb5b4 SHA1: 5b1ded469b4a80e7edc59fbcda5432295c3ff9f4 SHA256: a27323bc3deff1e3e4b9dbae784c3d5e1c6436357edd196770c37a742458310f pkg:maven/io.quarkus/quarkus-netty@3.30.6 io.quarkus.quarkus-netty-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-netty-3.30.6.jar MD5: be5f795a5dc49219012ebe4167ed38e5 SHA1: 1475255e8f4573361d1b9aa4cf93bd9a57a4570a SHA256: 4731eb231441a79371aec695eb42c758cc2b16291314402454bc43b766919abb quarkus-netty-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-netty/3.30.6/quarkus-netty-3.30.6.jar MD5: be5f795a5dc49219012ebe4167ed38e5 SHA1: 1475255e8f4573361d1b9aa4cf93bd9a57a4570a SHA256: 4731eb231441a79371aec695eb42c758cc2b16291314402454bc43b766919abb pkg:maven/io.quarkus/quarkus-netty@3.30.6 CVE-2019-20444 suppress
HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold." CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-20445 suppress
HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,RELEASE_NOTES,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,RELEASE_NOTES,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2025-55163 suppress
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.124.Final and 4.2.4.Final, Netty is vulnerable to MadeYouReset DDoS. This is a logical vulnerability in the HTTP/2 protocol, that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit - which results in resource exhaustion and distributed denial of service. This issue has been patched in versions 4.1.124.Final and 4.2.4.Final. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv4:
Base Score: HIGH (8.2) Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2019-16869 suppress
Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-37136 suppress
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37137 suppress
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-41881 suppress
Netty project is an event-driven asynchronous network application framework. In versions prior to 4.1.86.Final, a StackOverflowError can be raised when parsing a malformed crafted message due to an infinite recursion. This issue is patched in version 4.1.86.Final. There is no workaround, except using a custom HaProxyMessageDecoder. CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2023-44487 suppress
CISA Known Exploited Vulnerability: Product: IETF HTTP/2 Name: HTTP/2 Rapid Reset Attack Vulnerability Date Added: 2023-10-10 Description: HTTP/2 contains a rapid reset vulnerability that allows for a distributed denial-of-service attack (DDoS). Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Due Date: 2023-10-31 Notes: This vulnerability affects a common open-source component, third-party library, or protocol used by different products. For more information, please see: HTTP/2 Rapid Reset Vulnerability, CVE-2023-44487 | CISA: https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487; https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/; https://nvd.nist.gov/vuln/detail/CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. CWE-400 Uncontrolled Resource Consumption, NVD-CWE-noinfo
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
134c704f-9b21-4f2e-91b3-4a467353bcc0 - US_GOVERNMENT_RESOURCE af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PRODUCT af854a3a-2127-422b-91ae-364da2661108 - PRODUCT af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - PRODUCT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY cve@mitre.org - BROKEN_LINK cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING cve@mitre.org - ISSUE_TRACKING,MITIGATION,VENDOR_ADVISORY cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PATCH cve@mitre.org - ISSUE_TRACKING,PRESS/MEDIA_COVERAGE cve@mitre.org - ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY cve@mitre.org - ISSUE_TRACKING,VENDOR_ADVISORY cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST cve@mitre.org - MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,PATCH,VENDOR_ADVISORY cve@mitre.org - MAILING_LIST,RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY cve@mitre.org - MAILING_LIST,VENDOR_ADVISORY cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY cve@mitre.org - MITIGATION,PATCH,VENDOR_ADVISORY cve@mitre.org - MITIGATION,VENDOR_ADVISORY cve@mitre.org - PATCH cve@mitre.org - PATCH cve@mitre.org - PATCH cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - PRESS/MEDIA_COVERAGE cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY cve@mitre.org - PRESS/MEDIA_COVERAGE,THIRD_PARTY_ADVISORY cve@mitre.org - PRODUCT cve@mitre.org - PRODUCT cve@mitre.org - PRODUCT,RELEASE_NOTES cve@mitre.org - PRODUCT,THIRD_PARTY_ADVISORY cve@mitre.org - RELEASE_NOTES cve@mitre.org - RELEASE_NOTES cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY cve@mitre.org - TECHNICAL_DESCRIPTION,VENDOR_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY,US_GOVERNMENT_RESOURCE cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY,VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY cve@mitre.org - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2025-58057 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression. CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-43797 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-34462 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `SniHandler` can allocate up to 16MB of heap for each channel during the TLS handshake. When the handler or the channel does not have an idle timeout, it can be used to make a TCP server using the `SniHandler` to allocate 16MB of heap. The `SniHandler` class is a handler that waits for the TLS handshake to configure a `SslHandler` according to the indicated server name by the `ClientHello` record. For this matter it allocates a `ByteBuf` using the value defined in the `ClientHello` record. Normally the value of the packet should be smaller than the handshake packet but there are not checks done here and the way the code is written, it is possible to craft a packet that makes the `SslClientHelloHandler`. This vulnerability has been fixed in version 4.1.94.Final. CWE-400 Uncontrolled Resource Consumption, CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2025-67735 suppress
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.129.Final and 4.2.8.Final, the `io.netty.handler.codec.http.HttpRequestEncoder` has a CRLF injection with the request URI when constructing a request. This leads to request smuggling when `HttpRequestEncoder` is used without proper sanitization of the URI. Any application / framework using `HttpRequestEncoder` can be subject to be abused to perform request smuggling using CRLF injection. Versions 4.1.129.Final and 4.2.8.Final fix the issue. CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-21295 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has meaning and needs to be checked. An attacker can smuggle requests inside the body as it gets downgraded from HTTP/2 to HTTP/1.1. For an example attack refer to the linked GitHub Advisory. Users are only affected if all of this is true: `HTTP2MultiplexCodec` or `Http2FrameCodec` is used, `Http2StreamFrameToHttpObjectCodec` is used to convert to HTTP/1.1 objects, and these HTTP/1.1 objects are forwarded to another remote peer. This has been patched in 4.1.60.Final As a workaround, the user can do the validation by themselves by implementing a custom `ChannelInboundHandler` that is put in the `ChannelPipeline` behind `Http2StreamFrameToHttpObjectCodec`. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-21409 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-21290 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - EXPLOIT,THIRD_PARTY_ADVISORY security-advisories@github.com - MAILING_LIST,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-24823 suppress
Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. This only impacts applications running on Java version 6 and lower. Additionally, this vulnerability impacts code running on Unix-like systems, and very old versions of Mac OSX and Windows as they all share the system temporary directory between all users. Version 4.1.77.Final contains a patch for this vulnerability. As a workaround, specify one's own `java.io.tmpdir` when starting the JVM or use DefaultHttpDataFactory.setBaseDir(...) to set the directory to something that is only readable by the current user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY security-advisories@github.com - EXPLOIT,MITIGATION,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2024-47535 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crashes. This vulnerability is fixed in 4.1.115. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2025-25193 suppress
Netty, an asynchronous, event-driven network application framework, has a vulnerability in versions up to and including 4.1.118.Final. An unsafe reading of environment file could potentially cause a denial of service in Netty. When loaded on an Windows application, Netty attempts to load a file that does not exist. If an attacker creates such a large file, the Netty application crash. A similar issue was previously reported as CVE-2024-47535. This issue was fixed, but the fix was incomplete in that null-bytes were not counted against the input limit. Commit d1fbda62d3a47835d3fb35db8bd42ecc205a5386 contains an updated fix. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-29025 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. The `HttpPostRequestDecoder` can be tricked to accumulate data. While the decoder can store items on the disk if configured so, there are no limits to the number of fields the form can have, an attacher can send a chunked post consisting of many small fields that will be accumulated in the `bodyListHttpData` list. The decoder cumulates bytes in the `undecodedChunk` buffer until it can decode a field, this field can cumulate data without limits. This vulnerability is fixed in 4.1.108.Final. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2025-58056 suppress
Netty is an asynchronous event-driven network application framework for development of maintainable high performance protocol servers and clients. In versions 4.1.124.Final, and 4.2.0.Alpha3 through 4.2.4.Final, Netty incorrectly accepts standalone newline characters (LF) as a chunk-size line terminator, regardless of a preceding carriage return (CR), instead of requiring CRLF per HTTP/1.1 standards. When combined with reverse proxies that parse LF differently (treating it as part of the chunk extension), attackers can craft requests that the proxy sees as one request but Netty processes as two, enabling request smuggling attacks. This is fixed in versions 4.1.125.Final and 4.2.5.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv4:
Base Score: LOW (2.9) Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
io.quarkus.quarkus-spring-boot-orm-api-3.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-boot-orm-api-3.4.jarMD5: 5d74a221a73191bba2b4b2f47e2704b1SHA1: 7782f51796074d5e458a7aa20c7dcd95281351a0SHA256: 30b6f1fe6982527060a50ac56cb8b6438e49172c644417833812070c8a794a6d
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-spring-boot-orm-api High Vendor Manifest build-jdk-spec 17 Low Product file name io.quarkus.quarkus-spring-boot-orm-api High Product Manifest build-jdk-spec 17 Low Version file name io.quarkus.quarkus-spring-boot-orm-api Medium Version file version 3.4 High Version Manifest build-jdk-spec 17 Low
Related Dependencies io.quarkus.quarkus-spring-boot-orm-api-3.4.jar (shaded: io.quarkus:quarkus-spring-boot-orm-api:3.4)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-boot-orm-api-3.4.jar/META-INF/maven/io.quarkus/quarkus-spring-boot-orm-api/pom.xml MD5: 4fee74eed336f52f6f1da06dcb2caae4 SHA1: adc38400669585e4cdbb63af1874889e4a1f5534 SHA256: 3de8494e5cda3bd0d0e763c620c5a36fe108a78c0a6038e144ccde00794c6e1a pkg:maven/io.quarkus/quarkus-spring-boot-orm-api@3.4 io.quarkus.quarkus-spring-boot-orm-api-3.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-boot-orm-api-3.4.jar MD5: 5d74a221a73191bba2b4b2f47e2704b1 SHA1: 7782f51796074d5e458a7aa20c7dcd95281351a0 SHA256: 30b6f1fe6982527060a50ac56cb8b6438e49172c644417833812070c8a794a6d quarkus-spring-boot-orm-api-3.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-spring-boot-orm-api/3.4/quarkus-spring-boot-orm-api-3.4.jar MD5: 5d74a221a73191bba2b4b2f47e2704b1 SHA1: 7782f51796074d5e458a7aa20c7dcd95281351a0 SHA256: 30b6f1fe6982527060a50ac56cb8b6438e49172c644417833812070c8a794a6d pkg:maven/io.quarkus/quarkus-spring-boot-orm-api@3.4 cpe:2.3:a:quarkus:quarkus:3.4:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
io.quarkus.quarkus-spring-core-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-core-api-6.2.SP1.jarMD5: 25dc1b379a6de376c7659ef9d061e857SHA1: 40188dd302df5fa23d0e19dfd68b0bacb36faac3SHA256: 4fba49a4891d3133aa5032ade616ea65d96e99fee5bb225f4ee0c131a1f7fb75
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-spring-core-api High Vendor jar package name springframework Low Vendor jar package name util Low Vendor Manifest build-jdk-spec 17 Low Product file name io.quarkus.quarkus-spring-core-api High Product jar package name util Low Product Manifest build-jdk-spec 17 Low Version file name io.quarkus.quarkus-spring-core-api Medium Version file version 6.2.sp1 High Version Manifest build-jdk-spec 17 Low
Related Dependencies io.quarkus.quarkus-spring-aop-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-aop-api-6.2.SP1.jar MD5: 8989f1c552e2363235672129fd6e01b8 SHA1: fa1f1a19dace1ae30e5c00d9ddcd71d265a32962 SHA256: 9a31501c595ec9dcdbc35dd95a23c42a34d80d86448b4ec51d53feae81e37e70 io.quarkus.quarkus-spring-aop-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-aop-api-6.2.SP1.jar MD5: 8989f1c552e2363235672129fd6e01b8 SHA1: fa1f1a19dace1ae30e5c00d9ddcd71d265a32962 SHA256: 9a31501c595ec9dcdbc35dd95a23c42a34d80d86448b4ec51d53feae81e37e70 io.quarkus.quarkus-spring-beans-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-beans-api-6.2.SP1.jar MD5: d7815b618483eb4de2c51d0e707380f9 SHA1: d8a5bb87599066938a4c5b14489e9f9f67b6e648 SHA256: d1d3c0cbfb6d9dc07d130b16e04929c58ab3a972c1bf8fe3a1455f38505d5011 io.quarkus.quarkus-spring-beans-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-beans-api-6.2.SP1.jar MD5: d7815b618483eb4de2c51d0e707380f9 SHA1: d8a5bb87599066938a4c5b14489e9f9f67b6e648 SHA256: d1d3c0cbfb6d9dc07d130b16e04929c58ab3a972c1bf8fe3a1455f38505d5011 io.quarkus.quarkus-spring-context-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-context-api-6.2.SP1.jar MD5: 0380c384b382892870f3238ababf966b SHA1: d9547104e37cc1e70803024c494a8af848e4fa68 SHA256: 3f2c1c15a06bc698c5e1089c05c1653f0ef50990439dc263c65cc3053cc527ab io.quarkus.quarkus-spring-context-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-context-api-6.2.SP1.jar MD5: 0380c384b382892870f3238ababf966b SHA1: d9547104e37cc1e70803024c494a8af848e4fa68 SHA256: 3f2c1c15a06bc698c5e1089c05c1653f0ef50990439dc263c65cc3053cc527ab io.quarkus.quarkus-spring-core-api-6.2.SP1.jar (shaded: io.quarkus:quarkus-spring-core-api:6.2.SP1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-core-api-6.2.SP1.jar/META-INF/maven/io.quarkus/quarkus-spring-core-api/pom.xml MD5: 6d83e543f2fec37b54ee7532df0efa6e SHA1: 7339b580d64849dd692d36ce993b69ac69b0e0ef SHA256: 44095796279236e3bfc7dc73925f14f4ebb187118de19601dd770c7be9500aee pkg:maven/io.quarkus/quarkus-spring-core-api@6.2.SP1 io.quarkus.quarkus-spring-core-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-core-api-6.2.SP1.jar MD5: 25dc1b379a6de376c7659ef9d061e857 SHA1: 40188dd302df5fa23d0e19dfd68b0bacb36faac3 SHA256: 4fba49a4891d3133aa5032ade616ea65d96e99fee5bb225f4ee0c131a1f7fb75 quarkus-spring-core-api-6.2.SP1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-spring-core-api/6.2.SP1/quarkus-spring-core-api-6.2.SP1.jar MD5: 25dc1b379a6de376c7659ef9d061e857 SHA1: 40188dd302df5fa23d0e19dfd68b0bacb36faac3 SHA256: 4fba49a4891d3133aa5032ade616ea65d96e99fee5bb225f4ee0c131a1f7fb75 pkg:maven/io.quarkus/quarkus-spring-core-api@6.2.SP1 cpe:2.3:a:quarkus:quarkus:6.2.sp1:*:*:*:*:*:*:* (Confidence :Low) suppress io.quarkus.quarkus-spring-data-jpa-api-3.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-data-jpa-api-3.5.jarMD5: da133718d5470ec68d206526ace04cffSHA1: 7609a2c678612606b8b4245912f4c23ce8a9df5bSHA256: eea1d1f67f62d80eeb1d1ad848b8635734913754df233b1ec89d7b6c6431b58d
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-spring-data-jpa-api High Vendor jar package name data Low Vendor jar package name jpa Low Vendor jar package name springframework Low Vendor Manifest build-jdk-spec 17 Low Product file name io.quarkus.quarkus-spring-data-jpa-api High Product jar package name data Low Product jar package name jpa Low Product jar package name repository Low Product Manifest build-jdk-spec 17 Low Version file name io.quarkus.quarkus-spring-data-jpa-api Medium Version file version 3.5 High Version Manifest build-jdk-spec 17 Low
Related Dependencies io.quarkus.quarkus-spring-data-commons-api-3.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-data-commons-api-3.5.jar MD5: 7b54fabbc37472f92053d03bb7908023 SHA1: f1e658fbf96440c30f8a7ed2c954b52e768a8e48 SHA256: 21352eabee9afa085e744addd4b3bb51a7acca29f788be5826b7264543d99bb7 io.quarkus.quarkus-spring-data-commons-api-3.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-data-commons-api-3.5.jar MD5: 7b54fabbc37472f92053d03bb7908023 SHA1: f1e658fbf96440c30f8a7ed2c954b52e768a8e48 SHA256: 21352eabee9afa085e744addd4b3bb51a7acca29f788be5826b7264543d99bb7 io.quarkus.quarkus-spring-data-jpa-api-3.5.jar (shaded: io.quarkus:quarkus-spring-data-jpa-api:3.5)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-data-jpa-api-3.5.jar/META-INF/maven/io.quarkus/quarkus-spring-data-jpa-api/pom.xml MD5: d2e8d4400d9c8e37f90e3ba717f16028 SHA1: d8097cdc17e981e0806af1a77caed5230e58ae79 SHA256: 15587182e8a22020e4dcf1803b99593b6510423b2267b5d0b7774e7b8ac05d3c pkg:maven/io.quarkus/quarkus-spring-data-jpa-api@3.5 io.quarkus.quarkus-spring-data-jpa-api-3.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-data-jpa-api-3.5.jar MD5: da133718d5470ec68d206526ace04cff SHA1: 7609a2c678612606b8b4245912f4c23ce8a9df5b SHA256: eea1d1f67f62d80eeb1d1ad848b8635734913754df233b1ec89d7b6c6431b58d quarkus-spring-data-jpa-api-3.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-spring-data-jpa-api/3.5/quarkus-spring-data-jpa-api-3.5.jar MD5: da133718d5470ec68d206526ace04cff SHA1: 7609a2c678612606b8b4245912f4c23ce8a9df5b SHA256: eea1d1f67f62d80eeb1d1ad848b8635734913754df233b1ec89d7b6c6431b58d pkg:maven/io.quarkus/quarkus-spring-data-jpa-api@3.5 cpe:2.3:a:quarkus:quarkus:3.5:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
io.quarkus.quarkus-swagger-ui-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.quarkus-swagger-ui-3.30.6.jar
MD5: b0ec18ade1bc0ea63808d49d90239f8e
SHA1: 29e02d81660b510f9c76a41970d47aece5fb8879
SHA256: 8133515e8eb921cd369231095fa12c143b7a526de583b6fe87d83540176c13d0
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.quarkus-swagger-ui High Vendor jar package name io Low Vendor jar package name quarkus Low Vendor jar package name swaggerui Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.quarkus-swagger-ui High Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name runtime Highest Product jar package name runtime Low Product jar package name swaggerui Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Swagger UI - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Swagger UI - Runtime Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies io.quarkus.quarkus-swagger-ui-3.30.6.jar (shaded: io.quarkus:quarkus-swagger-ui:3.30.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-swagger-ui-3.30.6.jar/META-INF/maven/io.quarkus/quarkus-swagger-ui/pom.xml MD5: 0fdcd54be59d4e87ad8c1909c84871b0 SHA1: 657ddf271e2aea1ef06c33ce04eec8883ed0858e SHA256: 2a40514d1d1f189080ef7f38b03b21ed552b7c9925da20599de911c048bd74eb pkg:maven/io.quarkus/quarkus-swagger-ui@3.30.6 io.quarkus.quarkus-swagger-ui-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-swagger-ui-3.30.6.jar MD5: b0ec18ade1bc0ea63808d49d90239f8e SHA1: 29e02d81660b510f9c76a41970d47aece5fb8879 SHA256: 8133515e8eb921cd369231095fa12c143b7a526de583b6fe87d83540176c13d0 quarkus-swagger-ui-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-swagger-ui/3.30.6/quarkus-swagger-ui-3.30.6.jar MD5: b0ec18ade1bc0ea63808d49d90239f8e SHA1: 29e02d81660b510f9c76a41970d47aece5fb8879 SHA256: 8133515e8eb921cd369231095fa12c143b7a526de583b6fe87d83540176c13d0 pkg:maven/io.quarkus/quarkus-swagger-ui@3.30.6 io.quarkus.security.quarkus-security-2.2.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.quarkus.security.quarkus-security-2.2.1.jarMD5: 944193acec94a6890e628cb7dc7b87d9SHA1: 02879402ad326511ed8a65a6378731b4e45d12e4SHA256: b5020f6fcc506d2db71c17ac6854cc3a9078c0b73952918048d1f2cbb4a7d8f8
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.security.quarkus-security High Vendor hint analyzer vendor redhat Highest Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name quarkus Highest Vendor jar package name quarkus Low Vendor jar package name security Highest Vendor jar package name security Low Vendor Manifest automatic-module-name io.quarkus.security.api Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name io.quarkus.security.quarkus-security High Product jar package name io Highest Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name security Highest Product jar package name security Low Product Manifest automatic-module-name io.quarkus.security.api Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title quarkus-security High Product Manifest implementation-url http://www.jboss.org Low Product Manifest specification-title quarkus-security Medium Version file version 2.2.1 High Version Manifest Implementation-Version 2.2.1 High
Related Dependencies io.quarkus.security.quarkus-security-2.2.1.jar (shaded: io.quarkus.security:quarkus-security:2.2.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.security.quarkus-security-2.2.1.jar/META-INF/maven/io.quarkus.security/quarkus-security/pom.xml MD5: 3e1bda7fb683b18a3cecf8b4f34faa2d SHA1: 51dc568f3ded193a39b92627ad52f3d845aa587c SHA256: eb540ceabcdf856f2f85dd61cd70d50eb21848f6fa98c15c491ff99e059567ea pkg:maven/io.quarkus.security/quarkus-security@2.2.1 io.quarkus.security.quarkus-security-2.2.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.security.quarkus-security-2.2.1.jar MD5: 944193acec94a6890e628cb7dc7b87d9 SHA1: 02879402ad326511ed8a65a6378731b4e45d12e4 SHA256: b5020f6fcc506d2db71c17ac6854cc3a9078c0b73952918048d1f2cbb4a7d8f8 quarkus-security-2.2.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/security/quarkus-security/2.2.1/quarkus-security-2.2.1.jar MD5: 944193acec94a6890e628cb7dc7b87d9 SHA1: 02879402ad326511ed8a65a6378731b4e45d12e4 SHA256: b5020f6fcc506d2db71c17ac6854cc3a9078c0b73952918048d1f2cbb4a7d8f8 pkg:maven/io.quarkus.security/quarkus-security@2.2.1 CVE-2022-21724 suppress
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue. CWE-665 Improper Initialization
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-4116 suppress
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution. NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-6267 suppress
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security. CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2022-0981 suppress
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended. CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2023-4853 suppress
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. CWE-148 Improper Neutralization of Input Leaders, CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,TECHNICAL_DESCRIPTION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - EXPLOIT,MITIGATION,TECHNICAL_DESCRIPTION,VENDOR_ADVISORY secalert@redhat.com - ISSUE_TRACKING,VENDOR_ADVISORY secalert@redhat.com - MITIGATION,VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29428 suppress
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. This vulnerability impacted builds using precompiled script plugins written in Kotlin DSL and tests for Gradle plugins written using ProjectBuilder or TestKit. If you are on Windows or modern versions of macOS, you are not vulnerable. If you are on a Unix-like operating system with the "sticky" bit set on your system temporary directory, you are not vulnerable. The problem has been patched and released with Gradle 7.0. As a workaround, on Unix-like operating systems, ensure that the "sticky" bit is set. This only allows the original user (or root) to delete a file. If you are unable to change the permissions of the system temporary directory, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. For additional details refer to the referenced GitHub Security Advisory. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions
CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.4) Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37136 suppress
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37137 suppress
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37714 suppress
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes. CWE-248 Uncaught Exception, CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - RELEASE_NOTES,VENDOR_ADVISORY security-advisories@github.com - RELEASE_NOTES,VENDOR_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-4147 suppress
Quarkus CORS filter allows simple GET and POST requests with invalid Origin to proceed. Simple GET or POST requests made with XMLHttpRequest are the ones which have no event listeners registered on the object returned by the XMLHttpRequest upload property and have no ReadableStream object used in the request. CWE-1026
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2022-42003 suppress
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-42004 suppress
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2023-1584 suppress
A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens. NVD-CWE-noinfo, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2021-29427 suppress
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was introduced in the wake of the "A Confusing Dependency" blog post. In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file. This may change how dependencies are resolved for Gradle plugins and build scripts. For builds that are vulnerable, there are two risks: 1) Information disclosure: Gradle could make dependency requests to repositories outside your organization and leak internal package identifiers. 2) Dependency poisoning/Dependency confusion: Gradle could download a malicious binary from a repository outside your organization due to name squatting. For a full example and more details refer to the referenced GitHub Security Advisory. The problem has been patched and released with Gradle 7.0. Users relying on this feature should upgrade their build as soon as possible. As a workaround, users may use a company repository which has the right rules for fetching packages from public repositories, or use project level repository content filtering, inside `buildscript.repositories`. This option is available since Gradle 5.1 when the feature was introduced. CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:1.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-21363 suppress
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.6) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-43797 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-0044 suppress
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-2471 suppress
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H). NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.9) Vector: /AV:N/AC:M/Au:S/C:C/I:N/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2021-38153 suppress
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0. CWE-203 Observable Discrepancy
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-29429 suppress
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system temporary directory first. Sensitive information contained in these files can be exposed to other local users on the same system. If you do not use the `TextResourceFactory` API, you are not vulnerable. As of Gradle 7.0, uses of the system temporary directory have been moved to the Gradle User Home directory. By default, this directory is restricted to the user running the build. As a workaround, set a more restrictive umask that removes read access to other users. When files are created in the system temporary directory, they will not be accessible to other users. If you are unable to change your system's umask, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. CWE-377 Insecure Temporary File
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-28170 suppress
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. CWE-20 Improper Input Validation, CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-0481 suppress
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
io.quarkus.vertx.utils.quarkus-vertx-utils-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.vertx.utils.quarkus-vertx-utils-3.30.6.jar
MD5: e277f9cdd80923b7ce733c5ac228d2d7
SHA1: 201510a9d3fafcc654326547132921e28b625b9a
SHA256: 65801709ad8e18294556021948994cb9b9468f23dfda861750d367ff64f04ac1
Evidence Type Source Name Value Confidence Vendor file name io.quarkus.vertx.utils.quarkus-vertx-utils High Vendor jar package name io Low Vendor jar package name quarkus Low Vendor jar package name vertx Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://quarkus.io Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Product file name io.quarkus.vertx.utils.quarkus-vertx-utils High Product jar package name io Highest Product jar package name quarkus Highest Product jar package name quarkus Low Product jar package name utils Low Product jar package name vertx Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Ancillary classes for making third party frameworks to run on top of Vert.x High Product Manifest implementation-url https://quarkus.io Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Ancillary classes for making third party frameworks to run on top of Vert.x Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High
Related Dependencies quarkus-vertx-utils-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/vertx/utils/quarkus-vertx-utils/3.30.6/quarkus-vertx-utils-3.30.6.jar MD5: e277f9cdd80923b7ce733c5ac228d2d7 SHA1: 201510a9d3fafcc654326547132921e28b625b9a SHA256: 65801709ad8e18294556021948994cb9b9468f23dfda861750d367ff64f04ac1 pkg:maven/io.quarkus.vertx.utils/quarkus-vertx-utils@3.30.6 CVE-2021-4277 suppress
A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from observable state. The name of the patch is dbab1b66955eeb3d76b34612b358307f5c4e3944. It is recommended to apply a patch to fix this issue. The identifier VDB-216749 was assigned to this vulnerability. CWE-341 Predictable from Observable State, CWE-330 Use of Insufficiently Random Values
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
io.smallrye.certs.smallrye-private-key-pem-parser-0.9.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.certs.smallrye-private-key-pem-parser-0.9.2.jarMD5: eada66bbc084df9d8ab9747b826d6f7dSHA1: fffc0c86069623b021d8d2d222d09db52ae81994SHA256: 4ba98e92ed203593d87e384a1e09fa96c18c90173a6170fea71cf23a1c9c5286
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.certs.smallrye-private-key-pem-parser High Vendor jar package name certs Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/cescoffier/certificate-generator Low Product file name io.smallrye.certs.smallrye-private-key-pem-parser High Product jar package name certs Low Product jar package name pem Highest Product jar package name pem Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Certificate Generator - Private Key PEM utilities High Product Manifest implementation-url https://github.com/cescoffier/certificate-generator Low Product Manifest specification-title SmallRye Certificate Generator - Private Key PEM utilities Medium Version file version 0.9.2 High Version Manifest Implementation-Version 0.9.2 High
Related Dependencies io.smallrye.certs.smallrye-private-key-pem-parser-0.9.2.jar (shaded: io.smallrye.certs:smallrye-private-key-pem-parser:0.9.2)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.certs.smallrye-private-key-pem-parser-0.9.2.jar/META-INF/maven/io.smallrye.certs/smallrye-private-key-pem-parser/pom.xml MD5: 0235dec19da38bdd9ac6f46c5804afe7 SHA1: aa9d671cb5e04e67dddc7a2df633e05931f0edaf SHA256: c469960fec51ec08e3bd637797642c44adf2200148d31e832422e653a5cdfe8f pkg:maven/io.smallrye.certs/smallrye-private-key-pem-parser@0.9.2 io.smallrye.certs.smallrye-private-key-pem-parser-0.9.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.certs.smallrye-private-key-pem-parser-0.9.2.jar MD5: eada66bbc084df9d8ab9747b826d6f7d SHA1: fffc0c86069623b021d8d2d222d09db52ae81994 SHA256: 4ba98e92ed203593d87e384a1e09fa96c18c90173a6170fea71cf23a1c9c5286 smallrye-private-key-pem-parser-0.9.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/certs/smallrye-private-key-pem-parser/0.9.2/smallrye-private-key-pem-parser-0.9.2.jar MD5: eada66bbc084df9d8ab9747b826d6f7d SHA1: fffc0c86069623b021d8d2d222d09db52ae81994 SHA256: 4ba98e92ed203593d87e384a1e09fa96c18c90173a6170fea71cf23a1c9c5286 pkg:maven/io.smallrye.certs/smallrye-private-key-pem-parser@0.9.2 io.smallrye.common.smallrye-common-annotation-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-annotation-2.14.0.jarMD5: 6c13aca299ec50b0b72f1347058878a6SHA1: 5a2d58a31f47fa47a685238132bf20c6c085d5d7SHA256: 3c7fdeac90ed7acf97b03eb63d8e3286e9f0fa66c8450613d3453645725db010
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-annotation High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-annotation High Product jar package name annotation Low Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Annotations High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Annotations Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-annotation-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-annotation:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-annotation-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-annotation/pom.xml MD5: 54251d7936a3817e91a06f2788012d0b SHA1: 3ad4a937a6ee29787197e49a08a52184c5be58f1 SHA256: f2145f649129e9cb066f9297a53cb21e209f362bdd3c4c5f3a65c526dc1f5c76 pkg:maven/io.smallrye.common/smallrye-common-annotation@2.14.0 io.smallrye.common.smallrye-common-annotation-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-annotation-2.14.0.jar MD5: 6c13aca299ec50b0b72f1347058878a6 SHA1: 5a2d58a31f47fa47a685238132bf20c6c085d5d7 SHA256: 3c7fdeac90ed7acf97b03eb63d8e3286e9f0fa66c8450613d3453645725db010 smallrye-common-annotation-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-annotation/2.14.0/smallrye-common-annotation-2.14.0.jar MD5: 6c13aca299ec50b0b72f1347058878a6 SHA1: 5a2d58a31f47fa47a685238132bf20c6c085d5d7 SHA256: 3c7fdeac90ed7acf97b03eb63d8e3286e9f0fa66c8450613d3453645725db010 pkg:maven/io.smallrye.common/smallrye-common-annotation@2.14.0 io.smallrye.common.smallrye-common-classloader-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-classloader-2.14.0.jarMD5: 653284d41f4aead4069a70aa6e795817SHA1: ce5b85b059c257e4640752a4fea5f27ce64fc2beSHA256: 59194c310c755b75f84059c4923f9a3ef42cac6af568e35b2cc0b8c08d84adbc
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-classloader High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-classloader High Product jar package name classloader Highest Product jar package name classloader Low Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Classloader High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Classloader Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-classloader-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-classloader:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-classloader-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-classloader/pom.xml MD5: 08ecfcc658f7a5d7e03b14b642523fd0 SHA1: e4c767bd370a520eeb2fba0f136f5e5685112607 SHA256: 990447958b788087a50e9480d40f8371d246f6310bad97b2664eda8d0d508bf5 pkg:maven/io.smallrye.common/smallrye-common-classloader@2.14.0 io.smallrye.common.smallrye-common-classloader-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-classloader-2.14.0.jar MD5: 653284d41f4aead4069a70aa6e795817 SHA1: ce5b85b059c257e4640752a4fea5f27ce64fc2be SHA256: 59194c310c755b75f84059c4923f9a3ef42cac6af568e35b2cc0b8c08d84adbc smallrye-common-classloader-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-classloader/2.14.0/smallrye-common-classloader-2.14.0.jar MD5: 653284d41f4aead4069a70aa6e795817 SHA1: ce5b85b059c257e4640752a4fea5f27ce64fc2be SHA256: 59194c310c755b75f84059c4923f9a3ef42cac6af568e35b2cc0b8c08d84adbc pkg:maven/io.smallrye.common/smallrye-common-classloader@2.14.0 io.smallrye.common.smallrye-common-constraint-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-constraint-2.14.0.jarMD5: 5ec5cba75d9736ba6df20ca4d74a006bSHA1: 72145a1dc9b65e805dc82740f20a43817d4b21f0SHA256: 10bb72443594c780a80e011c7b5a1ca246e13860447cce278b6ebc448baddfce
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-constraint High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-constraint High Product jar package name common Highest Product jar package name common Low Product jar package name constraint Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Constraints High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Constraints Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-constraint-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-constraint:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-constraint-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-constraint/pom.xml MD5: 68f79381a3de17e109c8ee4adea9f74f SHA1: 1c2da11ce6b32b100e5b970df20806d7ee70410a SHA256: 7f908d904e1fe78f9f20fe748902c91559bd08ebaf66b7df45c9a7f55c496eb6 pkg:maven/io.smallrye.common/smallrye-common-constraint@2.14.0 io.smallrye.common.smallrye-common-constraint-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-constraint-2.14.0.jar MD5: 5ec5cba75d9736ba6df20ca4d74a006b SHA1: 72145a1dc9b65e805dc82740f20a43817d4b21f0 SHA256: 10bb72443594c780a80e011c7b5a1ca246e13860447cce278b6ebc448baddfce smallrye-common-constraint-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-constraint/2.14.0/smallrye-common-constraint-2.14.0.jar MD5: 5ec5cba75d9736ba6df20ca4d74a006b SHA1: 72145a1dc9b65e805dc82740f20a43817d4b21f0 SHA256: 10bb72443594c780a80e011c7b5a1ca246e13860447cce278b6ebc448baddfce pkg:maven/io.smallrye.common/smallrye-common-constraint@2.14.0 io.smallrye.common.smallrye-common-cpu-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-cpu-2.14.0.jarMD5: 05ae6cbeaf4411b7292a5836e5b9f9bbSHA1: a9d8c180721ca52f7bfd5ec1115d017fb1c5ce76SHA256: 1ee21c46d9c0b8cbdd1e489683fbd9976c0dce93b8e5a5af0543997577eb9969
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-cpu High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-cpu High Product jar package name common Highest Product jar package name common Low Product jar package name cpu Highest Product jar package name cpu Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: CPU High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: CPU Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-cpu-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-cpu:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-cpu-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-cpu/pom.xml MD5: 495a422317b74108be8873a7178d89b2 SHA1: c934de2b5ce488603aebbd3ee87ebe8faa756241 SHA256: 418ed6ba3359d23430d1c110433a0796f1252d59982ef0c6c9d15867a91196c4 pkg:maven/io.smallrye.common/smallrye-common-cpu@2.14.0 io.smallrye.common.smallrye-common-cpu-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-cpu-2.14.0.jar MD5: 05ae6cbeaf4411b7292a5836e5b9f9bb SHA1: a9d8c180721ca52f7bfd5ec1115d017fb1c5ce76 SHA256: 1ee21c46d9c0b8cbdd1e489683fbd9976c0dce93b8e5a5af0543997577eb9969 smallrye-common-cpu-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-cpu/2.14.0/smallrye-common-cpu-2.14.0.jar MD5: 05ae6cbeaf4411b7292a5836e5b9f9bb SHA1: a9d8c180721ca52f7bfd5ec1115d017fb1c5ce76 SHA256: 1ee21c46d9c0b8cbdd1e489683fbd9976c0dce93b8e5a5af0543997577eb9969 pkg:maven/io.smallrye.common/smallrye-common-cpu@2.14.0 io.smallrye.common.smallrye-common-expression-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-expression-2.14.0.jarMD5: 2808b062995dccdc2d16766a01c09182SHA1: c890291cf7b9d7703d685f9d643e1cf4b9a8a1f3SHA256: a17c1b4bf2366e2bc98cda96f4d0d5acc0c2cdbfa4341a592254ffb63cbb5253
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-expression High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-expression High Product jar package name common Highest Product jar package name common Low Product jar package name expression Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Expressions High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Expressions Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-expression-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-expression:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-expression-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-expression/pom.xml MD5: 058d5852209a6beef09c053c3d4e9b66 SHA1: b1bdac672ed6fca1b8ee2bb11bffd9a947f04d17 SHA256: ee583ea6c6b84e2d7ebd88b0e50046ed606c7375673800d58731d2ae41306e0f pkg:maven/io.smallrye.common/smallrye-common-expression@2.14.0 io.smallrye.common.smallrye-common-expression-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-expression-2.14.0.jar MD5: 2808b062995dccdc2d16766a01c09182 SHA1: c890291cf7b9d7703d685f9d643e1cf4b9a8a1f3 SHA256: a17c1b4bf2366e2bc98cda96f4d0d5acc0c2cdbfa4341a592254ffb63cbb5253 smallrye-common-expression-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-expression/2.14.0/smallrye-common-expression-2.14.0.jar MD5: 2808b062995dccdc2d16766a01c09182 SHA1: c890291cf7b9d7703d685f9d643e1cf4b9a8a1f3 SHA256: a17c1b4bf2366e2bc98cda96f4d0d5acc0c2cdbfa4341a592254ffb63cbb5253 pkg:maven/io.smallrye.common/smallrye-common-expression@2.14.0 io.smallrye.common.smallrye-common-function-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-function-2.14.0.jarMD5: b8bbb6957d14860c46ca002ffdffe7deSHA1: e2ea1d1c5baf4794133b4ff06712096149527329SHA256: f0e0c6c213c40665b3c29cede733f668f37e38aa5f3ab4335c55191fdc0c359d
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-function High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-function High Product jar package name common Highest Product jar package name common Low Product jar package name function Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Functions High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Functions Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-function-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-function:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-function-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-function/pom.xml MD5: f4a9d2bff37b2eee0fb7fb0e3d37ee61 SHA1: b50f94aa1ca307c0b88e8839618cb6887362b288 SHA256: 9da0bfe6ab4362ab5f6c98cc6b256e541a211d4f61611d432104b59a9e4d6e28 pkg:maven/io.smallrye.common/smallrye-common-function@2.14.0 io.smallrye.common.smallrye-common-function-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-function-2.14.0.jar MD5: b8bbb6957d14860c46ca002ffdffe7de SHA1: e2ea1d1c5baf4794133b4ff06712096149527329 SHA256: f0e0c6c213c40665b3c29cede733f668f37e38aa5f3ab4335c55191fdc0c359d smallrye-common-function-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-function/2.14.0/smallrye-common-function-2.14.0.jar MD5: b8bbb6957d14860c46ca002ffdffe7de SHA1: e2ea1d1c5baf4794133b4ff06712096149527329 SHA256: f0e0c6c213c40665b3c29cede733f668f37e38aa5f3ab4335c55191fdc0c359d pkg:maven/io.smallrye.common/smallrye-common-function@2.14.0 io.smallrye.common.smallrye-common-io-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-io-2.14.0.jarMD5: 890a846ea80f0195a7362a6753ddb7dcSHA1: ed4683202fb7d4307f010e0a4d6fce2642dea03aSHA256: 59e28aecccf6271dfbb3bde464cf91f89396ea1892f5ee18087b00baf1d3cec2
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-io High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-io High Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name io Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: IO High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: IO Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-io-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-io:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-io-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-io/pom.xml MD5: 0a88baaedf7413cc5fdce3cdadb11fd2 SHA1: 060cb744a490304b05c8839af35aba9f423003f9 SHA256: 0f209a4046c6377da031336b44ec975efffe1205b6f122527ce2bb09f8d12884 pkg:maven/io.smallrye.common/smallrye-common-io@2.14.0 io.smallrye.common.smallrye-common-io-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-io-2.14.0.jar MD5: 890a846ea80f0195a7362a6753ddb7dc SHA1: ed4683202fb7d4307f010e0a4d6fce2642dea03a SHA256: 59e28aecccf6271dfbb3bde464cf91f89396ea1892f5ee18087b00baf1d3cec2 smallrye-common-io-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-io/2.14.0/smallrye-common-io-2.14.0.jar MD5: 890a846ea80f0195a7362a6753ddb7dc SHA1: ed4683202fb7d4307f010e0a4d6fce2642dea03a SHA256: 59e28aecccf6271dfbb3bde464cf91f89396ea1892f5ee18087b00baf1d3cec2 pkg:maven/io.smallrye.common/smallrye-common-io@2.14.0 io.smallrye.common.smallrye-common-net-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-net-2.14.0.jarMD5: bf88f1b55ab7c679b101d6fae249eef7SHA1: 5f226a9edddd47b22205d153999f9fbada1d1c44SHA256: e82e4184532b5e2ac59b5ebb4ba2b14e31ca8164b4060dd8fd4315648ca09d22
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-net High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-net High Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name net Highest Product jar package name net Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Net High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Net Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-net-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-net:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-net-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-net/pom.xml MD5: 341404094b6a360678b2c7705b8501e0 SHA1: 17fe23f43992c537878859d96520ef64c3f0e85b SHA256: 9cc72bd709c147e52f0fdbe8f98d7151ff8676ae95aaf7ab2d1ec0df2dde1df1 pkg:maven/io.smallrye.common/smallrye-common-net@2.14.0 io.smallrye.common.smallrye-common-net-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-net-2.14.0.jar MD5: bf88f1b55ab7c679b101d6fae249eef7 SHA1: 5f226a9edddd47b22205d153999f9fbada1d1c44 SHA256: e82e4184532b5e2ac59b5ebb4ba2b14e31ca8164b4060dd8fd4315648ca09d22 smallrye-common-net-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-net/2.14.0/smallrye-common-net-2.14.0.jar MD5: bf88f1b55ab7c679b101d6fae249eef7 SHA1: 5f226a9edddd47b22205d153999f9fbada1d1c44 SHA256: e82e4184532b5e2ac59b5ebb4ba2b14e31ca8164b4060dd8fd4315648ca09d22 pkg:maven/io.smallrye.common/smallrye-common-net@2.14.0 io.smallrye.common.smallrye-common-os-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-os-2.14.0.jarMD5: a4f54058f329623dca36cffa3b34194eSHA1: 133f05bd41f41deb1ec863413d37c368978d43f4SHA256: 7f8b361b789ad1ec6066fe0bad7f6f75a1052d8eeb98535a6228bb92396380bc
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-os High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-os High Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name os Highest Product jar package name os Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: OS High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: OS Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-os-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-os:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-os-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-os/pom.xml MD5: ed16e2b7a8b10a001f132020818ae5fb SHA1: 8882c7067aaaa516886cf8577a486d18f33fccae SHA256: 14b77b9b94d6e8c7d5baeb8f2c80841f173eee8c8c31e6f0741a099f94e36924 pkg:maven/io.smallrye.common/smallrye-common-os@2.14.0 io.smallrye.common.smallrye-common-os-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-os-2.14.0.jar MD5: a4f54058f329623dca36cffa3b34194e SHA1: 133f05bd41f41deb1ec863413d37c368978d43f4 SHA256: 7f8b361b789ad1ec6066fe0bad7f6f75a1052d8eeb98535a6228bb92396380bc smallrye-common-os-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-os/2.14.0/smallrye-common-os-2.14.0.jar MD5: a4f54058f329623dca36cffa3b34194e SHA1: 133f05bd41f41deb1ec863413d37c368978d43f4 SHA256: 7f8b361b789ad1ec6066fe0bad7f6f75a1052d8eeb98535a6228bb92396380bc pkg:maven/io.smallrye.common/smallrye-common-os@2.14.0 io.smallrye.common.smallrye-common-ref-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-ref-2.14.0.jarMD5: ac2dc1ab64fe765d4e6aab724006f192SHA1: 77dc7cb1142cad32ab33987171d9b26e928d92feSHA256: 11cc65375d0ce0214c0a056a4964fc4791df4c4624747e45eca57d006deb502f
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-ref High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-ref High Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name ref Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: References High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: References Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-ref-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-ref:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-ref-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-ref/pom.xml MD5: 59df3341cd3c4071b250d17fe55f06e0 SHA1: 8bfbedb3c4c51d86e828c5f8ffcc29710eca2fbd SHA256: 9e7d9827d88c6900f3027057080afde3a6de5e72091d292a65334359b3ddad90 pkg:maven/io.smallrye.common/smallrye-common-ref@2.14.0 io.smallrye.common.smallrye-common-ref-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/io.smallrye.common.smallrye-common-ref-2.14.0.jar MD5: ac2dc1ab64fe765d4e6aab724006f192 SHA1: 77dc7cb1142cad32ab33987171d9b26e928d92fe SHA256: 11cc65375d0ce0214c0a056a4964fc4791df4c4624747e45eca57d006deb502f smallrye-common-ref-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-ref/2.14.0/smallrye-common-ref-2.14.0.jar MD5: ac2dc1ab64fe765d4e6aab724006f192 SHA1: 77dc7cb1142cad32ab33987171d9b26e928d92fe SHA256: 11cc65375d0ce0214c0a056a4964fc4791df4c4624747e45eca57d006deb502f pkg:maven/io.smallrye.common/smallrye-common-ref@2.14.0 io.smallrye.common.smallrye-common-vertx-context-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-vertx-context-2.14.0.jarMD5: 345274175735c5f264f45086293f13b8SHA1: 7d3982095d43fef84df5d7fd46dc7ee86786027fSHA256: 1fe19e794110f8c97efa248744612f6aed8d5013715964da52b40e102384793f
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.common.smallrye-common-vertx-context High Vendor jar package name common Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.common.smallrye-common-vertx-context High Product jar package name common Highest Product jar package name common Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name vertx Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Vert.x Context Utilities High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Vert.x Context Utilities Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High
Related Dependencies io.smallrye.common.smallrye-common-vertx-context-2.14.0.jar (shaded: io.smallrye.common:smallrye-common-vertx-context:2.14.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-vertx-context-2.14.0.jar/META-INF/maven/io.smallrye.common/smallrye-common-vertx-context/pom.xml MD5: eca1a1281e626b3f798bfbbe44b14515 SHA1: 5a4aaf209330527bb4c71380561e031ee1dd096e SHA256: 59e507d93f597dd2b4cb634b6fc7dfb350770b989952baf1058ff37601d6d644 pkg:maven/io.smallrye.common/smallrye-common-vertx-context@2.14.0 io.smallrye.common.smallrye-common-vertx-context-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.common.smallrye-common-vertx-context-2.14.0.jar MD5: 345274175735c5f264f45086293f13b8 SHA1: 7d3982095d43fef84df5d7fd46dc7ee86786027f SHA256: 1fe19e794110f8c97efa248744612f6aed8d5013715964da52b40e102384793f smallrye-common-vertx-context-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-vertx-context/2.14.0/smallrye-common-vertx-context-2.14.0.jar MD5: 345274175735c5f264f45086293f13b8 SHA1: 7d3982095d43fef84df5d7fd46dc7ee86786027f SHA256: 1fe19e794110f8c97efa248744612f6aed8d5013715964da52b40e102384793f pkg:maven/io.smallrye.common/smallrye-common-vertx-context@2.14.0 io.smallrye.config.smallrye-config-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-3.14.1.jarMD5: a91df3ce94d76628067db3e6e6520103SHA1: 278cdd1de27726b1a802b56c42763fefe97977caSHA256: dd1ebce3833a36330ea914b2cc17180de32281fd42782cec47a3276986f24ffe
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.config.smallrye-config High Vendor jar package name config Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Product file name io.smallrye.config.smallrye-config High Product jar package name config Highest Product jar package name config Low Product jar package name inject Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Config: CDI High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Config: CDI Medium Version file version 3.14.1 High Version Manifest Implementation-Version 3.14.1 High
Related Dependencies io.smallrye.config.smallrye-config-3.14.1.jar (shaded: io.smallrye.config:smallrye-config:3.14.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-3.14.1.jar/META-INF/maven/io.smallrye.config/smallrye-config/pom.xml MD5: d71a69af08141a3ba99976ebe60c7ab2 SHA1: 36b8cc9bd719e25a06247253ba75df1a34c19639 SHA256: 05ce372cfa7d4b4e2f293d4eea278477381a2d0941974ede4358718370392d82 pkg:maven/io.smallrye.config/smallrye-config@3.14.1 io.smallrye.config.smallrye-config-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-3.14.1.jar MD5: a91df3ce94d76628067db3e6e6520103 SHA1: 278cdd1de27726b1a802b56c42763fefe97977ca SHA256: dd1ebce3833a36330ea914b2cc17180de32281fd42782cec47a3276986f24ffe smallrye-config-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/config/smallrye-config/3.14.1/smallrye-config-3.14.1.jar MD5: a91df3ce94d76628067db3e6e6520103 SHA1: 278cdd1de27726b1a802b56c42763fefe97977ca SHA256: dd1ebce3833a36330ea914b2cc17180de32281fd42782cec47a3276986f24ffe pkg:maven/io.smallrye.config/smallrye-config@3.14.1 io.smallrye.config.smallrye-config-common-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-common-3.14.1.jarMD5: 3ecc60c7386819db10598fe018f223c9SHA1: 798e7d35f313ef80e34adecdf08b1debb8e5c7c7SHA256: df0f9a960b45ccf7599a376cceaf557ac3e13eabf54e12c07dcdb6a9cf7166d2
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.config.smallrye-config-common High Vendor jar package name config Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Product file name io.smallrye.config.smallrye-config-common High Product jar package name common Highest Product jar package name common Low Product jar package name config Highest Product jar package name config Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Config: Common High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Config: Common Medium Version file version 3.14.1 High Version Manifest Implementation-Version 3.14.1 High
Related Dependencies io.smallrye.config.smallrye-config-common-3.14.1.jar (shaded: io.smallrye.config:smallrye-config-common:3.14.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-common-3.14.1.jar/META-INF/maven/io.smallrye.config/smallrye-config-common/pom.xml MD5: 0ed4c022e2e202309135fb599331e15f SHA1: 93aeee0e88d8f9ec1096c8ad4f2e6e13866d2921 SHA256: 1c4e8bb2c27a1c4e9aa49980b01a670d935ab6e482c4ab3f0fd3acaa4f0a271d pkg:maven/io.smallrye.config/smallrye-config-common@3.14.1 io.smallrye.config.smallrye-config-common-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-common-3.14.1.jar MD5: 3ecc60c7386819db10598fe018f223c9 SHA1: 798e7d35f313ef80e34adecdf08b1debb8e5c7c7 SHA256: df0f9a960b45ccf7599a376cceaf557ac3e13eabf54e12c07dcdb6a9cf7166d2 smallrye-config-common-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/config/smallrye-config-common/3.14.1/smallrye-config-common-3.14.1.jar MD5: 3ecc60c7386819db10598fe018f223c9 SHA1: 798e7d35f313ef80e34adecdf08b1debb8e5c7c7 SHA256: df0f9a960b45ccf7599a376cceaf557ac3e13eabf54e12c07dcdb6a9cf7166d2 pkg:maven/io.smallrye.config/smallrye-config-common@3.14.1 io.smallrye.config.smallrye-config-core-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-core-3.14.1.jarMD5: 09fe61a586970ffae935effe9fae4fa5SHA1: afbddf21eab5f4972a59590fc1d769337465ce1aSHA256: b5d16df55956c38820f332e9bb93593e9c6988880cd234ae91c288410e383d39
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.config.smallrye-config-core High Vendor jar package name config Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Product file name io.smallrye.config.smallrye-config-core High Product jar package name config Highest Product jar package name config Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Config: Core High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Config: Core Medium Version file version 3.14.1 High Version Manifest Implementation-Version 3.14.1 High
Related Dependencies io.smallrye.config.smallrye-config-core-3.14.1.jar (shaded: io.smallrye.config:smallrye-config-core:3.14.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-core-3.14.1.jar/META-INF/maven/io.smallrye.config/smallrye-config-core/pom.xml MD5: bfdd7570474c81e533b62a2740dee9d2 SHA1: 3098875a9f565c628296da4c004f0a64989acee3 SHA256: ef24ae7d47aa2dd919f2238598625531066e4d041177f9d2a117a164a28b3621 pkg:maven/io.smallrye.config/smallrye-config-core@3.14.1 io.smallrye.config.smallrye-config-core-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-core-3.14.1.jar MD5: 09fe61a586970ffae935effe9fae4fa5 SHA1: afbddf21eab5f4972a59590fc1d769337465ce1a SHA256: b5d16df55956c38820f332e9bb93593e9c6988880cd234ae91c288410e383d39 smallrye-config-core-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/config/smallrye-config-core/3.14.1/smallrye-config-core-3.14.1.jar MD5: 09fe61a586970ffae935effe9fae4fa5 SHA1: afbddf21eab5f4972a59590fc1d769337465ce1a SHA256: b5d16df55956c38820f332e9bb93593e9c6988880cd234ae91c288410e383d39 pkg:maven/io.smallrye.config/smallrye-config-core@3.14.1 io.smallrye.config.smallrye-config-validator-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-validator-3.14.1.jarMD5: 409df1c5b4292a8829b51f0b07739d95SHA1: 96821ca6b9afb7979b44cf562792c75d64ef6896SHA256: 98fbc702b99cc7a4956a41a47f4cfd97d5ca1a88037570680740bd2bcff1f944
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.config.smallrye-config-validator High Vendor jar package name config Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Product file name io.smallrye.config.smallrye-config-validator High Product jar package name config Highest Product jar package name config Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name validator Highest Product jar package name validator Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Config: Validator High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Config: Validator Medium Version file version 3.14.1 High Version Manifest Implementation-Version 3.14.1 High
Related Dependencies io.smallrye.config.smallrye-config-validator-3.14.1.jar (shaded: io.smallrye.config:smallrye-config-validator:3.14.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-validator-3.14.1.jar/META-INF/maven/io.smallrye.config/smallrye-config-validator/pom.xml MD5: 3e2a8ccbd945f286b1d8c3f78a18c4a9 SHA1: f1f1359d5c3bb465923d840c8136a869131e8159 SHA256: f1b61475f1c4c8068a25a5867090398ca1fcb3b9bbb6f2c24c8ed5924bf34a01 pkg:maven/io.smallrye.config/smallrye-config-validator@3.14.1 io.smallrye.config.smallrye-config-validator-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.config.smallrye-config-validator-3.14.1.jar MD5: 409df1c5b4292a8829b51f0b07739d95 SHA1: 96821ca6b9afb7979b44cf562792c75d64ef6896 SHA256: 98fbc702b99cc7a4956a41a47f4cfd97d5ca1a88037570680740bd2bcff1f944 smallrye-config-validator-3.14.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/config/smallrye-config-validator/3.14.1/smallrye-config-validator-3.14.1.jar MD5: 409df1c5b4292a8829b51f0b07739d95 SHA1: 96821ca6b9afb7979b44cf562792c75d64ef6896 SHA256: 98fbc702b99cc7a4956a41a47f4cfd97d5ca1a88037570680740bd2bcff1f944 pkg:maven/io.smallrye.config/smallrye-config-validator@3.14.1 CVE-2025-15104 suppress
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd). CWE-918 Server-Side Request Forgery (SSRF)
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
io.smallrye.jandex-3.5.2.jarDescription:
SmallRye Build Parent POM License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.jandex-3.5.2.jar
MD5: 9b42b4d771cef1420c53a011e7ce1e7e
SHA1: 2e59141aa1fc93306265ea29337c09f68138d969
SHA256: bc7b27d6215a1f205ff6312594132f1bff9b8450009b59790e17e23982d8d9c0
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.jandex High Vendor jar package name jandex Highest Vendor jar package name jandex Low Vendor jar package name jboss Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-symbolicname io.smallrye.jandex Medium Vendor Manifest multi-release true Low Product file name io.smallrye.jandex High Product jar package name jandex Highest Product jar package name jandex Low Product Manifest build-jdk-spec 21 Low Product Manifest Bundle-Name Jandex: Core Medium Product Manifest bundle-symbolicname io.smallrye.jandex Medium Product Manifest multi-release true Low Version file name io.smallrye.jandex Medium Version file version 3.5.2 High Version Manifest build-jdk-spec 21 Low Version Manifest Bundle-Version 3.5.2 High
Related Dependencies io.smallrye.jandex-3.5.2.jar (shaded: io.smallrye:jandex:3.5.2)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.jandex-3.5.2.jar/META-INF/maven/io.smallrye/jandex/pom.xml MD5: 859087dfe658bb62e226547c1110597b SHA1: ea321ac32c043b4b4ee03a13f1785889495796c5 SHA256: 44d2fd0c46f699a7e0aa552f4b91163f11e70a71efd23671cf0b7398d28d65de pkg:maven/io.smallrye/jandex@3.5.2 io.smallrye.jandex-3.5.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.jandex-3.5.2.jar MD5: 9b42b4d771cef1420c53a011e7ce1e7e SHA1: 2e59141aa1fc93306265ea29337c09f68138d969 SHA256: bc7b27d6215a1f205ff6312594132f1bff9b8450009b59790e17e23982d8d9c0 jandex-3.5.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/jandex/3.5.2/jandex-3.5.2.jar MD5: 9b42b4d771cef1420c53a011e7ce1e7e SHA1: 2e59141aa1fc93306265ea29337c09f68138d969 SHA256: bc7b27d6215a1f205ff6312594132f1bff9b8450009b59790e17e23982d8d9c0 pkg:maven/io.smallrye/jandex@3.5.2 io.smallrye.reactive.mutiny-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-3.1.0.jarMD5: 2d84bdc850e8981446053036beb193b4SHA1: 4d089347cab12207bc62417df901fa40341f341cSHA256: 314bd5942c8a238d19edd000325b12cda54916a409f2c3af5c4e9e49c3a08db3
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.mutiny High Vendor jar package name io Low Vendor jar package name mutiny Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.mutiny High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name operators Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Core library High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny Low Product Manifest specification-title SmallRye Mutiny - Core library Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High
Related Dependencies io.smallrye.reactive.mutiny-3.1.0.jar (shaded: io.smallrye.reactive:mutiny:3.1.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-3.1.0.jar/META-INF/maven/io.smallrye.reactive/mutiny/pom.xml MD5: ad7e815b1beef5fede9685563fc4c9be SHA1: 699e37f9aaf0b6b12b2413bba874737dbd12e4b6 SHA256: 12d1a857d030a87d72c25a271d71dd2bac93333540b978d786a8bcebb94fcbfa pkg:maven/io.smallrye.reactive/mutiny@3.1.0 io.smallrye.reactive.mutiny-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-3.1.0.jar MD5: 2d84bdc850e8981446053036beb193b4 SHA1: 4d089347cab12207bc62417df901fa40341f341c SHA256: 314bd5942c8a238d19edd000325b12cda54916a409f2c3af5c4e9e49c3a08db3 io.smallrye.reactive.mutiny-reactive-streams-operators-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-reactive-streams-operators-3.1.0.jar MD5: f243d78b4020bd189bf755bf3d8f7d68 SHA1: ee5a9abe9d7c9d0f70d09c0961350c5e360f9779 SHA256: 56b298b1bccb87332c59a4bebd373491f268cb7ce209fe13b81a35911c877008 mutiny-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/mutiny/3.1.0/mutiny-3.1.0.jar MD5: 2d84bdc850e8981446053036beb193b4 SHA1: 4d089347cab12207bc62417df901fa40341f341c SHA256: 314bd5942c8a238d19edd000325b12cda54916a409f2c3af5c4e9e49c3a08db3 pkg:maven/io.smallrye.reactive/mutiny@3.1.0 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.mutiny-reactive-streams-operators-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-reactive-streams-operators-3.1.0.jarMD5: f243d78b4020bd189bf755bf3d8f7d68SHA1: ee5a9abe9d7c9d0f70d09c0961350c5e360f9779SHA256: 56b298b1bccb87332c59a4bebd373491f268cb7ce209fe13b81a35911c877008
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.mutiny-reactive-streams-operators High Vendor jar package name io Low Vendor jar package name mutiny Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.mutiny-reactive-streams-operators High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name streams Highest Product jar package name streams Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - MicroProfile Reactive Streams Operators implementation High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny Low Product Manifest specification-title SmallRye Mutiny - MicroProfile Reactive Streams Operators implementation Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High
Related Dependencies io.smallrye.reactive.mutiny-reactive-streams-operators-3.1.0.jar (shaded: io.smallrye.reactive:mutiny-reactive-streams-operators:3.1.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-reactive-streams-operators-3.1.0.jar/META-INF/maven/io.smallrye.reactive/mutiny-reactive-streams-operators/pom.xml MD5: 774134ac51811a70789bea6429735603 SHA1: 485bf504a3d15307cb6489dce5a54c2dc474493f SHA256: 6f82dfa0135041c5dffd3b77a030d5dcaa789f7cb3a8c9a8245c9f6ddd3235b2 pkg:maven/io.smallrye.reactive/mutiny-reactive-streams-operators@3.1.0 mutiny-reactive-streams-operators-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/mutiny-reactive-streams-operators/3.1.0/mutiny-reactive-streams-operators-3.1.0.jar MD5: f243d78b4020bd189bf755bf3d8f7d68 SHA1: ee5a9abe9d7c9d0f70d09c0961350c5e360f9779 SHA256: 56b298b1bccb87332c59a4bebd373491f268cb7ce209fe13b81a35911c877008 pkg:maven/io.smallrye.reactive/mutiny-reactive-streams-operators@3.1.0 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.mutiny-smallrye-context-propagation-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-smallrye-context-propagation-3.1.0.jarMD5: 796cd463f2e9ffcdd3c75a696ca65033SHA1: 0dca030f0c51f4626b608f97655001b91cadbe5dSHA256: 3d4c64d04a993ba19bf69a408f4851aa9cce1b01080939891a83996b12c1b4ac
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.mutiny-smallrye-context-propagation High Vendor jar package name context Highest Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name mutiny Highest Vendor jar package name mutiny Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest automatic-module-name io.smallrye.mutiny.context Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.mutiny-smallrye-context-propagation High Product jar package name context Highest Product jar package name context Low Product jar package name io Highest Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest automatic-module-name io.smallrye.mutiny.context Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Integration with SmallRye Context Propagation High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny Low Product Manifest specification-title SmallRye Mutiny - Integration with SmallRye Context Propagation Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High
Related Dependencies io.smallrye.reactive.mutiny-smallrye-context-propagation-3.1.0.jar (shaded: io.smallrye.reactive:mutiny-smallrye-context-propagation:3.1.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-smallrye-context-propagation-3.1.0.jar/META-INF/maven/io.smallrye.reactive/mutiny-smallrye-context-propagation/pom.xml MD5: 10e53fa6b0aa002691b142135ca30b3c SHA1: 1f327242044218aee1e94a62cea903d17f417241 SHA256: 8d5f613baeb4d2fe5b65e7f08b420a431373f81302e3853d0f038544da93f6a7 pkg:maven/io.smallrye.reactive/mutiny-smallrye-context-propagation@3.1.0 io.smallrye.reactive.mutiny-smallrye-context-propagation-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-smallrye-context-propagation-3.1.0.jar MD5: 796cd463f2e9ffcdd3c75a696ca65033 SHA1: 0dca030f0c51f4626b608f97655001b91cadbe5d SHA256: 3d4c64d04a993ba19bf69a408f4851aa9cce1b01080939891a83996b12c1b4ac mutiny-smallrye-context-propagation-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/mutiny-smallrye-context-propagation/3.1.0/mutiny-smallrye-context-propagation-3.1.0.jar MD5: 796cd463f2e9ffcdd3c75a696ca65033 SHA1: 0dca030f0c51f4626b608f97655001b91cadbe5d SHA256: 3d4c64d04a993ba19bf69a408f4851aa9cce1b01080939891a83996b12c1b4ac pkg:maven/io.smallrye.reactive/mutiny-smallrye-context-propagation@3.1.0 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.mutiny-zero-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-zero-1.1.1.jarMD5: 79002b47fccb84b304b2cb3a6866d30bSHA1: 73cc6067cc49cf8a351733f64ac093b7e019438eSHA256: 2ba037374ea75e29921726d34a2ac426b88bd425a9e646802f905c117457a7a8
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.mutiny-zero High Vendor jar package name internal Low Vendor jar package name mutiny Low Vendor jar package name zero Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.mutiny-zero High Product jar package name internal Low Product jar package name mutiny Highest Product jar package name zero Highest Product jar package name zero Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny Zero High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Mutiny Zero Medium Version file version 1.1.1 High Version Manifest Implementation-Version 1.1.1 High
Related Dependencies io.smallrye.reactive.mutiny-zero-1.1.1.jar (shaded: io.smallrye.reactive:mutiny-zero:1.1.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-zero-1.1.1.jar/META-INF/maven/io.smallrye.reactive/mutiny-zero/pom.xml MD5: 37bba27a3a5b7559623a47e206755a2d SHA1: 2d444871f0fe5a9261d0ec331d5fcf5b420ed57d SHA256: e2f401446a308f06342e4e07b6dae9b747bc69f66d913bb992088c8e9e84a0a6 pkg:maven/io.smallrye.reactive/mutiny-zero@1.1.1 io.smallrye.reactive.mutiny-zero-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-zero-1.1.1.jar MD5: 79002b47fccb84b304b2cb3a6866d30b SHA1: 73cc6067cc49cf8a351733f64ac093b7e019438e SHA256: 2ba037374ea75e29921726d34a2ac426b88bd425a9e646802f905c117457a7a8 io.smallrye.reactive.mutiny-zero-flow-adapters-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-zero-flow-adapters-1.1.1.jar MD5: 7d0609ddc6c96af1f9db3d89bd8b5e63 SHA1: b83c3d76c803b6362eb264c728ba95a30a72855d SHA256: 7e2576e235bcd277c52d67e11d70d1922040bc1b769883d985d68c60597a1ab2 mutiny-zero-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/mutiny-zero/1.1.1/mutiny-zero-1.1.1.jar MD5: 79002b47fccb84b304b2cb3a6866d30b SHA1: 73cc6067cc49cf8a351733f64ac093b7e019438e SHA256: 2ba037374ea75e29921726d34a2ac426b88bd425a9e646802f905c117457a7a8 pkg:maven/io.smallrye.reactive/mutiny-zero@1.1.1 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.mutiny-zero-flow-adapters-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-zero-flow-adapters-1.1.1.jarMD5: 7d0609ddc6c96af1f9db3d89bd8b5e63SHA1: b83c3d76c803b6362eb264c728ba95a30a72855dSHA256: 7e2576e235bcd277c52d67e11d70d1922040bc1b769883d985d68c60597a1ab2
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.mutiny-zero-flow-adapters High Vendor jar package name flow Low Vendor jar package name mutiny Low Vendor jar package name zero Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.mutiny-zero-flow-adapters High Product jar package name adapters Highest Product jar package name adapters Low Product jar package name flow Highest Product jar package name flow Low Product jar package name mutiny Highest Product jar package name zero Highest Product jar package name zero Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny Zero JDK Flow / Reactive Streams Adapters High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Mutiny Zero JDK Flow / Reactive Streams Adapters Medium Version file version 1.1.1 High Version Manifest Implementation-Version 1.1.1 High
Related Dependencies io.smallrye.reactive.mutiny-zero-flow-adapters-1.1.1.jar (shaded: io.smallrye.reactive:mutiny-zero-flow-adapters:1.1.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.mutiny-zero-flow-adapters-1.1.1.jar/META-INF/maven/io.smallrye.reactive/mutiny-zero-flow-adapters/pom.xml MD5: 73aff6fc3e9731e69aeb97eaee6649ba SHA1: fa24cff30244efa26f33533c81432c2ca66c2080 SHA256: c4720d5547f3a017e8d5c157e3f526e9bb8608cfe5a33721a10c6487ccd51861 pkg:maven/io.smallrye.reactive/mutiny-zero-flow-adapters@1.1.1 mutiny-zero-flow-adapters-1.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/mutiny-zero-flow-adapters/1.1.1/mutiny-zero-flow-adapters-1.1.1.jar MD5: 7d0609ddc6c96af1f9db3d89bd8b5e63 SHA1: b83c3d76c803b6362eb264c728ba95a30a72855d SHA256: 7e2576e235bcd277c52d67e11d70d1922040bc1b769883d985d68c60597a1ab2 pkg:maven/io.smallrye.reactive/mutiny-zero-flow-adapters@1.1.1 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.smallrye-mutiny-vertx-core-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-core-3.21.3.jarMD5: 87a71ec3819c68e8da0e7aa4e0769301SHA1: 1dc6919d982c70bd2a64a3df2e523e024dbb9c58SHA256: 53606c52da6c1b937b244532b1d8c40ae13ae0a78df1cb3808fcf6f7032c8616
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-mutiny-vertx-core High Vendor jar package name core Highest Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name mutiny Highest Vendor jar package name mutiny Low Vendor jar package name smallrye Highest Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.core Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-mutiny-vertx-core High Product jar package name core Highest Product jar package name core Low Product jar package name io Highest Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name smallrye Highest Product jar package name vertx Highest Product jar package name vertx Low Product Manifest automatic-module-name io.smallrye.mutiny.vertx.core Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x Core High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x Core Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-auth-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-auth-common-3.21.3.jar MD5: 3a314ccfc2fc5249098b72c899d0ba38 SHA1: a8ff5660a3af96f20ba6d40b3a6456c002320612 SHA256: cdfc220728c203f111c8897802a9844cff70796ad5269fc8009bf4177d65103f io.smallrye.reactive.smallrye-mutiny-vertx-auth-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-auth-common-3.21.3.jar MD5: 3a314ccfc2fc5249098b72c899d0ba38 SHA1: a8ff5660a3af96f20ba6d40b3a6456c002320612 SHA256: cdfc220728c203f111c8897802a9844cff70796ad5269fc8009bf4177d65103f io.smallrye.reactive.smallrye-mutiny-vertx-bridge-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-bridge-common-3.21.3.jar MD5: 4ea9045872070a9b835004b4bd157808 SHA1: 94a81c66ebe187a9bbac43361f8f843bbbfecaf1 SHA256: 7be0b77f9f8dc0c298796db8de7a25859c77c64e948c3a31f702fcaf234d9ec2 io.smallrye.reactive.smallrye-mutiny-vertx-bridge-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-bridge-common-3.21.3.jar MD5: 4ea9045872070a9b835004b4bd157808 SHA1: 94a81c66ebe187a9bbac43361f8f843bbbfecaf1 SHA256: 7be0b77f9f8dc0c298796db8de7a25859c77c64e948c3a31f702fcaf234d9ec2 io.smallrye.reactive.smallrye-mutiny-vertx-core-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-core:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-core-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-core/pom.xml MD5: 99d44c5f99cf613eb09c22db3a6a8cf1 SHA1: c1d40d8cbc00cc9075cdd32c1d42bca68f5d430e SHA256: f3172ed7cbebc049b433c2812d799829a7b2f0518cfb348d2dac7138c4b6c8c2 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-core@3.21.3 io.smallrye.reactive.smallrye-mutiny-vertx-core-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-core-3.21.3.jar MD5: 87a71ec3819c68e8da0e7aa4e0769301 SHA1: 1dc6919d982c70bd2a64a3df2e523e024dbb9c58 SHA256: 53606c52da6c1b937b244532b1d8c40ae13ae0a78df1cb3808fcf6f7032c8616 io.smallrye.reactive.smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jar MD5: 7d2bf2eaa4bb08877a1e76b8595607cb SHA1: 0c43a3e6a567abf6d87887593c7bb32d94c6d792 SHA256: 5e2005164b8e1c9e3cb6ee4de432eb6c58ceb3f8ab98fefa1432d3852c2bf00a io.smallrye.reactive.smallrye-mutiny-vertx-runtime-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-runtime-3.21.3.jar MD5: 3e308d0f504219aad672231bec0d1036 SHA1: 0b4b36261641dbd4e130fb22d2ba4b3b28693689 SHA256: 047c540d6d4b9e65569048d964525f8d306d43726d6ae9427ddb0395c9b457bb io.smallrye.reactive.smallrye-mutiny-vertx-uri-template-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-uri-template-3.21.3.jar MD5: d301b06de44f0fccf67686dd1c642e36 SHA1: b6669b4320339aefce224625aaeaf1ee57387158 SHA256: 847f3650e5fce6de00ca58e31665270a084ec6b283a039fe8848447e8d5a3be9 io.smallrye.reactive.smallrye-mutiny-vertx-web-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-3.21.3.jar MD5: 435ab21d8323db7d8ae10ce7843c5839 SHA1: 864472ea946d6b0b9b06bbfa7d58d34bab42318d SHA256: eb7152d5e737b920c03e8b2cfe1e5f2a15ac6b2eb6e65e284e1514844cc65973 io.smallrye.reactive.smallrye-mutiny-vertx-web-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-common-3.21.3.jar MD5: 47c969c198c1653b062e5a56d95c99fc SHA1: cfcdec164e8b3d98556eec6051b16c88e00b935c SHA256: 10c297b7d68d04343e2548c0814962b39123af69804f9f4da3e522b005f99db5 smallrye-mutiny-vertx-core-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-core/3.21.3/smallrye-mutiny-vertx-core-3.21.3.jar MD5: 87a71ec3819c68e8da0e7aa4e0769301 SHA1: 1dc6919d982c70bd2a64a3df2e523e024dbb9c58 SHA256: 53606c52da6c1b937b244532b1d8c40ae13ae0a78df1cb3808fcf6f7032c8616 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-core@3.21.3 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.smallrye-mutiny-vertx-web-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-3.21.3.jarMD5: 435ab21d8323db7d8ae10ce7843c5839SHA1: 864472ea946d6b0b9b06bbfa7d58d34bab42318dSHA256: eb7152d5e737b920c03e8b2cfe1e5f2a15ac6b2eb6e65e284e1514844cc65973
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-mutiny-vertx-web High Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name mutiny Highest Vendor jar package name mutiny Low Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.web Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-mutiny-vertx-web High Product jar package name ext Low Product jar package name io Highest Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name vertx Highest Product jar package name vertx Low Product Manifest automatic-module-name io.smallrye.mutiny.vertx.web Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x Web High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x Web Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jar MD5: 7d2bf2eaa4bb08877a1e76b8595607cb SHA1: 0c43a3e6a567abf6d87887593c7bb32d94c6d792 SHA256: 5e2005164b8e1c9e3cb6ee4de432eb6c58ceb3f8ab98fefa1432d3852c2bf00a io.smallrye.reactive.smallrye-mutiny-vertx-runtime-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-runtime-3.21.3.jar MD5: 3e308d0f504219aad672231bec0d1036 SHA1: 0b4b36261641dbd4e130fb22d2ba4b3b28693689 SHA256: 047c540d6d4b9e65569048d964525f8d306d43726d6ae9427ddb0395c9b457bb io.smallrye.reactive.smallrye-mutiny-vertx-uri-template-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-uri-template-3.21.3.jar MD5: d301b06de44f0fccf67686dd1c642e36 SHA1: b6669b4320339aefce224625aaeaf1ee57387158 SHA256: 847f3650e5fce6de00ca58e31665270a084ec6b283a039fe8848447e8d5a3be9 io.smallrye.reactive.smallrye-mutiny-vertx-web-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-web:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-web/pom.xml MD5: 09df72065c7f78418b60f731cc8e2ecf SHA1: 4511ad2d5be0fed48391dfa13b8f193bb1d1d615 SHA256: 0d40965d824752506fa51799a3e576212aa31be45b16dad8061e0d551a0b9cb1 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-web@3.21.3 io.smallrye.reactive.smallrye-mutiny-vertx-web-client-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-client-3.21.3.jar MD5: c461a025f29d76d549e1835a723df143 SHA1: a30e2ba3dddfda43688053fe1a38e12ed28ccba8 SHA256: 705f35b208c87f50b8401cec24af04c94a5e1e8943b421071f278b8a98c0082f io.smallrye.reactive.smallrye-mutiny-vertx-web-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-common-3.21.3.jar MD5: 47c969c198c1653b062e5a56d95c99fc SHA1: cfcdec164e8b3d98556eec6051b16c88e00b935c SHA256: 10c297b7d68d04343e2548c0814962b39123af69804f9f4da3e522b005f99db5 smallrye-mutiny-vertx-web-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-web/3.21.3/smallrye-mutiny-vertx-web-3.21.3.jar MD5: 435ab21d8323db7d8ae10ce7843c5839 SHA1: 864472ea946d6b0b9b06bbfa7d58d34bab42318d SHA256: eb7152d5e737b920c03e8b2cfe1e5f2a15ac6b2eb6e65e284e1514844cc65973 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-web@3.21.3 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.smallrye-reactive-converter-api-3.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-converter-api-3.0.3.jarMD5: 825d89264db4250072a5aec0d2ff5f98SHA1: d36f3eb155b6f7296f447f1d82249d07c3c2ea91SHA256: 8f47b3cbdef72c5875836011beb02f485918febbb73c15d51738c566eb669253
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-converter-api High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-converter-api High Product jar package name converters Highest Product jar package name converters Low Product jar package name io Highest Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Converters: API High Product Manifest implementation-url https://smallrye.io Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title SmallRye Reactive Converters: API Medium Version file version 3.0.3 High Version Manifest Implementation-Version 3.0.3 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-converter-api-3.0.3.jar (shaded: io.smallrye.reactive:smallrye-reactive-converter-api:3.0.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-converter-api-3.0.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-converter-api/pom.xml MD5: e5526076499fc22553a90e0f662211f7 SHA1: 3485fa463b8f10ab0ea196aac562ac40fc7dc635 SHA256: 129b08b5664c4b79e9493b2be0a50cbca8ea1c9700ccb7da95e67cc7781f1301 pkg:maven/io.smallrye.reactive/smallrye-reactive-converter-api@3.0.3 io.smallrye.reactive.smallrye-reactive-converter-api-3.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-converter-api-3.0.3.jar MD5: 825d89264db4250072a5aec0d2ff5f98 SHA1: d36f3eb155b6f7296f447f1d82249d07c3c2ea91 SHA256: 8f47b3cbdef72c5875836011beb02f485918febbb73c15d51738c566eb669253 smallrye-reactive-converter-api-3.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-converter-api/3.0.3/smallrye-reactive-converter-api-3.0.3.jar MD5: 825d89264db4250072a5aec0d2ff5f98 SHA1: d36f3eb155b6f7296f447f1d82249d07c3c2ea91 SHA256: 8f47b3cbdef72c5875836011beb02f485918febbb73c15d51738c566eb669253 pkg:maven/io.smallrye.reactive/smallrye-reactive-converter-api@3.0.3 io.smallrye.reactive.smallrye-reactive-converter-mutiny-3.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-converter-mutiny-3.0.3.jarMD5: 035cb1d3ba2b64b2b7d8e1f1cf5ed5cfSHA1: b0f37e345418b2d6d5e9f4b468be9d659c7391d7SHA256: 5255e5e77d38b0bc166511c3ce7af3a97cf1edeaa19d2946102f929d99273111
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-converter-mutiny High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-converter-mutiny High Product jar package name converters Highest Product jar package name converters Low Product jar package name io Highest Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Converters: Mutiny High Product Manifest implementation-url https://smallrye.io Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title SmallRye Reactive Converters: Mutiny Medium Version file version 3.0.3 High Version Manifest Implementation-Version 3.0.3 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-converter-mutiny-3.0.3.jar (shaded: io.smallrye.reactive:smallrye-reactive-converter-mutiny:3.0.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-converter-mutiny-3.0.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-converter-mutiny/pom.xml MD5: a5ac908bc6030b6e4e19334eaeb6cad2 SHA1: 45a3471491395fb7f1051f76f12aa67f063ca885 SHA256: aa79c9ef380c30e941ecde5fa3f0f0a942c1263762ea25401d8c78afd96604ad pkg:maven/io.smallrye.reactive/smallrye-reactive-converter-mutiny@3.0.3 io.smallrye.reactive.smallrye-reactive-converter-mutiny-3.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-converter-mutiny-3.0.3.jar MD5: 035cb1d3ba2b64b2b7d8e1f1cf5ed5cf SHA1: b0f37e345418b2d6d5e9f4b468be9d659c7391d7 SHA256: 5255e5e77d38b0bc166511c3ce7af3a97cf1edeaa19d2946102f929d99273111 smallrye-reactive-converter-mutiny-3.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-converter-mutiny/3.0.3/smallrye-reactive-converter-mutiny-3.0.3.jar MD5: 035cb1d3ba2b64b2b7d8e1f1cf5ed5cf SHA1: b0f37e345418b2d6d5e9f4b468be9d659c7391d7 SHA256: 5255e5e77d38b0bc166511c3ce7af3a97cf1edeaa19d2946102f929d99273111 pkg:maven/io.smallrye.reactive/smallrye-reactive-converter-mutiny@3.0.3 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.reactive.smallrye-reactive-messaging-api-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-api-4.31.0.jarMD5: c3bd114097f73e866e495d2ff1b469ffSHA1: 396d33d12894fafeae52e31c3b6315e5440529c0SHA256: f7843fc783d252ea517a35028e7ba39aa343c71c7035ea8e82e9cda77a97c965
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-messaging-api High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-messaging-api High Product jar package name io Highest Product jar package name messaging Highest Product jar package name messaging Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Messaging : API High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Reactive Messaging : API Medium Version file version 4.31.0 High Version Manifest Implementation-Version 4.31.0 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-messaging-api-4.31.0.jar (shaded: io.smallrye.reactive:smallrye-reactive-messaging-api:4.31.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-api-4.31.0.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-messaging-api/pom.xml MD5: fe138c4414373027002434b1ecd3f307 SHA1: 384742be4fb5fe1d619e8416b7b74dec37d0d532 SHA256: edb0718f6f563cbd4c3a81ce065343461a6b8ab02008b2844d2d991f5c47d9f4 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-api@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-api-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-api-4.31.0.jar MD5: c3bd114097f73e866e495d2ff1b469ff SHA1: 396d33d12894fafeae52e31c3b6315e5440529c0 SHA256: f7843fc783d252ea517a35028e7ba39aa343c71c7035ea8e82e9cda77a97c965 smallrye-reactive-messaging-api-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-messaging-api/4.31.0/smallrye-reactive-messaging-api-4.31.0.jar MD5: c3bd114097f73e866e495d2ff1b469ff SHA1: 396d33d12894fafeae52e31c3b6315e5440529c0 SHA256: f7843fc783d252ea517a35028e7ba39aa343c71c7035ea8e82e9cda77a97c965 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-api@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-health-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-health-4.31.0.jarMD5: bb61815b8fc1e08c4373733107b6e1cdSHA1: 626a6e1b0a506cd9b69b8c7d42594f9d2fdd949aSHA256: db7cdf1bcb10456252f19671e2d7c67c5f4e6d59302b3a384c52e77f92db2f40
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-messaging-health High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-messaging-health High Product jar package name io Highest Product jar package name messaging Highest Product jar package name messaging Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Messaging : Health High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Reactive Messaging : Health Medium Version file version 4.31.0 High Version Manifest Implementation-Version 4.31.0 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-messaging-health-4.31.0.jar (shaded: io.smallrye.reactive:smallrye-reactive-messaging-health:4.31.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-health-4.31.0.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-messaging-health/pom.xml MD5: c6e73cb4953d5fff0483b04896b0285f SHA1: 997072f3ab113eda774e27ba1d172de7655a3b1b SHA256: 192a986a9029dbd47c2b5a20f59a4107934947daa91e59cf0987aca3de366bc2 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-health@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-health-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-health-4.31.0.jar MD5: bb61815b8fc1e08c4373733107b6e1cd SHA1: 626a6e1b0a506cd9b69b8c7d42594f9d2fdd949a SHA256: db7cdf1bcb10456252f19671e2d7c67c5f4e6d59302b3a384c52e77f92db2f40 smallrye-reactive-messaging-health-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-messaging-health/4.31.0/smallrye-reactive-messaging-health-4.31.0.jar MD5: bb61815b8fc1e08c4373733107b6e1cd SHA1: 626a6e1b0a506cd9b69b8c7d42594f9d2fdd949a SHA256: db7cdf1bcb10456252f19671e2d7c67c5f4e6d59302b3a384c52e77f92db2f40 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-health@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-otel-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-otel-4.31.0.jarMD5: 22d59c91049adbea0056eaa2321c98b1SHA1: f47c5e9cef49812beab0314cb7ea1f836f8ad33fSHA256: 6e30fc940ff2e2fa8ff86cde99130e007fed6b3fa43ad8a51a3a3314bc9e76f8
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-messaging-otel High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-messaging-otel High Product jar package name io Highest Product jar package name messaging Highest Product jar package name messaging Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Messaging : Open Telemetry Instrumenter High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Reactive Messaging : Open Telemetry Instrumenter Medium Version file version 4.31.0 High Version Manifest Implementation-Version 4.31.0 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-messaging-otel-4.31.0.jar (shaded: io.smallrye.reactive:smallrye-reactive-messaging-otel:4.31.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-otel-4.31.0.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-messaging-otel/pom.xml MD5: 626912c325be77b6319b7bc8372fb367 SHA1: 0877e53470f40ed395a8abcee51ef8755b01069f SHA256: 9f9e53412be0ff92fe726d91cca78f08860401d43c15584260b848b92c8d4844 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-otel@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-otel-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-otel-4.31.0.jar MD5: 22d59c91049adbea0056eaa2321c98b1 SHA1: f47c5e9cef49812beab0314cb7ea1f836f8ad33f SHA256: 6e30fc940ff2e2fa8ff86cde99130e007fed6b3fa43ad8a51a3a3314bc9e76f8 smallrye-reactive-messaging-otel-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-messaging-otel/4.31.0/smallrye-reactive-messaging-otel-4.31.0.jar MD5: 22d59c91049adbea0056eaa2321c98b1 SHA1: f47c5e9cef49812beab0314cb7ea1f836f8ad33f SHA256: 6e30fc940ff2e2fa8ff86cde99130e007fed6b3fa43ad8a51a3a3314bc9e76f8 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-otel@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-provider-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-provider-4.31.0.jarMD5: 4c6c3eacf455bd762bcae7b45b300461SHA1: c0cd08c871461c33753b9610e135ac1462acadffSHA256: af688a218296a6ccd3aae5681cf05367fdd744a869bd55669eb7306a0ecb84c1
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-messaging-provider High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-messaging-provider High Product jar package name io Highest Product jar package name messaging Highest Product jar package name messaging Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Messaging : Provider High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Reactive Messaging : Provider Medium Version file version 4.31.0 High Version Manifest Implementation-Version 4.31.0 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-messaging-provider-4.31.0.jar (shaded: io.smallrye.reactive:smallrye-reactive-messaging-provider:4.31.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-provider-4.31.0.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-messaging-provider/pom.xml MD5: 337dfba2496166a57e0da48fef18593a SHA1: 81f64afac2821ebeba7f3b9e6465c60b8b19a0f4 SHA256: 9fbe5b63e4f0cb52432a8262a82481126a265e08124dca9c893e5e11f6e9b1e1 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-provider@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-provider-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-provider-4.31.0.jar MD5: 4c6c3eacf455bd762bcae7b45b300461 SHA1: c0cd08c871461c33753b9610e135ac1462acadff SHA256: af688a218296a6ccd3aae5681cf05367fdd744a869bd55669eb7306a0ecb84c1 smallrye-reactive-messaging-provider-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-messaging-provider/4.31.0/smallrye-reactive-messaging-provider-4.31.0.jar MD5: 4c6c3eacf455bd762bcae7b45b300461 SHA1: c0cd08c871461c33753b9610e135ac1462acadff SHA256: af688a218296a6ccd3aae5681cf05367fdd744a869bd55669eb7306a0ecb84c1 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-provider@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq-4.31.0.jarMD5: 8c54ca15fdf5ddf162bd2000db3c817eSHA1: 78ee63a9510484093ff333ed9c1a70ab67169c51SHA256: 6d9b00b67a6a593e12b7b50c91fa607b6d02b76af5d8f3b0bfc95705226bd1b8
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq High Vendor jar package name io Low Vendor jar package name reactive Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq High Product jar package name io Highest Product jar package name messaging Highest Product jar package name messaging Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Reactive Messaging : Connector :: RabbitMQ High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Reactive Messaging : Connector :: RabbitMQ Medium Version file version 4.31.0 High Version Manifest Implementation-Version 4.31.0 High
Related Dependencies io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq-4.31.0.jar (shaded: io.smallrye.reactive:smallrye-reactive-messaging-rabbitmq:4.31.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq-4.31.0.jar/META-INF/maven/io.smallrye.reactive/smallrye-reactive-messaging-rabbitmq/pom.xml MD5: 03ddfa13b6e23a86676524ee11e63e22 SHA1: 517bad80c81f012d746615f1e36d1566fa66e09d SHA256: 4f78e96eb4889f5d17b03d2baedbeadd44d872773b1c586e4294f950fb56706a pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-rabbitmq@4.31.0 io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-reactive-messaging-rabbitmq-4.31.0.jar MD5: 8c54ca15fdf5ddf162bd2000db3c817e SHA1: 78ee63a9510484093ff333ed9c1a70ab67169c51 SHA256: 6d9b00b67a6a593e12b7b50c91fa607b6d02b76af5d8f3b0bfc95705226bd1b8 smallrye-reactive-messaging-rabbitmq-4.31.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-reactive-messaging-rabbitmq/4.31.0/smallrye-reactive-messaging-rabbitmq-4.31.0.jar MD5: 8c54ca15fdf5ddf162bd2000db3c817e SHA1: 78ee63a9510484093ff333ed9c1a70ab67169c51 SHA256: 6d9b00b67a6a593e12b7b50c91fa607b6d02b76af5d8f3b0bfc95705226bd1b8 pkg:maven/io.smallrye.reactive/smallrye-reactive-messaging-rabbitmq@4.31.0 io.smallrye.reactive.vertx-mutiny-generator-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.reactive.vertx-mutiny-generator-3.21.3.jarMD5: 3cba529be09860afdb7ea3aeb124b601SHA1: 208f61c2efd4f889f2fa1025f1ac1682b28aed44SHA256: aa53ff28bd9caf0c7c32c8ebffe025a01d9f5c18b0e74be569060d7978e1f187
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.reactive.vertx-mutiny-generator High Vendor jar package name io Low Vendor jar package name mutiny Low Vendor jar package name smallrye Highest Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Product file name io.smallrye.reactive.vertx-mutiny-generator High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name mutiny Low Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name vertx Highest Product jar package name vertx Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Code Generator High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Code Generator Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High
Related Dependencies io.smallrye.reactive.vertx-mutiny-generator-3.21.3.jar (shaded: io.smallrye.reactive:vertx-mutiny-generator:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.vertx-mutiny-generator-3.21.3.jar/META-INF/maven/io.smallrye.reactive/vertx-mutiny-generator/pom.xml MD5: 5c55f12cb96e8b48b19cae0a96f7cdf9 SHA1: f6d1a99931bf850b159019441808d9e50d023ef4 SHA256: 3bbe6bea6e859ef3e798676206dec6601525bb4530f5b3394a3eb8647e7a99f8 pkg:maven/io.smallrye.reactive/vertx-mutiny-generator@3.21.3 io.smallrye.reactive.vertx-mutiny-generator-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.vertx-mutiny-generator-3.21.3.jar MD5: 3cba529be09860afdb7ea3aeb124b601 SHA1: 208f61c2efd4f889f2fa1025f1ac1682b28aed44 SHA256: aa53ff28bd9caf0c7c32c8ebffe025a01d9f5c18b0e74be569060d7978e1f187 vertx-mutiny-generator-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/vertx-mutiny-generator/3.21.3/vertx-mutiny-generator-3.21.3.jar MD5: 3cba529be09860afdb7ea3aeb124b601 SHA1: 208f61c2efd4f889f2fa1025f1ac1682b28aed44 SHA256: aa53ff28bd9caf0c7c32c8ebffe025a01d9f5c18b0e74be569060d7978e1f187 pkg:maven/io.smallrye.reactive/vertx-mutiny-generator@3.21.3 CVE-2022-37832 suppress
Mutiny 7.2.0-10788 suffers from Hardcoded root password. CWE-798 Use of Hard-coded Credentials
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2018-15529 suppress
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload. CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2013-0136 suppress
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: HIGH (8.5) Vector: /AV:N/AC:M/Au:S/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
io.smallrye.smallrye-context-propagation-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-2.3.0.jarMD5: 4ef0c3de062c91bb65d918cb8bd06c8bSHA1: dbbccd372f334e1deaa0b09832f0ddb278076a27SHA256: bc7d83a626d92d223c9f479c24c80e09df4c801781134ace9d826803b8f8eaff
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-context-propagation High Vendor jar package name context Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product file name io.smallrye.smallrye-context-propagation High Product jar package name context Highest Product jar package name context Low Product jar package name impl Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Context Propagation: Core High Product Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product Manifest specification-title SmallRye Context Propagation: Core Medium Version file version 2.3.0 High Version Manifest Implementation-Version 2.3.0 High
Related Dependencies io.smallrye.smallrye-context-propagation-2.3.0.jar (shaded: io.smallrye:smallrye-context-propagation:2.3.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-2.3.0.jar/META-INF/maven/io.smallrye/smallrye-context-propagation/pom.xml MD5: ecd8e3c073e509025c89ca62943c3bdb SHA1: 7a0e611755f403d5d6edd75ad5d6c3fc933d32d6 SHA256: 0ba9b3edcb507bdd5b48c4bbf94cec937a757941b43f8796745a451ce5c1f75c pkg:maven/io.smallrye/smallrye-context-propagation@2.3.0 io.smallrye.smallrye-context-propagation-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-2.3.0.jar MD5: 4ef0c3de062c91bb65d918cb8bd06c8b SHA1: dbbccd372f334e1deaa0b09832f0ddb278076a27 SHA256: bc7d83a626d92d223c9f479c24c80e09df4c801781134ace9d826803b8f8eaff smallrye-context-propagation-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-context-propagation/2.3.0/smallrye-context-propagation-2.3.0.jar MD5: 4ef0c3de062c91bb65d918cb8bd06c8b SHA1: dbbccd372f334e1deaa0b09832f0ddb278076a27 SHA256: bc7d83a626d92d223c9f479c24c80e09df4c801781134ace9d826803b8f8eaff pkg:maven/io.smallrye/smallrye-context-propagation@2.3.0 io.smallrye.smallrye-context-propagation-api-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-api-2.3.0.jarMD5: 4e1a2ef26afd73836da63cfebe546127SHA1: 668aff0e6b34b361f871a82e97c0be8f1c86b2e7SHA256: da0bc273588cefb478e98c4e137f65cc394a54253e35684d5d917060fdc4147c
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-context-propagation-api High Vendor jar package name context Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product file name io.smallrye.smallrye-context-propagation-api High Product jar package name api Highest Product jar package name api Low Product jar package name context Highest Product jar package name context Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Context Propagation: API High Product Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product Manifest specification-title SmallRye Context Propagation: API Medium Version file version 2.3.0 High Version Manifest Implementation-Version 2.3.0 High
Related Dependencies io.smallrye.smallrye-context-propagation-api-2.3.0.jar (shaded: io.smallrye:smallrye-context-propagation-api:2.3.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-api-2.3.0.jar/META-INF/maven/io.smallrye/smallrye-context-propagation-api/pom.xml MD5: c235feba7efcc5d2719c06a8021c4e72 SHA1: 7193e4cb893326387c3fd61b0f7bdd9bd90630b4 SHA256: f71992494edcf877c3a72fbca5146cb189e2084dd9cffe372bac18b7675b0f96 pkg:maven/io.smallrye/smallrye-context-propagation-api@2.3.0 io.smallrye.smallrye-context-propagation-api-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-api-2.3.0.jar MD5: 4e1a2ef26afd73836da63cfebe546127 SHA1: 668aff0e6b34b361f871a82e97c0be8f1c86b2e7 SHA256: da0bc273588cefb478e98c4e137f65cc394a54253e35684d5d917060fdc4147c smallrye-context-propagation-api-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-context-propagation-api/2.3.0/smallrye-context-propagation-api-2.3.0.jar MD5: 4e1a2ef26afd73836da63cfebe546127 SHA1: 668aff0e6b34b361f871a82e97c0be8f1c86b2e7 SHA256: da0bc273588cefb478e98c4e137f65cc394a54253e35684d5d917060fdc4147c pkg:maven/io.smallrye/smallrye-context-propagation-api@2.3.0 io.smallrye.smallrye-context-propagation-jta-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-jta-2.3.0.jarMD5: d9ac65d67968915aa014694610db19e0SHA1: 4814d716333865d02ef811f4543c7dce3c7c4461SHA256: 40fdf6411e8cd7cdb493d1fdcf884d9304b72db58bc4efd077dfc960f8f1684a
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-context-propagation-jta High Vendor jar package name context Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product file name io.smallrye.smallrye-context-propagation-jta High Product jar package name context Highest Product jar package name context Low Product jar package name jta Highest Product jar package name jta Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Context Propagation: JTA High Product Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product Manifest specification-title SmallRye Context Propagation: JTA Medium Version file version 2.3.0 High Version Manifest Implementation-Version 2.3.0 High
Related Dependencies io.smallrye.smallrye-context-propagation-jta-2.3.0.jar (shaded: io.smallrye:smallrye-context-propagation-jta:2.3.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-jta-2.3.0.jar/META-INF/maven/io.smallrye/smallrye-context-propagation-jta/pom.xml MD5: 2a6174d1b70d0a8070759da458237e27 SHA1: 477bce84ccec45a44089ecca9dbed349329eb3c0 SHA256: 0fc84e2e160290e09dc136dac4a59065fd291e7458139659197344ba05b79658 pkg:maven/io.smallrye/smallrye-context-propagation-jta@2.3.0 io.smallrye.smallrye-context-propagation-jta-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-jta-2.3.0.jar MD5: d9ac65d67968915aa014694610db19e0 SHA1: 4814d716333865d02ef811f4543c7dce3c7c4461 SHA256: 40fdf6411e8cd7cdb493d1fdcf884d9304b72db58bc4efd077dfc960f8f1684a smallrye-context-propagation-jta-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-context-propagation-jta/2.3.0/smallrye-context-propagation-jta-2.3.0.jar MD5: d9ac65d67968915aa014694610db19e0 SHA1: 4814d716333865d02ef811f4543c7dce3c7c4461 SHA256: 40fdf6411e8cd7cdb493d1fdcf884d9304b72db58bc4efd077dfc960f8f1684a pkg:maven/io.smallrye/smallrye-context-propagation-jta@2.3.0 io.smallrye.smallrye-context-propagation-storage-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-storage-2.3.0.jarMD5: 893f9bf2b4dafa45cdb5fbbb56022f8eSHA1: 3b9e4ee4f440f4a1a34ad44882afe9ac8eff521aSHA256: 0fb685500b833b819c934147f0d2f0ab00397df196442aa3fa0b1a6d962dedd0
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-context-propagation-storage High Vendor jar package name context Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product file name io.smallrye.smallrye-context-propagation-storage High Product jar package name context Highest Product jar package name context Low Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name storage Highest Product jar package name storage Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Context Propagation: Storage High Product Manifest implementation-url https://github.com/smallrye/smallrye-context-propagation Low Product Manifest specification-title SmallRye Context Propagation: Storage Medium Version file version 2.3.0 High Version Manifest Implementation-Version 2.3.0 High
Related Dependencies io.smallrye.smallrye-context-propagation-storage-2.3.0.jar (shaded: io.smallrye:smallrye-context-propagation-storage:2.3.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-storage-2.3.0.jar/META-INF/maven/io.smallrye/smallrye-context-propagation-storage/pom.xml MD5: a1b82a374fa50dcbafe1d7905296c671 SHA1: 2288546bf302767b27167ffa25bf99118993832e SHA256: 1c0cd0ab3f3bed74445a3927ec814c7229c1bccb99b12fc03012692dfe0472a3 pkg:maven/io.smallrye/smallrye-context-propagation-storage@2.3.0 io.smallrye.smallrye-context-propagation-storage-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-context-propagation-storage-2.3.0.jar MD5: 893f9bf2b4dafa45cdb5fbbb56022f8e SHA1: 3b9e4ee4f440f4a1a34ad44882afe9ac8eff521a SHA256: 0fb685500b833b819c934147f0d2f0ab00397df196442aa3fa0b1a6d962dedd0 smallrye-context-propagation-storage-2.3.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-context-propagation-storage/2.3.0/smallrye-context-propagation-storage-2.3.0.jar MD5: 893f9bf2b4dafa45cdb5fbbb56022f8e SHA1: 3b9e4ee4f440f4a1a34ad44882afe9ac8eff521a SHA256: 0fb685500b833b819c934147f0d2f0ab00397df196442aa3fa0b1a6d962dedd0 pkg:maven/io.smallrye/smallrye-context-propagation-storage@2.3.0 io.smallrye.smallrye-fault-tolerance-vertx-6.9.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-fault-tolerance-vertx-6.9.3.jarMD5: b010d72377f058f7e87a6c846422ea80SHA1: 37d7933fd9a763c8903347826bee526d9aa7f39bSHA256: 41087ca2ccf9c0f258df3639f6e4f959b7911596d0f175ee94278d59bc4884a0
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-fault-tolerance-vertx High Vendor jar package name faulttolerance Low Vendor jar package name io Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Product file name io.smallrye.smallrye-fault-tolerance-vertx High Product jar package name faulttolerance Low Product jar package name io Highest Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name vertx Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Fault Tolerance: Vert.x Integration High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye Fault Tolerance: Vert.x Integration Medium Version file version 6.9.3 High Version Manifest Implementation-Version 6.9.3 High
Related Dependencies io.smallrye.smallrye-fault-tolerance-vertx-6.9.3.jar (shaded: io.smallrye:smallrye-fault-tolerance-vertx:6.9.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-fault-tolerance-vertx-6.9.3.jar/META-INF/maven/io.smallrye/smallrye-fault-tolerance-vertx/pom.xml MD5: faa99a2e39c8f82e242056fdc7bfafad SHA1: 3361947778342b3675c7f8a46e20a02d801210fa SHA256: 861a499257e44bc3116bd0c900d1923c0cc787c248dd1cc6ed8326ff812f0979 pkg:maven/io.smallrye/smallrye-fault-tolerance-vertx@6.9.3 io.smallrye.smallrye-fault-tolerance-vertx-6.9.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-fault-tolerance-vertx-6.9.3.jar MD5: b010d72377f058f7e87a6c846422ea80 SHA1: 37d7933fd9a763c8903347826bee526d9aa7f39b SHA256: 41087ca2ccf9c0f258df3639f6e4f959b7911596d0f175ee94278d59bc4884a0 smallrye-fault-tolerance-vertx-6.9.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-fault-tolerance-vertx/6.9.3/smallrye-fault-tolerance-vertx-6.9.3.jar MD5: b010d72377f058f7e87a6c846422ea80 SHA1: 37d7933fd9a763c8903347826bee526d9aa7f39b SHA256: 41087ca2ccf9c0f258df3639f6e4f959b7911596d0f175ee94278d59bc4884a0 pkg:maven/io.smallrye/smallrye-fault-tolerance-vertx@6.9.3 io.smallrye.smallrye-jwt-4.6.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-jwt-4.6.2.jarMD5: 9e7f91c5a6a5137b4a4aa6ccc5b0707cSHA1: 4660d56a93b32e3c8fc7bc9e23111396178ffca7SHA256: 37e7fedccd0b86b1347213d50f9f084f2060ddf1d939156771f95061c71cc115
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-jwt High Vendor jar package name io Low Vendor jar package name jwt Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.smallrye-jwt High Product jar package name auth Low Product jar package name io Highest Product jar package name jwt Highest Product jar package name jwt Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: MicroProfile JWT Implementation High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: MicroProfile JWT Implementation Medium Version file version 4.6.2 High Version Manifest Implementation-Version 4.6.2 High
Related Dependencies smallrye-jwt-4.6.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-jwt/4.6.2/smallrye-jwt-4.6.2.jar MD5: 9e7f91c5a6a5137b4a4aa6ccc5b0707c SHA1: 4660d56a93b32e3c8fc7bc9e23111396178ffca7 SHA256: 37e7fedccd0b86b1347213d50f9f084f2060ddf1d939156771f95061c71cc115 pkg:maven/io.smallrye/smallrye-jwt@4.6.2 io.smallrye.smallrye-jwt-build-4.6.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-jwt-build-4.6.2.jarMD5: 0b03f75a78fd04a0109b0b3725006649SHA1: 99618086e5f4f1e4d4375f3365ba3ea529507028SHA256: 310ce632b19ab52bf4c8e213f25987a134ac2396d078d1f546a3cf3c09db3e84
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-jwt-build High Vendor jar package name io Low Vendor jar package name jwt Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.smallrye-jwt-build High Product jar package name build Highest Product jar package name build Low Product jar package name io Highest Product jar package name jwt Highest Product jar package name jwt Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: MicroProfile JWT Build Implementation High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: MicroProfile JWT Build Implementation Medium Version file version 4.6.2 High Version Manifest Implementation-Version 4.6.2 High
Related Dependencies smallrye-jwt-build-4.6.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-jwt-build/4.6.2/smallrye-jwt-build-4.6.2.jar MD5: 0b03f75a78fd04a0109b0b3725006649 SHA1: 99618086e5f4f1e4d4375f3365ba3ea529507028 SHA256: 310ce632b19ab52bf4c8e213f25987a134ac2396d078d1f546a3cf3c09db3e84 pkg:maven/io.smallrye/smallrye-jwt-build@4.6.2 io.smallrye.smallrye-jwt-common-4.6.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-jwt-common-4.6.2.jarMD5: 22655f52b4438fef42cc906683f47bc9SHA1: cfaa0245f68eee96c8b1fc608e11f5ce03d47841SHA256: df1d4b6b4b8daf88ff9d2318c43b48a8876a2f0aa57fc578b5ee772df21296bf
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-jwt-common High Vendor jar package name io Low Vendor jar package name jwt Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.smallrye-jwt-common High Product jar package name io Highest Product jar package name jwt Highest Product jar package name jwt Low Product jar package name smallrye Highest Product jar package name smallrye Low Product jar package name util Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: MicroProfile JWT Implementation Common High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: MicroProfile JWT Implementation Common Medium Version file version 4.6.2 High Version Manifest Implementation-Version 4.6.2 High
Related Dependencies smallrye-jwt-common-4.6.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-jwt-common/4.6.2/smallrye-jwt-common-4.6.2.jar MD5: 22655f52b4438fef42cc906683f47bc9 SHA1: cfaa0245f68eee96c8b1fc608e11f5ce03d47841 SHA256: df1d4b6b4b8daf88ff9d2318c43b48a8876a2f0aa57fc578b5ee772df21296bf pkg:maven/io.smallrye/smallrye-jwt-common@4.6.2 io.smallrye.smallrye-open-api-core-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-open-api-core-4.2.3.jarMD5: bafa9c188e07f117aa45bbf6d5662281SHA1: a018f7ff45d3c90bd728f09167dd2184ced8e209SHA256: f2bfb7e12046123e91ccb3927ebe4873956ce14596e04c29c2cb808e5a216d9e
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-open-api-core High Vendor jar package name io Low Vendor jar package name openapi Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.smallrye-open-api-core High Product jar package name io Highest Product jar package name openapi Highest Product jar package name openapi Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: OpenAPI Core High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: OpenAPI Core Medium Version file version 4.2.3 High Version Manifest Implementation-Version 4.2.3 High
Related Dependencies io.smallrye.smallrye-open-api-core-4.2.3.jar (shaded: io.smallrye:smallrye-open-api-core:4.2.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-open-api-core-4.2.3.jar/META-INF/maven/io.smallrye/smallrye-open-api-core/pom.xml MD5: 49cb80790ecf71b389bc888b553dc918 SHA1: b7a64d096874b9fee075f5820424af0972ce40a9 SHA256: 49e3ea1cd3cd989ce72be813cdfad603873e182d7cc46e97982e6c86ab64bbd2 pkg:maven/io.smallrye/smallrye-open-api-core@4.2.3 io.smallrye.smallrye-open-api-core-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-open-api-core-4.2.3.jar MD5: bafa9c188e07f117aa45bbf6d5662281 SHA1: a018f7ff45d3c90bd728f09167dd2184ced8e209 SHA256: f2bfb7e12046123e91ccb3927ebe4873956ce14596e04c29c2cb808e5a216d9e smallrye-open-api-core-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-core/4.2.3/smallrye-open-api-core-4.2.3.jar MD5: bafa9c188e07f117aa45bbf6d5662281 SHA1: a018f7ff45d3c90bd728f09167dd2184ced8e209 SHA256: f2bfb7e12046123e91ccb3927ebe4873956ce14596e04c29c2cb808e5a216d9e pkg:maven/io.smallrye/smallrye-open-api-core@4.2.3 io.smallrye.smallrye-open-api-model-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.smallrye.smallrye-open-api-model-4.2.3.jarMD5: b293460a7faa594ac2d5f9e82d44a247SHA1: be7ab33ee89bd40965d90f76d74ebeaae4090df8SHA256: 1e1e0bc7ea5593c3218943b734a114acfc09f604ff309606de167f6b902d6b3c
Evidence Type Source Name Value Confidence Vendor file name io.smallrye.smallrye-open-api-model High Vendor jar package name io Low Vendor jar package name openapi Low Vendor jar package name smallrye Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Product file name io.smallrye.smallrye-open-api-model High Product jar package name io Highest Product jar package name model Highest Product jar package name model Low Product jar package name openapi Highest Product jar package name openapi Low Product jar package name smallrye Highest Product jar package name smallrye Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: OpenAPI Model High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: OpenAPI Model Medium Version file version 4.2.3 High Version Manifest Implementation-Version 4.2.3 High
Related Dependencies io.smallrye.smallrye-open-api-model-4.2.3.jar (shaded: io.smallrye:smallrye-open-api-model:4.2.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-open-api-model-4.2.3.jar/META-INF/maven/io.smallrye/smallrye-open-api-model/pom.xml MD5: d6bb5b66ebd3da4b838306135fe44988 SHA1: a51d1da18fc771066c3f1b77f97a0d2ddd20d2e7 SHA256: bb9285ed782930b78dccec153092855d7347d198e6ea28bc3503767621c6cc9e pkg:maven/io.smallrye/smallrye-open-api-model@4.2.3 io.smallrye.smallrye-open-api-model-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.smallrye-open-api-model-4.2.3.jar MD5: b293460a7faa594ac2d5f9e82d44a247 SHA1: be7ab33ee89bd40965d90f76d74ebeaae4090df8 SHA256: 1e1e0bc7ea5593c3218943b734a114acfc09f604ff309606de167f6b902d6b3c smallrye-open-api-model-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-model/4.2.3/smallrye-open-api-model-4.2.3.jar MD5: b293460a7faa594ac2d5f9e82d44a247 SHA1: be7ab33ee89bd40965d90f76d74ebeaae4090df8 SHA256: 1e1e0bc7ea5593c3218943b734a114acfc09f604ff309606de167f6b902d6b3c pkg:maven/io.smallrye/smallrye-open-api-model@4.2.3 io.vertx.vertx-codegen-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-codegen-4.5.23.jarMD5: 40e06a88fc3bbaca9a6afbc42b076864SHA1: d0efbf69dc108cbfe980f83d2a11c3ff3b841203SHA256: 4ddef372bba04e0191c99f3956c63bfaccc5cf4a129669c4e99f9b02632988a6
Evidence Type Source Name Value Confidence Vendor file name io.vertx.vertx-codegen High Vendor jar package name codegen Highest Vendor jar package name codegen Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor Manifest automatic-module-name io.vertx.codegen Medium Product file name io.vertx.vertx-codegen High Product jar package name codegen Highest Product jar package name codegen Low Product jar package name io Highest Product jar package name vertx Highest Product jar package name vertx Low Product Manifest automatic-module-name io.vertx.codegen Medium Version file name io.vertx.vertx-codegen Medium Version file version 4.5.23 High
Related Dependencies io.vertx.vertx-codegen-4.5.23.jar (shaded: io.vertx:vertx-codegen:4.5.23)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-codegen-4.5.23.jar/META-INF/maven/io.vertx/vertx-codegen/pom.xml MD5: 06621ad896f30fe1d877ca9ae78efb73 SHA1: 0ca2e2e707995dcee3fd097064582f657319d6e2 SHA256: 58c3055cca38bb27d40094b40df1f0dfde0d3579f666c970e2ef6f030fb499bb pkg:maven/io.vertx/vertx-codegen@4.5.23 io.vertx.vertx-codegen-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-codegen-4.5.23.jar MD5: 40e06a88fc3bbaca9a6afbc42b076864 SHA1: d0efbf69dc108cbfe980f83d2a11c3ff3b841203 SHA256: 4ddef372bba04e0191c99f3956c63bfaccc5cf4a129669c4e99f9b02632988a6 vertx-codegen-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/vertx/vertx-codegen/4.5.23/vertx-codegen-4.5.23.jar MD5: 40e06a88fc3bbaca9a6afbc42b076864 SHA1: d0efbf69dc108cbfe980f83d2a11c3ff3b841203 SHA256: 4ddef372bba04e0191c99f3956c63bfaccc5cf4a129669c4e99f9b02632988a6 pkg:maven/io.vertx/vertx-codegen@4.5.23 io.vertx.vertx-core-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-core-4.5.23.jarMD5: bf80e0d53392e4c257b3364832d20116SHA1: f83109594d263d5dc3b8e2d49649a8e13769e28eSHA256: d119aba508e88e1a54bd449baf27d5b229cf3025fa9ca92f9fb84c3a63c1143b
Evidence Type Source Name Value Confidence Vendor file name io.vertx.vertx-core High Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor Manifest automatic-module-name io.vertx.core Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Eclipse High Vendor Manifest maven-artifact-id vertx-core Low Vendor Manifest multi-release true Low Vendor Manifest specification-vendor Eclipse Low Product file name io.vertx.vertx-core High Product jar package name core Highest Product jar package name core Low Product jar package name io Highest Product jar package name vertx Highest Product jar package name vertx Low Product Manifest automatic-module-name io.vertx.core Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Vert.x Core High Product Manifest maven-artifact-id vertx-core Low Product Manifest multi-release true Low Product Manifest specification-title Vert.x Core Medium Version file version 4.5.23 High Version Manifest Implementation-Version 4.5.23 High
Related Dependencies io.vertx.vertx-auth-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-auth-common-4.5.23.jar MD5: e78a9d57cecfa492133ede51c32ac182 SHA1: 4b115c6aba2ee3676b4ac25803de1773506eaeff SHA256: dc14e872a7e444f9ca375a89dc3da299d12632a777458816c3f6bcbcb842f145 io.vertx.vertx-auth-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-auth-common-4.5.23.jar MD5: e78a9d57cecfa492133ede51c32ac182 SHA1: 4b115c6aba2ee3676b4ac25803de1773506eaeff SHA256: dc14e872a7e444f9ca375a89dc3da299d12632a777458816c3f6bcbcb842f145 io.vertx.vertx-bridge-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-bridge-common-4.5.23.jar MD5: c0676d4695de1fbc1427b46365bc59ea SHA1: a00e24676c73909407f8dc0382295b88509c0d63 SHA256: e5ce830fadbc5a8e67f818c0692d89bff5879612df21fefc0373bcb35b7a1391 io.vertx.vertx-bridge-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-bridge-common-4.5.23.jar MD5: c0676d4695de1fbc1427b46365bc59ea SHA1: a00e24676c73909407f8dc0382295b88509c0d63 SHA256: e5ce830fadbc5a8e67f818c0692d89bff5879612df21fefc0373bcb35b7a1391 io.vertx.vertx-core-4.5.23.jar (shaded: io.vertx:vertx-core:4.5.23)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-core-4.5.23.jar/META-INF/maven/io.vertx/vertx-core/pom.xml MD5: ceb0b590de43528bc9f30a8a35ae6b0c SHA1: fe4112444315c244ed84939237e5e09733ae2d79 SHA256: 325693c2e1349cb74bab08cb6902a3a14d5fe728707c880dbfae921e60675832 pkg:maven/io.vertx/vertx-core@4.5.23 io.vertx.vertx-core-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-core-4.5.23.jar MD5: bf80e0d53392e4c257b3364832d20116 SHA1: f83109594d263d5dc3b8e2d49649a8e13769e28e SHA256: d119aba508e88e1a54bd449baf27d5b229cf3025fa9ca92f9fb84c3a63c1143b io.vertx.vertx-rabbitmq-client-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-rabbitmq-client-4.5.23.jar MD5: ee05c8beddac0842bb9e95f3f2753862 SHA1: 34deedff2737f455b198e1b12b9d6358e8f8f417 SHA256: 94f7a29dd969c1c13c8dedf921063b151e350bf20f05612b1563f7e301baa2ae io.vertx.vertx-uri-template-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-uri-template-4.5.23.jar MD5: bd636053bc2925804841b11961ec7d33 SHA1: e09ad88bf3c6d11e95f89fff273fc075bf45c384 SHA256: fbbdc0e3067dd68d194e8d81b0e5d94ab8cd15a93718c9961e9612554816466f vertx-core-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/vertx/vertx-core/4.5.23/vertx-core-4.5.23.jar MD5: bf80e0d53392e4c257b3364832d20116 SHA1: f83109594d263d5dc3b8e2d49649a8e13769e28e SHA256: d119aba508e88e1a54bd449baf27d5b229cf3025fa9ca92f9fb84c3a63c1143b pkg:maven/io.vertx/vertx-core@4.5.23 io.vertx.vertx-uri-template-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-uri-template-4.5.23.jarMD5: bd636053bc2925804841b11961ec7d33SHA1: e09ad88bf3c6d11e95f89fff273fc075bf45c384SHA256: fbbdc0e3067dd68d194e8d81b0e5d94ab8cd15a93718c9961e9612554816466f
Evidence Type Source Name Value Confidence Vendor file name io.vertx.vertx-uri-template High Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name uritemplate Highest Vendor jar package name uritemplate Low Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor Manifest automatic-module-name io.vertx.uritemplate Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Eclipse High Vendor Manifest maven-artifact-id vertx-uri-template Low Vendor Manifest specification-vendor Eclipse Low Product file name io.vertx.vertx-uri-template High Product jar package name impl Low Product jar package name io Highest Product jar package name uritemplate Highest Product jar package name uritemplate Low Product jar package name vertx Highest Product jar package name vertx Low Product Manifest automatic-module-name io.vertx.uritemplate Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Vert.x URI Template High Product Manifest maven-artifact-id vertx-uri-template Low Product Manifest specification-title Vert.x URI Template Medium Version file version 4.5.23 High Version Manifest Implementation-Version 4.5.23 High
Related Dependencies io.vertx.vertx-rabbitmq-client-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-rabbitmq-client-4.5.23.jar MD5: ee05c8beddac0842bb9e95f3f2753862 SHA1: 34deedff2737f455b198e1b12b9d6358e8f8f417 SHA256: 94f7a29dd969c1c13c8dedf921063b151e350bf20f05612b1563f7e301baa2ae io.vertx.vertx-uri-template-4.5.23.jar (shaded: io.vertx:vertx-uri-template:4.5.23)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-uri-template-4.5.23.jar/META-INF/maven/io.vertx/vertx-uri-template/pom.xml MD5: 8de68d24f3e88bf02206c3761ad3fd53 SHA1: b172af9a0a19f069cef32c320bec4289911c305d SHA256: e5ebf6bb7d2724e6e5509ccdff326f8ae02fb5dd810ffa9787cf8a6733d437f1 pkg:maven/io.vertx/vertx-uri-template@4.5.23 vertx-uri-template-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/vertx/vertx-uri-template/4.5.23/vertx-uri-template-4.5.23.jar MD5: bd636053bc2925804841b11961ec7d33 SHA1: e09ad88bf3c6d11e95f89fff273fc075bf45c384 SHA256: fbbdc0e3067dd68d194e8d81b0e5d94ab8cd15a93718c9961e9612554816466f pkg:maven/io.vertx/vertx-uri-template@4.5.23 io.vertx.vertx-web-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-web-4.5.23.jarMD5: c0fef503b7ac301588460530af20b605SHA1: 0d11afd9769f71e5718ee3082a088e46cf1b1a20SHA256: 4e3fa04ff835aa8dfe8e6b9fdf6bce9c76eaf762b3b8f63a31c2c252816a22a4
Evidence Type Source Name Value Confidence Vendor file name io.vertx.vertx-web High Vendor jar package name ext Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor jar package name web Highest Vendor Manifest automatic-module-name io.vertx.web Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Eclipse High Vendor Manifest maven-artifact-id vertx-web Low Vendor Manifest specification-vendor Eclipse Low Product file name io.vertx.vertx-web High Product jar package name ext Low Product jar package name io Highest Product jar package name vertx Highest Product jar package name vertx Low Product jar package name web Highest Product jar package name web Low Product Manifest automatic-module-name io.vertx.web Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Vert.x Web High Product Manifest maven-artifact-id vertx-web Low Product Manifest specification-title Vert.x Web Medium Version file version 4.5.23 High Version Manifest Implementation-Version 4.5.23 High
Related Dependencies io.vertx.vertx-web-4.5.23.jar (shaded: io.vertx:vertx-web:4.5.23)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-web-4.5.23.jar/META-INF/maven/io.vertx/vertx-web/pom.xml MD5: c1f8baa016cb3ccd53d8c0fed3b25854 SHA1: a8eb6cc21ab5c71d18f448fcd7a7d53c49f180b1 SHA256: dc927535458d924b2caa9e9373c66f86cc53b56c68514319118b0fd83a72f0ab pkg:maven/io.vertx/vertx-web@4.5.23 io.vertx.vertx-web-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-web-4.5.23.jar MD5: c0fef503b7ac301588460530af20b605 SHA1: 0d11afd9769f71e5718ee3082a088e46cf1b1a20 SHA256: 4e3fa04ff835aa8dfe8e6b9fdf6bce9c76eaf762b3b8f63a31c2c252816a22a4 io.vertx.vertx-web-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.vertx.vertx-web-common-4.5.23.jar MD5: 36f7bd7a0281881b446101e5f4d21474 SHA1: 8f043782d643441ad50f4cfd3aa0e71728d6dbd2 SHA256: e2c04fc9a4914af93e50728878c3b59afcacba2365fa92adf193e33ece44e51a vertx-web-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/vertx/vertx-web/4.5.23/vertx-web-4.5.23.jar MD5: c0fef503b7ac301588460530af20b605 SHA1: 0d11afd9769f71e5718ee3082a088e46cf1b1a20 SHA256: 4e3fa04ff835aa8dfe8e6b9fdf6bce9c76eaf762b3b8f63a31c2c252816a22a4 pkg:maven/io.vertx/vertx-web@4.5.23 io.vertx.vertx-web-client-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-web-client-4.5.23.jarMD5: 71c2810b3f3299bfedad743035c1a2afSHA1: 80f09036dea414dcfa03f41a5b6b5778f3a82325SHA256: 6e7b26669708107f96f8d0356971e06867e30e0a3a7d1f6467b7382b588ddfc9
Evidence Type Source Name Value Confidence Vendor file name io.vertx.vertx-web-client High Vendor jar package name ext Low Vendor jar package name io Highest Vendor jar package name io Low Vendor jar package name vertx Highest Vendor jar package name vertx Low Vendor jar package name web Highest Vendor Manifest automatic-module-name io.vertx.web.client Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Eclipse High Vendor Manifest maven-artifact-id vertx-web-client Low Vendor Manifest specification-vendor Eclipse Low Product file name io.vertx.vertx-web-client High Product jar package name ext Low Product jar package name io Highest Product jar package name vertx Highest Product jar package name vertx Low Product jar package name web Highest Product jar package name web Low Product Manifest automatic-module-name io.vertx.web.client Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Vert.x Web Client High Product Manifest maven-artifact-id vertx-web-client Low Product Manifest specification-title Vert.x Web Client Medium Version file version 4.5.23 High Version Manifest Implementation-Version 4.5.23 High
Related Dependencies io.vertx.vertx-web-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-web-common-4.5.23.jar MD5: 36f7bd7a0281881b446101e5f4d21474 SHA1: 8f043782d643441ad50f4cfd3aa0e71728d6dbd2 SHA256: e2c04fc9a4914af93e50728878c3b59afcacba2365fa92adf193e33ece44e51a vertx-web-client-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/vertx/vertx-web-client/4.5.23/vertx-web-client-4.5.23.jar MD5: 71c2810b3f3299bfedad743035c1a2af SHA1: 80f09036dea414dcfa03f41a5b6b5778f3a82325 SHA256: 6e7b26669708107f96f8d0356971e06867e30e0a3a7d1f6467b7382b588ddfc9 pkg:maven/io.vertx/vertx-web-client@4.5.23 itu-1.14.0.jarDescription:
Extremely fast date-time parser and formatter - RFC 3339 (ISO 8601 profile) and W3C format
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/ethlo/time/itu/1.14.0/itu-1.14.0.jar
MD5: e537d0a2bc8066726f7e4654c253cf84
SHA1: c0f9f9d4f4404787e992ab3af5ae95f2fad79e47
SHA256: 5cf40ab0cc77828ab2b875b1f3ecd71c8295d7721933476abc2e08fddcea164a
Evidence Type Source Name Value Confidence Vendor file name itu High Vendor jar package name ethlo Highest Vendor jar package name itu Highest Vendor jar package name time Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-symbolicname com.ethlo.time.itu Medium Vendor Manifest multi-release true Low Vendor pom artifactid itu Low Vendor pom developer name Morten Haraldsen Medium Vendor pom groupid com.ethlo.time Highest Vendor pom name Internet Time Utility High Vendor pom url ethlo/itu Highest Product file name itu High Product jar package name ethlo Highest Product jar package name itu Highest Product jar package name time Highest Product Manifest build-jdk-spec 21 Low Product Manifest Bundle-Name Internet Time Utility Medium Product Manifest bundle-symbolicname com.ethlo.time.itu Medium Product Manifest multi-release true Low Product pom artifactid itu Highest Product pom developer name Morten Haraldsen Low Product pom groupid com.ethlo.time Highest Product pom name Internet Time Utility High Product pom url ethlo/itu High Version file version 1.14.0 High Version Manifest Bundle-Version 1.14.0 High Version pom version 1.14.0 Highest
jackson-dataformat-xml-2.20.1.jarDescription:
Data format extension for Jackson to offer
alternative support for serializing POJOs as XML and deserializing XML as POJOs.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-xml/2.20.1/jackson-dataformat-xml-2.20.1.jar
MD5: 55a13effaac5ed19e8393cba5e05f195
SHA1: 3a8e1f06f8bdfd9f2c29f1b2bdad970b02dff4c9
SHA256: 190ad4eba35d89dba3517da279e0690681c4745174b94b09ea78f81ceae140f0
Evidence Type Source Name Value Confidence Vendor file name jackson-dataformat-xml High Vendor jar package name dataformat Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformat-xml Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-xml Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-dataformat-xml Low Vendor pom groupid com.fasterxml.jackson.dataformat Highest Vendor pom name Jackson-dataformat-XML High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-dataformat-xml Highest Product file name jackson-dataformat-xml High Product jar package name dataformat Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name xml Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformat-xml Low Product Manifest Bundle-Name Jackson-dataformat-XML Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-xml Medium Product Manifest Implementation-Title Jackson-dataformat-XML High Product Manifest multi-release true Low Product Manifest specification-title Jackson-dataformat-XML Medium Product pom artifactid jackson-dataformat-xml Highest Product pom groupid com.fasterxml.jackson.dataformat Highest Product pom name Jackson-dataformat-XML High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-dataformat-xml High Version file version 2.20.1 High Version Manifest Bundle-Version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High Version pom version 2.20.1 Highest
Related Dependencies jackson-dataformat-yaml-2.20.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/dataformat/jackson-dataformat-yaml/2.20.1/jackson-dataformat-yaml-2.20.1.jar MD5: 66dc3c5f31150557109b14182ed7ed8a SHA1: e6da043059c9ec631a3429ded461d5d92f240c3f SHA256: 030f1d91f7df278e86e1ba3e129fb520871ac16ce53017c735f708823be970db pkg:maven/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml@2.20.1 jackson-module-parameter-names-2.20.1.jarDescription:
Add-on module for Jackson (https://github.com/FasterXML/jackson) to support
introspection of method/constructor parameter names, without having to add explicit property name annotation.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/jackson/module/jackson-module-parameter-names/2.20.1/jackson-module-parameter-names-2.20.1.jar
MD5: 4670f258db373db07ab0c552696c4aa2
SHA1: 4214b732f1bd4e640e8e51ab6c5a73f6a418aaeb
SHA256: 3b7e3702fce28ff4819bc5d3f18ff513c3cd32eda46e74cf3328142dea882aa9
Evidence Type Source Name Value Confidence Vendor file name jackson-module-parameter-names High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name module Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-module-parameter-names Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-parameter-names Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-module-parameter-names Low Vendor pom groupid com.fasterxml.jackson.module Highest Vendor pom name Jackson-module-parameter-names High Vendor pom parent-artifactid jackson-modules-java8 Low Product file name jackson-module-parameter-names High Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name module Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-module-parameter-names Low Product Manifest Bundle-Name Jackson-module-parameter-names Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-parameter-names Medium Product Manifest Implementation-Title Jackson-module-parameter-names High Product Manifest multi-release true Low Product Manifest specification-title Jackson-module-parameter-names Medium Product pom artifactid jackson-module-parameter-names Highest Product pom groupid com.fasterxml.jackson.module Highest Product pom name Jackson-module-parameter-names High Product pom parent-artifactid jackson-modules-java8 Medium Version file version 2.20.1 High Version Manifest Bundle-Version 2.20.1 High Version Manifest Implementation-Version 2.20.1 High Version pom version 2.20.1 Highest
Related Dependencies com.fasterxml.jackson.module.jackson-module-parameter-names-2.20.1.jar (shaded: com.fasterxml.jackson.module:jackson-module-parameter-names:2.20.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/com.fasterxml.jackson.module.jackson-module-parameter-names-2.20.1.jar/META-INF/maven/com.fasterxml.jackson.module/jackson-module-parameter-names/pom.xml MD5: 3a340f6f61eb0f5519fb642a7a01b157 SHA1: 7fe9459193939895ebadb73a1b07337e11b18801 SHA256: b709ca432fac1a752e0fa210b0fee0ec8885221ee3e35f0fd2f8d845b0083b5f pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.20.1 pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.20.1 (Confidence :High) cpe:2.3:a:fasterxml:jackson-modules-java8:2.20.1:*:*:*:*:*:*:* (Confidence :Low) suppress jacoco-maven-plugin-0.8.13.jarDescription:
The JaCoCo Maven Plugin provides the JaCoCo runtime agent to your tests and allows basic report creation. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/jacoco-maven-plugin/0.8.13/jacoco-maven-plugin-0.8.13.jarMD5: b88d7622d5fe551c17efe93f5380007bSHA1: 4c2dd426a24fcb4f2e7413eefb45a5b7b4278defSHA256: 73aa57883c00d0ec952a44e01dbe086efab0dc4098edfea9aaf927a9444d6636
Evidence Type Source Name Value Confidence Vendor file name jacoco-maven-plugin High Vendor jar package name jacoco Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid jacoco-maven-plugin Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Maven Plugin High Vendor pom parent-artifactid org.jacoco.build Low Vendor pom url https://www.jacoco.org/jacoco/trunk/doc/maven.html Highest Product file name jacoco-maven-plugin High Product jar package name jacoco Highest Product jar package name maven Highest Product Manifest build-jdk-spec 21 Low Product pom artifactid jacoco-maven-plugin Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Maven Plugin High Product pom parent-artifactid org.jacoco.build Medium Product pom url https://www.jacoco.org/jacoco/trunk/doc/maven.html Medium Version file version 0.8.13 High Version pom version 0.8.13 Highest
pkg:maven/org.jacoco/jacoco-maven-plugin@0.8.13 (Confidence :High) jakarta.activation.jakarta.activation-api-2.1.4.jarDescription:
Jakarta Activation API 2.1 Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.activation.jakarta.activation-api-2.1.4.jar
MD5: bc1602eee7bc61a0b86f14bbbb0cc794
SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8
SHA256: c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004
Evidence Type Source Name Value Confidence Vendor file name jakarta.activation.jakarta.activation-api High Vendor jar package name activation Highest Vendor jar package name activation Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest implementation-build-id 3dad341 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.activation.jakarta.activation-api High Product jar package name activation Highest Product jar package name activation Low Product jar package name jakarta Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Activation API Medium Product Manifest bundle-symbolicname jakarta.activation-api Medium Product Manifest extension-name jakarta.activation Medium Product Manifest implementation-build-id 3dad341 Low Product Manifest Implementation-Title Jakarta Activation API High Product Manifest specification-title Jakarta Activation Specification Medium Version file name jakarta.activation.jakarta.activation-api Medium Version file version 2.1.4 High Version Manifest Bundle-Version 2.1.4 High Version Manifest specification-version 2.1 High
Related Dependencies jakarta.activation-api-2.1.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/activation/jakarta.activation-api/2.1.4/jakarta.activation-api-2.1.4.jar MD5: bc1602eee7bc61a0b86f14bbbb0cc794 SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8 SHA256: c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004 pkg:maven/jakarta.activation/jakarta.activation-api@2.1.4 jakarta.activation.jakarta.activation-api-2.1.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.activation.jakarta.activation-api-2.1.4.jar MD5: bc1602eee7bc61a0b86f14bbbb0cc794 SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8 SHA256: c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004 jakarta.annotation.jakarta.annotation-api-3.0.0.jarDescription:
Jakarta Annotations API License:
https://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.annotation.jakarta.annotation-api-3.0.0.jar
MD5: 7faffaab962918da4cf5ddfd76609dd2
SHA1: 54f928fadec906a99d558536756d171917b9d936
SHA256: b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2
Evidence Type Source Name Value Confidence Vendor file name jakarta.annotation.jakarta.annotation-api High Vendor jar package name annotation Highest Vendor jar package name annotation Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor Manifest build-jdk-spec 18 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium Vendor Manifest extension-name jakarta.annotation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.annotation.jakarta.annotation-api High Product jar package name annotation Highest Product jar package name annotation Low Product jar package name jakarta Highest Product Manifest build-jdk-spec 18 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Annotations API Medium Product Manifest bundle-symbolicname jakarta.annotation-api Medium Product Manifest extension-name jakarta.annotation Medium Version file version 3.0.0 High Version Manifest Implementation-Version 3.0.0 High
Related Dependencies jakarta.annotation-api-3.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/annotation/jakarta.annotation-api/3.0.0/jakarta.annotation-api-3.0.0.jar MD5: 7faffaab962918da4cf5ddfd76609dd2 SHA1: 54f928fadec906a99d558536756d171917b9d936 SHA256: b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2 pkg:maven/jakarta.annotation/jakarta.annotation-api@3.0.0 jakarta.annotation.jakarta.annotation-api-3.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.annotation.jakarta.annotation-api-3.0.0.jar MD5: 7faffaab962918da4cf5ddfd76609dd2 SHA1: 54f928fadec906a99d558536756d171917b9d936 SHA256: b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2 jakarta.el.jakarta.el-api-6.0.1.jarDescription:
Jakarta Expression Language 6.0 License:
https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.el.jakarta.el-api-6.0.1.jar
MD5: a98f097e059552a75748fcdd067e5c16
SHA1: c7c4a2eb1e40e0ff45ab5e2e52bd77d8c7a75176
SHA256: 7e84b5bed49de32b79cc5e85d90b6f5adb1a953ac67283adbb41c1e297f9c605
Evidence Type Source Name Value Confidence Vendor file name jakarta.el.jakarta.el-api High Vendor jar package name el Highest Vendor jar package name el Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.el-api Medium Vendor Manifest extension-name jakarta.el Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.el.jakarta.el-api High Product jar package name el Highest Product jar package name el Low Product jar package name expression Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Expression Language API Medium Product Manifest bundle-symbolicname jakarta.el-api Medium Product Manifest extension-name jakarta.el Medium Version file version 6.0.1 High Version Manifest Implementation-Version 6.0.1 High
Related Dependencies jakarta.el-api-6.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/el/jakarta.el-api/6.0.1/jakarta.el-api-6.0.1.jar MD5: a98f097e059552a75748fcdd067e5c16 SHA1: c7c4a2eb1e40e0ff45ab5e2e52bd77d8c7a75176 SHA256: 7e84b5bed49de32b79cc5e85d90b6f5adb1a953ac67283adbb41c1e297f9c605 pkg:maven/jakarta.el/jakarta.el-api@6.0.1 jakarta.el.jakarta.el-api-6.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.el.jakarta.el-api-6.0.1.jar MD5: a98f097e059552a75748fcdd067e5c16 SHA1: c7c4a2eb1e40e0ff45ab5e2e52bd77d8c7a75176 SHA256: 7e84b5bed49de32b79cc5e85d90b6f5adb1a953ac67283adbb41c1e297f9c605 jakarta.enterprise.jakarta.enterprise.cdi-api-4.1.0.jarDescription:
APIs for CDI (Contexts and Dependency Injection for Java) License:
https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.enterprise.jakarta.enterprise.cdi-api-4.1.0.jar
MD5: f72ee39b19274ffe26cac952acae6dc3
SHA1: fed9518709d33252bfe0817fe61ad4dfd1b2e848
SHA256: c42c808f17925129a0800f618febe050d966e181a4c7384c8a5e7a0283d68699
Evidence Type Source Name Value Confidence Vendor file name jakarta.enterprise.jakarta.enterprise.cdi-api High Vendor jar package name enterprise Highest Vendor jar package name enterprise Low Vendor jar package name inject Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor Manifest automatic-module-name jakarta.cdi Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.enterprise.cdi-api Medium Product file name jakarta.enterprise.jakarta.enterprise.cdi-api High Product jar package name enterprise Highest Product jar package name enterprise Low Product jar package name inject Low Product jar package name jakarta Highest Product Manifest automatic-module-name jakarta.cdi Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name CDI APIs Medium Product Manifest bundle-symbolicname jakarta.enterprise.cdi-api Medium Version file name jakarta.enterprise.jakarta.enterprise.cdi-api Medium Version file version 4.1.0 High Version Manifest build-jdk-spec 17 Low Version Manifest Bundle-Version 4.1.0 High
Related Dependencies jakarta.enterprise.cdi-api-4.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/enterprise/jakarta.enterprise.cdi-api/4.1.0/jakarta.enterprise.cdi-api-4.1.0.jar MD5: f72ee39b19274ffe26cac952acae6dc3 SHA1: fed9518709d33252bfe0817fe61ad4dfd1b2e848 SHA256: c42c808f17925129a0800f618febe050d966e181a4c7384c8a5e7a0283d68699 pkg:maven/jakarta.enterprise/jakarta.enterprise.cdi-api@4.1.0 jakarta.enterprise.jakarta.enterprise.cdi-api-4.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.enterprise.jakarta.enterprise.cdi-api-4.1.0.jar MD5: f72ee39b19274ffe26cac952acae6dc3 SHA1: fed9518709d33252bfe0817fe61ad4dfd1b2e848 SHA256: c42c808f17925129a0800f618febe050d966e181a4c7384c8a5e7a0283d68699 jakarta.enterprise.jakarta.enterprise.lang-model-4.1.0.jarDescription:
Build Compatible (Reflection-Free) Java Language Model for CDI License:
https://apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.enterprise.jakarta.enterprise.lang-model-4.1.0.jar
MD5: fd9efbe0808984a89690e04ea28cd368
SHA1: 9270ae3df4239d4f337215403ebc9801fe659a2b
SHA256: bb56f571f60d2862b2387d5468fe8f5540f8094727283ed991f89082708095ee
Evidence Type Source Name Value Confidence Vendor file name jakarta.enterprise.jakarta.enterprise.lang-model High Vendor jar package name enterprise Highest Vendor jar package name enterprise Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name lang Highest Vendor jar package name lang Low Vendor jar package name model Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.enterprise.lang-model Medium Product file name jakarta.enterprise.jakarta.enterprise.lang-model High Product jar package name enterprise Highest Product jar package name enterprise Low Product jar package name jakarta Highest Product jar package name lang Highest Product jar package name lang Low Product jar package name model Highest Product jar package name model Low Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name CDI Language Model Medium Product Manifest bundle-symbolicname jakarta.enterprise.lang-model Medium Version file name jakarta.enterprise.jakarta.enterprise.lang-model Medium Version file version 4.1.0 High Version Manifest build-jdk-spec 17 Low Version Manifest Bundle-Version 4.1.0 High
Related Dependencies jakarta.enterprise.jakarta.enterprise.lang-model-4.1.0.jar (shaded: jakarta.enterprise:jakarta.enterprise.lang-model:4.1.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.enterprise.jakarta.enterprise.lang-model-4.1.0.jar/META-INF/maven/jakarta.enterprise/jakarta.enterprise.lang-model/pom.xml MD5: f982e75afb385848641c5d6cbe37b793 SHA1: 83b4a4c7863657ce9731287d876b5740c06f66fb SHA256: ff6c448799024c694bac8b52b7dee3b1f264a22718a5e2af4dd4d5fb42c98b02 pkg:maven/jakarta.enterprise/jakarta.enterprise.lang-model@4.1.0 jakarta.enterprise.jakarta.enterprise.lang-model-4.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.enterprise.jakarta.enterprise.lang-model-4.1.0.jar MD5: fd9efbe0808984a89690e04ea28cd368 SHA1: 9270ae3df4239d4f337215403ebc9801fe659a2b SHA256: bb56f571f60d2862b2387d5468fe8f5540f8094727283ed991f89082708095ee jakarta.enterprise.lang-model-4.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/enterprise/jakarta.enterprise.lang-model/4.1.0/jakarta.enterprise.lang-model-4.1.0.jar MD5: fd9efbe0808984a89690e04ea28cd368 SHA1: 9270ae3df4239d4f337215403ebc9801fe659a2b SHA256: bb56f571f60d2862b2387d5468fe8f5540f8094727283ed991f89082708095ee pkg:maven/jakarta.enterprise/jakarta.enterprise.lang-model@4.1.0 jakarta.inject.jakarta.inject-api-2.0.1.jarDescription:
Jakarta Dependency Injection License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.inject.jakarta.inject-api-2.0.1.jar
MD5: 72003bf6efcc8455d414bbd7da86c11c
SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e
SHA256: f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c
Evidence Type Source Name Value Confidence Vendor file name jakarta.inject.jakarta.inject-api High Vendor jar package name inject Highest Vendor jar package name inject Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium Product file name jakarta.inject.jakarta.inject-api High Product jar package name inject Highest Product jar package name inject Low Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Dependency Injection Medium Product Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium Version file name jakarta.inject.jakarta.inject-api Medium Version file version 2.0.1 High Version Manifest build-jdk-spec 11 Low Version Manifest Bundle-Version 2.0.1 High Version Manifest Implementation-Version 2.0 High
Related Dependencies jakarta.inject-api-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/inject/jakarta.inject-api/2.0.1/jakarta.inject-api-2.0.1.jar MD5: 72003bf6efcc8455d414bbd7da86c11c SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e SHA256: f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c pkg:maven/jakarta.inject/jakarta.inject-api@2.0.1 jakarta.inject.jakarta.inject-api-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.inject.jakarta.inject-api-2.0.1.jar MD5: 72003bf6efcc8455d414bbd7da86c11c SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e SHA256: f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c jakarta.interceptor.jakarta.interceptor-api-2.2.0.jarDescription:
Jakarta Interceptors 2.2 Specification License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.interceptor.jakarta.interceptor-api-2.2.0.jar
MD5: ef5c0cb454edafbd9e5b3cb0f728f61f
SHA1: ed3605f9c5428d45549d4720235f3e943339f39a
SHA256: d240d72b4dd38a2e431c804079810010cb97903678fa5f987fb7434878b04398
Evidence Type Source Name Value Confidence Vendor file name jakarta.interceptor.jakarta.interceptor-api High Vendor jar package name interceptor Highest Vendor jar package name interceptor Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.interceptor-api Medium Vendor Manifest extension-name jakarta.interceptor Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Product file name jakarta.interceptor.jakarta.interceptor-api High Product jar package name interceptor Highest Product jar package name interceptor Low Product jar package name interceptors Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Interceptors Medium Product Manifest bundle-symbolicname jakarta.interceptor-api Medium Product Manifest extension-name jakarta.interceptor Medium Version file version 2.2.0 High Version Manifest Implementation-Version 2.2.0 High
Related Dependencies jakarta.interceptor-api-2.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/interceptor/jakarta.interceptor-api/2.2.0/jakarta.interceptor-api-2.2.0.jar MD5: ef5c0cb454edafbd9e5b3cb0f728f61f SHA1: ed3605f9c5428d45549d4720235f3e943339f39a SHA256: d240d72b4dd38a2e431c804079810010cb97903678fa5f987fb7434878b04398 pkg:maven/jakarta.interceptor/jakarta.interceptor-api@2.2.0 jakarta.interceptor.jakarta.interceptor-api-2.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.interceptor.jakarta.interceptor-api-2.2.0.jar MD5: ef5c0cb454edafbd9e5b3cb0f728f61f SHA1: ed3605f9c5428d45549d4720235f3e943339f39a SHA256: d240d72b4dd38a2e431c804079810010cb97903678fa5f987fb7434878b04398 jakarta.json.jakarta.json-api-2.1.3.jarDescription:
Jakarta JSON Processing API 2.1 License:
https://projects.eclipse.org/license/epl-2.0, https://projects.eclipse.org/license/secondary-gpl-2.0-cp File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.json.jakarta.json-api-2.1.3.jar
MD5: 596997520702889d4afef9cffbd4b71a
SHA1: 4febd83e1d9d1561d078af460ecd19532383735c
SHA256: bc934142805ea1d794f1440563965a3861a2a9fb7414ecd3fe44f26500734414
Evidence Type Source Name Value Confidence Vendor file name jakarta.json.jakarta.json-api High Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name json Highest Vendor jar package name json Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.json-api Medium Vendor Manifest extension-name jakarta.json Medium Vendor Manifest implementation-build-id b7f9d85 Low Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.json.jakarta.json-api High Product jar package name jakarta Highest Product jar package name json Highest Product jar package name json Low Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta JSON Processing API Medium Product Manifest bundle-symbolicname jakarta.json-api Medium Product Manifest extension-name jakarta.json Medium Product Manifest implementation-build-id b7f9d85 Low Version file version 2.1.3 High Version Manifest Implementation-Version 2.1.3 High
Related Dependencies jakarta.json-api-2.1.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/json/jakarta.json-api/2.1.3/jakarta.json-api-2.1.3.jar MD5: 596997520702889d4afef9cffbd4b71a SHA1: 4febd83e1d9d1561d078af460ecd19532383735c SHA256: bc934142805ea1d794f1440563965a3861a2a9fb7414ecd3fe44f26500734414 pkg:maven/jakarta.json/jakarta.json-api@2.1.3 jakarta.json.jakarta.json-api-2.1.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.json.jakarta.json-api-2.1.3.jar MD5: 596997520702889d4afef9cffbd4b71a SHA1: 4febd83e1d9d1561d078af460ecd19532383735c SHA256: bc934142805ea1d794f1440563965a3861a2a9fb7414ecd3fe44f26500734414 jakarta.persistence.jakarta.persistence-api-3.2.0.jarDescription:
Jakarta Persistence 3.2 API jar License:
http://www.eclipse.org/legal/epl-2.0, http://www.eclipse.org/org/documents/edl-v10.php File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.persistence.jakarta.persistence-api-3.2.0.jar
MD5: 79acec18d202797dcba1fff596a47684
SHA1: bb75a113f3fa191c2c7ee7b206d8e674251b3129
SHA256: be8a26b0e75c84c1b7600f759256fbc68d60333d89ec0ce3f784fc3ffa09aa8c
Evidence Type Source Name Value Confidence Vendor file name jakarta.persistence.jakarta.persistence-api High Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name persistence Highest Vendor jar package name persistence Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.persistence-api Medium Vendor Manifest extension-name jakarta.persistence Medium Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.persistence.jakarta.persistence-api High Product jar package name jakarta Highest Product jar package name persistence Highest Product jar package name persistence Low Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Persistence API jar Medium Product Manifest bundle-symbolicname jakarta.persistence-api Medium Product Manifest extension-name jakarta.persistence Medium Version file version 3.2.0 High Version Manifest Implementation-Version 3.2.0 High
Related Dependencies jakarta.persistence-api-3.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/persistence/jakarta.persistence-api/3.2.0/jakarta.persistence-api-3.2.0.jar MD5: 79acec18d202797dcba1fff596a47684 SHA1: bb75a113f3fa191c2c7ee7b206d8e674251b3129 SHA256: be8a26b0e75c84c1b7600f759256fbc68d60333d89ec0ce3f784fc3ffa09aa8c pkg:maven/jakarta.persistence/jakarta.persistence-api@3.2.0 jakarta.persistence.jakarta.persistence-api-3.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.persistence.jakarta.persistence-api-3.2.0.jar MD5: 79acec18d202797dcba1fff596a47684 SHA1: bb75a113f3fa191c2c7ee7b206d8e674251b3129 SHA256: be8a26b0e75c84c1b7600f759256fbc68d60333d89ec0ce3f784fc3ffa09aa8c jakarta.resource.jakarta.resource-api-2.1.0.jarDescription:
Jakarta Connectors 2.1 Specification License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.resource.jakarta.resource-api-2.1.0.jar
MD5: d1bc3f1bcfb4be1a9d810195eba05927
SHA1: d98f0ac826cdc85f80061c21bc061841ac6d374c
SHA256: 4d26ad86a5f72cd2f9c4a31cc4524f7bf3ec0ff74416f081f8642b7ce8041067
Evidence Type Source Name Value Confidence Vendor file name jakarta.resource.jakarta.resource-api High Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name resource Highest Vendor jar package name resource Low Vendor jar package name spi Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.resource-api Medium Vendor Manifest extension-name jakarta.resource Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Jakarta Connectors Low Product file name jakarta.resource.jakarta.resource-api High Product jar package name jakarta Highest Product jar package name resource Highest Product jar package name resource Low Product jar package name spi Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name jakarta.resource API Medium Product Manifest bundle-symbolicname jakarta.resource-api Medium Product Manifest extension-name jakarta.resource Medium Version file version 2.1.0 High Version Manifest Implementation-Version 2.1.0 High
Related Dependencies jakarta.resource-api-2.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/resource/jakarta.resource-api/2.1.0/jakarta.resource-api-2.1.0.jar MD5: d1bc3f1bcfb4be1a9d810195eba05927 SHA1: d98f0ac826cdc85f80061c21bc061841ac6d374c SHA256: 4d26ad86a5f72cd2f9c4a31cc4524f7bf3ec0ff74416f081f8642b7ce8041067 pkg:maven/jakarta.resource/jakarta.resource-api@2.1.0 jakarta.resource.jakarta.resource-api-2.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.resource.jakarta.resource-api-2.1.0.jar MD5: d1bc3f1bcfb4be1a9d810195eba05927 SHA1: d98f0ac826cdc85f80061c21bc061841ac6d374c SHA256: 4d26ad86a5f72cd2f9c4a31cc4524f7bf3ec0ff74416f081f8642b7ce8041067 jakarta.transaction.jakarta.transaction-api-2.0.1.jarDescription:
Jakarta(TM) Transactions 2.0 API Design Specification License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.transaction.jakarta.transaction-api-2.0.1.jar
MD5: 5315974a3935e342b40849478e1c9966
SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a
SHA256: 50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875
Evidence Type Source Name Value Confidence Vendor file name jakarta.transaction.jakarta.transaction-api High Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name transaction Highest Vendor jar package name transaction Low Vendor Manifest automatic-module-name jakarta.transaction Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/eclipse-ee4j Low Vendor Manifest bundle-symbolicname jakarta.transaction-api Medium Vendor Manifest extension-name jakarta.transaction Medium Vendor Manifest Implementation-Vendor EE4J Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Product file name jakarta.transaction.jakarta.transaction-api High Product jar package name jakarta Highest Product jar package name transaction Highest Product jar package name transaction Low Product Manifest automatic-module-name jakarta.transaction Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/eclipse-ee4j Low Product Manifest Bundle-Name jakarta.transaction API Medium Product Manifest bundle-symbolicname jakarta.transaction-api Medium Product Manifest extension-name jakarta.transaction Medium Version file version 2.0.1 High Version Manifest Implementation-Version 2.0.1 High
Related Dependencies jakarta.transaction-api-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/transaction/jakarta.transaction-api/2.0.1/jakarta.transaction-api-2.0.1.jar MD5: 5315974a3935e342b40849478e1c9966 SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a SHA256: 50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875 pkg:maven/jakarta.transaction/jakarta.transaction-api@2.0.1 jakarta.transaction.jakarta.transaction-api-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.transaction.jakarta.transaction-api-2.0.1.jar MD5: 5315974a3935e342b40849478e1c9966 SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a SHA256: 50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875 jakarta.validation.jakarta.validation-api-3.1.1.jarDescription:
Jakarta Validation API License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.validation.jakarta.validation-api-3.1.1.jar
MD5: 93ce96e77734f4280157edeffcae44e8
SHA1: ec8622148afc5564235d17af80ea80288d0e7f92
SHA256: 63ce00156388c365f3ac1be71fcfaf114682fc0c452020b5df6e7ec236e142ab
Evidence Type Source Name Value Confidence Vendor file name jakarta.validation.jakarta.validation-api High Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name validation Highest Vendor jar package name validation Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium Product file name jakarta.validation.jakarta.validation-api High Product jar package name jakarta Highest Product jar package name validation Highest Product jar package name validation Low Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Validation API Medium Product Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium Version file name jakarta.validation.jakarta.validation-api Medium Version file version 3.1.1 High Version Manifest build-jdk-spec 11 Low Version Manifest Bundle-Version 3.1.1 High
Related Dependencies jakarta.validation-api-3.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/validation/jakarta.validation-api/3.1.1/jakarta.validation-api-3.1.1.jar MD5: 93ce96e77734f4280157edeffcae44e8 SHA1: ec8622148afc5564235d17af80ea80288d0e7f92 SHA256: 63ce00156388c365f3ac1be71fcfaf114682fc0c452020b5df6e7ec236e142ab pkg:maven/jakarta.validation/jakarta.validation-api@3.1.1 jakarta.validation.jakarta.validation-api-3.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.validation.jakarta.validation-api-3.1.1.jar MD5: 93ce96e77734f4280157edeffcae44e8 SHA1: ec8622148afc5564235d17af80ea80288d0e7f92 SHA256: 63ce00156388c365f3ac1be71fcfaf114682fc0c452020b5df6e7ec236e142ab jakarta.ws.rs.jakarta.ws.rs-api-3.1.0.jarDescription:
Jakarta RESTful Web Services API (JAX-RS) License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.ws.rs.jakarta.ws.rs-api-3.1.0.jar
MD5: 6ce4c6749e048456b2c452c1091689ca
SHA1: 15ce10d249a38865b58fc39521f10f29ab0e3363
SHA256: 6b3b3628b8b4aedda0d24c3354335e985497d8ef3c510b8f3028e920d5b8663d
Evidence Type Source Name Value Confidence Vendor file name jakarta.ws.rs.jakarta.ws.rs-api High Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name rs Highest Vendor jar package name rs Low Vendor jar package name ws Highest Vendor jar package name ws Low Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low Vendor Manifest bundle-symbolicname jakarta.ws.rs-api Medium Vendor Manifest extension-name jakarta.ws.rs Medium Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.ws.rs.jakarta.ws.rs-api High Product jar package name jakarta Highest Product jar package name rs Highest Product jar package name rs Low Product jar package name ws Highest Product jar package name ws Low Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low Product Manifest Bundle-Name Jakarta RESTful WS API Medium Product Manifest bundle-symbolicname jakarta.ws.rs-api Medium Product Manifest extension-name jakarta.ws.rs Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High
Related Dependencies jakarta.ws.rs-api-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/ws/rs/jakarta.ws.rs-api/3.1.0/jakarta.ws.rs-api-3.1.0.jar MD5: 6ce4c6749e048456b2c452c1091689ca SHA1: 15ce10d249a38865b58fc39521f10f29ab0e3363 SHA256: 6b3b3628b8b4aedda0d24c3354335e985497d8ef3c510b8f3028e920d5b8663d pkg:maven/jakarta.ws.rs/jakarta.ws.rs-api@3.1.0 jakarta.ws.rs.jakarta.ws.rs-api-3.1.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.ws.rs.jakarta.ws.rs-api-3.1.0.jar MD5: 6ce4c6749e048456b2c452c1091689ca SHA1: 15ce10d249a38865b58fc39521f10f29ab0e3363 SHA256: 6b3b3628b8b4aedda0d24c3354335e985497d8ef3c510b8f3028e920d5b8663d jakarta.xml.bind.jakarta.xml.bind-api-4.0.4.jarDescription:
Jakarta XML Binding API 4.0 Design Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/jakarta.xml.bind.jakarta.xml.bind-api-4.0.4.jar
MD5: 6dd465a232e545193ab8ab77cc4fbdb9
SHA1: d6d2327f3817d9a33a3b6b8f2e15a96bc2e7afdc
SHA256: c507ca69a8c6dd11bf4afeec9e0d412c4fa3933fffb0a84680ea5727e8472124
Evidence Type Source Name Value Confidence Vendor file name jakarta.xml.bind.jakarta.xml.bind-api High Vendor jar package name bind Highest Vendor jar package name bind Low Vendor jar package name jakarta Highest Vendor jar package name jakarta Low Vendor jar package name xml Highest Vendor jar package name xml Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium Vendor Manifest extension-name jakarta.xml.bind Medium Vendor Manifest implementation-build-id 1df980a Low Vendor Manifest specification-vendor Eclipse Foundation Low Product file name jakarta.xml.bind.jakarta.xml.bind-api High Product jar package name bind Highest Product jar package name bind Low Product jar package name jakarta Highest Product jar package name xml Highest Product jar package name xml Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta XML Binding API Medium Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium Product Manifest extension-name jakarta.xml.bind Medium Product Manifest implementation-build-id 1df980a Low Version file version 4.0.4 High Version Manifest Implementation-Version 4.0.4 High
Related Dependencies jakarta.xml.bind-api-4.0.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/jakarta/xml/bind/jakarta.xml.bind-api/4.0.4/jakarta.xml.bind-api-4.0.4.jar MD5: 6dd465a232e545193ab8ab77cc4fbdb9 SHA1: d6d2327f3817d9a33a3b6b8f2e15a96bc2e7afdc SHA256: c507ca69a8c6dd11bf4afeec9e0d412c4fa3933fffb0a84680ea5727e8472124 pkg:maven/jakarta.xml.bind/jakarta.xml.bind-api@4.0.4 jakarta.xml.bind.jakarta.xml.bind-api-4.0.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/jakarta.xml.bind.jakarta.xml.bind-api-4.0.4.jar MD5: 6dd465a232e545193ab8ab77cc4fbdb9 SHA1: d6d2327f3817d9a33a3b6b8f2e15a96bc2e7afdc SHA256: c507ca69a8c6dd11bf4afeec9e0d412c4fa3933fffb0a84680ea5727e8472124 jandex-3.3.1.jarDescription:
SmallRye Build Parent POM License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/jandex/3.3.1/jandex-3.3.1.jar
MD5: d9c0812db44cdbffce4d4f35356547b9
SHA1: cea8c28faa729cbc00a6d397cf28f12ae9a577f0
SHA256: 01301f7118eac2b8731c292d58e73f6f96e57b1c89c00aa82e96cd8facd29898
Evidence Type Source Name Value Confidence Vendor file name jandex High Vendor jar package name jandex Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-symbolicname io.smallrye.jandex Medium Vendor Manifest multi-release true Low Vendor pom artifactid jandex Low Vendor pom groupid io.smallrye Highest Vendor pom name Jandex: Core High Vendor pom parent-artifactid jandex-parent Low Product file name jandex High Product jar package name jandex Highest Product Manifest build-jdk-spec 21 Low Product Manifest Bundle-Name Jandex: Core Medium Product Manifest bundle-symbolicname io.smallrye.jandex Medium Product Manifest multi-release true Low Product pom artifactid jandex Highest Product pom groupid io.smallrye Highest Product pom name Jandex: Core High Product pom parent-artifactid jandex-parent Medium Version file version 3.3.1 High Version Manifest Bundle-Version 3.3.1 High Version pom version 3.3.1 Highest
pkg:maven/io.smallrye/jandex@3.3.1 (Confidence :High) jandex-gizmo2-3.5.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/jandex-gizmo2/3.5.2/jandex-gizmo2-3.5.2.jarMD5: 9f82f047d4e16cf1f3cb3485c9825ae3SHA1: dff50a3fff893da7c7e433daeb7e0e048ca5c961SHA256: 8b83c031f4d597956ae94834bd779a423f50b115aa51882d8c332f5675272376
Evidence Type Source Name Value Confidence Vendor file name jandex-gizmo2 High Vendor jar package name gizmo2 Highest Vendor jar package name jandex Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor pom artifactid jandex-gizmo2 Low Vendor pom groupid io.smallrye Highest Vendor pom name Jandex: Gizmo2 Integration High Vendor pom parent-artifactid jandex-parent Low Product file name jandex-gizmo2 High Product jar package name gizmo2 Highest Product jar package name jandex Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Jandex: Gizmo2 Integration High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title Jandex: Gizmo2 Integration Medium Product pom artifactid jandex-gizmo2 Highest Product pom groupid io.smallrye Highest Product pom name Jandex: Gizmo2 Integration High Product pom parent-artifactid jandex-parent Medium Version file version 3.5.2 High Version Manifest Implementation-Version 3.5.2 High Version pom version 3.5.2 Highest
pkg:maven/io.smallrye/jandex-gizmo2@3.5.2 (Confidence :High) jandex-maven-plugin-3.3.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/jandex-maven-plugin/3.3.1/jandex-maven-plugin-3.3.1.jarMD5: 64d5804802af17b798c266d5b8b816b8SHA1: 7e7c6430fcb95af2061ec08f1b7d2362b8b23579SHA256: 716cc7565ac6f056cbe74d05e3409b7e2bc95e4758b504ddaf71d0c93268efff
Evidence Type Source Name Value Confidence Vendor file name jandex-maven-plugin High Vendor jar package name jandex Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor pom artifactid jandex-maven-plugin Low Vendor pom groupid io.smallrye Highest Vendor pom name Jandex: Maven Plugin High Vendor pom parent-artifactid jandex-parent Low Product file name jandex-maven-plugin High Product jar package name jandex Highest Product jar package name maven Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Jandex: Maven Plugin High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title Jandex: Maven Plugin Medium Product pom artifactid jandex-maven-plugin Highest Product pom groupid io.smallrye Highest Product pom name Jandex: Maven Plugin High Product pom parent-artifactid jandex-parent Medium Version file version 3.3.1 High Version Manifest Implementation-Version 3.3.1 High Version pom version 3.3.1 Highest
pkg:maven/io.smallrye/jandex-maven-plugin@3.3.1 (Confidence :High) jansi-2.4.0.jarDescription:
Jansi is a java library for generating and interpreting ANSI escape sequences. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/fusesource/jansi/jansi/2.4.0/jansi-2.4.0.jar
MD5: bb0f7e4e04a71518dfe5b4ec102aa61f
SHA1: 321c614f85f1dea6bb08c1817c60d53b7f3552fd
SHA256: 6cd91991323dd7b2fb28ca93d7ac12af5a86a2f53279e2b35827b30313fd0b9f
Evidence Type Source Name Value Confidence Vendor file name jansi High Vendor jar package name fusesource Highest Vendor jar package name jansi Highest Vendor Manifest automatic-module-name org.fusesource.jansi Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl http://fusesource.com/ Low Vendor Manifest bundle-symbolicname org.fusesource.jansi Medium Vendor Manifest Implementation-Vendor FuseSource, Corp. High Vendor pom artifactid jansi Low Vendor pom developer email gnodet@gmail.com Low Vendor pom developer email hiram@hiramchirino.com Low Vendor pom developer id chirino Medium Vendor pom developer id gnodet Medium Vendor pom developer name Guillaume Nodet Medium Vendor pom developer name Hiram Chirino Medium Vendor pom groupid org.fusesource.jansi Highest Vendor pom name ${project.artifactId} High Vendor pom parent-artifactid fusesource-pom Low Vendor pom parent-groupid org.fusesource Medium Vendor pom url http://fusesource.github.io/jansi Highest Product file name jansi High Product jar package name fusesource Highest Product jar package name jansi Highest Product Manifest automatic-module-name org.fusesource.jansi Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl http://fusesource.com/ Low Product Manifest Bundle-Name jansi Medium Product Manifest bundle-symbolicname org.fusesource.jansi Medium Product Manifest Implementation-Title jansi High Product Manifest specification-title jansi Medium Product pom artifactid jansi Highest Product pom developer email gnodet@gmail.com Low Product pom developer email hiram@hiramchirino.com Low Product pom developer id chirino Low Product pom developer id gnodet Low Product pom developer name Guillaume Nodet Low Product pom developer name Hiram Chirino Low Product pom groupid org.fusesource.jansi Highest Product pom name ${project.artifactId} High Product pom parent-artifactid fusesource-pom Medium Product pom parent-groupid org.fusesource Medium Product pom url http://fusesource.github.io/jansi Medium Version file version 2.4.0 High Version Manifest Bundle-Version 2.4.0 High Version Manifest Implementation-Version 2.4.0 High Version pom parent-version 2.4.0 Low Version pom version 2.4.0 Highest
pkg:maven/org.fusesource.jansi/jansi@2.4.0 (Confidence :High) java-properties-0.0.7.jarDescription:
A simple Java Properties parser that retains the exact format of the input file, including any comments License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codejive/java-properties/0.0.7/java-properties-0.0.7.jar
MD5: 0ca54f73f449df958cc7e75a3d86e595
SHA1: c3daffce710cde2591a936e7d9a4028eb7b803c7
SHA256: 0b89124daefd48fe8c0f43449be3a98ba609b460f018a80c704c74544f62286a
Evidence Type Source Name Value Confidence Vendor file name java-properties High Vendor jar package name codejive Highest Vendor jar package name codejive Low Vendor jar package name properties Highest Vendor jar package name properties Low Vendor pom artifactid java-properties Low Vendor pom developer email tako@codejive.org Low Vendor pom developer name Tako Schotanus Medium Vendor pom developer org Codejive Medium Vendor pom developer org URL https://github.com/quintesse Medium Vendor pom groupid org.codejive Highest Vendor pom name Java Properties parser High Vendor pom url codejive/java-properties Highest Product file name java-properties High Product jar package name codejive Highest Product jar package name properties Highest Product jar package name properties Low Product pom artifactid java-properties Highest Product pom developer email tako@codejive.org Low Product pom developer name Tako Schotanus Low Product pom developer org Codejive Low Product pom developer org URL https://github.com/quintesse Low Product pom groupid org.codejive Highest Product pom name Java Properties parser High Product pom url codejive/java-properties High Version file version 0.0.7 High Version pom version 0.0.7 Highest
pkg:maven/org.codejive/java-properties@0.0.7 (Confidence :High) javax.annotation-api-1.3.2.jarDescription:
Common Annotations for the JavaTM Platform API License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.annotation/blob/master/LICENSE File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/javax/annotation/javax.annotation-api/1.3.2/javax.annotation-api-1.3.2.jar
MD5: 2ab1973eefffaa2aeec47d50b9e40b9d
SHA1: 934c04d3cfef185a8008e7bf34331b79730a9d43
SHA256: e04ba5195bcd555dc95650f7cc614d151e4bcd52d29a10b8aa2197f3ab89ab9b
Evidence Type Source Name Value Confidence Vendor file name javax.annotation-api High Vendor jar package name annotation Highest Vendor jar package name javax Highest Vendor Manifest automatic-module-name java.annotation Medium Vendor Manifest bundle-docurl https://javaee.github.io/glassfish Low Vendor Manifest bundle-symbolicname javax.annotation-api Medium Vendor Manifest extension-name javax.annotation Medium Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.annotation-api Low Vendor pom developer id ldemichiel Medium Vendor pom developer name Linda De Michiel Medium Vendor pom developer org Oracle Corp. Medium Vendor pom groupid javax.annotation Highest Vendor pom name API High Vendor pom name ${extension.name} API High Vendor pom organization name GlassFish Community High Vendor pom organization url https://javaee.github.io/glassfish Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://jcp.org/en/jsr/detail?id=250 Highest Product file name javax.annotation-api High Product jar package name annotation Highest Product jar package name javax Highest Product Manifest automatic-module-name java.annotation Medium Product Manifest bundle-docurl https://javaee.github.io/glassfish Low Product Manifest Bundle-Name javax.annotation API Medium Product Manifest bundle-symbolicname javax.annotation-api Medium Product Manifest extension-name javax.annotation Medium Product pom artifactid javax.annotation-api Highest Product pom developer id ldemichiel Low Product pom developer name Linda De Michiel Low Product pom developer org Oracle Corp. Low Product pom groupid javax.annotation Highest Product pom name API High Product pom name ${extension.name} API High Product pom organization name GlassFish Community Low Product pom organization url https://javaee.github.io/glassfish Low Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://jcp.org/en/jsr/detail?id=250 Medium Version file version 1.3.2 High Version Manifest Bundle-Version 1.3.2 High Version Manifest Implementation-Version 1.3.2 High Version pom parent-version 1.3.2 Low Version pom version 1.3.2 Highest
pkg:maven/javax.annotation/javax.annotation-api@1.3.2 (Confidence :High) javax.inject-1.jarDescription:
The javax.inject API License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256: 91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Evidence Type Source Name Value Confidence Vendor file name javax.inject-1 High Vendor jar package name inject Highest Vendor jar package name inject Low Vendor jar package name javax Highest Vendor jar package name javax Low Vendor pom artifactid javax.inject Low Vendor pom groupid javax.inject Highest Vendor pom name javax.inject High Vendor pom url http://code.google.com/p/atinject/ Highest Product file name javax.inject-1 High Product jar package name inject Highest Product jar package name inject Low Product jar package name javax Highest Product pom artifactid javax.inject Highest Product pom groupid javax.inject Highest Product pom name javax.inject High Product pom url http://code.google.com/p/atinject/ Medium Version file version 1 Medium Version pom version 1 Highest
pkg:maven/javax.inject/javax.inject@1 (Confidence :High) jdbc-1.21.3.jarDescription:
Isolated container management for Java code testing License:
MIT: http://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/testcontainers/jdbc/1.21.3/jdbc-1.21.3.jar
MD5: d7236e530d2db9f67bdf81fed07b474c
SHA1: add1cf7b1c8f0ec3a3189793e90a7a967000cf95
SHA256: 8162137442982ef42a70a86fd50362d48d2a2366bf13787f98696735aecf7a57
Evidence Type Source Name Value Confidence Vendor file name jdbc High Vendor jar package name jdbc Highest Vendor jar package name jdbc Low Vendor jar package name testcontainers Highest Vendor jar package name testcontainers Low Vendor pom artifactid jdbc Low Vendor pom developer email rich.north@gmail.com Low Vendor pom developer id rnorth Medium Vendor pom developer name Richard North Medium Vendor pom groupid org.testcontainers Highest Vendor pom name Testcontainers :: JDBC High Vendor pom url https://java.testcontainers.org Highest Product file name jdbc High Product jar package name jdbc Highest Product jar package name jdbc Low Product jar package name testcontainers Highest Product pom artifactid jdbc Highest Product pom developer email rich.north@gmail.com Low Product pom developer id rnorth Low Product pom developer name Richard North Low Product pom groupid org.testcontainers Highest Product pom name Testcontainers :: JDBC High Product pom url https://java.testcontainers.org Medium Version file version 1.21.3 High Version pom version 1.21.3 Highest
pkg:maven/org.testcontainers/jdbc@1.21.3 (Confidence :High) jdk-classfile-backport-25.1.jarDescription:
An unofficial backport of the JDK Classfile API to Java 17 License:
GNU General Public License, version 2, with the Classpath Exception: http://openjdk.java.net/legal/gplv2+ce.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/github/dmlloyd/jdk-classfile-backport/25.1/jdk-classfile-backport-25.1.jar
MD5: 702df1fba3112d187310a54faa8da542
SHA1: 78f035319ccbc5c1d2c65fe2854290e0f15a8fb1
SHA256: 2156731c92362678945300ed39b7bf954c8338ecd1f5880995cfbd95d46dbbfe
Evidence Type Source Name Value Confidence Vendor file name jdk-classfile-backport High Vendor jar package name classfile Highest Vendor jar package name dmlloyd Highest Vendor jar package name github Highest Vendor jar package name io Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid jdk-classfile-backport Low Vendor pom developer email david.lloyd@redhat.com Low Vendor pom developer name David Lloyd Medium Vendor pom developer org Contributors to the unofficial JDK classfile backporting project Medium Vendor pom developer org URL https://github.com/dmlloyd/jdk-classfile-backport Medium Vendor pom groupid io.github.dmlloyd Highest Vendor pom name JDK Classfile API backport (Unofficial) High Vendor pom url dmlloyd/jdk-classfile-backport Highest Product file name jdk-classfile-backport High Product jar package name classfile Highest Product jar package name dmlloyd Highest Product jar package name github Highest Product jar package name io Highest Product Manifest build-jdk-spec 21 Low Product pom artifactid jdk-classfile-backport Highest Product pom developer email david.lloyd@redhat.com Low Product pom developer name David Lloyd Low Product pom developer org Contributors to the unofficial JDK classfile backporting project Low Product pom developer org URL https://github.com/dmlloyd/jdk-classfile-backport Low Product pom groupid io.github.dmlloyd Highest Product pom name JDK Classfile API backport (Unofficial) High Product pom url dmlloyd/jdk-classfile-backport High Version file version 25.1 High Version pom version 25.1 Highest
pkg:maven/io.github.dmlloyd/jdk-classfile-backport@25.1 (Confidence :High) jdom2-2.0.6.1.jarDescription:
A complete, Java-based solution for accessing, manipulating,
and outputting XML data
License:
Similar to Apache License but with the acknowledgment clause removed: https://raw.github.com/hunterhacker/jdom/master/LICENSE.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jdom/jdom2/2.0.6.1/jdom2-2.0.6.1.jar
MD5: 5be72710c66f3c9ba71f8009e92597d1
SHA1: dc15dff8f701b227ee523eeb7a17f77c10eafe2f
SHA256: 0b20f45e3a0fd8f0d12cdc5316b06776e902b1365db00118876f9175c60f302c
Evidence Type Source Name Value Confidence Vendor file name jdom2 High Vendor jar package name jdom2 Highest Vendor Manifest automatic-module-name org.jdom2 Medium Vendor manifest: org/jdom2/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/adapters/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/filter/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/input/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/output/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/transform/ Implementation-Vendor jdom.org Medium Vendor manifest: org/jdom2/xpath/ Implementation-Vendor jdom.org Medium Vendor pom artifactid jdom2 Low Vendor pom developer email jdom@tuis.net Low Vendor pom developer email jhunter@servlets.com Low Vendor pom developer id hunterhacker Medium Vendor pom developer id rolfl Medium Vendor pom developer name Jason Hunter Medium Vendor pom developer name Rolf Lear Medium Vendor pom groupid org.jdom Highest Vendor pom name JDOM High Vendor pom organization name JDOM High Vendor pom organization url http://www.jdom.org Medium Vendor pom url http://www.jdom.org Highest Product file name jdom2 High Product jar package name adapters Highest Product jar package name filter Highest Product jar package name input Highest Product jar package name jdom2 Highest Product jar package name output Highest Product jar package name transform Highest Product jar package name xpath Highest Product Manifest automatic-module-name org.jdom2 Medium Product manifest: org/jdom2/ Implementation-Title org.jdom2 Medium Product manifest: org/jdom2/ Specification-Title JDOM Classes Medium Product manifest: org/jdom2/adapters/ Implementation-Title org.jdom2.adapters Medium Product manifest: org/jdom2/adapters/ Specification-Title JDOM Adapter Classes Medium Product manifest: org/jdom2/filter/ Implementation-Title org.jdom2.filter Medium Product manifest: org/jdom2/filter/ Specification-Title JDOM Filter Classes Medium Product manifest: org/jdom2/input/ Implementation-Title org.jdom2.input Medium Product manifest: org/jdom2/input/ Specification-Title JDOM Input Classes Medium Product manifest: org/jdom2/output/ Implementation-Title org.jdom2.output Medium Product manifest: org/jdom2/output/ Specification-Title JDOM Output Classes Medium Product manifest: org/jdom2/transform/ Implementation-Title org.jdom2.transform Medium Product manifest: org/jdom2/transform/ Specification-Title JDOM Transformation Classes Medium Product manifest: org/jdom2/xpath/ Implementation-Title org.jdom2.xpath Medium Product manifest: org/jdom2/xpath/ Specification-Title JDOM XPath Classes Medium Product pom artifactid jdom2 Highest Product pom developer email jdom@tuis.net Low Product pom developer email jhunter@servlets.com Low Product pom developer id hunterhacker Low Product pom developer id rolfl Low Product pom developer name Jason Hunter Low Product pom developer name Rolf Lear Low Product pom groupid org.jdom Highest Product pom name JDOM High Product pom organization name JDOM Low Product pom organization url http://www.jdom.org Low Product pom url http://www.jdom.org Medium Version file version 2.0.6.1 High Version pom version 2.0.6.1 Highest
jib-build-plan-0.4.0.jarDescription:
Jib Container Build Plan API License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/cloud/tools/jib-build-plan/0.4.0/jib-build-plan-0.4.0.jar
MD5: 2db509a6a4956ce9c88f4b7993aa5fe5
SHA1: b16394e7eda9aeff338841c6dc47ed5a8a9d8120
SHA256: 9b74d6be551b8bf079d711148769150d566512db5a50b1e9c7c445c69c08d182
Evidence Type Source Name Value Confidence Vendor file name jib-build-plan High Vendor jar package name cloud Highest Vendor jar package name google Highest Vendor jar package name jib Highest Vendor jar package name tools Highest Vendor Manifest automatic-module-name com.google.cloud.tools.jib.api.buildplan Medium Vendor Manifest built-date Tue Aug 04 15:27:25 PDT 2020 Low Vendor Manifest built-gradle 5.2.1 Low Vendor Manifest bundle-docurl https://github.com/GoogleContainerTools/jib Low Vendor Manifest bundle-symbolicname com.google.cloud.tools.jib.api.buildplan Medium Vendor pom artifactid jib-build-plan Low Vendor pom developer email appu@google.com Low Vendor pom developer email bdealwis@google.com Low Vendor pom developer email chanseok@google.com Low Vendor pom developer email tcordle@google.com Low Vendor pom developer id briandealwis Medium Vendor pom developer id chanseokoh Medium Vendor pom developer id coollog Medium Vendor pom developer id loosebazooka Medium Vendor pom developer id TadCordle Medium Vendor pom developer name Appu Goundan Medium Vendor pom developer name Brian de Alwis Medium Vendor pom developer name Chanseok Oh Medium Vendor pom developer name Qingyang Chen Medium Vendor pom developer name Tad Cordle Medium Vendor pom groupid com.google.cloud.tools Highest Vendor pom name Jib Container Build Plan API High Vendor pom url GoogleContainerTools/jib Highest Product file name jib-build-plan High Product jar package name cloud Highest Product jar package name google Highest Product jar package name jib Highest Product jar package name tools Highest Product Manifest automatic-module-name com.google.cloud.tools.jib.api.buildplan Medium Product Manifest built-date Tue Aug 04 15:27:25 PDT 2020 Low Product Manifest built-gradle 5.2.1 Low Product Manifest bundle-docurl https://github.com/GoogleContainerTools/jib Low Product Manifest Bundle-Name Jib Container Build Plan API Medium Product Manifest bundle-symbolicname com.google.cloud.tools.jib.api.buildplan Medium Product Manifest Implementation-Title jib-build-plan High Product pom artifactid jib-build-plan Highest Product pom developer email appu@google.com Low Product pom developer email bdealwis@google.com Low Product pom developer email chanseok@google.com Low Product pom developer email tcordle@google.com Low Product pom developer id briandealwis Low Product pom developer id chanseokoh Low Product pom developer id coollog Low Product pom developer id loosebazooka Low Product pom developer id TadCordle Low Product pom developer name Appu Goundan Low Product pom developer name Brian de Alwis Low Product pom developer name Chanseok Oh Low Product pom developer name Qingyang Chen Low Product pom developer name Tad Cordle Low Product pom groupid com.google.cloud.tools Highest Product pom name Jib Container Build Plan API High Product pom url GoogleContainerTools/jib High Version file version 0.4.0 High Version Manifest Implementation-Version 0.4.0 High Version pom version 0.4.0 Highest
pkg:maven/com.google.cloud.tools/jib-build-plan@0.4.0 (Confidence :High) jib-core-0.27.3.jarDescription:
Build container images. License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/google/cloud/tools/jib-core/0.27.3/jib-core-0.27.3.jar
MD5: aab99306ed92805afd7617a892186419
SHA1: 5916b17257df977aea79fd934b9f62a5d16e396c
SHA256: 27ba15f857b60d505e9604104412c4b832b01353c6a8289d7851801e3b4f6b5f
Evidence Type Source Name Value Confidence Vendor file name jib-core High Vendor jar package name cloud Highest Vendor jar package name google Highest Vendor jar package name jib Highest Vendor jar package name tools Highest Vendor Manifest automatic-module-name com.google.cloud.tools.jib Medium Vendor Manifest built-date Mon Mar 17 14:57:49 EDT 2025 Low Vendor Manifest built-gradle 6.9.2 Low Vendor Manifest bundle-docurl https://github.com/GoogleContainerTools/jib Low Vendor Manifest bundle-symbolicname com.google.cloud.tools.jib Medium Vendor pom artifactid jib-core Low Vendor pom developer email appu@google.com Low Vendor pom developer email bdealwis@google.com Low Vendor pom developer email chanseok@google.com Low Vendor pom developer email tcordle@google.com Low Vendor pom developer id briandealwis Medium Vendor pom developer id chanseokoh Medium Vendor pom developer id coollog Medium Vendor pom developer id loosebazooka Medium Vendor pom developer id TadCordle Medium Vendor pom developer name Appu Goundan Medium Vendor pom developer name Brian de Alwis Medium Vendor pom developer name Chanseok Oh Medium Vendor pom developer name Qingyang Chen Medium Vendor pom developer name Tad Cordle Medium Vendor pom groupid com.google.cloud.tools Highest Vendor pom name Jib Core High Vendor pom url GoogleContainerTools/jib Highest Product file name jib-core High Product jar package name cloud Highest Product jar package name google Highest Product jar package name jib Highest Product jar package name tools Highest Product Manifest automatic-module-name com.google.cloud.tools.jib Medium Product Manifest built-date Mon Mar 17 14:57:49 EDT 2025 Low Product Manifest built-gradle 6.9.2 Low Product Manifest bundle-docurl https://github.com/GoogleContainerTools/jib Low Product Manifest Bundle-Name Jib library for building Docker and OCI images Medium Product Manifest bundle-symbolicname com.google.cloud.tools.jib Medium Product Manifest Implementation-Title jib-core High Product pom artifactid jib-core Highest Product pom developer email appu@google.com Low Product pom developer email bdealwis@google.com Low Product pom developer email chanseok@google.com Low Product pom developer email tcordle@google.com Low Product pom developer id briandealwis Low Product pom developer id chanseokoh Low Product pom developer id coollog Low Product pom developer id loosebazooka Low Product pom developer id TadCordle Low Product pom developer name Appu Goundan Low Product pom developer name Brian de Alwis Low Product pom developer name Chanseok Oh Low Product pom developer name Qingyang Chen Low Product pom developer name Tad Cordle Low Product pom groupid com.google.cloud.tools Highest Product pom name Jib Core High Product pom url GoogleContainerTools/jib High Version file version 0.27.3 High Version Manifest Implementation-Version 0.27.3 High Version pom version 0.27.3 Highest
jna-5.8.0.jarDescription:
Java Native Access License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/java/dev/jna/jna/5.8.0/jna-5.8.0.jar
MD5: 3e1988240662c4f068e8ff5df505f6a0
SHA1: 3551d8d827e54858214107541d3aff9c615cb615
SHA256: 930273cc1c492f25661ea62413a6da3fd7f6e01bf1c4dcc0817fc8696a7b07ac
Evidence Type Source Name Value Confidence Vendor file name jna High Vendor jar package name jna Highest Vendor jar package name native Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest automatic-module-name com.sun.jna Medium Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-category jni Low Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor Manifest bundle-symbolicname com.sun.jna Medium Vendor Manifest Implementation-Vendor JNA Development Team High Vendor Manifest specification-vendor JNA Development Team Low Vendor pom artifactid jna Low Vendor pom developer email mblaesing@doppel-helix.eu Low Vendor pom developer id twall Medium Vendor pom developer name Matthias Bläsing Medium Vendor pom developer name Timothy Wall Medium Vendor pom groupid net.java.dev.jna Highest Vendor pom name Java Native Access High Vendor pom url java-native-access/jna Highest Product file name jna High Product jar package name jna Highest Product jar package name library Highest Product jar package name native Highest Product jar package name sun Highest Product jar package name win32 Highest Product Manifest automatic-module-name com.sun.jna Medium Product Manifest bundle-activationpolicy lazy Low Product Manifest bundle-category jni Low Product Manifest Bundle-Name jna Medium Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product Manifest bundle-symbolicname com.sun.jna Medium Product Manifest Implementation-Title com.sun.jna High Product Manifest specification-title Java Native Access (JNA) Medium Product pom artifactid jna Highest Product pom developer email mblaesing@doppel-helix.eu Low Product pom developer id twall Low Product pom developer name Matthias Bläsing Low Product pom developer name Timothy Wall Low Product pom groupid net.java.dev.jna Highest Product pom name Java Native Access High Product pom url java-native-access/jna High Version file version 5.8.0 High Version Manifest Bundle-Version 5.8.0 High Version pom version 5.8.0 Highest
pkg:maven/net.java.dev.jna/jna@5.8.0 (Confidence :High) cpe:2.3:a:oracle:java_se:5.8.0:*:*:*:*:*:*:* (Confidence :Low) suppress jna-5.8.0.jar: jnidispatch.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/java/dev/jna/jna/5.8.0/jna-5.8.0.jar/com/sun/jna/win32-aarch64/jnidispatch.dllMD5: bf93f6b98af1987a7536d69202e0dda9SHA1: d8b5600b6c8254afd68068f130bc6f75c62f0a7aSHA256: 749e807fa10407e43cf2cf98e885e5ef76a95751c143c0c3326ad1366f3e9179
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-5.8.0.jar: jnidispatch.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/java/dev/jna/jna/5.8.0/jna-5.8.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dllMD5: a004906b9067501293107be3a92c3401SHA1: ed9f50de6051aaa1f26e61c64a5c6b0eba407d93SHA256: 76f19b52423774932831dcba0596989ec56213f9b217a0432fbc122f99704a2a
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-5.8.0.jar: jnidispatch.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/java/dev/jna/jna/5.8.0/jna-5.8.0.jar/com/sun/jna/win32-x86/jnidispatch.dllMD5: 7668f8f21cba1d0d7e2cc39379b8a3c3SHA1: 332887373846943f479dac9fabfd42fbe58d723aSHA256: 39bab69f5ead37326cb4c032c621dbddbc5093932871f2010120819a4100abdf
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
json-path-5.5.6.jarDescription:
Java DSL for easy testing of REST services License:
https://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/rest-assured/json-path/5.5.6/json-path-5.5.6.jar
MD5: 4ddeef986a004b50b948ac68109c53b3
SHA1: 2735e5e64a86338f6823664737a087cf5c63f278
SHA256: 46f7c91ce540d33ceda741ad5db6eb5ee2d0ad000dbb8eb9837b2f5c1c2d3a46
Evidence Type Source Name Value Confidence Vendor file name json-path High Vendor jar package name io Highest Vendor jar package name json Highest Vendor jar package name path Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname io.rest-assured.json-path Medium Vendor pom artifactid json-path Low Vendor pom groupid io.rest-assured Highest Vendor pom name json-path High Vendor pom parent-artifactid rest-assured-parent Low Vendor pom url https://rest-assured.io/ Highest Product file name json-path High Product jar package name io Highest Product jar package name json Highest Product jar package name path Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name json-path Medium Product Manifest bundle-symbolicname io.rest-assured.json-path Medium Product pom artifactid json-path Highest Product pom groupid io.rest-assured Highest Product pom name json-path High Product pom parent-artifactid rest-assured-parent Medium Product pom url https://rest-assured.io/ Medium Version file version 5.5.6 High Version Manifest Bundle-Version 5.5.6 High Version pom version 5.5.6 Highest
pkg:maven/io.rest-assured/json-path@5.5.6 (Confidence :High) json-schema-validator-1.5.9.jarDescription:
A json schema validator that supports draft v4, v6, v7, v2019-09 and v2020-12 License:
Apache License Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/networknt/json-schema-validator/1.5.9/json-schema-validator-1.5.9.jar
MD5: 84622292ac5001bac8f16dc5002a8b94
SHA1: 6a2f9fe324b9dc8d8e0c3d7b435f7ae99595a556
SHA256: e0b8baeb78fd1ba027454ee3974d8a02f54447eaa510d3052820a7d2160d9ae4
Evidence Type Source Name Value Confidence Vendor file name json-schema-validator High Vendor jar package name networknt Highest Vendor jar package name schema Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-symbolicname com.networknt.json-schema-validator Medium Vendor Manifest multi-release true Low Vendor pom artifactid json-schema-validator Low Vendor pom developer email stevehu@gmail.com Low Vendor pom developer id stevehu Medium Vendor pom developer name Steve Hu Medium Vendor pom groupid com.networknt Highest Vendor pom name JsonSchemaValidator High Vendor pom url networknt/json-schema-validator Highest Product file name json-schema-validator High Product jar package name networknt Highest Product jar package name schema Highest Product Manifest build-jdk-spec 21 Low Product Manifest Bundle-Name JsonSchemaValidator Medium Product Manifest bundle-symbolicname com.networknt.json-schema-validator Medium Product Manifest multi-release true Low Product pom artifactid json-schema-validator Highest Product pom developer email stevehu@gmail.com Low Product pom developer id stevehu Low Product pom developer name Steve Hu Low Product pom groupid com.networknt Highest Product pom name JsonSchemaValidator High Product pom url networknt/json-schema-validator High Version file version 1.5.9 High Version Manifest Bundle-Version 1.5.9 High Version pom version 1.5.9 Highest
jsoup-1.17.2.jarDescription:
jsoup is a Java library that simplifies working with real-world HTML and XML. It offers an easy-to-use API for URL fetching, data parsing, extraction, and manipulation using DOM API methods, CSS, and xpath selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers. License:
The MIT License: https://jsoup.org/license File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jsoup/jsoup/1.17.2/jsoup-1.17.2.jar
MD5: d9dd58c3f8a09f45e57d85e78993be6e
SHA1: 1e75b08d7019546a954f1e359477f916f537a34d
SHA256: f60b33b38e9d7ac93eaaa68a6c70f706bb99036494b2e2add2bfee11d09ac6f5
Evidence Type Source Name Value Confidence Vendor file name jsoup High Vendor jar package name jsoup Highest Vendor jar package name org Highest Vendor jar package name parser Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://jsoup.org/ Low Vendor Manifest bundle-symbolicname org.jsoup Medium Vendor Manifest Implementation-Vendor Jonathan Hedley High Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor pom artifactid jsoup Low Vendor pom developer email jonathan@hedley.net Low Vendor pom developer id jhy Medium Vendor pom developer name Jonathan Hedley Medium Vendor pom groupid org.jsoup Highest Vendor pom name jsoup Java HTML Parser High Vendor pom organization name Jonathan Hedley High Vendor pom organization url https://jhy.io/ Medium Vendor pom url https://jsoup.org/ Highest Product file name jsoup High Product jar package name 9 Highest Product jar package name jsoup Highest Product jar package name org Highest Product jar package name parser Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://jsoup.org/ Low Product Manifest Bundle-Name jsoup Java HTML Parser Medium Product Manifest bundle-symbolicname org.jsoup Medium Product Manifest Implementation-Title jsoup Java HTML Parser High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product pom artifactid jsoup Highest Product pom developer email jonathan@hedley.net Low Product pom developer id jhy Low Product pom developer name Jonathan Hedley Low Product pom groupid org.jsoup Highest Product pom name jsoup Java HTML Parser High Product pom organization name Jonathan Hedley Low Product pom organization url https://jhy.io/ Low Product pom url https://jsoup.org/ Medium Version file version 1.17.2 High Version Manifest Bundle-Version 1.17.2 High Version Manifest Implementation-Version 1.17.2 High Version pom version 1.17.2 Highest
junit-jupiter-5.13.4.jarDescription:
Module "junit-jupiter" of JUnit 5. License:
Eclipse Public License v2.0: https://www.eclipse.org/legal/epl-v20.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/jupiter/junit-jupiter/5.13.4/junit-jupiter-5.13.4.jar
MD5: 3f4e38bdbea73c98a50f08b7c6e33426
SHA1: 93547b3eca48a61f65f735c1898d3ec196e34149
SHA256: b960f79217dd01c863031b678f07df4730bbf1eac650c74ad6b0c61faad78379
Evidence Type Source Name Value Confidence Vendor file name junit-jupiter High Vendor Manifest build-date 2025-07-21 Low Vendor Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Vendor Manifest build-time 08:57:57.538+0200 Low Vendor Manifest bundle-symbolicname junit-jupiter Medium Vendor Manifest Implementation-Vendor junit.org High Vendor Manifest specification-vendor junit.org Low Vendor pom artifactid junit-jupiter Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email derancourt.juliette@gmail.com Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email sormuras@gmail.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id juliette-derancourt Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer id sormuras Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Juliette de Rancourt Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.junit.jupiter Highest Vendor pom name JUnit Jupiter (Aggregator) High Vendor pom url https://junit.org/ Highest Product file name junit-jupiter High Product Manifest build-date 2025-07-21 Low Product Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Product Manifest build-time 08:57:57.538+0200 Low Product Manifest Bundle-Name JUnit Jupiter (Aggregator) Medium Product Manifest bundle-symbolicname junit-jupiter Medium Product Manifest Implementation-Title junit-jupiter High Product Manifest specification-title junit-jupiter Medium Product pom artifactid junit-jupiter Highest Product pom developer email business@johanneslink.net Low Product pom developer email derancourt.juliette@gmail.com Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email sormuras@gmail.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id juliette-derancourt Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer id sormuras Low Product pom developer name Christian Stein Low Product pom developer name Johannes Link Low Product pom developer name Juliette de Rancourt Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.junit.jupiter Highest Product pom name JUnit Jupiter (Aggregator) High Product pom url https://junit.org/ Medium Version file version 5.13.4 High Version Manifest Bundle-Version 5.13.4 High Version Manifest Implementation-Version 5.13.4 High Version pom version 5.13.4 Highest
pkg:maven/org.junit.jupiter/junit-jupiter@5.13.4 (Confidence :High) junit-jupiter-api-5.13.4.jarDescription:
Module "junit-jupiter-api" of JUnit 5. License:
Eclipse Public License v2.0: https://www.eclipse.org/legal/epl-v20.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/jupiter/junit-jupiter-api/5.13.4/junit-jupiter-api-5.13.4.jar
MD5: d9981621212d598a4ba380342094c92f
SHA1: 2817f736551fe4949b79924715ef6f594ee072f4
SHA256: d1bb81abfd9e03418306b4e6a3390c8db52c58372e749c2980ac29f0c08278f1
Evidence Type Source Name Value Confidence Vendor file name junit-jupiter-api High Vendor jar package name api Highest Vendor jar package name junit Highest Vendor jar package name jupiter Highest Vendor Manifest build-date 2025-07-21 Low Vendor Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Vendor Manifest build-time 08:57:57.538+0200 Low Vendor Manifest bundle-symbolicname junit-jupiter-api Medium Vendor Manifest Implementation-Vendor junit.org High Vendor Manifest specification-vendor junit.org Low Vendor pom artifactid junit-jupiter-api Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email derancourt.juliette@gmail.com Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email sormuras@gmail.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id juliette-derancourt Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer id sormuras Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Juliette de Rancourt Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.junit.jupiter Highest Vendor pom name JUnit Jupiter API High Vendor pom url https://junit.org/ Highest Product file name junit-jupiter-api High Product jar package name api Highest Product jar package name junit Highest Product jar package name jupiter Highest Product Manifest build-date 2025-07-21 Low Product Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Product Manifest build-time 08:57:57.538+0200 Low Product Manifest Bundle-Name JUnit Jupiter API Medium Product Manifest bundle-symbolicname junit-jupiter-api Medium Product Manifest Implementation-Title junit-jupiter-api High Product Manifest specification-title junit-jupiter-api Medium Product pom artifactid junit-jupiter-api Highest Product pom developer email business@johanneslink.net Low Product pom developer email derancourt.juliette@gmail.com Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email sormuras@gmail.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id juliette-derancourt Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer id sormuras Low Product pom developer name Christian Stein Low Product pom developer name Johannes Link Low Product pom developer name Juliette de Rancourt Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.junit.jupiter Highest Product pom name JUnit Jupiter API High Product pom url https://junit.org/ Medium Version file version 5.13.4 High Version Manifest Bundle-Version 5.13.4 High Version Manifest Implementation-Version 5.13.4 High Version pom version 5.13.4 Highest
pkg:maven/org.junit.jupiter/junit-jupiter-api@5.13.4 (Confidence :High) junit-jupiter-engine-5.13.4.jarDescription:
Module "junit-jupiter-engine" of JUnit 5. License:
Eclipse Public License v2.0: https://www.eclipse.org/legal/epl-v20.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/jupiter/junit-jupiter-engine/5.13.4/junit-jupiter-engine-5.13.4.jar
MD5: 3416ff6cff3dd4ea789b92338a49b9b2
SHA1: d29fc8b6a28d21b8741f299ae4deb3e3aa68b2e8
SHA256: 027404a92fe618b72465792a257951495c503a7d5751e2791e0f51c87f67f5bc
Evidence Type Source Name Value Confidence Vendor file name junit-jupiter-engine High Vendor jar package name engine Highest Vendor jar package name junit Highest Vendor jar package name jupiter Highest Vendor Manifest build-date 2025-07-21 Low Vendor Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Vendor Manifest build-time 08:57:57.538+0200 Low Vendor Manifest bundle-symbolicname junit-jupiter-engine Medium Vendor Manifest Implementation-Vendor junit.org High Vendor Manifest provide-capability org.junit.platform.engine;org.junit.platform.engine=junit-jupiter;version:Version="5.13.4" Low Vendor Manifest specification-vendor junit.org Low Vendor pom artifactid junit-jupiter-engine Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email derancourt.juliette@gmail.com Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email sormuras@gmail.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id juliette-derancourt Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer id sormuras Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Juliette de Rancourt Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.junit.jupiter Highest Vendor pom name JUnit Jupiter Engine High Vendor pom url https://junit.org/ Highest Product file name junit-jupiter-engine High Product jar package name engine Highest Product jar package name junit Highest Product jar package name jupiter Highest Product Manifest build-date 2025-07-21 Low Product Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Product Manifest build-time 08:57:57.538+0200 Low Product Manifest Bundle-Name JUnit Jupiter Engine Medium Product Manifest bundle-symbolicname junit-jupiter-engine Medium Product Manifest Implementation-Title junit-jupiter-engine High Product Manifest provide-capability org.junit.platform.engine;org.junit.platform.engine=junit-jupiter;version:Version="5.13.4" Low Product Manifest specification-title junit-jupiter-engine Medium Product pom artifactid junit-jupiter-engine Highest Product pom developer email business@johanneslink.net Low Product pom developer email derancourt.juliette@gmail.com Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email sormuras@gmail.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id juliette-derancourt Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer id sormuras Low Product pom developer name Christian Stein Low Product pom developer name Johannes Link Low Product pom developer name Juliette de Rancourt Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.junit.jupiter Highest Product pom name JUnit Jupiter Engine High Product pom url https://junit.org/ Medium Version file version 5.13.4 High Version Manifest Bundle-Version 5.13.4 High Version Manifest Implementation-Version 5.13.4 High Version pom version 5.13.4 Highest
pkg:maven/org.junit.jupiter/junit-jupiter-engine@5.13.4 (Confidence :High) junit-jupiter-params-5.13.4.jarDescription:
Module "junit-jupiter-params" of JUnit 5. License:
Eclipse Public License v2.0: https://www.eclipse.org/legal/epl-v20.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/jupiter/junit-jupiter-params/5.13.4/junit-jupiter-params-5.13.4.jar
MD5: a1db21cc54b627a085918626a3908c9e
SHA1: 0c8930eb7fcfbed0b191703ab53f48475a75bd17
SHA256: 3a8c6365716dbb698c0d49a05456c1e1ad05c406613c550f9dd50037872efc41
Evidence Type Source Name Value Confidence Vendor file name junit-jupiter-params High Vendor jar package name junit Highest Vendor jar package name jupiter Highest Vendor jar package name params Highest Vendor Manifest build-date 2025-07-21 Low Vendor Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Vendor Manifest build-time 08:57:57.538+0200 Low Vendor Manifest bundle-symbolicname junit-jupiter-params Medium Vendor Manifest Implementation-Vendor junit.org High Vendor Manifest specification-vendor junit.org Low Vendor pom artifactid junit-jupiter-params Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email derancourt.juliette@gmail.com Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email sormuras@gmail.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id juliette-derancourt Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer id sormuras Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Juliette de Rancourt Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.junit.jupiter Highest Vendor pom name JUnit Jupiter Params High Vendor pom url https://junit.org/ Highest Product file name junit-jupiter-params High Product jar package name junit Highest Product jar package name jupiter Highest Product jar package name params Highest Product Manifest build-date 2025-07-21 Low Product Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Product Manifest build-time 08:57:57.538+0200 Low Product Manifest Bundle-Name JUnit Jupiter Params Medium Product Manifest bundle-symbolicname junit-jupiter-params Medium Product Manifest Implementation-Title junit-jupiter-params High Product Manifest specification-title junit-jupiter-params Medium Product pom artifactid junit-jupiter-params Highest Product pom developer email business@johanneslink.net Low Product pom developer email derancourt.juliette@gmail.com Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email sormuras@gmail.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id juliette-derancourt Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer id sormuras Low Product pom developer name Christian Stein Low Product pom developer name Johannes Link Low Product pom developer name Juliette de Rancourt Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.junit.jupiter Highest Product pom name JUnit Jupiter Params High Product pom url https://junit.org/ Medium Version file version 5.13.4 High Version Manifest Bundle-Version 5.13.4 High Version Manifest Implementation-Version 5.13.4 High Version pom version 5.13.4 Highest
pkg:maven/org.junit.jupiter/junit-jupiter-params@5.13.4 (Confidence :High) junit-platform-engine-1.13.4.jarDescription:
Module "junit-platform-engine" of JUnit 5. License:
Eclipse Public License v2.0: https://www.eclipse.org/legal/epl-v20.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/platform/junit-platform-engine/1.13.4/junit-platform-engine-1.13.4.jar
MD5: 736aa9e83f7ba2b54adb5f86821fd4dd
SHA1: cdd49063ae6e25494d1a9a08f4a9ab5de2b73bcb
SHA256: 390c5f77b84283a64b644f88251b397e0b0debb80bdcc50f899881aecff43a5a
Evidence Type Source Name Value Confidence Vendor file name junit-platform-engine High Vendor jar package name engine Highest Vendor jar package name junit Highest Vendor jar package name platform Highest Vendor Manifest build-date 2025-07-21 Low Vendor Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Vendor Manifest build-time 08:57:57.538+0200 Low Vendor Manifest bundle-symbolicname junit-platform-engine Medium Vendor Manifest Implementation-Vendor junit.org High Vendor Manifest specification-vendor junit.org Low Vendor pom artifactid junit-platform-engine Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email derancourt.juliette@gmail.com Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email sormuras@gmail.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id juliette-derancourt Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer id sormuras Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Juliette de Rancourt Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.junit.platform Highest Vendor pom name JUnit Platform Engine API High Vendor pom url https://junit.org/ Highest Product file name junit-platform-engine High Product jar package name engine Highest Product jar package name junit Highest Product jar package name platform Highest Product Manifest build-date 2025-07-21 Low Product Manifest build-revision 8a21048605e61dc388c1c83cbecf9dd5097a595d Low Product Manifest build-time 08:57:57.538+0200 Low Product Manifest Bundle-Name JUnit Platform Engine API Medium Product Manifest bundle-symbolicname junit-platform-engine Medium Product Manifest Implementation-Title junit-platform-engine High Product Manifest specification-title junit-platform-engine Medium Product pom artifactid junit-platform-engine Highest Product pom developer email business@johanneslink.net Low Product pom developer email derancourt.juliette@gmail.com Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email sormuras@gmail.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id juliette-derancourt Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer id sormuras Low Product pom developer name Christian Stein Low Product pom developer name Johannes Link Low Product pom developer name Juliette de Rancourt Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.junit.platform Highest Product pom name JUnit Platform Engine API High Product pom url https://junit.org/ Medium Version file version 1.13.4 High Version Manifest Bundle-Version 1.13.4 High Version Manifest Implementation-Version 1.13.4 High Version pom version 1.13.4 Highest
Related Dependencies junit-platform-commons-1.13.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/platform/junit-platform-commons/1.13.4/junit-platform-commons-1.13.4.jar MD5: 7c39b85780e5bec0a23408959ac83fa9 SHA1: 8f63c7ed05b473d95cc63d1082054d7bfcf9c0e5 SHA256: 1c25ca641ebaae44ff3ad21ca1b2ef68d0dd84bfeb07c4805ba7840899b77408 pkg:maven/org.junit.platform/junit-platform-commons@1.13.4 junit-platform-launcher-1.13.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/platform/junit-platform-launcher/1.13.4/junit-platform-launcher-1.13.4.jar MD5: bdfea9c8c038752c70631934b2067073 SHA1: e72a4d00af6177569fd57df4c8c4bb241c6aa4b6 SHA256: 0b0beaeb6880a31149641d2d848b863712885469670c12099586d7f798522564 pkg:maven/org.junit.platform/junit-platform-launcher@1.13.4 pkg:maven/org.junit.platform/junit-platform-engine@1.13.4 (Confidence :High) cpe:2.3:a:fan_platform_project:fan_platform:1.13.4:*:*:*:*:*:*:* (Confidence :Low) suppress junit-platform-engine-1.9.3.jarDescription:
Module "junit-platform-engine" of JUnit 5. License:
Eclipse Public License v2.0: https://www.eclipse.org/legal/epl-v20.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/platform/junit-platform-engine/1.9.3/junit-platform-engine-1.9.3.jar
MD5: 97839fdbdebfeabba70719f4d81d88c4
SHA1: 8616734a190f8d307376aeb7353dba0a2c037a09
SHA256: 0c39553d9a03510757227f5a1c6cc6530287b1a321ed6258450664874aa2a16a
Evidence Type Source Name Value Confidence Vendor file name junit-platform-engine High Vendor jar package name engine Highest Vendor jar package name junit Highest Vendor jar package name platform Highest Vendor Manifest build-date 2023-04-26 Low Vendor Manifest build-revision bd7d03f517dfca3730fbd123c5fd4d4b70930129 Low Vendor Manifest build-time 08:27:29.511+0200 Low Vendor Manifest bundle-symbolicname junit-platform-engine Medium Vendor Manifest Implementation-Vendor junit.org High Vendor Manifest specification-vendor junit.org Low Vendor pom artifactid junit-platform-engine Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email derancourt.juliette@gmail.com Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email sormuras@gmail.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id juliette-derancourt Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer id sormuras Medium Vendor pom developer name Christian Stein Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Juliette de Rancourt Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.junit.platform Highest Vendor pom name JUnit Platform Engine API High Vendor pom url https://junit.org/junit5/ Highest Product file name junit-platform-engine High Product jar package name engine Highest Product jar package name junit Highest Product jar package name platform Highest Product Manifest build-date 2023-04-26 Low Product Manifest build-revision bd7d03f517dfca3730fbd123c5fd4d4b70930129 Low Product Manifest build-time 08:27:29.511+0200 Low Product Manifest Bundle-Name JUnit Platform Engine API Medium Product Manifest bundle-symbolicname junit-platform-engine Medium Product Manifest Implementation-Title junit-platform-engine High Product Manifest specification-title junit-platform-engine Medium Product pom artifactid junit-platform-engine Highest Product pom developer email business@johanneslink.net Low Product pom developer email derancourt.juliette@gmail.com Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email sormuras@gmail.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id juliette-derancourt Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer id sormuras Low Product pom developer name Christian Stein Low Product pom developer name Johannes Link Low Product pom developer name Juliette de Rancourt Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.junit.platform Highest Product pom name JUnit Platform Engine API High Product pom url https://junit.org/junit5/ Medium Version file version 1.9.3 High Version Manifest Bundle-Version 1.9.3 High Version Manifest Implementation-Version 1.9.3 High Version pom version 1.9.3 Highest
Related Dependencies junit-platform-commons-1.9.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/platform/junit-platform-commons/1.9.3/junit-platform-commons-1.9.3.jar MD5: b604474c7be847bca1589ba61a8434e0 SHA1: 36b2e26a90c41603be7f0094bee80e3f8a2cd4d4 SHA256: 8519157df813c210e85fc1414b74109e3d85f43d7092563ed704c43c48f0d5e6 pkg:maven/org.junit.platform/junit-platform-commons@1.9.3 junit-platform-launcher-1.9.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/junit/platform/junit-platform-launcher/1.9.3/junit-platform-launcher-1.9.3.jar MD5: de8e8991e5781799453d60065f634e42 SHA1: 485650bfe2a2f39b606a6ca013285afda2eaee79 SHA256: 8515e91808a09c8c9af5e359185b5991b5e76b8adcf185b9a3dab4ec8e5ba8ff pkg:maven/org.junit.platform/junit-platform-launcher@1.9.3 pkg:maven/org.junit.platform/junit-platform-engine@1.9.3 (Confidence :High) cpe:2.3:a:fan_platform_project:fan_platform:1.9.3:*:*:*:*:*:*:* (Confidence :Low) suppress keycloak-client-common-synced-26.0.7.jarDescription:
Keycloak Client Common Synced File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/keycloak/keycloak-client-common-synced/26.0.7/keycloak-client-common-synced-26.0.7.jarMD5: 99422f2b1b494b85d4a232098639ae6fSHA1: ee4998aa57c2e49c450308b3859c64c535a47179SHA256: b4b1e29b62504bf1822a9885f88061efa4d31af49d86012ac43add69819daf51
Evidence Type Source Name Value Confidence Vendor file name keycloak-client-common-synced High Vendor hint analyzer vendor redhat Highest Vendor jar package name client Highest Vendor jar package name common Highest Vendor jar package name keycloak Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url https://keycloak.org/keycloak-client-common-synced Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid keycloak-client-common-synced Low Vendor pom groupid org.keycloak Highest Vendor pom name Keycloak Client Common Synced High Vendor pom parent-artifactid keycloak-client-parent Low Product file name keycloak-client-common-synced High Product jar package name client Highest Product jar package name common Highest Product jar package name keycloak Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Keycloak Client Common Synced High Product Manifest implementation-url https://keycloak.org/keycloak-client-common-synced Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Keycloak Client Common Synced Medium Product pom artifactid keycloak-client-common-synced Highest Product pom groupid org.keycloak Highest Product pom name Keycloak Client Common Synced High Product pom parent-artifactid keycloak-client-parent Medium Version file version 26.0.7 High Version Manifest Implementation-Version 26.0.7 High Version pom version 26.0.7 Highest
legacy.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/legacy/legacy.nomodule.jsMD5: 9361539a28868f7d0b2c550cc62a7a59SHA1: 719fa6978e60cdbebb6060b7a8fc3bcaf2eee883SHA256: d5da0303995acf3a35202bc13ffc94758a26ae71a01d14065746bb490868308a
Evidence Type Source Name Value Confidence
legacy.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/legacy/legacy.nomodule.min.jsMD5: 5a67d58bbb647d58fbc1e2d46a119b3aSHA1: 47ab7dc2bc9d08a4c41b4b00de171b842b1d7247SHA256: 936ff3368a427cbc6887879100925204f54f5cdf0d28ced1ccb41e4e6d5cf383
Evidence Type Source Name Value Confidence
lombok-1.18.42.jarDescription:
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more! License:
The MIT License: https://projectlombok.org/LICENSE File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/projectlombok/lombok/1.18.42/lombok-1.18.42.jar
MD5: f29149836e0187fb9fd95d82dc718d36
SHA1: 8365263844ebb62398e0dc33057ba10ba472d3b8
SHA256: 3488a4e9994c26596baaceebee58cad36a50e3bdaec5be72b5834d3c3b560306
Evidence Type Source Name Value Confidence Vendor file name lombok High Vendor jar package name java Highest Vendor jar package name lombok Highest Vendor jar package name tostring Highest Vendor Manifest automatic-module-name lombok Medium Vendor Manifest can-redefine-classes true Low Vendor pom artifactid lombok Low Vendor pom developer email reinier@projectlombok.org Low Vendor pom developer email roel@projectlombok.org Low Vendor pom developer id rspilker Medium Vendor pom developer id rzwitserloot Medium Vendor pom developer name Reinier Zwitserloot Medium Vendor pom developer name Roel Spilker Medium Vendor pom groupid org.projectlombok Highest Vendor pom name Project Lombok High Vendor pom url https://projectlombok.org Highest Product file name lombok High Product jar package name java Highest Product jar package name lombok Highest Product jar package name tostring Highest Product Manifest automatic-module-name lombok Medium Product Manifest can-redefine-classes true Low Product pom artifactid lombok Highest Product pom developer email reinier@projectlombok.org Low Product pom developer email roel@projectlombok.org Low Product pom developer id rspilker Low Product pom developer id rzwitserloot Low Product pom developer name Reinier Zwitserloot Low Product pom developer name Roel Spilker Low Product pom groupid org.projectlombok Highest Product pom name Project Lombok High Product pom url https://projectlombok.org Medium Version file version 1.18.42 High Version Manifest lombok-version 1.18.42 Medium Version pom version 1.18.42 Highest
pkg:maven/org.projectlombok/lombok@1.18.42 (Confidence :High) lombok-1.18.42.jar: mavenEcjBootstrapAgent.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/projectlombok/lombok/1.18.42/lombok-1.18.42.jar/lombok/launch/mavenEcjBootstrapAgent.jarMD5: 885d5d6be90a5dcd4b82cdf741e3f31aSHA1: e1f7f1779f40157fd0b984c1bc32a0cb45cae66eSHA256: 74a80a6ee84e5c6fe497dfcc46a46dbe30578525e747eb531e918ee0750c8da9
Evidence Type Source Name Value Confidence Vendor file name mavenEcjBootstrapAgent High Vendor jar package name launch Low Vendor jar package name lombok Low Vendor Manifest can-redefine-classes true Low Product file name mavenEcjBootstrapAgent High Product jar package name launch Low Product Manifest can-redefine-classes true Low
mapstruct-processor-1.6.3.jarDescription:
An annotation processor for generating type-safe bean mappers License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/mapstruct/mapstruct-processor/1.6.3/mapstruct-processor-1.6.3.jar
MD5: 6a092af2c0e165e8cb8997b9123393cb
SHA1: 52e345c907fbf173b376586c7f8b131d53fa5867
SHA256: 0305b6e2eee678974cde0c4e87e09d66926290b640173ec3ca5a81dedbc56bff
Evidence Type Source Name Value Confidence Vendor file name mapstruct-processor High Vendor jar package name mapstruct Highest Vendor jar package name org Highest Vendor jar package name processor Highest Vendor Manifest automatic-module-name org.mapstruct.processor Medium Vendor Manifest implementation-url https://mapstruct.org/mapstruct-processor/ Low Vendor Manifest Implementation-Vendor-Id org.mapstruct Medium Vendor Manifest spring-boot-jar-type annotation-processor Low Vendor pom artifactid mapstruct-processor Low Vendor pom developer email gunnar@mapstruct.org Low Vendor pom developer id filiphr Medium Vendor pom developer id gunnarmorling Medium Vendor pom developer name Filip Hrisafov Medium Vendor pom developer name Gunnar Morling Medium Vendor pom groupid org.mapstruct Highest Vendor pom name MapStruct Processor High Vendor pom parent-artifactid mapstruct-parent Low Vendor pom url https://mapstruct.org/mapstruct-processor/ Highest Product file name mapstruct-processor High Product jar package name mapstruct Highest Product jar package name org Highest Product jar package name processor Highest Product Manifest automatic-module-name org.mapstruct.processor Medium Product Manifest Implementation-Title MapStruct Processor High Product Manifest implementation-url https://mapstruct.org/mapstruct-processor/ Low Product Manifest spring-boot-jar-type annotation-processor Low Product pom artifactid mapstruct-processor Highest Product pom developer email gunnar@mapstruct.org Low Product pom developer id filiphr Low Product pom developer id gunnarmorling Low Product pom developer name Filip Hrisafov Low Product pom developer name Gunnar Morling Low Product pom groupid org.mapstruct Highest Product pom name MapStruct Processor High Product pom parent-artifactid mapstruct-parent Medium Product pom url https://mapstruct.org/mapstruct-processor/ Medium Version file version 1.6.3 High Version Manifest Implementation-Version 1.6.3 High Version pom version 1.6.3 Highest
pkg:maven/org.mapstruct/mapstruct-processor@1.6.3 (Confidence :High) maven-antrun-plugin-3.1.0.jarDescription:
Runs Ant scripts embedded in the POM File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-antrun-plugin/3.1.0/maven-antrun-plugin-3.1.0.jarMD5: 2c07943675c06289f5ba11db82c2c24dSHA1: d4c0e1e9e814f5a705b81f8117d9753719d670c7SHA256: 8ae8f570b8f4ea46fa7f3df27f22ce4c6b6c1f387a6eaeefae6c896aebae1455
Evidence Type Source Name Value Confidence Vendor file name maven-antrun-plugin High Vendor jar package name ant Highest Vendor jar package name antrun Highest Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-antrun-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven AntRun Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-antrun-plugin High Product jar package name ant Highest Product jar package name antrun Highest Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven AntRun Plugin High Product Manifest specification-title Apache Maven AntRun Plugin Medium Product pom artifactid maven-antrun-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven AntRun Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
maven-api-meta-4.0.0-alpha-7.jarDescription:
Java annotations for Maven 4 Immutable API. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-api-meta/4.0.0-alpha-7/maven-api-meta-4.0.0-alpha-7.jarMD5: 0571b58631234946491bc5f7a91d8c74SHA1: db4b391f5341ef940fb3a79060865b7edda6c6d5SHA256: c4f6f3868f5b280cc7e268f0f95e1bb1d2a824afe92a8029e861be7ec48b1272
Evidence Type Source Name Value Confidence Vendor file name maven-api-meta High Vendor jar package name annotations Highest Vendor jar package name apache Highest Vendor jar package name api Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-api-meta Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven 4 API Meta annotations High Vendor pom parent-artifactid maven-api Low Product file name maven-api-meta High Product jar package name annotations Highest Product jar package name apache Highest Product jar package name api Highest Product jar package name maven Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Maven 4 API Meta annotations High Product Manifest specification-title Maven 4 API Meta annotations Medium Product pom artifactid maven-api-meta Highest Product pom groupid org.apache.maven Highest Product pom name Maven 4 API Meta annotations High Product pom parent-artifactid maven-api Medium Version Manifest Implementation-Version 4.0.0-alpha-7 High Version pom version 4.0.0-alpha-7 Highest
pkg:maven/org.apache.maven/maven-api-meta@4.0.0-alpha-7 (Confidence :High) maven-api-xml-4.0.0-alpha-7.jarDescription:
Maven 4 API immutable XML helper. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-api-xml/4.0.0-alpha-7/maven-api-xml-4.0.0-alpha-7.jarMD5: eaa62eb9c8cf3e767bdc81991079aae6SHA1: ae85bf0c76a6b868058af3e0ec89c78d9acd4effSHA256: 3388f4d0465f5a7e9a6264baf506da1b052c51f7cc10b7ce73f09723e6cf1d92
Evidence Type Source Name Value Confidence Vendor file name maven-api-xml High Vendor jar package name apache Highest Vendor jar package name api Highest Vendor jar package name maven Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-api-xml Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven 4 API XML High Vendor pom parent-artifactid maven-api Low Product file name maven-api-xml High Product jar package name apache Highest Product jar package name api Highest Product jar package name maven Highest Product jar package name xml Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Maven 4 API XML High Product Manifest specification-title Maven 4 API XML Medium Product pom artifactid maven-api-xml Highest Product pom groupid org.apache.maven Highest Product pom name Maven 4 API XML High Product pom parent-artifactid maven-api Medium Version Manifest Implementation-Version 4.0.0-alpha-7 High Version pom version 4.0.0-alpha-7 Highest
pkg:maven/org.apache.maven/maven-api-xml@4.0.0-alpha-7 (Confidence :High) maven-archiver-3.6.0.jarDescription:
Provides utility methods for creating JARs and other archive files from a Maven project. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-archiver/3.6.0/maven-archiver-3.6.0.jarMD5: b12cc59931ba53459a09e12db692b55dSHA1: 0a7cc4e331cd64ad9cfd049b661e89b3065ce1b8SHA256: 020221526ffc406d04c2ba5913a4201c55635a620302bdecc7de400e3681a754
Evidence Type Source Name Value Confidence Vendor file name maven-archiver High Vendor jar package name apache Highest Vendor jar package name archiver Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-archiver Low Vendor pom groupid org.apache.maven Highest Vendor pom name Apache Maven Archiver High Vendor pom parent-artifactid maven-shared-components Low Vendor pom parent-groupid org.apache.maven.shared Medium Product file name maven-archiver High Product jar package name apache Highest Product jar package name archiver Highest Product jar package name maven Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Archiver High Product Manifest specification-title Apache Maven Archiver Medium Product pom artifactid maven-archiver Highest Product pom groupid org.apache.maven Highest Product pom name Apache Maven Archiver High Product pom parent-artifactid maven-shared-components Medium Product pom parent-groupid org.apache.maven.shared Medium Version file version 3.6.0 High Version Manifest Implementation-Version 3.6.0 High Version pom parent-version 3.6.0 Low Version pom version 3.6.0 Highest
pkg:maven/org.apache.maven/maven-archiver@3.6.0 (Confidence :High) maven-artifact-3.9.12.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-artifact/3.9.12/maven-artifact-3.9.12.jarMD5: d834fe188642d22ce7318e6af0a605ddSHA1: 39acdd4ad6b74b1c001ae7c0858482a11d0ead59SHA256: 4361cecd7e863c0992a6c901202afbb6db2a06b4f9a5e4b22481d4d39bcf137c
Evidence Type Source Name Value Confidence Vendor file name maven-artifact High Vendor jar package name apache Highest Vendor jar package name artifact Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-artifact Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Artifact High Vendor pom parent-artifactid maven Low Product file name maven-artifact High Product jar package name apache Highest Product jar package name artifact Highest Product jar package name maven Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Artifact High Product Manifest specification-title Maven Artifact Medium Product pom artifactid maven-artifact Highest Product pom groupid org.apache.maven Highest Product pom name Maven Artifact High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-artifact@3.9.12 (Confidence :High) maven-assembly-plugin-3.6.0.jarDescription:
A Maven plugin to create archives of your project's sources, classes, dependencies etc. from flexible assembly descriptors. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-assembly-plugin/3.6.0/maven-assembly-plugin-3.6.0.jarMD5: 719c7e8e641afa114e9078ef2420045bSHA1: 5398ecbe94c874042cb5f6f683e723306f51a625SHA256: 53c887c082345b07dfe486b08cc805126c62fe863a027ce696db60428f4ab47c
Evidence Type Source Name Value Confidence Vendor file name maven-assembly-plugin High Vendor jar package name apache Highest Vendor jar package name assembly Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-assembly-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Assembly Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-assembly-plugin High Product jar package name apache Highest Product jar package name assembly Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Assembly Plugin High Product Manifest specification-title Apache Maven Assembly Plugin Medium Product pom artifactid maven-assembly-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Assembly Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.6.0 High Version Manifest Implementation-Version 3.6.0 High Version pom parent-version 3.6.0 Low Version pom version 3.6.0 Highest
pkg:maven/org.apache.maven.plugins/maven-assembly-plugin@3.6.0 (Confidence :High) maven-builder-support-3.9.12.jarDescription:
Support for descriptor builders (model, setting, toolchains) File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-builder-support/3.9.12/maven-builder-support-3.9.12.jarMD5: 6afaba813236d781c7b3865f9fab3a44SHA1: fe2fe54522eb2f77bd9b30cefc959d728d3f8105SHA256: 22a0345c7a90dbe7758209d52135967daa8aae6543c7016cb635891b0eceeed4
Evidence Type Source Name Value Confidence Vendor file name maven-builder-support High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-builder-support Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Builder Support High Vendor pom parent-artifactid maven Low Product file name maven-builder-support High Product jar package name apache Highest Product jar package name maven Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Builder Support High Product Manifest specification-title Maven Builder Support Medium Product pom artifactid maven-builder-support Highest Product pom groupid org.apache.maven Highest Product pom name Maven Builder Support High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-builder-support@3.9.12 (Confidence :High) maven-clean-plugin-3.2.0.jarDescription:
The Maven Clean Plugin is a plugin that removes files generated at build-time in a project's directory.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-clean-plugin/3.2.0/maven-clean-plugin-3.2.0.jarMD5: 001d7cf439e67c15577412c936111278SHA1: 556f5c71be8788c70a94a43d66af7fe35acee21fSHA256: b657bef2e1eb11e029a70cd688bde6adad29e4e99dacb18516bf651ecca32435
Evidence Type Source Name Value Confidence Vendor file name maven-clean-plugin High Vendor jar package name apache Highest Vendor jar package name clean Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-clean-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Clean Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-clean-plugin High Product jar package name apache Highest Product jar package name clean Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 11 Low Product Manifest Implementation-Title Apache Maven Clean Plugin High Product Manifest specification-title Apache Maven Clean Plugin Medium Product pom artifactid maven-clean-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Clean Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.2.0 High Version Manifest Implementation-Version 3.2.0 High Version pom parent-version 3.2.0 Low Version pom version 3.2.0 Highest
pkg:maven/org.apache.maven.plugins/maven-clean-plugin@3.2.0 (Confidence :High) maven-common-artifact-filters-3.1.1.jarDescription:
A collection of ready-made filters to control inclusion/exclusion of artifacts during dependency resolution. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/shared/maven-common-artifact-filters/3.1.1/maven-common-artifact-filters-3.1.1.jarMD5: bbafdd6747cc103b96bbff6dc06f9124SHA1: 044f7d167891f281160764ef1a687dcf487d3a2cSHA256: 4a8eea7663992e49206d9f928138f334a835ad3fbbc40929342ef007ccf5471b
Evidence Type Source Name Value Confidence Vendor file name maven-common-artifact-filters High Vendor jar package name apache Highest Vendor jar package name artifact Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-common-artifact-filters Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Common Artifact Filters High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-common-artifact-filters High Product jar package name apache Highest Product jar package name artifact Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest build-jdk-spec 11 Low Product Manifest Implementation-Title Apache Maven Common Artifact Filters High Product Manifest specification-title Apache Maven Common Artifact Filters Medium Product pom artifactid maven-common-artifact-filters Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Common Artifact Filters High Product pom parent-artifactid maven-shared-components Medium Version file version 3.1.1 High Version Manifest Implementation-Version 3.1.1 High Version pom parent-version 3.1.1 Low Version pom version 3.1.1 Highest
pkg:maven/org.apache.maven.shared/maven-common-artifact-filters@3.1.1 (Confidence :High) maven-compiler-plugin-3.14.0.jarDescription:
The Compiler Plugin is used to compile the sources of your project. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-compiler-plugin/3.14.0/maven-compiler-plugin-3.14.0.jarMD5: d126f464338b2ff99b825de0f4a4a2faSHA1: 8da644b4b26eb34e626ad9482a884a89e6657901SHA256: e55fe35b95cf499e5092f146c6613984cff896a8947c2f347ab88270f11acb76
Evidence Type Source Name Value Confidence Vendor file name maven-compiler-plugin High Vendor jar package name apache Highest Vendor jar package name compiler Highest Vendor jar package name maven Highest Vendor jar package name plugin Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-compiler-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Compiler Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-compiler-plugin High Product jar package name apache Highest Product jar package name compiler Highest Product jar package name maven Highest Product jar package name plugin Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Apache Maven Compiler Plugin High Product Manifest specification-title Apache Maven Compiler Plugin Medium Product pom artifactid maven-compiler-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Compiler Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.14.0 High Version Manifest Implementation-Version 3.14.0 High Version pom parent-version 3.14.0 Low Version pom version 3.14.0 Highest
pkg:maven/org.apache.maven.plugins/maven-compiler-plugin@3.14.0 (Confidence :High) maven-core-3.9.12.jarDescription:
Maven Core classes. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-core/3.9.12/maven-core-3.9.12.jarMD5: 5988619119b33562228343c4ded75b9eSHA1: a349a9dadebca9f2a2d1f99876f651a02961a366SHA256: 1ee217c759a895771a07a2018c026bba01373305d9bad0099f06dbbdbcf2c332
Evidence Type Source Name Value Confidence Vendor file name maven-core High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-core Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Core High Vendor pom parent-artifactid maven Low Product file name maven-core High Product jar package name apache Highest Product jar package name maven Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Core High Product Manifest specification-title Maven Core Medium Product pom artifactid maven-core Highest Product pom groupid org.apache.maven Highest Product pom name Maven Core High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
maven-dependency-plugin-3.6.1.jarDescription:
Provides utility goals to work with dependencies like copying, unpacking, analyzing, resolving and many more. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-dependency-plugin/3.6.1/maven-dependency-plugin-3.6.1.jarMD5: 69dc0f7f4ec84a2940916509d5c3480dSHA1: 7d6cba536d202a0680cf674ff7fda94dc40f3a5eSHA256: da6a0ed58ab849b0de0fd9a676b17726a3cdb0e87e86a4a90b5287878912279a
Evidence Type Source Name Value Confidence Vendor file name maven-dependency-plugin High Vendor jar package name apache Highest Vendor jar package name dependency Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-dependency-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Dependency Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-dependency-plugin High Product jar package name apache Highest Product jar package name dependency Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Dependency Plugin High Product Manifest specification-title Apache Maven Dependency Plugin Medium Product pom artifactid maven-dependency-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Dependency Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.6.1 High Version Manifest Implementation-Version 3.6.1 High Version pom parent-version 3.6.1 Low Version pom version 3.6.1 Highest
pkg:maven/org.apache.maven.plugins/maven-dependency-plugin@3.6.1 (Confidence :High) maven-deploy-plugin-3.1.1.jarDescription:
Uploads the project artifacts to the internal remote repository. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-deploy-plugin/3.1.1/maven-deploy-plugin-3.1.1.jarMD5: ff117d599c98db969f3d75a816cbc26fSHA1: 05fe43502757269d4934cbda35e5e74399187286SHA256: c7c973af372dadb83c41e760a86af98b6291150ecdd235319c2a3635b85383ff
Evidence Type Source Name Value Confidence Vendor file name maven-deploy-plugin High Vendor jar package name apache Highest Vendor jar package name deploy Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-deploy-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Deploy Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-deploy-plugin High Product jar package name apache Highest Product jar package name deploy Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Deploy Plugin High Product Manifest specification-title Apache Maven Deploy Plugin Medium Product pom artifactid maven-deploy-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Deploy Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.1.1 High Version Manifest Implementation-Version 3.1.1 High Version pom parent-version 3.1.1 Low Version pom version 3.1.1 Highest
pkg:maven/org.apache.maven.plugins/maven-deploy-plugin@3.1.1 (Confidence :High) maven-embedder-3.9.12.jarDescription:
Maven embeddable component, with CLI and logging support. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-embedder/3.9.12/maven-embedder-3.9.12.jarMD5: b270f033fb844a10af9c6528e3b352d7SHA1: dea388fd5b198516175443c098ea1e8d6c2d8bb5SHA256: 8cd71547431f8a908345869c5884ddae51cf3acba8d4592ea19d3b844563d345
Evidence Type Source Name Value Confidence Vendor file name maven-embedder High Vendor jar package name apache Highest Vendor jar package name cli Highest Vendor jar package name logging Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-embedder Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Embedder High Vendor pom parent-artifactid maven Low Product file name maven-embedder High Product jar package name apache Highest Product jar package name cli Highest Product jar package name logging Highest Product jar package name maven Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Embedder High Product Manifest specification-title Maven Embedder Medium Product pom artifactid maven-embedder Highest Product pom groupid org.apache.maven Highest Product pom name Maven Embedder High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-embedder@3.9.12 (Confidence :High) maven-filtering-3.3.1.jarDescription:
A component to assist in filtering of resource files with properties from a Maven project. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/shared/maven-filtering/3.3.1/maven-filtering-3.3.1.jarMD5: 81f9ea936b2b3c12899901fe0999348bSHA1: 7b613072bcce1d949b6d82f714af08b4535aae2bSHA256: b12663187d9ffc6a1ee76139c0ef497fe9400efbe2ebe01616fe2703656fb4f0
Evidence Type Source Name Value Confidence Vendor file name maven-filtering High Vendor jar package name apache Highest Vendor jar package name filtering Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-filtering Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Filtering High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-filtering High Product jar package name apache Highest Product jar package name filtering Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Filtering High Product Manifest specification-title Apache Maven Filtering Medium Product pom artifactid maven-filtering Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Filtering High Product pom parent-artifactid maven-shared-components Medium Version file version 3.3.1 High Version Manifest Implementation-Version 3.3.1 High Version pom parent-version 3.3.1 Low Version pom version 3.3.1 Highest
pkg:maven/org.apache.maven.shared/maven-filtering@3.3.1 (Confidence :High) maven-help-plugin-3.5.1.jarDescription:
The Maven Help plugin provides goals aimed at helping to make sense out of
the build environment. It includes the ability to view the effective
POM and settings files, after inheritance and active profiles
have been applied, as well as a describe a particular plugin goal to give usage information. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-help-plugin/3.5.1/maven-help-plugin-3.5.1.jarMD5: 0916cef032bdc95cdecc1f507ccf13ceSHA1: 3a6e526788e0564766f44d31b677648a7d9207efSHA256: db1296f90c93cd1ac763f8262674dc376cf7670166dc2c270a498b1141a51865
Evidence Type Source Name Value Confidence Vendor file name maven-help-plugin High Vendor jar package name apache Highest Vendor jar package name help Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-help-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Help Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-help-plugin High Product jar package name apache Highest Product jar package name help Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Help Plugin High Product Manifest specification-title Apache Maven Help Plugin Medium Product pom artifactid maven-help-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Help Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.5.1 High Version Manifest Implementation-Version 3.5.1 High Version pom parent-version 3.5.1 Low Version pom version 3.5.1 Highest
pkg:maven/org.apache.maven.plugins/maven-help-plugin@3.5.1 (Confidence :High) maven-install-plugin-3.1.1.jarDescription:
Copies the project artifacts to the user's local repository. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-install-plugin/3.1.1/maven-install-plugin-3.1.1.jarMD5: 82c003d21a28f7ae89e89f2bff8bbb3aSHA1: 011abc20d7e1ee82e6cb55e2a03f405cd97325b6SHA256: 6bf2f4a06369f599818c5cee1d5ed957b7caf4aa0003b9867ad5525f8bca8086
Evidence Type Source Name Value Confidence Vendor file name maven-install-plugin High Vendor jar package name apache Highest Vendor jar package name install Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-install-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Install Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-install-plugin High Product jar package name apache Highest Product jar package name install Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Install Plugin High Product Manifest specification-title Apache Maven Install Plugin Medium Product pom artifactid maven-install-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Install Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.1.1 High Version Manifest Implementation-Version 3.1.1 High Version pom parent-version 3.1.1 Low Version pom version 3.1.1 Highest
pkg:maven/org.apache.maven.plugins/maven-install-plugin@3.1.1 (Confidence :High) maven-jar-plugin-3.3.0.jarDescription:
Builds a Java Archive (JAR) file from the compiled project classes and resources. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-jar-plugin/3.3.0/maven-jar-plugin-3.3.0.jarMD5: 86757837fbad6c11499131998fd31e01SHA1: 21829ae5feec95ae6fec425f2d85bbbfe49880c4SHA256: 17edc5d0289dc0a9b61bd5db15fdb5804b5fb73d7dbe458771e33fbc1d51fa94
Evidence Type Source Name Value Confidence Vendor file name maven-jar-plugin High Vendor jar package name apache Highest Vendor jar package name jar Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-jar-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven JAR Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-jar-plugin High Product jar package name apache Highest Product jar package name jar Highest Product jar package name maven Highest Product jar package name plugins Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven JAR Plugin High Product Manifest specification-title Apache Maven JAR Plugin Medium Product pom artifactid maven-jar-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven JAR Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.3.0 High Version Manifest Implementation-Version 3.3.0 High Version pom parent-version 3.3.0 Low Version pom version 3.3.0 Highest
pkg:maven/org.apache.maven.plugins/maven-jar-plugin@3.3.0 (Confidence :High) maven-model-3.9.12.jarDescription:
Model for Maven POM (Project Object Model) File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-model/3.9.12/maven-model-3.9.12.jarMD5: 2eca810310f90f79e048265eb29165b9SHA1: 6f91cb0e47b7fc6db492ed307b0c91b38bfce924SHA256: d443a20cb801a7f116e10a80dd1ebf7aaae7182880d1097e0681d498c45e168b
Evidence Type Source Name Value Confidence Vendor file name maven-model High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name model Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-model Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Model High Vendor pom parent-artifactid maven Low Product file name maven-model High Product jar package name apache Highest Product jar package name maven Highest Product jar package name model Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Model High Product Manifest specification-title Maven Model Medium Product pom artifactid maven-model Highest Product pom groupid org.apache.maven Highest Product pom name Maven Model High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-model@3.9.12 (Confidence :High) maven-model-builder-3.9.12.jarDescription:
The effective model builder, with inheritance, profile activation, interpolation, ... File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-model-builder/3.9.12/maven-model-builder-3.9.12.jarMD5: 8d8d8278aeb6a462ce3421a5d1b7d7d5SHA1: c1a74479d447e70d98ed5f03f6b32d54818ca046SHA256: 1cb12b9e51b9855599dd1d02e77f08ff88772e9d4b4a7c4ee1e5d7a4f2b9b9ea
Evidence Type Source Name Value Confidence Vendor file name maven-model-builder High Vendor jar package name apache Highest Vendor jar package name inheritance Highest Vendor jar package name interpolation Highest Vendor jar package name maven Highest Vendor jar package name model Highest Vendor jar package name profile Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-model-builder Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Model Builder High Vendor pom parent-artifactid maven Low Product file name maven-model-builder High Product jar package name apache Highest Product jar package name inheritance Highest Product jar package name interpolation Highest Product jar package name maven Highest Product jar package name model Highest Product jar package name profile Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Model Builder High Product Manifest specification-title Maven Model Builder Medium Product pom artifactid maven-model-builder Highest Product pom groupid org.apache.maven Highest Product pom name Maven Model Builder High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-model-builder@3.9.12 (Confidence :High) maven-model-helper-37.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/fabric8/maven-model-helper/37/maven-model-helper-37.jarMD5: ba228c5d8c44211e1455465fb4ae42ccSHA1: 050eb2d61bf9dfc2d5cd288cb12a7d774bf3212eSHA256: b071da0e5c7197e7010e0deb63fb6a1a0d32fc1e003ebdbfc311ac5193773a0f
Evidence Type Source Name Value Confidence Vendor file name maven-model-helper-37 High Vendor hint analyzer vendor redhat Highest Vendor jar package name fabric8 Highest Vendor jar package name io Highest Vendor jar package name maven Highest Vendor Manifest build-jdk-spec 22 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid maven-model-helper Low Vendor pom groupid io.fabric8 Highest Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Product file name maven-model-helper-37 High Product jar package name fabric8 Highest Product jar package name io Highest Product jar package name maven Highest Product Manifest build-jdk-spec 22 Low Product Manifest Implementation-Title maven-model-helper High Product Manifest implementation-url http://www.jboss.org Low Product Manifest specification-title maven-model-helper Medium Product pom artifactid maven-model-helper Highest Product pom groupid io.fabric8 Highest Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Version file version 37 Medium Version Manifest Implementation-Version 37 High Version pom parent-version 37 Low Version pom version 37 Highest
maven-plugin-api-3.9.12.jarDescription:
The API for plugins - Mojos - development. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-plugin-api/3.9.12/maven-plugin-api-3.9.12.jarMD5: 8fcc7f1f1457476e6c0d6c7746bd0960SHA1: 2c2d5180b3dae0e6f91575fc2507429727e01cc9SHA256: 104a1e073e5484eae2eac594c6e49b59bdd1103fe480ceb9a3468cd427449570
Evidence Type Source Name Value Confidence Vendor file name maven-plugin-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugin Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-plugin-api Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Plugin API High Vendor pom parent-artifactid maven Low Product file name maven-plugin-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugin Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Plugin API High Product Manifest specification-title Maven Plugin API Medium Product pom artifactid maven-plugin-api Highest Product pom groupid org.apache.maven Highest Product pom name Maven Plugin API High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-plugin-api@3.9.12 (Confidence :High) maven-plugin-tools-generators-3.13.1.jarDescription:
The Maven Plugin Tools Generators provide content generation (XML descriptor, documentation, help goal) from
plugin descriptor extracted from plugin sources. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugin-tools/maven-plugin-tools-generators/3.13.1/maven-plugin-tools-generators-3.13.1.jarMD5: 9800815e852aae8f276ddbad618b31a0SHA1: 482ce5970ee727317a9272b7ac0603e4bc728baeSHA256: a201ac701319c9ce54bd85c7c8e877e867495cd5f509f26ae5f2b408eafbf68f
Evidence Type Source Name Value Confidence Vendor file name maven-plugin-tools-generators High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugin Highest Vendor jar package name tools Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-plugin-tools-generators Low Vendor pom groupid org.apache.maven.plugin-tools Highest Vendor pom name Maven Plugin Tools Generators High Vendor pom parent-artifactid maven-plugin-tools Low Product file name maven-plugin-tools-generators High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugin Highest Product jar package name tools Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Maven Plugin Tools Generators High Product Manifest specification-title Maven Plugin Tools Generators Medium Product pom artifactid maven-plugin-tools-generators Highest Product pom groupid org.apache.maven.plugin-tools Highest Product pom name Maven Plugin Tools Generators High Product pom parent-artifactid maven-plugin-tools Medium Version file version 3.13.1 High Version Manifest Implementation-Version 3.13.1 High Version pom version 3.13.1 Highest
pkg:maven/org.apache.maven.plugin-tools/maven-plugin-tools-generators@3.13.1 (Confidence :High) maven-release-plugin-3.0.1.jarDescription:
This plugin is used to release a project with Maven, saving a lot of repetitive, manual work. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-release-plugin/3.0.1/maven-release-plugin-3.0.1.jarMD5: 4835b0d2d8f25f3d880eaaad639b371bSHA1: 53c2004bcf1569cfe6bfbcb12c422c3f760c3a22SHA256: 01c2906ddcc673cad8eac7af423dba9932f07c48d1decd13229a5ea9273f9fc6
Evidence Type Source Name Value Confidence Vendor file name maven-release-plugin High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor jar package name release Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-release-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Maven Release Plugin High Vendor pom parent-artifactid maven-release Low Vendor pom parent-groupid org.apache.maven.release Medium Product file name maven-release-plugin High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugins Highest Product jar package name release Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Maven Release Plugin High Product Manifest specification-title Maven Release Plugin Medium Product pom artifactid maven-release-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Maven Release Plugin High Product pom parent-artifactid maven-release Medium Product pom parent-groupid org.apache.maven.release Medium Version file version 3.0.1 High Version Manifest Implementation-Version 3.0.1 High Version pom version 3.0.1 Highest
pkg:maven/org.apache.maven.plugins/maven-release-plugin@3.0.1 (Confidence :High) maven-reporting-api-3.0.jarDescription:
API to manage report generation. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/reporting/maven-reporting-api/3.0/maven-reporting-api-3.0.jarMD5: 48cd00abc388c5156879b335e869adabSHA1: b2541dd07d08cd5eff9bd4554a2ad6a4198e2dfeSHA256: 498949e5576b022559d1622e534c18e052f94dec883924b67e0a4e8676c07b17
Evidence Type Source Name Value Confidence Vendor file name maven-reporting-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name reporting Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.reporting Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-reporting-api Low Vendor pom developer email vincent.siveton@gmail.com Low Vendor pom developer id vsiveton Medium Vendor pom developer name Vincent Siveton Medium Vendor pom groupid org.apache.maven.reporting Highest Vendor pom name Maven Reporting API High Vendor pom parent-artifactid maven-shared-components Low Vendor pom parent-groupid org.apache.maven.shared Medium Product file name maven-reporting-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name reporting Highest Product Manifest Implementation-Title Maven Reporting API High Product Manifest specification-title Maven Reporting API Medium Product pom artifactid maven-reporting-api Highest Product pom developer email vincent.siveton@gmail.com Low Product pom developer id vsiveton Low Product pom developer name Vincent Siveton Low Product pom groupid org.apache.maven.reporting Highest Product pom name Maven Reporting API High Product pom parent-artifactid maven-shared-components Medium Product pom parent-groupid org.apache.maven.shared Medium Version file version 3.0 High Version Manifest Implementation-Version 3.0 High Version pom parent-version 3.0 Low Version pom version 3.0 Highest
pkg:maven/org.apache.maven.reporting/maven-reporting-api@3.0 (Confidence :High) maven-reporting-api-4.0.0.jarDescription:
API to manage report generation. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/reporting/maven-reporting-api/4.0.0/maven-reporting-api-4.0.0.jarMD5: 9c49fcb81d69bb5ec513d624c181fc05SHA1: d3ad7e3d03463b5bd77e7d3ce94539cc723c8dfbSHA256: cb2cbde3c9c7288f7398a250dcf3c90cf92714cff301f22b298e1091b5def33c
Evidence Type Source Name Value Confidence Vendor file name maven-reporting-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name reporting Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-reporting-api Low Vendor pom groupid org.apache.maven.reporting Highest Vendor pom name Apache Maven Reporting API High Vendor pom parent-artifactid maven-shared-components Low Vendor pom parent-groupid org.apache.maven.shared Medium Product file name maven-reporting-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name reporting Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Reporting API High Product Manifest specification-title Apache Maven Reporting API Medium Product pom artifactid maven-reporting-api Highest Product pom groupid org.apache.maven.reporting Highest Product pom name Apache Maven Reporting API High Product pom parent-artifactid maven-shared-components Medium Product pom parent-groupid org.apache.maven.shared Medium Version file version 4.0.0 High Version Manifest Implementation-Version 4.0.0 High Version pom parent-version 4.0.0 Low Version pom version 4.0.0 Highest
pkg:maven/org.apache.maven.reporting/maven-reporting-api@4.0.0 (Confidence :High) maven-repository-metadata-3.9.12.jarDescription:
Per-directory local and remote repository metadata. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-repository-metadata/3.9.12/maven-repository-metadata-3.9.12.jarMD5: 6099a10e5063820edf75037e3e777863SHA1: 3ecfc216f9a56f15c6bd6b3e22567b0b6cb2183eSHA256: b3688646dde74429e2e04ba4d7e1482f720bd68ab53824990089d0d8c821f1da
Evidence Type Source Name Value Confidence Vendor file name maven-repository-metadata High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name repository Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-repository-metadata Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Repository Metadata Model High Vendor pom parent-artifactid maven Low Product file name maven-repository-metadata High Product jar package name apache Highest Product jar package name maven Highest Product jar package name repository Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Repository Metadata Model High Product Manifest specification-title Maven Repository Metadata Model Medium Product pom artifactid maven-repository-metadata Highest Product pom groupid org.apache.maven Highest Product pom name Maven Repository Metadata Model High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-repository-metadata@3.9.12 (Confidence :High) maven-resolver-api-1.9.25.jarDescription:
The application programming interface for the repository system. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-api/1.9.25/maven-resolver-api-1.9.25.jar
MD5: 11a370687a765c2c2288bcff6f4f73cb
SHA1: 8b670256b812a45b1ca9ae1bbf7f1c0d00a9d4e4
SHA256: f414e7f40aff338cef65f836aabf6cd9a9e2a0f1bfa88589315beb0ac2f498c5
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-api High Vendor jar package name artifact Highest Vendor jar package name repository Highest Vendor Manifest automatic-module-name org.apache.maven.resolver Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-api/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.api Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-api Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver API High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-api High Product jar package name artifact Highest Product jar package name repository Highest Product Manifest automatic-module-name org.apache.maven.resolver Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-api/ Low Product Manifest Bundle-Name Maven Artifact Resolver API Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.api Medium Product Manifest Implementation-Title Maven Artifact Resolver API High Product Manifest specification-title Maven Artifact Resolver API Medium Product pom artifactid maven-resolver-api Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver API High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-api@1.9.25 (Confidence :High) maven-resolver-connector-basic-1.9.25.jarDescription:
A repository connector implementation for repositories using URI-based layouts. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-connector-basic/1.9.25/maven-resolver-connector-basic-1.9.25.jar
MD5: 491deb147e1f47d54f17a40ae47dbacc
SHA1: 6dcd7e2076baecbcfa77e781112bd110ea379d07
SHA256: 23639c6186c9f06477a166e72df4556f1172ace1eddae5e7a04a009fbcabfdf0
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-connector-basic High Vendor jar package name basic Highest Vendor jar package name connector Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.connector.basic Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-connector-basic/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.connector.basic Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-connector-basic Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver Connector Basic High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-connector-basic High Product jar package name basic Highest Product jar package name connector Highest Product Manifest automatic-module-name org.apache.maven.resolver.connector.basic Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-connector-basic/ Low Product Manifest Bundle-Name Maven Artifact Resolver Connector Basic Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.connector.basic Medium Product Manifest Implementation-Title Maven Artifact Resolver Connector Basic High Product Manifest specification-title Maven Artifact Resolver Connector Basic Medium Product pom artifactid maven-resolver-connector-basic Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver Connector Basic High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-connector-basic@1.9.25 (Confidence :High) maven-resolver-impl-1.9.25.jarDescription:
An implementation of the repository system. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-impl/1.9.25/maven-resolver-impl-1.9.25.jar
MD5: 4792489c7592c08bebd235a7f2a3d4a1
SHA1: cc1bde9b56a2e95a181207958dcf40715dc71ab3
SHA256: 8d28766de3a000efa3662d5f67e428ca225498a89001195f7b3c55ea7a8bc56d
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-impl High Vendor jar package name impl Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.impl Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-impl/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.impl Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-impl Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver Implementation High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-impl High Product jar package name impl Highest Product Manifest automatic-module-name org.apache.maven.resolver.impl Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-impl/ Low Product Manifest Bundle-Name Maven Artifact Resolver Implementation Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.impl Medium Product Manifest Implementation-Title Maven Artifact Resolver Implementation High Product Manifest specification-title Maven Artifact Resolver Implementation Medium Product pom artifactid maven-resolver-impl Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver Implementation High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-impl@1.9.25 (Confidence :High) maven-resolver-named-locks-1.9.25.jarDescription:
A synchronization utility implementation using Named locks. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-named-locks/1.9.25/maven-resolver-named-locks-1.9.25.jar
MD5: d14b4f832e13dc00cfa3e5e36a60f666
SHA1: fb1c8c95f17c816c3ceb8692aa84cbb068df5d94
SHA256: e9fc779106713c33b4b5a7ed85e4273cfd7b9a96df7cf678eb0ac588f72669e3
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-named-locks High Vendor jar package name named Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.named.locks Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-named-locks/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.named.locks Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-named-locks Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver Named Locks High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-named-locks High Product jar package name named Highest Product jar package name support Highest Product Manifest automatic-module-name org.apache.maven.resolver.named.locks Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-named-locks/ Low Product Manifest Bundle-Name Maven Artifact Resolver Named Locks Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.named.locks Medium Product Manifest Implementation-Title Maven Artifact Resolver Named Locks High Product Manifest specification-title Maven Artifact Resolver Named Locks Medium Product pom artifactid maven-resolver-named-locks Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver Named Locks High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-named-locks@1.9.25 (Confidence :High) maven-resolver-provider-3.9.12.jarDescription:
Extensions to Maven Resolver for utilizing Maven POM and repository metadata. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-resolver-provider/3.9.12/maven-resolver-provider-3.9.12.jarMD5: f7b422b347c8009da8335e848b00b800SHA1: 44963f45b78f89a8479705493c48e01fc54ff9d6SHA256: 79be07f591709b41d35e3ede06244a3447330fad469499fd5decb7606be01005
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-provider High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name repository Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-provider Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Artifact Resolver Provider High Vendor pom parent-artifactid maven Low Product file name maven-resolver-provider High Product jar package name apache Highest Product jar package name maven Highest Product jar package name repository Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Artifact Resolver Provider High Product Manifest specification-title Maven Artifact Resolver Provider Medium Product pom artifactid maven-resolver-provider Highest Product pom groupid org.apache.maven Highest Product pom name Maven Artifact Resolver Provider High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-resolver-provider@3.9.12 (Confidence :High) maven-resolver-spi-1.9.25.jarDescription:
The service provider interface for repository system implementations and repository connectors. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-spi/1.9.25/maven-resolver-spi-1.9.25.jar
MD5: 49f5e30b9862b489b9e8066c9744869a
SHA1: f81237d0140f9222cf4437c44756a53368a2d152
SHA256: 781fafec23ea24f2624f3e3b48c674912f4bb1a1009a051df194307ed380280e
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-spi High Vendor jar package name spi Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.spi Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-spi/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.spi Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-spi Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver SPI High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-spi High Product jar package name spi Highest Product Manifest automatic-module-name org.apache.maven.resolver.spi Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-spi/ Low Product Manifest Bundle-Name Maven Artifact Resolver SPI Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.spi Medium Product Manifest Implementation-Title Maven Artifact Resolver SPI High Product Manifest specification-title Maven Artifact Resolver SPI Medium Product pom artifactid maven-resolver-spi Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver SPI High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-spi@1.9.25 (Confidence :High) maven-resolver-transport-http-1.9.23.jarDescription:
A transport implementation for repositories using http:// and https:// URLs. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-transport-http/1.9.23/maven-resolver-transport-http-1.9.23.jar
MD5: 016925c46ade15fe641bf329b72fc03f
SHA1: 38ed4a6a80408e6e186cfc5d94d080b5b5148099
SHA256: 7c4d762c4c604db5c8a9eeadd5c98b8f2e03556b853b48aa3346eb8cef67b54d
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-transport-http High Vendor jar package name http Highest Vendor jar package name transport Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.transport.http Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles="PMC Member";timezone=-5,jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-transport-http/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.transport.http Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-transport-http Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver Transport HTTP High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-transport-http High Product jar package name http Highest Product jar package name transport Highest Product Manifest automatic-module-name org.apache.maven.resolver.transport.http Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles="PMC Member";timezone=-5,jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-transport-http/ Low Product Manifest Bundle-Name Maven Artifact Resolver Transport HTTP Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.transport.http Medium Product Manifest Implementation-Title Maven Artifact Resolver Transport HTTP High Product Manifest specification-title Maven Artifact Resolver Transport HTTP Medium Product pom artifactid maven-resolver-transport-http Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver Transport HTTP High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.23 High Version Manifest Bundle-Version 1.9.23 High Version Manifest Implementation-Version 1.9.23 High Version pom version 1.9.23 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-transport-http@1.9.23 (Confidence :High) maven-resolver-transport-wagon-1.9.25.jarDescription:
A transport implementation based on Maven Wagon. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-transport-wagon/1.9.25/maven-resolver-transport-wagon-1.9.25.jar
MD5: ed17496e7eb59c3782a9f441eb70e87e
SHA1: 9b5af36b4bafbec8f71430b6bb3a4802a9ebbf65
SHA256: 73425c699e593cbb5b51dc01efc8cd334bdf793bb3c4070d48f32a72e99b61ed
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-transport-wagon High Vendor jar package name transport Highest Vendor jar package name wagon Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.transport.wagon Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-transport-wagon/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.transport.wagon Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-transport-wagon Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver Transport Wagon High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-transport-wagon High Product jar package name transport Highest Product jar package name wagon Highest Product Manifest automatic-module-name org.apache.maven.resolver.transport.wagon Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-transport-wagon/ Low Product Manifest Bundle-Name Maven Artifact Resolver Transport Wagon Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.transport.wagon Medium Product Manifest Implementation-Title Maven Artifact Resolver Transport Wagon High Product Manifest specification-title Maven Artifact Resolver Transport Wagon Medium Product pom artifactid maven-resolver-transport-wagon Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver Transport Wagon High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
maven-resolver-util-1.9.25.jarDescription:
A collection of utility classes to ease usage of the repository system. License:
"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/resolver/maven-resolver-util/1.9.25/maven-resolver-util-1.9.25.jar
MD5: 8c4a25d08ba8ba18a9f93a821d518273
SHA1: f755f6816d8fd63b09b8f2c9e1eaaa1f60c179e8
SHA256: e31330fdb29045f3087b4985cb488a5b5ebbcbd7d879fda14e6ed4dd61b1fdf7
Evidence Type Source Name Value Confidence Vendor file name maven-resolver-util High Vendor jar package name artifact Highest Vendor jar package name repository Highest Vendor jar package name util Highest Vendor Manifest automatic-module-name org.apache.maven.resolver.util Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Vendor Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-util/ Low Vendor Manifest bundle-symbolicname org.apache.maven.resolver.util Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resolver-util Low Vendor pom groupid org.apache.maven.resolver Highest Vendor pom name Maven Artifact Resolver Utilities High Vendor pom parent-artifactid maven-resolver Low Product file name maven-resolver-util High Product jar package name artifact Highest Product jar package name repository Highest Product jar package name util Highest Product Manifest automatic-module-name org.apache.maven.resolver.util Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-developers hboutemy;email="hboutemy@apache.org";name="Hervé Boutemy";organization=ASF;roles="PMC Chair";timezone="Europe/Paris",aheritier;email="aheritier@apache.org";name="Arnaud Héritier";roles="PMC Member";timezone="+1",andham;email="andham@apache.org";name="Anders Hammar";roles="PMC Member";timezone="+1",baerrach;email="baerrach@apache.org";name="Barrie Treloar";roles="PMC Member";timezone="Australia/Adelaide",bimargulies;email="bimargulies@apache.org";name="Benson Margulies";roles="PMC Member";timezone="America/New_York",bmarwell;email="bmarwell@apache.org";name="Benjamin Marwell";organization=ASF;roles="PMC Member";timezone="Europe/Berlin",brianf;email="brianf@apache.org";name="Brian Fox";organization=Sonatype;roles="PMC Member";timezone=-5,cstamas;email="cstamas@apache.org";name="Tamas Cservenak";roles="PMC Member";timezone="+1",dennisl;email="dennisl@apache.org";name="Dennis Lundberg";organization=ASF;roles="PMC Member";timezone="+1",dkulp;email="dkulp@apache.org";name="Daniel Kulp";organization=ASF;roles="PMC Member";timezone=-5,evenisse;email="evenisse@apache.org";name="Emmanuel Venisse";organization=ASF;roles="PMC Member";timezone="+1",gboue;email="gboue@apache.org";name="Guillaume Boué";roles="PMC Member";timezone="Europe/Paris",gnodet;email="gnodet@apache.org";name="Guillaume Nodet";organization="Red Hat";roles="PMC Member";timezone="Europe/Paris",henning;email="henning@apache.org";name="Henning Schmiedehausen";organization=ASF;roles="PMC Member";timezone="America/Los_Angeles",jvanzyl;email="jason@maven.org";name="Jason van Zyl";roles="PMC Member";timezone=-5,khmarbaise;email="khmarbaise@apache.org";name="Karl Heinz Marbaise";roles="PMC Member";timezone="+1",krosenvold;email="krosenvold@apache.org";name="Kristian Rosenvold";roles="PMC Member";timezone="+1",kwin;email="kwin@apache.org";name="Konrad Windszus";organization="Cognizant Netcentric";roles="PMC Member";timezone="Europe/Berlin",mkleint;name="Milos Kleint";roles="PMC Member",mthmulders;email="mthmulders@apache.org";name="Maarten Mulders";organization="Info Support";roles="PMC Member";timezone="Europe/Amsterdam",olamy;email="olamy@apache.org";name="Olivier Lamy";roles="PMC Member";timezone="Australia/Brisbane",michaelo;email="michaelo@apache.org";name="Michael Osipov";roles="PMC Member";timezone="Europe/Berlin",rfscholte;email="rfscholte@apache.org";name="Robert Scholte";roles="PMC Member";timezone="Europe/Amsterdam",rgoers;email="rgoers@apache.org";name="Ralph Goers";organization=Intuit;roles="PMC Member";timezone=-8,sjaranowski;email="sjaranowski@apache.org";name="Slawomir Jaranowski";roles="PMC Member";timezone="Europe/Warsaw",stephenc;email="stephenc@apache.org";name="Stephen Connolly";roles="PMC Member";timezone=0,slachiewicz;email="slachiewicz@apache.org";name="Sylwester Lachiewicz";roles="PMC Member";timezone="Europe/Warsaw",struberg;email="struberg@apache.org";name="Mark Struberg";roles="PMC Member",tibordigana;email="tibordigana@apache.org";name="Tibor Digaňa";roles="PMC Member";timezone="Europe/Bratislava",vsiveton;email="vsiveton@apache.org";name="Vincent Siveton";organization=ASF;roles="PMC Member";timezone=-5,wfay;email="wfay@apache.org";name="Wayne Fay";organization=ASF;roles="PMC Member";timezone=-6,adangel;email="adangel@apache.org";name="Andreas Dangel";roles=Committer;timezone="Europe/Berlin",bdemers;email="bdemers@apache.org";name="Brian Demers";organization=Sonatype;roles=Committer;timezone=-5,bellingard;name="Fabrice Bellingard";roles=Committer,bentmann;email="bentmann@apache.org";name="Benjamin Bentmann";organization=Sonatype;roles=Committer;timezone="+1",chrisgwarp;email="chrisgwarp@apache.org";name="Chris Graham";roles=Committer;timezone="Australia/Melbourne",dantran;email="dantran@apache.org";name="Dan Tran";roles=Committer;timezone=-8,dbradicich;email="dbradicich@apache.org";name="Damian Bradicich";organization=Sonatype;roles=Committer;timezone=-5,brett;email="brett@apache.org";name="Brett Porter";organization=ASF;roles=Committer;timezone="+10",dfabulich;email="dfabulich@apache.org";name="Daniel Fabulich";roles=Committer;timezone=-8,eolivelli;email="eolivelli@apache.org";name="Enrico Olivelli";organization=Diennea;roles=Committer;timezone="Europe/Rome",fgiust;email="fgiust@apache.org";name="Fabrizio Giustina";organization=openmind;roles=Committer;timezone="+1",godin;email="godin@apache.org";name="Evgeny Mandrikov";organization=SonarSource;roles=Committer;timezone="+3",handyande;email="handyande@apache.org";name="Andrew Williams";roles=Committer;timezone=0,imod;email="imod@apache.org";name="Dominik Bartholdi";roles=Committer;timezone="Europe/Zurich",jjensen;name="Jeff Jensen";roles=Committer,ltheussl;email="ltheussl@apache.org";name="Lukas Theussl";roles=Committer;timezone="+1",markh;email="markh@apache.org";name="Mark Hobson";roles=Committer;timezone=0,martinkanters;email="martinkanters@apache.org";name="Martin Kanters";organization=JPoint;roles=Committer;timezone="Europe/Amsterdam",mauro;name="Mauro Talevi";roles=Committer,mbuenger;email="mbuenger@apache.org";name="Matthias Bünger";roles=Committer;timezone="Europe/Berlin",mfriedenhagen;email="mfriedenhagen@apache.org";name="Mirko Friedenhagen";roles=Committer;timezone="+1",mmoser;email="mmoser@apache.org";name="Manfred Moser";roles=Committer;timezone=-8,nicolas;name="Nicolas de Loof";roles=Committer,oching;name="Maria Odea B. Ching";roles=Committer,pgier;email="pgier@apache.org";name="Paul Gier";organization="Red Hat";roles=Committer;timezone=-6,ptahchiev;email="ptahchiev@apache.org";name="Petar Tahchiev";roles=Committer;timezone="+2",rafale;email="rafale@apache.org";name="Raphaël Piéroni";organization=Dexem;roles=Committer;timezone="+1",schulte;email="schulte@apache.org";name="Christian Schulte";roles=Committer;timezone="Europe/Berlin",snicoll;email="snicoll@apache.org";name="Stephane Nicoll";roles=Committer;timezone="+1",simonetripodi;email="simonetripodi@apache.org";name="Simone Tripodi";roles=Committer;timezone="+1",sor;email="sor@apache.org";name="Christian Stein";roles=Committer;timezone="Europe/Berlin",sparsick;email="sparsick@apache.org";name="Sandra Parsick";roles=Committer;timezone="Europe/Berlin",tchemit;email="tchemit@apache.org";name="Tony Chemit";organization=CodeLutin;roles=Committer;timezone="Europe/Paris",vmassol;email="vmassol@apache.org";name="Vincent Massol";organization=ASF;roles=Committer;timezone="+1",elharo;email="elharo@apache.org";name="Elliotte Rusty Harold";roles=Committer;timezone="America/New_York",agudian;email="agudian@apache.org";name="Andreas Gudian";roles=Emeritus;timezone="Europe/Berlin",aramirez;name="Allan Q. Ramirez";roles=Emeritus,bayard;name="Henri Yandell";roles=Emeritus,carlos;email="carlos@apache.org";name="Carlos Sanchez";organization=ASF;roles=Emeritus;timezone="+1",chrisjs;name="Chris Stevenson";roles=Emeritus,dblevins;name="David Blevins";roles=Emeritus,dlr;name="Daniel Rall";roles=Emeritus,epunzalan;email="epunzalan@apache.org";name="Edwin Punzalan";roles=Emeritus;timezone=-8,felipeal;name="Felipe Leme";roles=Emeritus,ifedorenko;email="igor@ifedorenko.com";name="Igor Fedorenko";organization=Sonatype;roles=Emeritus;timezone=-5,jdcasey;email="jdcasey@apache.org";name="John Casey";organization=ASF;roles=Emeritus;timezone=-6,jmcconnell;email="jmcconnell@apache.org";name="Jesse McConnell";organization=ASF;roles=Emeritus;timezone=-6,joakime;email="joakime@apache.org";name="Joakim Erdfelt";organization=ASF;roles=Emeritus;timezone=-5,jruiz;email="jruiz@apache.org";name="Johnny Ruiz III";roles=Emeritus,jstrachan;name="James Strachan";roles=Emeritus,jtolentino;email="jtolentino@apache.org";name="Ernesto Tolentino Jr.";organization=ASF;roles=Emeritus;timezone="+8",kenney;email="kenney@apache.org";name="Kenney Westerhof";organization=Neonics;roles=Emeritus;timezone="+1",mperham;email="mperham@gmail.com";name="Mike Perham";organization=IBM;roles=Emeritus;timezone=-6,ogusakov;name="Oleg Gusakov";roles=Emeritus,pschneider;email="pschneider@gmail.com";name="Patrick Schneider";roles=Emeritus;timezone=-6,rinku;name="Rahul Thakur";roles=Emeritus,shinobu;name="Shinobu Kuwai";roles=Emeritus,smorgrav;name="Torbjorn Eikli Smorgrav";roles=Emeritus,trygvis;email="trygvis@apache.org";name="Trygve Laugstol";organization=ASF;roles=Emeritus;timezone="+1",wsmoak;email="wsmoak@apache.org";name="Wendy Smoak";roles=Emeritus;timezone=-7 Low Product Manifest bundle-docurl https://maven.apache.org/resolver/maven-resolver-util/ Low Product Manifest Bundle-Name Maven Artifact Resolver Utilities Medium Product Manifest bundle-symbolicname org.apache.maven.resolver.util Medium Product Manifest Implementation-Title Maven Artifact Resolver Utilities High Product Manifest specification-title Maven Artifact Resolver Utilities Medium Product pom artifactid maven-resolver-util Highest Product pom groupid org.apache.maven.resolver Highest Product pom name Maven Artifact Resolver Utilities High Product pom parent-artifactid maven-resolver Medium Version file version 1.9.25 High Version Manifest Bundle-Version 1.9.25 High Version Manifest Implementation-Version 1.9.25 High Version pom version 1.9.25 Highest
pkg:maven/org.apache.maven.resolver/maven-resolver-util@1.9.25 (Confidence :High) maven-resources-plugin-3.3.1.jarDescription:
The Resources Plugin handles the copying of project resources to the output
directory. There are two different kinds of resources: main resources and test resources. The
difference is that the main resources are the resources associated with the main
source code while the test resources are associated with the test source code.
Thus, this allows the separation of resources for the main source code and its
unit tests. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-resources-plugin/3.3.1/maven-resources-plugin-3.3.1.jarMD5: 2161e818c9c8bec0ad7e16caba1f5a55SHA1: 5a0e59faaaec9485868660696dd0808f483917d0SHA256: eb4069c7fe50a313b3f5295ccd214f30402f63971c26f443f7f3e798be8cc2a7
Evidence Type Source Name Value Confidence Vendor file name maven-resources-plugin High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor jar package name resources Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-resources-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Resources Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-resources-plugin High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugins Highest Product jar package name resources Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Resources Plugin High Product Manifest specification-title Apache Maven Resources Plugin Medium Product pom artifactid maven-resources-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Resources Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.3.1 High Version Manifest Implementation-Version 3.3.1 High Version pom parent-version 3.3.1 Low Version pom version 3.3.1 Highest
pkg:maven/org.apache.maven.plugins/maven-resources-plugin@3.3.1 (Confidence :High) maven-settings-3.9.12.jarDescription:
Maven Settings model. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-settings/3.9.12/maven-settings-3.9.12.jarMD5: c36d21412549711847bf183674c8d2eeSHA1: ca072f2b90a59d36d8218dd4e1460722db6e2322SHA256: eabb1adfa3ce3c9217318b6d289de20259ee42d7290660ed4358eecd56b5664f
Evidence Type Source Name Value Confidence Vendor file name maven-settings High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name settings Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-settings Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Settings High Vendor pom parent-artifactid maven Low Product file name maven-settings High Product jar package name apache Highest Product jar package name maven Highest Product jar package name settings Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Settings High Product Manifest specification-title Maven Settings Medium Product pom artifactid maven-settings Highest Product pom groupid org.apache.maven Highest Product pom name Maven Settings High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-settings@3.9.12 (Confidence :High) maven-settings-builder-3.9.12.jarDescription:
The effective settings builder, with inheritance and password decryption. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-settings-builder/3.9.12/maven-settings-builder-3.9.12.jarMD5: d9dad42925db531f32bcc320783e7322SHA1: 1ddd0b8da05d120768142176476a06f489cea11cSHA256: 92d137e366a4b4549eda848b52d968ef076ce24b9fb2db1b7a3083b9cc896eb1
Evidence Type Source Name Value Confidence Vendor file name maven-settings-builder High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name settings Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-settings-builder Low Vendor pom groupid org.apache.maven Highest Vendor pom name Maven Settings Builder High Vendor pom parent-artifactid maven Low Product file name maven-settings-builder High Product jar package name apache Highest Product jar package name maven Highest Product jar package name settings Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Maven Settings Builder High Product Manifest specification-title Maven Settings Builder Medium Product pom artifactid maven-settings-builder Highest Product pom groupid org.apache.maven Highest Product pom name Maven Settings Builder High Product pom parent-artifactid maven Medium Version file version 3.9.12 High Version Manifest Implementation-Version 3.9.12 High Version pom version 3.9.12 Highest
pkg:maven/org.apache.maven/maven-settings-builder@3.9.12 (Confidence :High) maven-shared-incremental-1.1.jarDescription:
Various utility classes and plexus components for supporting
incremental build functionality in maven plugins.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/shared/maven-shared-incremental/1.1/maven-shared-incremental-1.1.jarMD5: 8a48e08aa027a7ac33fcc85054512021SHA1: 9d017a7584086755445c0a260dd9a1e9eae161a5SHA256: 61988e54486a5dc38f06c70fdae5b108556c63bd433697b9f4305fcdb30fa40e
Evidence Type Source Name Value Confidence Vendor file name maven-shared-incremental High Vendor jar package name apache Highest Vendor jar package name incremental Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.maven.shared Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-shared-incremental Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Maven Incremental Build support utilities High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-shared-incremental High Product jar package name apache Highest Product jar package name incremental Highest Product jar package name maven Highest Product jar package name shared Highest Product Manifest Implementation-Title Maven Incremental Build support utilities High Product Manifest specification-title Maven Incremental Build support utilities Medium Product pom artifactid maven-shared-incremental Highest Product pom groupid org.apache.maven.shared Highest Product pom name Maven Incremental Build support utilities High Product pom parent-artifactid maven-shared-components Medium Version file version 1.1 High Version Manifest Implementation-Version 1.1 High Version pom parent-version 1.1 Low Version pom version 1.1 Highest
pkg:maven/org.apache.maven.shared/maven-shared-incremental@1.1 (Confidence :High) maven-shared-utils-3.3.4.jarDescription:
Shared utilities for use by Maven core and plugins File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/shared/maven-shared-utils/3.3.4/maven-shared-utils-3.3.4.jarMD5: 908f2a0107ff330ac9b856356a0acaefSHA1: f87a61adb1e12a00dcc6cc6005a51e693aa7c4acSHA256: 7925d9c5a0e2040d24b8fae3f612eb399cbffe5838b33ba368777dc7bddf6dda
Evidence Type Source Name Value Confidence Vendor file name maven-shared-utils High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor jar package name utils Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-shared-utils Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Shared Utils High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-shared-utils High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product jar package name utils Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Shared Utils High Product Manifest specification-title Apache Maven Shared Utils Medium Product pom artifactid maven-shared-utils Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Shared Utils High Product pom parent-artifactid maven-shared-components Medium Version file version 3.3.4 High Version Manifest Implementation-Version 3.3.4 High Version pom parent-version 3.3.4 Low Version pom version 3.3.4 Highest
maven-shared-utils-3.4.2.jarDescription:
Shared utilities for use by Maven core and plugins File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/shared/maven-shared-utils/3.4.2/maven-shared-utils-3.4.2.jarMD5: 53a038f77a81cb5816ad2b1c7daa8711SHA1: bfa28296272a5915b08de9f11f34a94b0a818fd0SHA256: b613357e1bad4dfc1dead801691c9460f9585fe7c6b466bc25186212d7d18487
Evidence Type Source Name Value Confidence Vendor file name maven-shared-utils High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor jar package name utils Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-shared-utils Low Vendor pom groupid org.apache.maven.shared Highest Vendor pom name Apache Maven Shared Utils High Vendor pom parent-artifactid maven-shared-components Low Product file name maven-shared-utils High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product jar package name utils Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Apache Maven Shared Utils High Product Manifest specification-title Apache Maven Shared Utils Medium Product pom artifactid maven-shared-utils Highest Product pom groupid org.apache.maven.shared Highest Product pom name Apache Maven Shared Utils High Product pom parent-artifactid maven-shared-components Medium Version file version 3.4.2 High Version Manifest Implementation-Version 3.4.2 High Version pom parent-version 3.4.2 Low Version pom version 3.4.2 Highest
maven-site-plugin-3.12.1.jarDescription:
The Maven Site Plugin is a plugin that generates a site for the current project. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-site-plugin/3.12.1/maven-site-plugin-3.12.1.jarMD5: 61c90676990821dfc5caacb5e18586eeSHA1: 60f12a786e1ef2c344b239228ff815f4f63c2644SHA256: f7bd8e943977ca85022e1252d52575b769d12d49565375550251d2f471aa350c
Evidence Type Source Name Value Confidence Vendor file name maven-site-plugin High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugins Highest Vendor jar package name site Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-site-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Apache Maven Site Plugin High Vendor pom parent-artifactid maven-plugins Low Product file name maven-site-plugin High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugins Highest Product jar package name site Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Site Plugin High Product Manifest specification-title Apache Maven Site Plugin Medium Product pom artifactid maven-site-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Apache Maven Site Plugin High Product pom parent-artifactid maven-plugins Medium Version file version 3.12.1 High Version Manifest Implementation-Version 3.12.1 High Version pom parent-version 3.12.1 Low Version pom version 3.12.1 Highest
pkg:maven/org.apache.maven.plugins/maven-site-plugin@3.12.1 (Confidence :High) maven-surefire-common-3.2.2.jarDescription:
API used in Surefire and Failsafe MOJO. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/maven-surefire-common/3.2.2/maven-surefire-common-3.2.2.jarMD5: 5af1a9b35a6662d16964ef7df7cc7b7aSHA1: f76740de8cbb4578348ff441e05b92112053f4dfSHA256: be29879c7fd69d1ae225dce241524992046b270d84cf125bb372ebf62cf8762d
Evidence Type Source Name Value Confidence Vendor file name maven-surefire-common High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-surefire-common Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Maven Surefire Common High Vendor pom parent-artifactid surefire Low Product file name maven-surefire-common High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Maven Surefire Common High Product Manifest specification-title Maven Surefire Common Medium Product pom artifactid maven-surefire-common Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Maven Surefire Common High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/maven-surefire-common@3.2.2 (Confidence :High) maven-surefire-common-3.2.3.jarDescription:
API used in Surefire and Failsafe MOJO. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/maven-surefire-common/3.2.3/maven-surefire-common-3.2.3.jarMD5: 8d4cb30aff4cfa5ae7eb05554797d03cSHA1: d2b1afbe237f80314f0610dae71ac7628e6699b3SHA256: 286535a6c799516033535892613a89a32e3cb1e2b7076726a61451b222aac4e3
Evidence Type Source Name Value Confidence Vendor file name maven-surefire-common High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-surefire-common Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Maven Surefire Common High Vendor pom parent-artifactid surefire Low Product file name maven-surefire-common High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Maven Surefire Common High Product Manifest specification-title Maven Surefire Common Medium Product pom artifactid maven-surefire-common Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Maven Surefire Common High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/maven-surefire-common@3.2.3 (Confidence :High) maven-surefire-plugin-3.2.2.jarDescription:
Maven Surefire MOJO in maven-surefire-plugin. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-surefire-plugin/3.2.2/maven-surefire-plugin-3.2.2.jarMD5: 4fd8ea1ba31b9b25e196e7ad1c88a8efSHA1: 11d4e9b45ce0953096896475ab212a605a63854eSHA256: fc1e5c8d637337551dac8c47a6f7a89a0e912b34d9dca781463c54ff89c51504
Evidence Type Source Name Value Confidence Vendor file name maven-surefire-plugin High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugin Highest Vendor jar package name plugins Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-surefire-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Maven Surefire Plugin High Vendor pom parent-artifactid surefire Low Vendor pom parent-groupid org.apache.maven.surefire Medium Product file name maven-surefire-plugin High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugin Highest Product jar package name plugins Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Maven Surefire Plugin High Product Manifest specification-title Maven Surefire Plugin Medium Product pom artifactid maven-surefire-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Maven Surefire Plugin High Product pom parent-artifactid surefire Medium Product pom parent-groupid org.apache.maven.surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.plugins/maven-surefire-plugin@3.2.2 (Confidence :High) maven-surefire-plugin-3.2.3.jarDescription:
Maven Surefire MOJO in maven-surefire-plugin. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/plugins/maven-surefire-plugin/3.2.3/maven-surefire-plugin-3.2.3.jarMD5: 712aed086ad83fbbd1086e75b9bb0a73SHA1: 6bdd6a313718aebbbc297deba8930cf828427864SHA256: b395caef49297e4f5316ae442b6490f0f4dd3f51c81a1ebcc191441dc5e3d16e
Evidence Type Source Name Value Confidence Vendor file name maven-surefire-plugin High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name plugin Highest Vendor jar package name plugins Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-surefire-plugin Low Vendor pom groupid org.apache.maven.plugins Highest Vendor pom name Maven Surefire Plugin High Vendor pom parent-artifactid surefire Low Vendor pom parent-groupid org.apache.maven.surefire Medium Product file name maven-surefire-plugin High Product jar package name apache Highest Product jar package name maven Highest Product jar package name plugin Highest Product jar package name plugins Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Maven Surefire Plugin High Product Manifest specification-title Maven Surefire Plugin Medium Product pom artifactid maven-surefire-plugin Highest Product pom groupid org.apache.maven.plugins Highest Product pom name Maven Surefire Plugin High Product pom parent-artifactid surefire Medium Product pom parent-groupid org.apache.maven.surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.plugins/maven-surefire-plugin@3.2.3 (Confidence :High) maven-wrapper.jarDescription:
Maven Wrapper Jar download, installs and launches installed target Maven distribution as part of Maven Wrapper scripts run. File Path: /builds/pub/numeco/misis/misis-backend/.mvn/wrapper/maven-wrapper.jarMD5: 6058337c6ed4603858c3b72f754efa9bSHA1: daa475c180514b4f190714f7a4df4ce4ec7b772dSHA256: e63a53cfb9c4d291ebe3c2b0edacb7622bbc480326beaa5a0456e412f52f066a
Evidence Type Source Name Value Confidence Vendor file name maven-wrapper High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name wrapper Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-wrapper Low Vendor pom groupid org.apache.maven.wrapper Highest Vendor pom name Maven Wrapper Jar High Vendor pom parent-artifactid maven-wrapper-parent Low Product file name maven-wrapper High Product jar package name apache Highest Product jar package name maven Highest Product jar package name wrapper Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Maven Wrapper Jar High Product Manifest specification-title Maven Wrapper Jar Medium Product pom artifactid maven-wrapper Highest Product pom groupid org.apache.maven.wrapper Highest Product pom name Maven Wrapper Jar High Product pom parent-artifactid maven-wrapper-parent Medium Version Manifest Implementation-Version 3.2.0 High Version pom version 3.2.0 Highest
pkg:maven/org.apache.maven.wrapper/maven-wrapper@3.2.0 (Confidence :High) maven-xml-impl-4.0.0-alpha-7.jarDescription:
Provides the implementation classes for the Maven API XML File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/maven-xml-impl/4.0.0-alpha-7/maven-xml-impl-4.0.0-alpha-7.jarMD5: ec115686a695a77105dcca8dfd5d40b4SHA1: 06678934d540a73916c58993f09495d53aac1291SHA256: c89323b70dd491a3ef21432dba4cad2b74e26caaafd77178b0f15313fe0bd5f0
Evidence Type Source Name Value Confidence Vendor file name maven-xml-impl High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid maven-xml-impl Low Vendor pom groupid org.apache.maven Highest Vendor pom name Implementation of Maven API XML High Vendor pom parent-artifactid maven Low Product file name maven-xml-impl High Product jar package name apache Highest Product jar package name maven Highest Product jar package name xml Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Implementation of Maven API XML High Product Manifest specification-title Implementation of Maven API XML Medium Product pom artifactid maven-xml-impl Highest Product pom groupid org.apache.maven Highest Product pom name Implementation of Maven API XML High Product pom parent-artifactid maven Medium Version Manifest Implementation-Version 4.0.0-alpha-7 High Version pom version 4.0.0-alpha-7 Highest
pkg:maven/org.apache.maven/maven-xml-impl@4.0.0-alpha-7 (Confidence :High) mockito-core-5.20.0.jarDescription:
Mockito mock objects library core API and implementation License:
MIT: https://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/mockito/mockito-core/5.20.0/mockito-core-5.20.0.jar
MD5: 05f1af408a8a9599b65453c3c3082f6e
SHA1: a32f446f38acf636363c5693db6498047731b9e0
SHA256: d1a96d252128d3a4247cfd8a2e76412efa3cc103977be17933c942117a24f374
Evidence Type Source Name Value Confidence Vendor file name mockito-core High Vendor jar package name and Highest Vendor jar package name api Highest Vendor jar package name mockito Highest Vendor Manifest bundle-symbolicname org.mockito.mockito-core Medium Vendor Manifest can-retransform-classes true Low Vendor pom artifactid mockito-core Low Vendor pom developer id bric3 Medium Vendor pom developer id mockitoguy Medium Vendor pom developer id raphw Medium Vendor pom developer id TimvdLippe Medium Vendor pom developer name Brice Dutheil Medium Vendor pom developer name Rafael Winterhalter Medium Vendor pom developer name Szczepan Faber Medium Vendor pom developer name Tim van der Lippe Medium Vendor pom groupid org.mockito Highest Vendor pom name mockito-core High Vendor pom url mockito/mockito Highest Product file name mockito-core High Product jar package name and Highest Product jar package name api Highest Product jar package name mockito Highest Product Manifest Bundle-Name Mockito Mock Library for Java. Core bundle requires Byte Buddy and Objenesis. Medium Product Manifest bundle-symbolicname org.mockito.mockito-core Medium Product Manifest can-retransform-classes true Low Product pom artifactid mockito-core Highest Product pom developer id bric3 Low Product pom developer id mockitoguy Low Product pom developer id raphw Low Product pom developer id TimvdLippe Low Product pom developer name Brice Dutheil Low Product pom developer name Rafael Winterhalter Low Product pom developer name Szczepan Faber Low Product pom developer name Tim van der Lippe Low Product pom groupid org.mockito Highest Product pom name mockito-core High Product pom url mockito/mockito High Version file version 5.20.0 High Version Manifest Bundle-Version 5.20.0 High Version pom version 5.20.0 Highest
pkg:maven/org.mockito/mockito-core@5.20.0 (Confidence :High) mockito-junit-jupiter-5.20.0.jarDescription:
Mockito JUnit 5 support License:
MIT: https://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/mockito/mockito-junit-jupiter/5.20.0/mockito-junit-jupiter-5.20.0.jar
MD5: 34ac767475d435d77ed12d40847fd4a2
SHA1: 58ed6603af5f8f53886d49be00264a3fdd1278d5
SHA256: fd6c703c2b00b914f3adbc27b18077a708f3d6992f19242c444e737c6cce024e
Evidence Type Source Name Value Confidence Vendor file name mockito-junit-jupiter High Vendor jar package name junit Highest Vendor jar package name jupiter Highest Vendor jar package name mockito Highest Vendor Manifest bundle-symbolicname org.mockito.junit-jupiter Medium Vendor pom artifactid mockito-junit-jupiter Low Vendor pom developer id bric3 Medium Vendor pom developer id mockitoguy Medium Vendor pom developer id raphw Medium Vendor pom developer id TimvdLippe Medium Vendor pom developer name Brice Dutheil Medium Vendor pom developer name Rafael Winterhalter Medium Vendor pom developer name Szczepan Faber Medium Vendor pom developer name Tim van der Lippe Medium Vendor pom groupid org.mockito Highest Vendor pom name mockito-junit-jupiter High Vendor pom url mockito/mockito Highest Product file name mockito-junit-jupiter High Product jar package name junit Highest Product jar package name jupiter Highest Product jar package name mockito Highest Product Manifest Bundle-Name Mockito Extension Library for JUnit 5. Medium Product Manifest bundle-symbolicname org.mockito.junit-jupiter Medium Product pom artifactid mockito-junit-jupiter Highest Product pom developer id bric3 Low Product pom developer id mockitoguy Low Product pom developer id raphw Low Product pom developer id TimvdLippe Low Product pom developer name Brice Dutheil Low Product pom developer name Rafael Winterhalter Low Product pom developer name Szczepan Faber Low Product pom developer name Tim van der Lippe Low Product pom groupid org.mockito Highest Product pom name mockito-junit-jupiter High Product pom url mockito/mockito High Version file version 5.20.0 High Version Manifest Bundle-Version 5.20.0 High Version pom version 5.20.0 Highest
pkg:maven/org.mockito/mockito-junit-jupiter@5.20.0 (Confidence :High) modal.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/modal/modal.module.jsMD5: 5874142d9289911ba4deb3c6ca639d83SHA1: b603a6a49d3edc52afac2e6ead54e42bac0075ebSHA256: 8ec34dfcd327e972fa50a079882f63dbbd285a464f73de6ebf2e30c2ee0b0100
Evidence Type Source Name Value Confidence
modal.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/modal/modal.module.min.jsMD5: 9e568d506474bc6e1631fc11f5afc324SHA1: 3f0cb4c6de99c1dcbb93f7d899445fe79c73ec91SHA256: 0db8472eaea8656a4200b281b636221e9e95897da12a115e9d93bf7f1093052d
Evidence Type Source Name Value Confidence
modal.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/modal/modal.nomodule.jsMD5: a3b481766f92594533eae843f05ccf91SHA1: e7ee1be86960ee9b158a9f0431b6875368f04db1SHA256: 552c2b668a0f66c07fc3fce37f5cc6a6c7f25fd2e4efe153831444d74fe55666
Evidence Type Source Name Value Confidence
modal.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/modal/modal.nomodule.min.jsMD5: 15b7b33d1fca3bb795c8a83fc6da623eSHA1: 3b4b79b6d36215e2de78fb1673f08f56354d8602SHA256: 7309e087664b68717981b771255ff1a64c596fa4ad93214114dad437026922b2
Evidence Type Source Name Value Confidence
mojo-executor-2.4.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/twdata/maven/mojo-executor/2.4.0/mojo-executor-2.4.0.jarMD5: ba2b0edcf5cfc3b5c2ba166aecc6c27cSHA1: 64f0498596a62e2917519268183e06b08ca3e4e1SHA256: 7be7713cfd9f0e9fab9acbe2538bf06186ea6ae0cc80b324afdb3861aaf18889
Evidence Type Source Name Value Confidence Vendor file name mojo-executor High Vendor jar package name maven Highest Vendor jar package name maven Low Vendor jar package name mojoexecutor Low Vendor jar package name twdata Highest Vendor jar package name twdata Low Vendor pom artifactid mojo-executor Low Vendor pom groupid org.twdata.maven Highest Vendor pom name Mojo Executor High Vendor pom parent-artifactid mojo-executor-parent Low Product file name mojo-executor High Product jar package name maven Highest Product jar package name maven Low Product jar package name mojoexecutor Low Product jar package name twdata Highest Product pom artifactid mojo-executor Highest Product pom groupid org.twdata.maven Highest Product pom name Mojo Executor High Product pom parent-artifactid mojo-executor-parent Medium Version file version 2.4.0 High Version pom version 2.4.0 Highest
pkg:maven/org.twdata.maven/mojo-executor@2.4.0 (Confidence :High) mxparser-1.2.2.jarDescription:
MXParser is a fork of xpp3_min 1.1.7 containing only the parser with merged changes of the Plexus fork.
License:
Indiana University Extreme! Lab Software License: https://raw.githubusercontent.com/x-stream/mxparser/master/LICENSE.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/github/x-stream/mxparser/1.2.2/mxparser-1.2.2.jar
MD5: 9d7e42409dfdcee9bd17903015bdeae2
SHA1: 476fb3b3bb3716cad797cd054ce45f89445794e9
SHA256: aeeee23a3303d811bca8790ea7f25b534314861c03cff36dafdcc2180969eb97
Evidence Type Source Name Value Confidence Vendor file name mxparser High Vendor jar package name github Highest Vendor jar package name io Highest Vendor jar package name mxparser Highest Vendor jar package name xstream Highest Vendor Manifest automatic-module-name io.github.xstream.mxparser Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname mxparser Medium Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Vendor Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Vendor Manifest x-build-os Linux Low Vendor Manifest x-build-time 2021-08-18T22:35:34Z Low Vendor Manifest x-builder Maven 3.8.1 Low Vendor Manifest x-compile-source 1.4 Low Vendor Manifest x-compile-target 1.4 Low Vendor pom artifactid mxparser Low Vendor pom developer id mxparser Medium Vendor pom developer name XStream Committers Medium Vendor pom groupid io.github.x-stream Highest Vendor pom name MXParser High Vendor pom url http://x-stream.github.io/mxparser Highest Product file name mxparser High Product jar package name github Highest Product jar package name io Highest Product jar package name mxparser Highest Product jar package name xstream Highest Product Manifest automatic-module-name io.github.xstream.mxparser Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name MXParser Medium Product Manifest bundle-symbolicname mxparser Medium Product Manifest Implementation-Title MXParser High Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Product Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Product Manifest specification-title MXParser Medium Product Manifest x-build-os Linux Low Product Manifest x-build-time 2021-08-18T22:35:34Z Low Product Manifest x-builder Maven 3.8.1 Low Product Manifest x-compile-source 1.4 Low Product Manifest x-compile-target 1.4 Low Product pom artifactid mxparser Highest Product pom developer id mxparser Low Product pom developer name XStream Committers Low Product pom groupid io.github.x-stream Highest Product pom name MXParser High Product pom url http://x-stream.github.io/mxparser Medium Version file version 1.2.2 High Version Manifest Bundle-Version 1.2.2 High Version Manifest Implementation-Version 1.2.2 High Version pom version 1.2.2 Highest
pkg:maven/io.github.x-stream/mxparser@1.2.2 (Confidence :High) nativeimage-23.1.2.jarDescription:
A framework that allows to customize native image generation. License:
Universal Permissive License, Version 1.0: http://opensource.org/licenses/UPL File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/graalvm/sdk/nativeimage/23.1.2/nativeimage-23.1.2.jar
MD5: bd492b0ac8b2711d5e59ec24467fb2f7
SHA1: f5e116ec7e2f59c6975229aa762b7a07598e77a0
SHA256: b20c00823c194cadcafc8e853b96a5754e641b467dc56634e738d756b308ad9a
Evidence Type Source Name Value Confidence Vendor file name nativeimage High Vendor jar package name graalvm Highest Vendor jar package name graalvm Low Vendor jar package name nativeimage Highest Vendor jar package name nativeimage Low Vendor jar package name oracle Highest Vendor jar (hint) package name sun Highest Vendor pom artifactid nativeimage Low Vendor pom developer email graalvm-dev@oss.oracle.com Low Vendor pom developer name GraalVM Development Medium Vendor pom developer org Oracle Corporation Medium Vendor pom developer org URL http://www.graalvm.org/ Medium Vendor pom groupid org.graalvm.sdk Highest Vendor pom name Nativeimage High Vendor pom url oracle/graal Highest Product file name nativeimage High Product jar package name graalvm Highest Product jar package name nativeimage Highest Product jar package name nativeimage Low Product jar package name oracle Highest Product pom artifactid nativeimage Highest Product pom developer email graalvm-dev@oss.oracle.com Low Product pom developer name GraalVM Development Low Product pom developer org Oracle Corporation Low Product pom developer org URL http://www.graalvm.org/ Low Product pom groupid org.graalvm.sdk Highest Product pom name Nativeimage High Product pom url oracle/graal High Version file version 23.1.2 High Version pom version 23.1.2 Highest
navigation.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/navigation/navigation.module.jsMD5: 31b789b22d9661d7e6e08d907f72e8a7SHA1: cdbc912ce5e7cc33b0c59e2adcb1c02775b1743aSHA256: 6b85d74cde05b6cbdb685f30ffeb0f2f926599fe54eb67d7a8a851aaefb15713
Evidence Type Source Name Value Confidence
navigation.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/navigation/navigation.module.min.jsMD5: 1db8d2a46b86a1b6875504ede01cbfafSHA1: a6265ca6a82afbf2e507a7b19b67c8650ef3361bSHA256: 1181819e7395c16c14d96d46fdde5f8b15d544638750a9ab5efc1b228197c4d6
Evidence Type Source Name Value Confidence
navigation.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/navigation/navigation.nomodule.jsMD5: 74f3ef0259f99df98c136eaab4bf48e3SHA1: f9f8703e3a384100d90cc2ff17c6f7f8440a8c8eSHA256: f25cc9c06161b9b0c0fa8152e25277913060764d309b7b2de35eec7f04568158
Evidence Type Source Name Value Confidence
navigation.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/navigation/navigation.nomodule.min.jsMD5: b1d9282f5a6bb93cd99e7fd8ebd8633cSHA1: d15d35a7f70a0b0bc57106bfd1cbb814526a8dc8SHA256: 18a8ab74dc07b60cb40d57b5aa6a672ae00a22c476c46eeb771bd20e477d5c4d
Evidence Type Source Name Value Confidence
net.bytebuddy.byte-buddy-1.17.6.jarDescription:
Byte Buddy is a Java library for creating Java classes at run time. This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/net.bytebuddy.byte-buddy-1.17.6.jar
MD5: 8fc1457d342211ca6b76691d09fe982f
SHA1: 8c70cbc6950b2ae5291a98d5003e06406d633803
SHA256: d26382a839cb26d5c62a0b0f04715bcef55a531f96ac6ce40de452a1c0539e70
Evidence Type Source Name Value Confidence Vendor file name net.bytebuddy.byte-buddy High Vendor jar package name bytebuddy Highest Vendor jar package name meta-inf Low Vendor jar package name net Highest Vendor jar package name versions Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Vendor Manifest multi-release true Low Product file name net.bytebuddy.byte-buddy High Product jar package name asm Highest Product jar package name build Highest Product jar package name bytebuddy Highest Product jar package name net Highest Product jar package name net Low Product jar package name versions Low Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Byte Buddy (without dependencies) Medium Product Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Product Manifest multi-release true Low Version file name net.bytebuddy.byte-buddy Medium Version file version 1.17.6 High Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 1.17.6 High
Related Dependencies byte-buddy-1.17.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/net/bytebuddy/byte-buddy/1.17.6/byte-buddy-1.17.6.jar MD5: 8fc1457d342211ca6b76691d09fe982f SHA1: 8c70cbc6950b2ae5291a98d5003e06406d633803 SHA256: d26382a839cb26d5c62a0b0f04715bcef55a531f96ac6ce40de452a1c0539e70 pkg:maven/net.bytebuddy/byte-buddy@1.17.6 net.bytebuddy.byte-buddy-1.17.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/net.bytebuddy.byte-buddy-1.17.6.jar MD5: 8fc1457d342211ca6b76691d09fe982f SHA1: 8c70cbc6950b2ae5291a98d5003e06406d633803 SHA256: d26382a839cb26d5c62a0b0f04715bcef55a531f96ac6ce40de452a1c0539e70 objenesis-3.3.jarDescription:
A library for instantiating Java objects License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/objenesis/objenesis/3.3/objenesis-3.3.jar
MD5: ab0e0b2ab81affdd7f38bcc60fd85571
SHA1: 1049c09f1de4331e8193e579448d0916d75b7631
SHA256: 02dfd0b0439a5591e35b708ed2f5474eb0948f53abf74637e959b8e4ef69bfeb
Evidence Type Source Name Value Confidence Vendor file name objenesis High Vendor jar package name objenesis Highest Vendor Manifest automatic-module-name org.objenesis Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname org.objenesis Medium Vendor Manifest Implementation-Vendor Joe Walnes, Henri Tremblay, Leonardo Mesquita High Vendor Manifest specification-vendor Joe Walnes, Henri Tremblay, Leonardo Mesquita Low Vendor pom artifactid objenesis Low Vendor pom groupid org.objenesis Highest Vendor pom name Objenesis High Vendor pom parent-artifactid objenesis-parent Low Product file name objenesis High Product jar package name objenesis Highest Product Manifest automatic-module-name org.objenesis Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Objenesis Medium Product Manifest bundle-symbolicname org.objenesis Medium Product Manifest Implementation-Title Objenesis High Product Manifest specification-title Objenesis Medium Product pom artifactid objenesis Highest Product pom groupid org.objenesis Highest Product pom name Objenesis High Product pom parent-artifactid objenesis-parent Medium Version file version 3.3 High Version Manifest Implementation-Version 3.3 High Version pom version 3.3 Highest
pkg:maven/org.objenesis/objenesis@3.3 (Confidence :High) opencensus-api-0.31.1.jarDescription:
null License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opencensus/opencensus-api/0.31.1/opencensus-api-0.31.1.jar
MD5: a5e7092bb89baaaee424f5a7b20d1bad
SHA1: 66a60c7201c2b8b20ce495f0295b32bb0ccbbc57
SHA256: f1474d47f4b6b001558ad27b952e35eda5cc7146788877fc52938c6eba24b382
Evidence Type Source Name Value Confidence Vendor file name opencensus-api High Vendor jar package name io Highest Vendor jar package name opencensus Highest Vendor Manifest source-compatibility 1.7 Low Vendor Manifest target-compatibility 1.7 Low Vendor pom artifactid opencensus-api Low Vendor pom developer email census-developers@googlegroups.com Low Vendor pom developer id io.opencensus Medium Vendor pom developer name OpenCensus Contributors Medium Vendor pom developer org OpenCensus Authors Medium Vendor pom developer org URL https://www.opencensus.io Medium Vendor pom groupid io.opencensus Highest Vendor pom name OpenCensus High Vendor pom url census-instrumentation/opencensus-java Highest Product file name opencensus-api High Product jar package name io Highest Product jar package name opencensus Highest Product Manifest Implementation-Title opencensus-api High Product Manifest source-compatibility 1.7 Low Product Manifest target-compatibility 1.7 Low Product pom artifactid opencensus-api Highest Product pom developer email census-developers@googlegroups.com Low Product pom developer id io.opencensus Low Product pom developer name OpenCensus Contributors Low Product pom developer org OpenCensus Authors Low Product pom developer org URL https://www.opencensus.io Low Product pom groupid io.opencensus Highest Product pom name OpenCensus High Product pom url census-instrumentation/opencensus-java High Version file version 0.31.1 High Version Manifest Implementation-Version 0.31.1 High Version pom version 0.31.1 Highest
pkg:maven/io.opencensus/opencensus-api@0.31.1 (Confidence :High) opencensus-contrib-http-util-0.31.1.jarDescription:
null License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opencensus/opencensus-contrib-http-util/0.31.1/opencensus-contrib-http-util-0.31.1.jar
MD5: 9ecc9c428eb87dc734ae8d07b820ce26
SHA1: 3c13fc5715231fadb16a9b74a44d9d59c460cfa8
SHA256: 3ea995b55a4068be22989b70cc29a4d788c2d328d1d50613a7a9afd13fdd2d0a
Evidence Type Source Name Value Confidence Vendor file name opencensus-contrib-http-util High Vendor jar package name contrib Highest Vendor jar package name http Highest Vendor jar package name io Highest Vendor jar package name opencensus Highest Vendor Manifest source-compatibility 1.7 Low Vendor Manifest target-compatibility 1.7 Low Vendor pom artifactid opencensus-contrib-http-util Low Vendor pom developer email census-developers@googlegroups.com Low Vendor pom developer id io.opencensus Medium Vendor pom developer name OpenCensus Contributors Medium Vendor pom developer org OpenCensus Authors Medium Vendor pom developer org URL https://www.opencensus.io Medium Vendor pom groupid io.opencensus Highest Vendor pom name OpenCensus High Vendor pom url census-instrumentation/opencensus-java Highest Product file name opencensus-contrib-http-util High Product jar package name contrib Highest Product jar package name http Highest Product jar package name io Highest Product jar package name opencensus Highest Product Manifest Implementation-Title opencensus-contrib-http-util High Product Manifest source-compatibility 1.7 Low Product Manifest target-compatibility 1.7 Low Product pom artifactid opencensus-contrib-http-util Highest Product pom developer email census-developers@googlegroups.com Low Product pom developer id io.opencensus Low Product pom developer name OpenCensus Contributors Low Product pom developer org OpenCensus Authors Low Product pom developer org URL https://www.opencensus.io Low Product pom groupid io.opencensus Highest Product pom name OpenCensus High Product pom url census-instrumentation/opencensus-java High Version file version 0.31.1 High Version Manifest Implementation-Version 0.31.1 High Version pom version 0.31.1 Highest
pkg:maven/io.opencensus/opencensus-contrib-http-util@0.31.1 (Confidence :High) opentelemetry-sdk-1.55.0.jarDescription:
OpenTelemetry SDK License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk/1.55.0/opentelemetry-sdk-1.55.0.jar
MD5: 1c5e0a162ef1b99da83cc1a0324c8127
SHA1: 457309ce1ed276bd9b1f4029c97c22721f58f346
SHA256: d63231ea6fd33e0457c776a9aa8ae7ba778379b03119228ec56a5c8c16f9480e
Evidence Type Source Name Value Confidence Vendor file name opentelemetry-sdk High Vendor jar package name io Highest Vendor jar package name opentelemetry Highest Vendor jar package name sdk Highest Vendor Manifest automatic-module-name io.opentelemetry.sdk Medium Vendor pom artifactid opentelemetry-sdk Low Vendor pom developer id opentelemetry Medium Vendor pom developer name OpenTelemetry Medium Vendor pom groupid io.opentelemetry Highest Vendor pom name OpenTelemetry Java High Vendor pom url open-telemetry/opentelemetry-java Highest Product file name opentelemetry-sdk High Product jar package name io Highest Product jar package name opentelemetry Highest Product jar package name sdk Highest Product Manifest automatic-module-name io.opentelemetry.sdk Medium Product Manifest Implementation-Title all High Product pom artifactid opentelemetry-sdk Highest Product pom developer id opentelemetry Low Product pom developer name OpenTelemetry Low Product pom groupid io.opentelemetry Highest Product pom name OpenTelemetry Java High Product pom url open-telemetry/opentelemetry-java High Version file version 1.55.0 High Version Manifest Implementation-Version 1.55.0 High Version pom version 1.55.0 Highest
Related Dependencies opentelemetry-context-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-context/1.55.0/opentelemetry-context-1.55.0.jar MD5: f1e3c1cdfad72db43ca23f02c7b442da SHA1: a3e7c14152b6b6c62e0c64f991791fa0c5cbf02d SHA256: f34a4718b70446ec462703ced5cc2c9ad4c9b7c69dcb41d0f032ba51c625a3dd pkg:maven/io.opentelemetry/opentelemetry-context@1.55.0 opentelemetry-exporter-logging-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-exporter-logging/1.55.0/opentelemetry-exporter-logging-1.55.0.jar MD5: db368c1dd575972e8685cafb06f7c02c SHA1: e15ff02ddc81aa8e07438b40c8aa9eb8297275eb SHA256: 068ce0d75097e6ac655e179aa007d816204e8ac8892f193e15a7fa8d9b1c3ef8 pkg:maven/io.opentelemetry/opentelemetry-exporter-logging@1.55.0 opentelemetry-sdk-common-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk-common/1.55.0/opentelemetry-sdk-common-1.55.0.jar MD5: d2b6d07f9a62cc3011ab97d903e68acc SHA1: c43e69b259fe060b67520e4f011fa776a2dcca58 SHA256: e28bb83d0ae5a760ba95952daf820180ee7defb0c5783c9d21f9c00ada80020e pkg:maven/io.opentelemetry/opentelemetry-sdk-common@1.55.0 opentelemetry-sdk-extension-autoconfigure-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk-extension-autoconfigure/1.55.0/opentelemetry-sdk-extension-autoconfigure-1.55.0.jar MD5: e1ee40b0fa7f827b1f883e620c8af5cd SHA1: c513f20e376a495dc24fd28793632736660a705c SHA256: 88c32085a6f9cdd7725514ed1bbec3b196ecbd97d9375ca9b7f84c6163a48f1e pkg:maven/io.opentelemetry/opentelemetry-sdk-extension-autoconfigure@1.55.0 opentelemetry-sdk-extension-autoconfigure-spi-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk-extension-autoconfigure-spi/1.55.0/opentelemetry-sdk-extension-autoconfigure-spi-1.55.0.jar MD5: b3d1b801b1ea32432690e43742e652c6 SHA1: f20fc03f7ea80cd062520f6cda3b1a61a107860f SHA256: 3ee1f647238bb77df7b7bde47bc87a35a7807b3c5bb389ca81b0ba16c77824ff pkg:maven/io.opentelemetry/opentelemetry-sdk-extension-autoconfigure-spi@1.55.0 opentelemetry-sdk-logs-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk-logs/1.55.0/opentelemetry-sdk-logs-1.55.0.jar MD5: 029da7104d349af7cb68f33f545d4747 SHA1: 0b4c62673fb2f2385b691d6600a194f98fbc8625 SHA256: d917bb833899057c7cbdbcc30290e816071b90e52c965693aaad4cc1b32ecc11 pkg:maven/io.opentelemetry/opentelemetry-sdk-logs@1.55.0 opentelemetry-sdk-metrics-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk-metrics/1.55.0/opentelemetry-sdk-metrics-1.55.0.jar MD5: 3a1985ee03d33b6251bf10dbd5174d98 SHA1: 2db32c617c5d37c9ee69d58009edcc9a12ba6a24 SHA256: 6219d69c3abdd6113bee35df94826f48e84b742041f5124b5857a2b801f74573 pkg:maven/io.opentelemetry/opentelemetry-sdk-metrics@1.55.0 opentelemetry-sdk-trace-1.55.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/opentelemetry/opentelemetry-sdk-trace/1.55.0/opentelemetry-sdk-trace-1.55.0.jar MD5: b8b03a9eee54376a6874dfc8cb4714a6 SHA1: b0334b4edb3d14e181f9f4fdc40a0dd5a6bcbffd SHA256: e593660b9fad8bfdb5e981ccd392aa030f788d577c55f8bac3b6c4c6dae509bb pkg:maven/io.opentelemetry/opentelemetry-sdk-trace@1.55.0 opentest4j-1.2.0.jarDescription:
Open Test Alliance for the JVM License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/opentest4j/opentest4j/1.2.0/opentest4j-1.2.0.jar
MD5: 45c9a837c21f68e8c93e85b121e2fb90
SHA1: 28c11eb91f9b6d8e200631d46e20a7f407f2a046
SHA256: 58812de60898d976fb81ef3b62da05c6604c18fd4a249f5044282479fc286af2
Evidence Type Source Name Value Confidence Vendor file name opentest4j High Vendor jar package name opentest4j Highest Vendor Manifest build-date 2019-06-06 Low Vendor Manifest build-revision 75136304fab712895090c9c4678dc72ccbcb5e21 Low Vendor Manifest build-time 21:23:52.218+0200 Low Vendor Manifest bundle-symbolicname org.opentest4j Medium Vendor Manifest Implementation-Vendor opentest4j.org High Vendor Manifest specification-vendor opentest4j.org Low Vendor pom artifactid opentest4j Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email Matthias.Merdes@heidelberg-mobil.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.opentest4j Highest Vendor pom name org.opentest4j:opentest4j High Vendor pom url ota4j-team/opentest4j Highest Product file name opentest4j High Product jar package name opentest4j Highest Product Manifest build-date 2019-06-06 Low Product Manifest build-revision 75136304fab712895090c9c4678dc72ccbcb5e21 Low Product Manifest build-time 21:23:52.218+0200 Low Product Manifest Bundle-Name opentest4j Medium Product Manifest bundle-symbolicname org.opentest4j Medium Product Manifest Implementation-Title opentest4j High Product Manifest specification-title opentest4j Medium Product pom artifactid opentest4j Highest Product pom developer email business@johanneslink.net Low Product pom developer email mail@marcphilipp.de Low Product pom developer email Matthias.Merdes@heidelberg-mobil.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer name Johannes Link Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.opentest4j Highest Product pom name org.opentest4j:opentest4j High Product pom url ota4j-team/opentest4j High Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High Version pom version 1.2.0 Highest
pkg:maven/org.opentest4j/opentest4j@1.2.0 (Confidence :High) opentest4j-1.3.0.jarDescription:
Open Test Alliance for the JVM License:
The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/opentest4j/opentest4j/1.3.0/opentest4j-1.3.0.jar
MD5: 03c404f727531f3fd3b4c73997899327
SHA1: 152ea56b3a72f655d4fd677fc0ef2596c3dd5e6e
SHA256: 48e2df636cab6563ced64dcdff8abb2355627cb236ef0bf37598682ddf742f1b
Evidence Type Source Name Value Confidence Vendor file name opentest4j High Vendor jar package name opentest4j Highest Vendor Manifest build-date 2023-07-06 Low Vendor Manifest build-revision 214973bfa4e7e9be7d04e623202cc4147c7036d2 Low Vendor Manifest build-time 14:25:06.116+0200 Low Vendor Manifest bundle-symbolicname org.opentest4j Medium Vendor Manifest Implementation-Vendor opentest4j.org High Vendor Manifest specification-vendor opentest4j.org Low Vendor pom artifactid opentest4j Low Vendor pom developer email business@johanneslink.net Low Vendor pom developer email mail@marcphilipp.de Low Vendor pom developer email matthias.merdes@heidelpay.com Low Vendor pom developer email sam@sambrannen.com Low Vendor pom developer email stefan.bechtold@me.com Low Vendor pom developer id bechte Medium Vendor pom developer id jlink Medium Vendor pom developer id marcphilipp Medium Vendor pom developer id mmerdes Medium Vendor pom developer id sbrannen Medium Vendor pom developer name Johannes Link Medium Vendor pom developer name Marc Philipp Medium Vendor pom developer name Matthias Merdes Medium Vendor pom developer name Sam Brannen Medium Vendor pom developer name Stefan Bechtold Medium Vendor pom groupid org.opentest4j Highest Vendor pom name org.opentest4j:opentest4j High Vendor pom url ota4j-team/opentest4j Highest Product file name opentest4j High Product jar package name opentest4j Highest Product Manifest build-date 2023-07-06 Low Product Manifest build-revision 214973bfa4e7e9be7d04e623202cc4147c7036d2 Low Product Manifest build-time 14:25:06.116+0200 Low Product Manifest Bundle-Name opentest4j Medium Product Manifest bundle-symbolicname org.opentest4j Medium Product Manifest Implementation-Title opentest4j High Product Manifest specification-title opentest4j Medium Product pom artifactid opentest4j Highest Product pom developer email business@johanneslink.net Low Product pom developer email mail@marcphilipp.de Low Product pom developer email matthias.merdes@heidelpay.com Low Product pom developer email sam@sambrannen.com Low Product pom developer email stefan.bechtold@me.com Low Product pom developer id bechte Low Product pom developer id jlink Low Product pom developer id marcphilipp Low Product pom developer id mmerdes Low Product pom developer id sbrannen Low Product pom developer name Johannes Link Low Product pom developer name Marc Philipp Low Product pom developer name Matthias Merdes Low Product pom developer name Sam Brannen Low Product pom developer name Stefan Bechtold Low Product pom groupid org.opentest4j Highest Product pom name org.opentest4j:opentest4j High Product pom url ota4j-team/opentest4j High Version file version 1.3.0 High Version Manifest Bundle-Version 1.3.0 High Version Manifest Implementation-Version 1.3.0 High Version pom version 1.3.0 Highest
pkg:maven/org.opentest4j/opentest4j@1.3.0 (Confidence :High) org.antlr.antlr4-runtime-4.13.2.jarDescription:
The ANTLR 4 Runtime License:
https://www.antlr.org/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.antlr.antlr4-runtime-4.13.2.jar
MD5: eecf1908f0cfff10f8bb82878b5ca401
SHA1: fc3db6d844df652a3d5db31c87fa12757f13691d
SHA256: dd3e8a13a2d669bf84fb8d834de35ce4875f27157698d206241ec8488aadcaf7
Evidence Type Source Name Value Confidence Vendor file name org.antlr.antlr4-runtime High Vendor jar package name antlr Highest Vendor jar package name antlr Low Vendor jar package name runtime Highest Vendor jar package name runtime Low Vendor jar package name v4 Low Vendor Manifest automatic-module-name org.antlr.antlr4.runtime Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.antlr.org/ Low Vendor Manifest bundle-symbolicname org.antlr.antlr4-runtime Medium Vendor Manifest Implementation-Vendor ANTLR High Product file name org.antlr.antlr4-runtime High Product jar package name antlr Highest Product jar package name runtime Highest Product jar package name runtime Low Product jar package name v4 Low Product Manifest automatic-module-name org.antlr.antlr4.runtime Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.antlr.org/ Low Product Manifest Bundle-Name ANTLR 4 Runtime Medium Product Manifest bundle-symbolicname org.antlr.antlr4-runtime Medium Product Manifest Implementation-Title ANTLR 4 Runtime High Version file version 4.13.2 High Version Manifest Implementation-Version 4.13.2 High
Related Dependencies antlr4-runtime-4.13.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/antlr/antlr4-runtime/4.13.2/antlr4-runtime-4.13.2.jar MD5: eecf1908f0cfff10f8bb82878b5ca401 SHA1: fc3db6d844df652a3d5db31c87fa12757f13691d SHA256: dd3e8a13a2d669bf84fb8d834de35ce4875f27157698d206241ec8488aadcaf7 pkg:maven/org.antlr/antlr4-runtime@4.13.2 org.antlr.antlr4-runtime-4.13.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.antlr.antlr4-runtime-4.13.2.jar MD5: eecf1908f0cfff10f8bb82878b5ca401 SHA1: fc3db6d844df652a3d5db31c87fa12757f13691d SHA256: dd3e8a13a2d669bf84fb8d834de35ce4875f27157698d206241ec8488aadcaf7 org.apache.camel.camel-api-4.16.0.jar (shaded: org.apache.camel:camel-api:4.16.0)Description:
The Camel API License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-api-4.16.0.jar/META-INF/maven/org.apache.camel/camel-api/pom.xml
MD5: b8559fefb3d61f7240361cb07c5bd632
SHA1: 4398efe9b9674fa57143a1fb8f7cf69b135e1e7f
SHA256: 8c23c50b4a609f9eafa867d9aaea9f428ac14ae4bed3eadb850debb7b8a5eb0a
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-api Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: API High Vendor pom parent-artifactid core Low Product pom artifactid camel-api Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: API High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-api-4.16.0.jar (shaded: org.apache.camel:camel-api:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-api-4.16.0.jar/META-INF/maven/org.apache.camel/camel-api/pom.xml MD5: b8559fefb3d61f7240361cb07c5bd632 SHA1: 4398efe9b9674fa57143a1fb8f7cf69b135e1e7f SHA256: 8c23c50b4a609f9eafa867d9aaea9f428ac14ae4bed3eadb850debb7b8a5eb0a pkg:maven/org.apache.camel/camel-api@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-base-4.16.0.jar (shaded: org.apache.camel:camel-base:4.16.0)Description:
The Base Camel Framework License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-base-4.16.0.jar/META-INF/maven/org.apache.camel/camel-base/pom.xml
MD5: eaa68109dd3afd1221b2a1df06e7d9ab
SHA1: c439401e7c34e54bb4f0f294430f35a90f9836ee
SHA256: f0100ecd9c631a6794135db3dea0ea033ba089791759718c44f03ee6cd365160
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-base Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Base High Vendor pom parent-artifactid core Low Product pom artifactid camel-base Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Base High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-base-4.16.0.jar (shaded: org.apache.camel:camel-base:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-base-4.16.0.jar/META-INF/maven/org.apache.camel/camel-base/pom.xml MD5: eaa68109dd3afd1221b2a1df06e7d9ab SHA1: c439401e7c34e54bb4f0f294430f35a90f9836ee SHA256: f0100ecd9c631a6794135db3dea0ea033ba089791759718c44f03ee6cd365160 pkg:maven/org.apache.camel/camel-base@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-base-engine-4.16.0.jar (shaded: org.apache.camel:camel-base-engine:4.16.0)Description:
The Base Engine Camel Framework License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-base-engine-4.16.0.jar/META-INF/maven/org.apache.camel/camel-base-engine/pom.xml
MD5: e60bc48f016a9c862a4c724a62744431
SHA1: c5282e19ecea31c83efc087a48b8d8b137400760
SHA256: b07cbad0126cc2508bf51dce43d56d6128a12ea0318a4af06a5acc87a79b4344
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-base-engine Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Base Engine High Vendor pom parent-artifactid core Low Product pom artifactid camel-base-engine Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Base Engine High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-base-engine-4.16.0.jar (shaded: org.apache.camel:camel-base-engine:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-base-engine-4.16.0.jar/META-INF/maven/org.apache.camel/camel-base-engine/pom.xml MD5: e60bc48f016a9c862a4c724a62744431 SHA1: c5282e19ecea31c83efc087a48b8d8b137400760 SHA256: b07cbad0126cc2508bf51dce43d56d6128a12ea0318a4af06a5acc87a79b4344 pkg:maven/org.apache.camel/camel-base-engine@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-componentdsl-4.16.0.jar (shaded: org.apache.camel:camel-componentdsl:4.16.0)Description:
The Camel Component DSL License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-componentdsl-4.16.0.jar/META-INF/maven/org.apache.camel/camel-componentdsl/pom.xml
MD5: 81cbc74d3000ac07ec19019ee79ded43
SHA1: 289c25af37043368645b8f94bef61aa96006d80d
SHA256: 0e57d7033209f0974fc4fc69560ce957ac783bdfd56c426953a7b1fb60c4a518
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-componentdsl Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Component DSL High Vendor pom parent-artifactid dsl Low Product pom artifactid camel-componentdsl Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Component DSL High Product pom parent-artifactid dsl Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-componentdsl-4.16.0.jar (shaded: org.apache.camel:camel-componentdsl:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-componentdsl-4.16.0.jar/META-INF/maven/org.apache.camel/camel-componentdsl/pom.xml MD5: 81cbc74d3000ac07ec19019ee79ded43 SHA1: 289c25af37043368645b8f94bef61aa96006d80d SHA256: 0e57d7033209f0974fc4fc69560ce957ac783bdfd56c426953a7b1fb60c4a518 pkg:maven/org.apache.camel/camel-componentdsl@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-catalog-4.16.0.jar (shaded: org.apache.camel:camel-core-catalog:4.16.0)Description:
The Camel Core Catalog License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-core-catalog-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-catalog/pom.xml
MD5: f8c1f74ce5e59f414c763e7f13251d67
SHA1: 5dad93df999e49b440413e09fa4d76518df7e9e8
SHA256: 1cb1bf15015fc7fb667d3c656ac8b0315d3a9fb9f87fe35d8314e292526f319d
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-core-catalog Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Core Catalog High Vendor pom parent-artifactid core Low Product pom artifactid camel-core-catalog Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Core Catalog High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-core-catalog-4.16.0.jar (shaded: org.apache.camel:camel-core-catalog:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-catalog-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-catalog/pom.xml MD5: f8c1f74ce5e59f414c763e7f13251d67 SHA1: 5dad93df999e49b440413e09fa4d76518df7e9e8 SHA256: 1cb1bf15015fc7fb667d3c656ac8b0315d3a9fb9f87fe35d8314e292526f319d pkg:maven/org.apache.camel/camel-core-catalog@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-engine-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-core-engine-4.16.0.jarMD5: b9d717c0d1fb31854058e553d6da4fccSHA1: 47fc90a9555ecbc98b20f41704f51b5abe3ac62cSHA256: 377a95fe31dd96aa0541b059c380177d0cc464019baf5e6e7647e40b9b380c3b
Evidence Type Source Name Value Confidence Vendor file name org.apache.camel.camel-core-engine High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name camel Low Vendor jar package name impl Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Product file name org.apache.camel.camel-core-engine High Product jar package name camel Highest Product jar package name camel Low Product jar package name impl Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Camel :: Core Engine High Version file version 4.16.0 High Version Manifest Implementation-Version 4.16.0 High
Related Dependencies CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-languages-4.16.0.jar (shaded: org.apache.camel:camel-core-languages:4.16.0)Description:
Camel Core Languages License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-core-languages-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-languages/pom.xml
MD5: 6695f48602ba77a1dddd9cc69c284409
SHA1: 07b854d4736adfd96fbfdd8f5ae00d7fbd26a382
SHA256: e81f88f095874a6b9c48656763ee01ef0eee0ca40e7a2c04519907aaa40c3a36
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-core-languages Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Core Languages High Vendor pom parent-artifactid core Low Product pom artifactid camel-core-languages Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Core Languages High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-core-languages-4.16.0.jar (shaded: org.apache.camel:camel-core-languages:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-languages-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-languages/pom.xml MD5: 6695f48602ba77a1dddd9cc69c284409 SHA1: 07b854d4736adfd96fbfdd8f5ae00d7fbd26a382 SHA256: e81f88f095874a6b9c48656763ee01ef0eee0ca40e7a2c04519907aaa40c3a36 pkg:maven/org.apache.camel/camel-core-languages@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-model-4.16.0.jar (shaded: org.apache.camel:camel-core-model:4.16.0)Description:
Camel model License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-core-model-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-model/pom.xml
MD5: 6e656068f50855ac4e28dde86f9444d4
SHA1: 2070c7b69c08f54c97c8873c1f7b9f9b60aa9fa8
SHA256: 5a17861ebf44c6c9375e70471996e1ab49becb5d25a7b7492ae38cce08ee4100
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-core-model Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Core Model High Vendor pom parent-artifactid core Low Product pom artifactid camel-core-model Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Core Model High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-core-model-4.16.0.jar (shaded: org.apache.camel:camel-core-model:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-model-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-model/pom.xml MD5: 6e656068f50855ac4e28dde86f9444d4 SHA1: 2070c7b69c08f54c97c8873c1f7b9f9b60aa9fa8 SHA256: 5a17861ebf44c6c9375e70471996e1ab49becb5d25a7b7492ae38cce08ee4100 pkg:maven/org.apache.camel/camel-core-model@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-model-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-model-4.16.0.jarMD5: 9b2306c6feb4c5a0bd89412b9097e426SHA1: 56dd95d102c749883955dbdcbbfb03c794cac709SHA256: d2c14e1709572fcf588c07f79fe176d144defd6d4f3661da8d4527b62fded8be
Evidence Type Source Name Value Confidence Vendor file name org.apache.camel.camel-core-model High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name camel Low Vendor jar package name model Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Product file name org.apache.camel.camel-core-model High Product jar package name camel Highest Product jar package name camel Low Product jar package name model Highest Product jar package name model Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Camel :: Core Model High Version file version 4.16.0 High Version Manifest Implementation-Version 4.16.0 High
Related Dependencies org.apache.camel.camel-core-languages-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-languages-4.16.0.jar MD5: f1c9b3e0ee1aaa1068e91aeadc5aa297 SHA1: 978dbf3b6cf548a2cfd77a5d9d10e2026653fe49 SHA256: a41243a7e0252b3358493970c1e09525a7b7939dff9ad238656fc29e7055c002 org.apache.camel.camel-core-processor-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-processor-4.16.0.jar MD5: 824c438108b62aa0540894ba4c780c0e SHA1: a8604c2f62c24699e6cb472b7d386db97ae10d1d SHA256: ebbf7f65aff116b2b2fd275ef8818cfe6f0073432ce080f11952bd2894473628 org.apache.camel.camel-core-reifier-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-reifier-4.16.0.jar MD5: 2aa4d8d222b4408e15375f7ba5f548cf SHA1: 000bf9b22e232b8c74a085ca5d4e5661d89116e7 SHA256: 83cccb315d600c2d27a87183c25a0ce5ca1e415bd64e3d2635b7c6d95f0178a7 org.apache.camel.camel-endpointdsl-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-endpointdsl-4.16.0.jar MD5: 8e6de7bd8561446a56e0d109fc5b13c8 SHA1: 5bb36eabf574c853f3b05fd05edb6ef1d7e3c57a SHA256: 14dd3e3a19794d67ccf0eae4e96e75760d7e043072e2e8bc83962c8fd327c9a6 org.apache.camel.camel-main-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-main-4.16.0.jar MD5: 188ab049c269a7dbde3d4f6d091dda04 SHA1: a3e24c3551d82923075d40fd52af0fa38befa865 SHA256: c050e35b70fdc5090d777e98acfc60a3fb3bdf5d3552677972c9d0d1f9b75320 org.apache.camel.camel-management-api-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-management-api-4.16.0.jar MD5: 3a4b446c957a7fb2047782749bf3cb1d SHA1: 9191bd0b4f4f0ce4c1dcfe4a7a3a98e8c5a125fc SHA256: 790d46f6e4f87b87fdb16927fe5d791c606ebf15cab8bcf8d732d76fb5e14c86 org.apache.camel.camel-mapstruct-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-mapstruct-4.16.0.jar MD5: bf8b125182e4644556b84668875ffcf3 SHA1: e3177116b1a488bc6fb5a4af956c14f05d0ddc8b SHA256: 0857681c8fdab10813218d351252a6d813147326895489f13f34f72a81bef420 org.apache.camel.camel-microprofile-config-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-microprofile-config-4.16.0.jar MD5: 896de5b13fc2dcd2add1963cb45ff8c4 SHA1: 03fbb4c83c91b8005a49283f2877d5e8764cb8ab SHA256: e7c6c2bdeedea2cb4b832a9801f74cf9ecbfbbafb6f3b54b4a1f114d21ba84ce org.apache.camel.camel-support-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-support-4.16.0.jar MD5: a3f02e896fefd4279dbe031523d56590 SHA1: 856e56c01fdb7a13e31f929db158b2b4dda38bc4 SHA256: 704ceada175427f9d9e2dfda31bcebbd6ede5505ae4d4435faa8c7e4ba318357 org.apache.camel.camel-tooling-model-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-tooling-model-4.16.0.jar MD5: 6daabd17a08429e2fd7768964e7716f4 SHA1: 5fd9a8a6381c7b6943ab3ae9b0f1b316b7481d69 SHA256: 2772798c2708832c332a5934b7c1be7a3db2c8653e73f4cdbfb3c0217ddb9adb org.apache.camel.camel-util-json-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-util-json-4.16.0.jar MD5: 52d27634b0166e93310e971c9b4c378c SHA1: 7b65c0a0bbc8eba6feab902bbc82f6039e78a0b0 SHA256: e5e491312130e49647018c2bcdc8d955d38f09f51fd831c9c0bb79672d3a0702 org.apache.camel.camel-xml-jaxp-util-4.16.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-xml-jaxp-util-4.16.0.jar MD5: e413a268f9eca948424c4504bdbf1d74 SHA1: 4cef63bcb803222a2ae54db8c9e571ed572e9306 SHA256: 4854b0272d84418de052a3fe2cdbc8b4b061f5a0513f31196edf2ba829979d25 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-processor-4.16.0.jar (shaded: org.apache.camel:camel-core-processor:4.16.0)Description:
Camel core processors License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-core-processor-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-processor/pom.xml
MD5: 4fbefd9c591ce477c41497cddd53043e
SHA1: 26d344b1d0e5db5a56c067ee2796ca1c626d82c4
SHA256: 4b4487d2976eaa9ce6ac662f1efad485746a6f613b677b0c484c1a6eb7da448e
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-core-processor Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Core Processor High Vendor pom parent-artifactid core Low Product pom artifactid camel-core-processor Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Core Processor High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-core-processor-4.16.0.jar (shaded: org.apache.camel:camel-core-processor:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-processor-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-processor/pom.xml MD5: 4fbefd9c591ce477c41497cddd53043e SHA1: 26d344b1d0e5db5a56c067ee2796ca1c626d82c4 SHA256: 4b4487d2976eaa9ce6ac662f1efad485746a6f613b677b0c484c1a6eb7da448e pkg:maven/org.apache.camel/camel-core-processor@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-core-reifier-4.16.0.jar (shaded: org.apache.camel:camel-core-reifier:4.16.0)Description:
Camel model to processor reifiers License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-core-reifier-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-reifier/pom.xml
MD5: 8618604cdf3596c727bb23d3218d8b19
SHA1: 2844e79fd00c59b6559180e7345cc8c491b9a618
SHA256: 8c0dca36a833bb831671a69a5f953749b08ce088384c754a0919a1ed4d6e3508
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-core-reifier Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Core Reifier High Vendor pom parent-artifactid core Low Product pom artifactid camel-core-reifier Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Core Reifier High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-core-reifier-4.16.0.jar (shaded: org.apache.camel:camel-core-reifier:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-core-reifier-4.16.0.jar/META-INF/maven/org.apache.camel/camel-core-reifier/pom.xml MD5: 8618604cdf3596c727bb23d3218d8b19 SHA1: 2844e79fd00c59b6559180e7345cc8c491b9a618 SHA256: 8c0dca36a833bb831671a69a5f953749b08ce088384c754a0919a1ed4d6e3508 pkg:maven/org.apache.camel/camel-core-reifier@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-endpointdsl-4.16.0.jar (shaded: org.apache.camel:camel-endpointdsl:4.16.0)Description:
The Camel Endpoint DSL License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-endpointdsl-4.16.0.jar/META-INF/maven/org.apache.camel/camel-endpointdsl/pom.xml
MD5: ccb04b7c58ece53530fa409e119f2019
SHA1: 112f4c4ebb0bb6ee373594a1015905ec508b0e08
SHA256: aafba87114c916d4f439ccdc7aafb1b702640685bcbe0373eabc073a8965eb42
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-endpointdsl Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Endpoint DSL High Vendor pom parent-artifactid dsl Low Product pom artifactid camel-endpointdsl Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Endpoint DSL High Product pom parent-artifactid dsl Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-endpointdsl-4.16.0.jar (shaded: org.apache.camel:camel-endpointdsl:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-endpointdsl-4.16.0.jar/META-INF/maven/org.apache.camel/camel-endpointdsl/pom.xml MD5: ccb04b7c58ece53530fa409e119f2019 SHA1: 112f4c4ebb0bb6ee373594a1015905ec508b0e08 SHA256: aafba87114c916d4f439ccdc7aafb1b702640685bcbe0373eabc073a8965eb42 pkg:maven/org.apache.camel/camel-endpointdsl@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-main-4.16.0.jar (shaded: org.apache.camel:camel-main:4.16.0)Description:
Camel Main License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-main-4.16.0.jar/META-INF/maven/org.apache.camel/camel-main/pom.xml
MD5: 0e2e28e553ca8a070dfed6290e999d06
SHA1: 4af7b0e70fd192695deac476f80ea1556e5d154c
SHA256: a2e298075ea8cbb7e6dfc3830baa455b6df5ed3e2bf2f64a88de2bc504bb8055
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-main Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Main High Vendor pom parent-artifactid core Low Product pom artifactid camel-main Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Main High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-main-4.16.0.jar (shaded: org.apache.camel:camel-main:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-main-4.16.0.jar/META-INF/maven/org.apache.camel/camel-main/pom.xml MD5: 0e2e28e553ca8a070dfed6290e999d06 SHA1: 4af7b0e70fd192695deac476f80ea1556e5d154c SHA256: a2e298075ea8cbb7e6dfc3830baa455b6df5ed3e2bf2f64a88de2bc504bb8055 pkg:maven/org.apache.camel/camel-main@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-management-api-4.16.0.jar (shaded: org.apache.camel:camel-management-api:4.16.0)Description:
The Camel Management API License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-management-api-4.16.0.jar/META-INF/maven/org.apache.camel/camel-management-api/pom.xml
MD5: 2a457c37600b4b09e7d2e3b1cc1421a1
SHA1: 3a6b9430b009a470f1266ddb9051c9a2676f2ed5
SHA256: a7218c10828aa08bb3d91da0c396d355470820f8344fe2a9371b4c274a60a0e0
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-management-api Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Management API High Vendor pom parent-artifactid core Low Product pom artifactid camel-management-api Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Management API High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-management-api-4.16.0.jar (shaded: org.apache.camel:camel-management-api:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-management-api-4.16.0.jar/META-INF/maven/org.apache.camel/camel-management-api/pom.xml MD5: 2a457c37600b4b09e7d2e3b1cc1421a1 SHA1: 3a6b9430b009a470f1266ddb9051c9a2676f2ed5 SHA256: a7218c10828aa08bb3d91da0c396d355470820f8344fe2a9371b4c274a60a0e0 pkg:maven/org.apache.camel/camel-management-api@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-mapstruct-4.16.0.jar (shaded: org.apache.camel:camel-mapstruct:4.16.0)Description:
Type Conversion using Mapstruct License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-mapstruct-4.16.0.jar/META-INF/maven/org.apache.camel/camel-mapstruct/pom.xml
MD5: 0164270459c774cac392c5b4b15282f5
SHA1: 8802cba6cbd9fbf08529ec3e6d3c60185ace4f3d
SHA256: e09033778bd870a5157abc58bba01005a39f825fa897deb46eaed62510e6649b
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-mapstruct Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Mapstruct High Vendor pom parent-artifactid components Low Product pom artifactid camel-mapstruct Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Mapstruct High Product pom parent-artifactid components Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-mapstruct-4.16.0.jar (shaded: org.apache.camel:camel-mapstruct:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-mapstruct-4.16.0.jar/META-INF/maven/org.apache.camel/camel-mapstruct/pom.xml MD5: 0164270459c774cac392c5b4b15282f5 SHA1: 8802cba6cbd9fbf08529ec3e6d3c60185ace4f3d SHA256: e09033778bd870a5157abc58bba01005a39f825fa897deb46eaed62510e6649b pkg:maven/org.apache.camel/camel-mapstruct@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-microprofile-config-4.16.0.jar (shaded: org.apache.camel:camel-microprofile-config:4.16.0)Description:
Bridging Eclipse MicroProfile Config with Camel properties License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-microprofile-config-4.16.0.jar/META-INF/maven/org.apache.camel/camel-microprofile-config/pom.xml
MD5: 1077fc45a7424bc1972df6cdafeb046b
SHA1: a5a1daeef5bd01f095e232bc134277329dc1bfef
SHA256: e5aba8d2e71c539f0e0d8e1fc08c70d4d225f8184182a4513b0c87c8a594cec1
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-microprofile-config Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: MicroProfile :: Config High Vendor pom parent-artifactid camel-microprofile-parent Low Product pom artifactid camel-microprofile-config Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: MicroProfile :: Config High Product pom parent-artifactid camel-microprofile-parent Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-microprofile-config-4.16.0.jar (shaded: org.apache.camel:camel-microprofile-config:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-microprofile-config-4.16.0.jar/META-INF/maven/org.apache.camel/camel-microprofile-config/pom.xml MD5: 1077fc45a7424bc1972df6cdafeb046b SHA1: a5a1daeef5bd01f095e232bc134277329dc1bfef SHA256: e5aba8d2e71c539f0e0d8e1fc08c70d4d225f8184182a4513b0c87c8a594cec1 pkg:maven/org.apache.camel/camel-microprofile-config@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-support-4.16.0.jar (shaded: org.apache.camel:camel-support:4.16.0)Description:
The Camel Support License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-support-4.16.0.jar/META-INF/maven/org.apache.camel/camel-support/pom.xml
MD5: 7e97ef689926c32a0e7935d6371ccdc9
SHA1: e180b8060d0ee762045763f9897958951e2aba65
SHA256: cb1b0491718251d56c5f44d1e71f4dbd0a9a8d96cf25626ece1be36b828f62ec
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-support Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Support High Vendor pom parent-artifactid core Low Product pom artifactid camel-support Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Support High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-support-4.16.0.jar (shaded: org.apache.camel:camel-support:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-support-4.16.0.jar/META-INF/maven/org.apache.camel/camel-support/pom.xml MD5: 7e97ef689926c32a0e7935d6371ccdc9 SHA1: e180b8060d0ee762045763f9897958951e2aba65 SHA256: cb1b0491718251d56c5f44d1e71f4dbd0a9a8d96cf25626ece1be36b828f62ec pkg:maven/org.apache.camel/camel-support@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-tooling-model-4.16.0.jar (shaded: org.apache.camel:camel-tooling-model:4.16.0)Description:
Tooling Model License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-tooling-model-4.16.0.jar/META-INF/maven/org.apache.camel/camel-tooling-model/pom.xml
MD5: 2ec32fbabaecec395ae8fc17a51f64d2
SHA1: fd53719aef43b256896f155c30a2690433edebb9
SHA256: 852d375cfdf8e8b2c00337681092a52036f844f5b962d3ceab4a3b6a9368b0ae
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-tooling-model Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Tooling :: Model High Vendor pom parent-artifactid tooling Low Product pom artifactid camel-tooling-model Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Tooling :: Model High Product pom parent-artifactid tooling Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-tooling-model-4.16.0.jar (shaded: org.apache.camel:camel-tooling-model:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-tooling-model-4.16.0.jar/META-INF/maven/org.apache.camel/camel-tooling-model/pom.xml MD5: 2ec32fbabaecec395ae8fc17a51f64d2 SHA1: fd53719aef43b256896f155c30a2690433edebb9 SHA256: 852d375cfdf8e8b2c00337681092a52036f844f5b962d3ceab4a3b6a9368b0ae pkg:maven/org.apache.camel/camel-tooling-model@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-util-4.17.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-util-4.17.0.jarMD5: 7a8f182f2de653a5a2c1b9cc4e77a317SHA1: ef1cf9fbf3d316ffecb5229ac6047aaae181b4e5SHA256: 8834943ad996d92bbb855e371b3c1d2d298e16b26d1c65330f73f0029d042225
Evidence Type Source Name Value Confidence Vendor file name org.apache.camel.camel-util High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name camel Low Vendor jar package name util Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Product file name org.apache.camel.camel-util High Product jar package name 21 Highest Product jar package name camel Highest Product jar package name camel Low Product jar package name util Highest Product jar package name util Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Camel :: Util High Product Manifest multi-release true Low Version file version 4.17.0 High Version Manifest Implementation-Version 4.17.0 High
Related Dependencies camel-util-4.17.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/camel-util/4.17.0/camel-util-4.17.0.jar MD5: 7a8f182f2de653a5a2c1b9cc4e77a317 SHA1: ef1cf9fbf3d316ffecb5229ac6047aaae181b4e5 SHA256: 8834943ad996d92bbb855e371b3c1d2d298e16b26d1c65330f73f0029d042225 pkg:maven/org.apache.camel/camel-util@4.17.0 org.apache.camel.camel-util-4.17.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-util-4.17.0.jar MD5: 7a8f182f2de653a5a2c1b9cc4e77a317 SHA1: ef1cf9fbf3d316ffecb5229ac6047aaae181b4e5 SHA256: 8834943ad996d92bbb855e371b3c1d2d298e16b26d1c65330f73f0029d042225 org.apache.camel.camel-util-json-4.16.0.jar (shaded: org.apache.camel:camel-util-json:4.16.0)Description:
A json simple parser that preserves the ordering in Map as read from JSon source License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-util-json-4.16.0.jar/META-INF/maven/org.apache.camel/camel-util-json/pom.xml
MD5: e65f74805242e551da9e88188fbc80fc
SHA1: 477204676f3d1b88ac92f1215ed6847aa9a03a2e
SHA256: e0f8b89603896244c7720a7ed62ac74e46fdffe67d4721d6c051c114c392546d
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-util-json Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: Util :: JSon High Vendor pom parent-artifactid tooling Low Product pom artifactid camel-util-json Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: Util :: JSon High Product pom parent-artifactid tooling Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-util-json-4.16.0.jar (shaded: org.apache.camel:camel-util-json:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-util-json-4.16.0.jar/META-INF/maven/org.apache.camel/camel-util-json/pom.xml MD5: e65f74805242e551da9e88188fbc80fc SHA1: 477204676f3d1b88ac92f1215ed6847aa9a03a2e SHA256: e0f8b89603896244c7720a7ed62ac74e46fdffe67d4721d6c051c114c392546d pkg:maven/org.apache.camel/camel-util-json@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.camel-xml-jaxp-util-4.16.0.jar (shaded: org.apache.camel:camel-xml-jaxp-util:4.16.0)Description:
Camel XML JAXP Util License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.camel-xml-jaxp-util-4.16.0.jar/META-INF/maven/org.apache.camel/camel-xml-jaxp-util/pom.xml
MD5: 5172f3565ac6f23cf5fcdee13b3f23a4
SHA1: 617ffec3395bd6b46d006146a8379f5e5ca1af1d
SHA256: dcfb73cc69f86d84a01d847b0a4d392b9f42458d2a00b6377a4eebc40ce510d9
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-xml-jaxp-util Low Vendor pom groupid org.apache.camel Highest Vendor pom name Camel :: XML JAXP Util High Vendor pom parent-artifactid core Low Product pom artifactid camel-xml-jaxp-util Highest Product pom groupid org.apache.camel Highest Product pom name Camel :: XML JAXP Util High Product pom parent-artifactid core Medium Version pom version 4.16.0 Highest
Related Dependencies org.apache.camel.camel-xml-jaxp-util-4.16.0.jar (shaded: org.apache.camel:camel-xml-jaxp-util:4.16.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.camel-xml-jaxp-util-4.16.0.jar/META-INF/maven/org.apache.camel/camel-xml-jaxp-util/pom.xml MD5: 5172f3565ac6f23cf5fcdee13b3f23a4 SHA1: 617ffec3395bd6b46d006146a8379f5e5ca1af1d SHA256: dcfb73cc69f86d84a01d847b0a4d392b9f42458d2a00b6377a4eebc40ce510d9 pkg:maven/org.apache.camel/camel-xml-jaxp-util@4.16.0 CVE-2025-66169 suppress
Cypher Injection vulnerability in Apache Camel camel-neo4j component.
This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.3, from 4.15.0 before 4.17.0
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.camel.quarkus.camel-quarkus-core-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.quarkus.camel-quarkus-core-3.30.0.jarMD5: ad1624277e76740f54250074d7410d60SHA1: 840327cb6e6cb86811874aa2c1482b048d56f43eSHA256: ae20161e8b0f785b2249c2492ae0c8b599106f73b526c43dc321f580ee9af661
Evidence Type Source Name Value Confidence Vendor file name org.apache.camel.quarkus.camel-quarkus-core High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name camel Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Product file name org.apache.camel.quarkus.camel-quarkus-core High Product jar package name camel Highest Product jar package name camel Low Product jar package name core Highest Product jar package name core Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Camel Quarkus :: Core :: Runtime High Product Manifest specification-title Camel Quarkus :: Core :: Runtime Medium Version file version 3.30.0 High Version Manifest Implementation-Version 3.30.0 High
Related Dependencies camel-quarkus-core-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/camel/quarkus/camel-quarkus-core/3.30.0/camel-quarkus-core-3.30.0.jar MD5: ad1624277e76740f54250074d7410d60 SHA1: 840327cb6e6cb86811874aa2c1482b048d56f43e SHA256: ae20161e8b0f785b2249c2492ae0c8b599106f73b526c43dc321f580ee9af661 pkg:maven/org.apache.camel.quarkus/camel-quarkus-core@3.30.0 org.apache.camel.quarkus.camel-quarkus-core-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.quarkus.camel-quarkus-core-3.30.0.jar MD5: ad1624277e76740f54250074d7410d60 SHA1: 840327cb6e6cb86811874aa2c1482b048d56f43e SHA256: ae20161e8b0f785b2249c2492ae0c8b599106f73b526c43dc321f580ee9af661 org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jar MD5: e18edae76dc98448742539aa8215bc24 SHA1: d44c16ad408779bcaf43e48ff01e427ca13ecfa1 SHA256: 847fbd4fc58a2021c63dd5ddc6381d883d180a03919f184e6731a2c78cdc6080 org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jar (shaded: org.apache.camel.quarkus:camel-quarkus-mapstruct:3.30.0)Description:
Type Conversion using Mapstruct File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jar/META-INF/maven/org.apache.camel.quarkus/camel-quarkus-mapstruct/pom.xmlMD5: 320be069ad2833a65f3aebae78a4622dSHA1: 7bebec08f44742772f070069e7c44641604b9527SHA256: 7a1c6b8fefde26927bf13381741f6d881be2eb53631bc848f858a33319fb6a8e
Evidence Type Source Name Value Confidence Vendor pom artifactid camel-quarkus-mapstruct Low Vendor pom groupid org.apache.camel.quarkus Highest Vendor pom name Camel Quarkus :: MapStruct :: Runtime High Vendor pom parent-artifactid camel-quarkus-mapstruct-parent Low Product pom artifactid camel-quarkus-mapstruct Highest Product pom groupid org.apache.camel.quarkus Highest Product pom name Camel Quarkus :: MapStruct :: Runtime High Product pom parent-artifactid camel-quarkus-mapstruct-parent Medium Version pom version 3.30.0 Highest
Related Dependencies org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jar (shaded: org.apache.camel.quarkus:camel-quarkus-mapstruct:3.30.0)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jar/META-INF/maven/org.apache.camel.quarkus/camel-quarkus-mapstruct/pom.xml MD5: 320be069ad2833a65f3aebae78a4622d SHA1: 7bebec08f44742772f070069e7c44641604b9527 SHA256: 7a1c6b8fefde26927bf13381741f6d881be2eb53631bc848f858a33319fb6a8e pkg:maven/org.apache.camel.quarkus/camel-quarkus-mapstruct@3.30.0 org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.camel.quarkus.camel-quarkus-mapstruct-3.30.0.jarMD5: e18edae76dc98448742539aa8215bc24SHA1: d44c16ad408779bcaf43e48ff01e427ca13ecfa1SHA256: 847fbd4fc58a2021c63dd5ddc6381d883d180a03919f184e6731a2c78cdc6080
Evidence Type Source Name Value Confidence Vendor file name org.apache.camel.quarkus.camel-quarkus-mapstruct High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name camel Low Vendor jar package name quarkus Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Product file name org.apache.camel.quarkus.camel-quarkus-mapstruct High Product jar package name camel Highest Product jar package name camel Low Product jar package name component Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Camel Quarkus :: MapStruct :: Runtime High Product Manifest specification-title Camel Quarkus :: MapStruct :: Runtime Medium Version file version 3.30.0 High Version Manifest Implementation-Version 3.30.0 High
org.apache.commons.commons-collections4-4.5.0.jarDescription:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.commons.commons-collections4-4.5.0.jar
MD5: d564105594035b363b193d8ce3c18b98
SHA1: e5cf89f0c6e132fc970bd9a465fdcb8dbe94f75a
SHA256: 00f93263c267be201b8ae521b44a7137271b16688435340bf629db1bac0a5845
Evidence Type Source Name Value Confidence Vendor file name org.apache.commons.commons-collections4 High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name collections4 Highest Vendor jar package name collections4 Low Vendor jar package name commons Highest Vendor jar package name commons Low Vendor Manifest automatic-module-name org.apache.commons.collections4 Medium Vendor Manifest build-jdk-spec 23 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Product file name org.apache.commons.commons-collections4 High Product jar package name apache Highest Product jar package name collections4 Highest Product jar package name collections4 Low Product jar package name commons Highest Product jar package name commons Low Product Manifest automatic-module-name org.apache.commons.collections4 Medium Product Manifest build-jdk-spec 23 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Product Manifest Bundle-Name Apache Commons Collections Medium Product Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Product Manifest Implementation-Title Apache Commons Collections High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Collections Medium Version file version 4.5.0 High Version Manifest Implementation-Version 4.5.0 High
Related Dependencies commons-collections4-4.5.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-collections4/4.5.0/commons-collections4-4.5.0.jar MD5: d564105594035b363b193d8ce3c18b98 SHA1: e5cf89f0c6e132fc970bd9a465fdcb8dbe94f75a SHA256: 00f93263c267be201b8ae521b44a7137271b16688435340bf629db1bac0a5845 pkg:maven/org.apache.commons/commons-collections4@4.5.0 org.apache.commons.commons-exec-1.5.0.jarDescription:
Apache Commons Exec is a library to reliably execute external processes from within the JVM. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.apache.commons.commons-exec-1.5.0.jar
MD5: 9de95ba7000a7ea8643981e4fe87b01e
SHA1: d83ddeb0b9e0f3011a6902984551fc2d3aa1fe7c
SHA256: d52d35801747902527826cca30734034e65baa7f36836cc0facf67131025f703
Evidence Type Source Name Value Confidence Vendor file name org.apache.commons.commons-exec High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name commons Highest Vendor jar package name commons Low Vendor jar package name exec Highest Vendor jar package name exec Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-exec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-exec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Product file name org.apache.commons.commons-exec High Product jar package name apache Highest Product jar package name commons Highest Product jar package name commons Low Product jar package name exec Highest Product jar package name exec Low Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-exec/ Low Product Manifest Bundle-Name Apache Commons Exec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-exec Medium Product Manifest Implementation-Title Apache Commons Exec High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Exec Medium Version file version 1.5.0 High Version Manifest Implementation-Version 1.5.0 High
Related Dependencies commons-exec-1.5.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-exec/1.5.0/commons-exec-1.5.0.jar MD5: 9de95ba7000a7ea8643981e4fe87b01e SHA1: d83ddeb0b9e0f3011a6902984551fc2d3aa1fe7c SHA256: d52d35801747902527826cca30734034e65baa7f36836cc0facf67131025f703 pkg:maven/org.apache.commons/commons-exec@1.5.0 CVE-2021-37533 suppress
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711. CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions:
org.apache.commons.commons-lang3-3.17.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the classes that are in java.lang's hierarchy, or are considered to be so standard as to justify existence in java.lang. The code is tested using the latest revision of the JDK for supported LTS releases: 8, 11, 17 and 21 currently. See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml Please ensure your build environment is up-to-date and kindly report any build issues. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.commons.commons-lang3-3.17.0.jar
MD5: 7730df72b7fdff4a3a32d89a314f826a
SHA1: b17d2136f0460dcc0d2016ceefca8723bdf4ee70
SHA256: 6ee731df5c8e5a2976a1ca023b6bb320ea8d3539fbe64c8a1d5cb765127c33b4
Evidence Type Source Name Value Confidence Vendor file name org.apache.commons.commons-lang3 High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name commons Highest Vendor jar package name commons Low Vendor jar package name lang3 Highest Vendor jar package name lang3 Low Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Product file name org.apache.commons.commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name commons Low Product jar package name lang3 Highest Product jar package name lang3 Low Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Lang Medium Version file version 3.17.0 High Version Manifest Implementation-Version 3.17.0 High
Related Dependencies commons-lang3-3.17.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-lang3/3.17.0/commons-lang3-3.17.0.jar MD5: 7730df72b7fdff4a3a32d89a314f826a SHA1: b17d2136f0460dcc0d2016ceefca8723bdf4ee70 SHA256: 6ee731df5c8e5a2976a1ca023b6bb320ea8d3539fbe64c8a1d5cb765127c33b4 pkg:maven/org.apache.commons/commons-lang3@3.17.0 CVE-2025-48924 suppress
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue. CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
org.apache.commons.commons-text-1.14.0.jarDescription:
Apache Commons Text is a set of utility functions and reusable components for processing and manipulating text in a Java environment. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.apache.commons.commons-text-1.14.0.jar
MD5: 54960a12a82d52df3d5548d6934d87b2
SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a
SHA256: 121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92
Evidence Type Source Name Value Confidence Vendor file name org.apache.commons.commons-text High Vendor jar package name apache Highest Vendor jar package name apache Low Vendor jar package name commons Highest Vendor jar package name commons Low Vendor jar package name text Highest Vendor jar package name text Low Vendor Manifest automatic-module-name org.apache.commons.text Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Vendor Manifest bundle-symbolicname org.apache.commons.text Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Product file name org.apache.commons.commons-text High Product jar package name apache Highest Product jar package name commons Highest Product jar package name commons Low Product jar package name text Highest Product jar package name text Low Product Manifest automatic-module-name org.apache.commons.text Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Product Manifest Bundle-Name Apache Commons Text Medium Product Manifest bundle-symbolicname org.apache.commons.text Medium Product Manifest Implementation-Title Apache Commons Text High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Text Medium Version file version 1.14.0 High Version Manifest Implementation-Version 1.14.0 High
Related Dependencies commons-text-1.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/commons/commons-text/1.14.0/commons-text-1.14.0.jar MD5: 54960a12a82d52df3d5548d6934d87b2 SHA1: adcb0d4c67eabc79682604b47eb852aaff21138a SHA256: 121fce2282910c8f0c3ba793a5436b31beb710423cbe2d574a3fb7a73c508e92 pkg:maven/org.apache.commons/commons-text@1.14.0 CVE-2021-37533 suppress
Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. This may lead to leakage of information about services running on the private network of the client. The default in version 3.9.0 is now false to ignore such hosts, as cURL does. See https://issues.apache.org/jira/browse/NET-711. CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - ISSUE_TRACKING,MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - ISSUE_TRACKING,MAILING_LIST,VENDOR_ADVISORY security@apache.org - MAILING_LIST,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions:
org.bitbucket.b_c.jose4j-0.9.6.jarDescription:
The jose.4.j library is a robust and easy to use open source implementation of JSON Web Token (JWT) and the JOSE specification suite (JWS, JWE, and JWK). It is written in Java and relies solely on the JCA APIs for cryptography. Please see https://bitbucket.org/b_c/jose4j/wiki/Home for more info, examples, etc.. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.bitbucket.b_c.jose4j-0.9.6.jar
MD5: f57cb91efc5beaa940029f5515a888c2
SHA1: 357a3836bb5da16f314f3a1e954518e5468cd915
SHA256: 7314af50cde9c99e8eaf43eee617a23edcc6bb43036221064355094999d837ef
Evidence Type Source Name Value Confidence Vendor file name org.bitbucket.b_c.jose4j High Vendor jar package name jose4j Highest Vendor jar package name jose4j Low Vendor Manifest automatic-module-name org.jose4j Medium Vendor Manifest bundle-symbolicname org.bitbucket.b_c.jose4j Medium Product file name org.bitbucket.b_c.jose4j High Product jar package name jca Highest Product jar package name jose4j Highest Product jar package name json Highest Product jar package name jwe Highest Product jar package name jwk Highest Product jar package name jws Highest Product jar package name jwt Highest Product jar package name use Highest Product Manifest automatic-module-name org.jose4j Medium Product Manifest Bundle-Name jose4j Medium Product Manifest bundle-symbolicname org.bitbucket.b_c.jose4j Medium Version file name org.bitbucket.b_c.jose4j Medium Version file version 0.9.6 High Version Manifest Bundle-Version 0.9.6 High
Related Dependencies jose4j-0.9.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/bitbucket/b_c/jose4j/0.9.6/jose4j-0.9.6.jar MD5: f57cb91efc5beaa940029f5515a888c2 SHA1: 357a3836bb5da16f314f3a1e954518e5468cd915 SHA256: 7314af50cde9c99e8eaf43eee617a23edcc6bb43036221064355094999d837ef pkg:maven/org.bitbucket.b_c/jose4j@0.9.6 cpe:2.3:a:jose4j_project:jose4j:0.9.6:*:*:*:*:*:*:* (Confidence :Low) suppress org.crac.crac-1.5.0.jarDescription:
A wrapper for OpenJDK CRaC API to build and run on any JDK License:
BSD-2-Clause;link="https://opensource.org/licenses/BSD-2-Clause" File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/org.crac.crac-1.5.0.jar
MD5: 1f2036c6092e74113d21a0387eddbcfd
SHA1: 558290505b200b22bcd2396362877beae37f45b6
SHA256: f4426e1641c8f0fa2f025a4cd7c40c285abaf265930e6717adfcaef03d034850
Evidence Type Source Name Value Confidence Vendor file name org.crac.crac High Vendor jar package name crac Highest Vendor jar package name crac Low Vendor Manifest bundle-developers antonkozlov;email="akozlov@azul.com";name="Anton Kozlov" Low Vendor Manifest bundle-docurl https://github.com/crac/org.crac Low Vendor Manifest bundle-symbolicname org.crac Medium Product file name org.crac.crac High Product jar package name crac Highest Product Manifest bundle-developers antonkozlov;email="akozlov@azul.com";name="Anton Kozlov" Low Product Manifest bundle-docurl https://github.com/crac/org.crac Low Product Manifest Bundle-Name org.crac Medium Product Manifest bundle-symbolicname org.crac Medium Version file name org.crac.crac Medium Version file version 1.5.0 High Version jar package name crac Highest Version Manifest Bundle-Version 1.5.0 High
Related Dependencies crac-1.5.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/crac/crac/1.5.0/crac-1.5.0.jar MD5: 1f2036c6092e74113d21a0387eddbcfd SHA1: 558290505b200b22bcd2396362877beae37f45b6 SHA256: f4426e1641c8f0fa2f025a4cd7c40c285abaf265930e6717adfcaef03d034850 pkg:maven/org.crac/crac@1.5.0 org.crac.crac-1.5.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/org.crac.crac-1.5.0.jar MD5: 1f2036c6092e74113d21a0387eddbcfd SHA1: 558290505b200b22bcd2396362877beae37f45b6 SHA256: f4426e1641c8f0fa2f025a4cd7c40c285abaf265930e6717adfcaef03d034850 org.eclipse.angus.angus-activation-2.0.3.jarDescription:
Angus Activation Registries Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.angus.angus-activation-2.0.3.jar
MD5: ad20392145690b36b4f950fe31a31a2a
SHA1: 7f80607ea5014fef0b1779e6c33d63a88a45a563
SHA256: a6bd35c538cf90fff941ad6258c40c08fca0b5c9c3f536c657114f27ce0527a7
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.angus.angus-activation High Vendor jar package name activation Highest Vendor jar package name activation Low Vendor jar package name angus Highest Vendor jar package name angus Low Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname angus-activation Medium Vendor Manifest extension-name org.eclipse.angus Medium Vendor Manifest implementation-build-id 2.0.3-RELEASE-6eff4c5 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Vendor Manifest specification-vendor Eclipse Foundation Low Product file name org.eclipse.angus.angus-activation High Product jar package name activation Highest Product jar package name activation Low Product jar package name angus Highest Product jar package name angus Low Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Angus Activation Registries Medium Product Manifest bundle-symbolicname angus-activation Medium Product Manifest extension-name org.eclipse.angus Medium Product Manifest implementation-build-id 2.0.3-RELEASE-6eff4c5 Low Product Manifest Implementation-Title Angus Activation Registries High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Product Manifest specification-title Jakarta Activation Specification Medium Version file name org.eclipse.angus.angus-activation Medium Version file version 2.0.3 High Version jar package name activation Highest Version jar package name eclipse Highest Version Manifest Bundle-Version 2.0.3 High Version Manifest specification-version 2.1 High
Related Dependencies angus-activation-2.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/angus/angus-activation/2.0.3/angus-activation-2.0.3.jar MD5: ad20392145690b36b4f950fe31a31a2a SHA1: 7f80607ea5014fef0b1779e6c33d63a88a45a563 SHA256: a6bd35c538cf90fff941ad6258c40c08fca0b5c9c3f536c657114f27ce0527a7 pkg:maven/org.eclipse.angus/angus-activation@2.0.3 org.eclipse.angus.angus-activation-2.0.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.angus.angus-activation-2.0.3.jar MD5: ad20392145690b36b4f950fe31a31a2a SHA1: 7f80607ea5014fef0b1779e6c33d63a88a45a563 SHA256: a6bd35c538cf90fff941ad6258c40c08fca0b5c9c3f536c657114f27ce0527a7 CVE-2025-7962 suppress
In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages. CWE-147 Improper Neutralization of Input Terminators
CVSSv4:
Base Score: MEDIUM (6.0) Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-4218 suppress
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.0) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:1.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2008-7271 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2010-4647 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT secalert@redhat.com - EXPLOIT secalert@redhat.com - EXPLOIT Vulnerable Software & Versions: (show all )
org.eclipse.microprofile.config.microprofile-config-api-3.1.jarDescription:
MicroProfile Config :: API License:
"Apache License, Version 2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt" File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.microprofile.config.microprofile-config-api-3.1.jar
MD5: eafb265a1776be25ab19d4f7834c6ec8
SHA1: cef8b70598a93582a4084fe67f4686eb399e70fd
SHA256: dee277f81e1edfeafd5e43589441ecdf434500fe4a31d035e74b8e6d8e7bfd91
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.config.microprofile-config-api High Vendor jar package name config Highest Vendor jar package name config Low Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-developers Emily-Jiang;name="Emily Jiang";organization=IBM;organizationUrl="https://www.ibm.com",struberg;name="Mark Struberg",OndrejM;name="Ondro Mihalyi";organization="Payara Services";organizationUrl="https://www.payara.fish",radcortez;name="Roberto Cortez";organization="Red Hat Inc.";organizationUrl="https://redhat.com" Low Vendor Manifest bundle-docurl https://microprofile.io/project/eclipse/microprofile-config/microprofile-config-api Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.config Medium Product file name org.eclipse.microprofile.config.microprofile-config-api High Product jar package name config Highest Product jar package name config Low Product jar package name eclipse Highest Product jar package name microprofile Highest Product jar package name microprofile Low Product Manifest build-jdk-spec 11 Low Product Manifest bundle-developers Emily-Jiang;name="Emily Jiang";organization=IBM;organizationUrl="https://www.ibm.com",struberg;name="Mark Struberg",OndrejM;name="Ondro Mihalyi";organization="Payara Services";organizationUrl="https://www.payara.fish",radcortez;name="Roberto Cortez";organization="Red Hat Inc.";organizationUrl="https://redhat.com" Low Product Manifest bundle-docurl https://microprofile.io/project/eclipse/microprofile-config/microprofile-config-api Low Product Manifest Bundle-Name MicroProfile Config API Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.config Medium Version file name org.eclipse.microprofile.config.microprofile-config-api Medium Version file version 3.1 High Version jar package name config Highest Version jar package name eclipse Highest Version jar package name microprofile Highest Version Manifest build-jdk-spec 11 Low Version Manifest Bundle-Version 3.1.0 High
Related Dependencies microprofile-config-api-3.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/config/microprofile-config-api/3.1/microprofile-config-api-3.1.jar MD5: eafb265a1776be25ab19d4f7834c6ec8 SHA1: cef8b70598a93582a4084fe67f4686eb399e70fd SHA256: dee277f81e1edfeafd5e43589441ecdf434500fe4a31d035e74b8e6d8e7bfd91 pkg:maven/org.eclipse.microprofile.config/microprofile-config-api@3.1 org.eclipse.microprofile.config.microprofile-config-api-3.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.config.microprofile-config-api-3.1.jar MD5: eafb265a1776be25ab19d4f7834c6ec8 SHA1: cef8b70598a93582a4084fe67f4686eb399e70fd SHA256: dee277f81e1edfeafd5e43589441ecdf434500fe4a31d035e74b8e6d8e7bfd91 cpe:2.3:a:payara:payara:3.1:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2022-37422 suppress
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2022-45129 suppress
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0. CWE-552 Files or Directories Accessible to External Parties
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api-1.3.jarDescription:
"MicroProfile Context Propagation :: API" License:
"Apache License, Version 2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt";description="A business-friendly OSS license" File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api-1.3.jar
MD5: 14c55bb802683e780087d97fb9b92de1
SHA1: aab6a415754137629e725a9927702a5cd68038c2
SHA256: 69ccc04487e87779d4970aa50c673cc34a9df080c1c0e8d8eab2e8b46f825cf4
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api High Vendor jar package name context Highest Vendor jar package name context Low Vendor jar package name eclipse Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl http://microprofile.io/microprofile-context-propagation-api Low Vendor Manifest bundle-symbolicname microprofile-context-propagation-api Medium Product file name org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api High Product jar package name context Highest Product jar package name context Low Product jar package name microprofile Highest Product jar package name microprofile Low Product jar package name spi Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl http://microprofile.io/microprofile-context-propagation-api Low Product Manifest Bundle-Name MicroProfile Context Propagation Medium Product Manifest bundle-symbolicname microprofile-context-propagation-api Medium Version file name org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api Medium Version file version 1.3 High Version jar package name context Highest Version jar package name microprofile Highest Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 1.3.0 High
Related Dependencies microprofile-context-propagation-api-1.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/context-propagation/microprofile-context-propagation-api/1.3/microprofile-context-propagation-api-1.3.jar MD5: 14c55bb802683e780087d97fb9b92de1 SHA1: aab6a415754137629e725a9927702a5cd68038c2 SHA256: 69ccc04487e87779d4970aa50c673cc34a9df080c1c0e8d8eab2e8b46f825cf4 pkg:maven/org.eclipse.microprofile.context-propagation/microprofile-context-propagation-api@1.3 org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api-1.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.context-propagation.microprofile-context-propagation-api-1.3.jar MD5: 14c55bb802683e780087d97fb9b92de1 SHA1: aab6a415754137629e725a9927702a5cd68038c2 SHA256: 69ccc04487e87779d4970aa50c673cc34a9df080c1c0e8d8eab2e8b46f825cf4 org.eclipse.microprofile.health.microprofile-health-api-4.0.1.jarDescription:
MicroProfile Health :: API License:
Apache License, Version 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.microprofile.health.microprofile-health-api-4.0.1.jar
MD5: 1d023ee3b9b8545318fdeebe98d66d74
SHA1: 395ea08f4f636696fb23b84a18ba81430cfebe7c
SHA256: b89ca4b6c4f7a044250d31c0673f6bc221e40fd669fc5871dbad5e5a0769ca47
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.health.microprofile-health-api High Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name health Highest Vendor jar package name health Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://microprofile.io/project/eclipse/microprofile-health/microprofile-health-api Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.health Medium Product file name org.eclipse.microprofile.health.microprofile-health-api High Product jar package name eclipse Highest Product jar package name health Highest Product jar package name health Low Product jar package name microprofile Highest Product jar package name microprofile Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://microprofile.io/project/eclipse/microprofile-health/microprofile-health-api Low Product Manifest Bundle-Name MicroProfile Health Check Bundle Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.health Medium Version file name org.eclipse.microprofile.health.microprofile-health-api Medium Version file version 4.0.1 High Version jar package name eclipse Highest Version jar package name health Highest Version jar package name microprofile Highest Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 4.0.1 High
Related Dependencies microprofile-health-api-4.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/health/microprofile-health-api/4.0.1/microprofile-health-api-4.0.1.jar MD5: 1d023ee3b9b8545318fdeebe98d66d74 SHA1: 395ea08f4f636696fb23b84a18ba81430cfebe7c SHA256: b89ca4b6c4f7a044250d31c0673f6bc221e40fd669fc5871dbad5e5a0769ca47 pkg:maven/org.eclipse.microprofile.health/microprofile-health-api@4.0.1 org.eclipse.microprofile.health.microprofile-health-api-4.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.health.microprofile-health-api-4.0.1.jar MD5: 1d023ee3b9b8545318fdeebe98d66d74 SHA1: 395ea08f4f636696fb23b84a18ba81430cfebe7c SHA256: b89ca4b6c4f7a044250d31c0673f6bc221e40fd669fc5871dbad5e5a0769ca47 org.eclipse.microprofile.jwt.microprofile-jwt-auth-api-2.1.jarDescription:
MicroProfile Parent POM License:
Apache License, Version 2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.jwt.microprofile-jwt-auth-api-2.1.jar
MD5: eae8e3df5ec1c2ef20161232279b42ab
SHA1: 895da00d45d76ffcdaf5e3a45987a1b286e22a58
SHA256: e81a237ecb81e4f360ed5e7928d42bf3eedd1d73fe3a343d65ed1578f5169bad
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.jwt.microprofile-jwt-auth-api High Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name jwt Highest Vendor jar package name jwt Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-developers starksm64;name="Scott M Stark";organization="Red Hat Inc.";organizationUrl="https://redhat.com",dblevins;name="David Blevins";organization=Tomitribe;organizationUrl="https://tomitribe.com",sberyozkin;name="Sergey Beryozkin1";organization="Red Hat Inc.";organizationUrl="https://redhat.com",radcortez;name="Roberto Cortez";organization="Red Hat Inc.";organizationUrl="https://redhat.com",rdebusscher;name="Rudy De Busscher";organization=Payara;organizationUrl="https://www.payara.fish/",ayoho;name="Adam Yoho";organization=IBM;organizationUrl="https://www.ibm.com",teddyjtorres;name="Teddy Torres";organization=IBM;organizationUrl="https://www.ibm.com" Low Vendor Manifest bundle-docurl https://github.com/eclipse/microprofile-jwt-auth/microprofile-jwt-auth-api Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.jwt Medium Product file name org.eclipse.microprofile.jwt.microprofile-jwt-auth-api High Product jar package name auth Highest Product jar package name eclipse Highest Product jar package name jwt Highest Product jar package name jwt Low Product jar package name microprofile Highest Product jar package name microprofile Low Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-developers starksm64;name="Scott M Stark";organization="Red Hat Inc.";organizationUrl="https://redhat.com",dblevins;name="David Blevins";organization=Tomitribe;organizationUrl="https://tomitribe.com",sberyozkin;name="Sergey Beryozkin1";organization="Red Hat Inc.";organizationUrl="https://redhat.com",radcortez;name="Roberto Cortez";organization="Red Hat Inc.";organizationUrl="https://redhat.com",rdebusscher;name="Rudy De Busscher";organization=Payara;organizationUrl="https://www.payara.fish/",ayoho;name="Adam Yoho";organization=IBM;organizationUrl="https://www.ibm.com",teddyjtorres;name="Teddy Torres";organization=IBM;organizationUrl="https://www.ibm.com" Low Product Manifest bundle-docurl https://github.com/eclipse/microprofile-jwt-auth/microprofile-jwt-auth-api Low Product Manifest Bundle-Name MicroProfile JWT Auth Bundle Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.jwt Medium Version file name org.eclipse.microprofile.jwt.microprofile-jwt-auth-api Medium Version file version 2.1 High Version jar package name auth Highest Version jar package name eclipse Highest Version jar package name jwt Highest Version jar package name microprofile Highest Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 2.1.0 High
Related Dependencies microprofile-jwt-auth-api-2.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/jwt/microprofile-jwt-auth-api/2.1/microprofile-jwt-auth-api-2.1.jar MD5: eae8e3df5ec1c2ef20161232279b42ab SHA1: 895da00d45d76ffcdaf5e3a45987a1b286e22a58 SHA256: e81a237ecb81e4f360ed5e7928d42bf3eedd1d73fe3a343d65ed1578f5169bad pkg:maven/org.eclipse.microprofile.jwt/microprofile-jwt-auth-api@2.1 cpe:2.3:a:payara:payara:2.1:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2022-37422 suppress
Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2022-45129 suppress
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than CVE-2022-37422. This affects Payara Platform Community before 4.1.2.191.38, 5.x before 5.2022.4, and 6.x before 6.2022.1, and Payara Platform Enterprise before 5.45.0. CWE-552 Files or Directories Accessible to External Parties
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - EXPLOIT,THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY cve@mitre.org - RELEASE_NOTES,VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
org.eclipse.microprofile.openapi.microprofile-openapi-api-4.1.1.jarDescription:
MicroProfile OpenAPI :: API License:
Apache License, Version 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.microprofile.openapi.microprofile-openapi-api-4.1.1.jar
MD5: 00eafb191dca101c9674638209b2627f
SHA1: b5c2ba3a39e2f20f347754325b3136f6703a23fd
SHA256: 1e333f5bd206245e7a4d0a3dd5f2bab1820fc3b950b77e96008fcdb7b77d9150
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.openapi.microprofile-openapi-api High Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor jar package name openapi Highest Vendor jar package name openapi Low Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl http://microprofile.io/microprofile-openapi-parent/microprofile-openapi-api Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.openapi Medium Product file name org.eclipse.microprofile.openapi.microprofile-openapi-api High Product jar package name annotations Low Product jar package name eclipse Highest Product jar package name microprofile Highest Product jar package name microprofile Low Product jar package name openapi Highest Product jar package name openapi Low Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl http://microprofile.io/microprofile-openapi-parent/microprofile-openapi-api Low Product Manifest Bundle-Name MicroProfile OpenAPI Bundle Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.openapi Medium Version file name org.eclipse.microprofile.openapi.microprofile-openapi-api Medium Version file version 4.1.1 High Version jar package name microprofile Highest Version jar package name openapi Highest Version Manifest build-jdk-spec 17 Low Version Manifest Bundle-Version 4.1.1 High
Related Dependencies microprofile-openapi-api-4.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/openapi/microprofile-openapi-api/4.1.1/microprofile-openapi-api-4.1.1.jar MD5: 00eafb191dca101c9674638209b2627f SHA1: b5c2ba3a39e2f20f347754325b3136f6703a23fd SHA256: 1e333f5bd206245e7a4d0a3dd5f2bab1820fc3b950b77e96008fcdb7b77d9150 pkg:maven/org.eclipse.microprofile.openapi/microprofile-openapi-api@4.1.1 org.eclipse.microprofile.openapi.microprofile-openapi-api-4.1.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.openapi.microprofile-openapi-api-4.1.1.jar MD5: 00eafb191dca101c9674638209b2627f SHA1: b5c2ba3a39e2f20f347754325b3136f6703a23fd SHA256: 1e333f5bd206245e7a4d0a3dd5f2bab1820fc3b950b77e96008fcdb7b77d9150 org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api-3.0.1.jarDescription:
Eclipse MicroProfile Reactive Streams Operators :: API License:
Apache License, Version 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api-3.0.1.jar
MD5: 5faf3b618f3dbf5df1af27629d77d28b
SHA1: 2eff9f75a4188f3289714a98b93c2d9a68f0fd6b
SHA256: 2eb30081f2674e674c6587592747a81a4d92d2da1a735be5f645901de60f9f8d
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api High Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor jar package name reactive Highest Vendor jar package name reactive Low Vendor jar package name streams Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl http://microprofile.io/microprofile-reactive-streams-operators-parent/microprofile-reactive-streams-operators-api Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.reactive.streams.operators Medium Product file name org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api High Product jar package name eclipse Highest Product jar package name microprofile Highest Product jar package name microprofile Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name streams Highest Product jar package name streams Low Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl http://microprofile.io/microprofile-reactive-streams-operators-parent/microprofile-reactive-streams-operators-api Low Product Manifest Bundle-Name Eclipse MicroProfile Reactive Streams Operators API Bundle Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.reactive.streams.operators Medium Version file name org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api Medium Version file version 3.0.1 High Version jar package name microprofile Highest Version jar package name reactive Highest Version jar package name streams Highest Version Manifest build-jdk-spec 17 Low Version Manifest Bundle-Version 3.0.1 High
Related Dependencies microprofile-reactive-streams-operators-api-3.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/reactive-streams-operators/microprofile-reactive-streams-operators-api/3.0.1/microprofile-reactive-streams-operators-api-3.0.1.jar MD5: 5faf3b618f3dbf5df1af27629d77d28b SHA1: 2eff9f75a4188f3289714a98b93c2d9a68f0fd6b SHA256: 2eb30081f2674e674c6587592747a81a4d92d2da1a735be5f645901de60f9f8d pkg:maven/org.eclipse.microprofile.reactive-streams-operators/microprofile-reactive-streams-operators-api@3.0.1 org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api-3.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-api-3.0.1.jar MD5: 5faf3b618f3dbf5df1af27629d77d28b SHA1: 2eff9f75a4188f3289714a98b93c2d9a68f0fd6b SHA256: 2eb30081f2674e674c6587592747a81a4d92d2da1a735be5f645901de60f9f8d org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core-3.0.1.jarDescription:
MicroProfile Reactive Streams Operators :: Core Implementation License:
Apache License, Version 2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core-3.0.1.jar
MD5: 2d5566170cd86acda4806d3a9d5498c7
SHA1: aed680b9237e81d375f449a7ee816f38c9159f6a
SHA256: 276810a28dcab1ae1b929f0ade42581d6553847fc42acbf9b5d89904cf9c2f4a
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core High Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name microprofile Highest Vendor jar package name microprofile Low Vendor jar package name reactive Highest Vendor jar package name reactive Low Vendor jar package name streams Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl http://microprofile.io/microprofile-reactive-streams-operators-parent/microprofile-reactive-streams-operators-core Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.reactive.streams.operators.core Medium Product file name org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core High Product jar package name eclipse Highest Product jar package name microprofile Highest Product jar package name microprofile Low Product jar package name reactive Highest Product jar package name reactive Low Product jar package name streams Highest Product jar package name streams Low Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl http://microprofile.io/microprofile-reactive-streams-operators-parent/microprofile-reactive-streams-operators-core Low Product Manifest Bundle-Name Eclipse MicroProfile Reactive Streams Operators Core Bundle Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.reactive.streams.operators.core Medium Version file name org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core Medium Version file version 3.0.1 High Version jar package name microprofile Highest Version jar package name reactive Highest Version jar package name streams Highest Version Manifest build-jdk-spec 17 Low Version Manifest Bundle-Version 3.0.1 High
Related Dependencies microprofile-reactive-streams-operators-core-3.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/microprofile/reactive-streams-operators/microprofile-reactive-streams-operators-core/3.0.1/microprofile-reactive-streams-operators-core-3.0.1.jar MD5: 2d5566170cd86acda4806d3a9d5498c7 SHA1: aed680b9237e81d375f449a7ee816f38c9159f6a SHA256: 276810a28dcab1ae1b929f0ade42581d6553847fc42acbf9b5d89904cf9c2f4a pkg:maven/org.eclipse.microprofile.reactive-streams-operators/microprofile-reactive-streams-operators-core@3.0.1 org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core-3.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.microprofile.reactive-streams-operators.microprofile-reactive-streams-operators-core-3.0.1.jar MD5: 2d5566170cd86acda4806d3a9d5498c7 SHA1: aed680b9237e81d375f449a7ee816f38c9159f6a SHA256: 276810a28dcab1ae1b929f0ade42581d6553847fc42acbf9b5d89904cf9c2f4a org.eclipse.parsson.parsson-1.1.7.jarDescription:
Jakarta JSON Processing provider License:
https://projects.eclipse.org/license/epl-2.0, https://projects.eclipse.org/license/secondary-gpl-2.0-cp File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.eclipse.parsson.parsson-1.1.7.jar
MD5: 2aeb1c0343fb4bcb8a0e4cf9ec063950
SHA1: f5825abecd373006262dd319d7df8c5cdbd140ca
SHA256: c21db018f8ac6cf79893f1af77f1cd337937bd12ae6fa3d4b10f5a00819ee56c
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.parsson.parsson High Vendor jar package name eclipse Highest Vendor jar package name eclipse Low Vendor jar package name parsson Highest Vendor jar package name parsson Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.eclipse.parsson Medium Vendor Manifest hk2-bundle-name org.eclipse.parsson:parsson Medium Vendor Manifest implementation-build-id 1.1.7 - 6087705 Low Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.json.spi.JsonProvider" Low Product file name org.eclipse.parsson.parsson High Product jar package name eclipse Highest Product jar package name parsson Highest Product jar package name parsson Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Eclipse Parsson Medium Product Manifest bundle-symbolicname org.eclipse.parsson Medium Product Manifest hk2-bundle-name org.eclipse.parsson:parsson Medium Product Manifest implementation-build-id 1.1.7 - 6087705 Low Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.json.spi.JsonProvider" Low Version file name org.eclipse.parsson.parsson Medium Version file version 1.1.7 High Version jar package name eclipse Highest Version Manifest Bundle-Version 1.1.7 High Version Manifest implementation-build-id 1.1.7 Low Version Manifest implementation-build-id 6087705 Low
Related Dependencies org.eclipse.parsson.parsson-1.1.7.jar (shaded: org.eclipse.parsson:parsson:1.1.7)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.parsson.parsson-1.1.7.jar/META-INF/maven/org.eclipse.parsson/parsson/pom.xml MD5: d20f59a54874d1e9cecf8bb784b2b023 SHA1: e4b1a17f8b52c3bdf91777594142a7bf696f3773 SHA256: aeb404e7f0c14a76ecc8ba6e21ecd92f80f7c10402a446ff5d9c31d50f08e2d3 pkg:maven/org.eclipse.parsson/parsson@1.1.7 org.eclipse.parsson.parsson-1.1.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.eclipse.parsson.parsson-1.1.7.jar MD5: 2aeb1c0343fb4bcb8a0e4cf9ec063950 SHA1: f5825abecd373006262dd319d7df8c5cdbd140ca SHA256: c21db018f8ac6cf79893f1af77f1cd337937bd12ae6fa3d4b10f5a00819ee56c parsson-1.1.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/parsson/parsson/1.1.7/parsson-1.1.7.jar MD5: 2aeb1c0343fb4bcb8a0e4cf9ec063950 SHA1: f5825abecd373006262dd319d7df8c5cdbd140ca SHA256: c21db018f8ac6cf79893f1af77f1cd337937bd12ae6fa3d4b10f5a00819ee56c pkg:maven/org.eclipse.parsson/parsson@1.1.7 cpe:2.3:a:eclipse:eclipse_ide:1.1.7:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:eclipse:parsson:1.1.7:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2023-4218 suppress
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: MEDIUM (5.0) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:1.3/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2008-7271 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2010-4647 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT secalert@redhat.com - EXPLOIT secalert@redhat.com - EXPLOIT Vulnerable Software & Versions: (show all )
org.eclipse.sisu.inject-0.9.0.M3.jarDescription:
JSR330-based container; supports classpath scanning, auto-binding, and dynamic auto-wiring License:
"Eclipse Public License, Version 2.0";link="https://www.eclipse.org/legal/epl-v20.html" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/sisu/org.eclipse.sisu.inject/0.9.0.M3/org.eclipse.sisu.inject-0.9.0.M3.jar
MD5: 643a13084e0ac59cdda06319e1b348ea
SHA1: 3665002ba4d16dfa779ef658a63d0608c4bd898b
SHA256: 15335c4dcf082f599fb8eddcfb58d6a7e9a9c97de2883c257089a479b9b24522
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.sisu.inject High Vendor jar package name dynamic Highest Vendor jar package name eclipse Highest Vendor jar package name inject Highest Vendor jar package name sisu Highest Vendor jar package name wiring Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Vendor Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Vendor Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Vendor Manifest bundle-symbolicname org.eclipse.sisu.inject;singleton:=true Medium Vendor pom artifactid eclipse.sisu.inject Low Vendor pom groupid org.eclipse.sisu Highest Vendor pom parent-artifactid sisu-inject Low Product file name org.eclipse.sisu.inject High Product jar package name dynamic Highest Product jar package name eclipse Highest Product jar package name inject Highest Product jar package name sisu Highest Product jar package name sonatype Highest Product jar package name wiring Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Product Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Product Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Product Manifest Bundle-Name Sisu-Inject (Incubation) Medium Product Manifest bundle-symbolicname org.eclipse.sisu.inject;singleton:=true Medium Product pom artifactid eclipse.sisu.inject Highest Product pom groupid org.eclipse.sisu Highest Product pom parent-artifactid sisu-inject Medium Version Manifest Bundle-Version 0.9.0.M3 High Version pom version 0.9.0.M3 Highest
pkg:maven/org.eclipse.sisu/org.eclipse.sisu.inject@0.9.0.M3 (Confidence :High) org.eclipse.sisu.inject-0.9.0.M4.jarDescription:
JSR330-based container; supports classpath scanning, auto-binding, and dynamic auto-wiring License:
"Eclipse Public License, Version 2.0";link="https://www.eclipse.org/legal/epl-v20.html" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/sisu/org.eclipse.sisu.inject/0.9.0.M4/org.eclipse.sisu.inject-0.9.0.M4.jar
MD5: ee95c1a11ba4ca38368d71ef05676cfc
SHA1: a062d8e12dc62e698c9f943a3fce94e366b4e220
SHA256: 1cbd7a965a5e2a9ea823bab311962a4e5aa5c240705bdbad5a52b40ffdfa1004
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.sisu.inject High Vendor jar package name dynamic Highest Vendor jar package name eclipse Highest Vendor jar package name inject Highest Vendor jar package name sisu Highest Vendor jar package name wiring Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Vendor Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Vendor Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Vendor Manifest bundle-symbolicname org.eclipse.sisu.inject;singleton:=true Medium Vendor pom artifactid eclipse.sisu.inject Low Vendor pom groupid org.eclipse.sisu Highest Vendor pom name : High Vendor pom parent-artifactid sisu-inject Low Product file name org.eclipse.sisu.inject High Product jar package name dynamic Highest Product jar package name eclipse Highest Product jar package name inject Highest Product jar package name sisu Highest Product jar package name sonatype Highest Product jar package name wiring Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Product Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Product Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Product Manifest Bundle-Name Sisu-Inject (Incubation) Medium Product Manifest bundle-symbolicname org.eclipse.sisu.inject;singleton:=true Medium Product pom artifactid eclipse.sisu.inject Highest Product pom groupid org.eclipse.sisu Highest Product pom name : High Product pom parent-artifactid sisu-inject Medium Version Manifest Bundle-Version 0.9.0.M4 High Version pom version 0.9.0.M4 Highest
pkg:maven/org.eclipse.sisu/org.eclipse.sisu.inject@0.9.0.M4 (Confidence :High) org.eclipse.sisu.plexus-0.9.0.M3.jarDescription:
Plexus-JSR330 adapter; adds Plexus support to the Sisu-Inject container License:
"Eclipse Public License, Version 2.0";link="https://www.eclipse.org/legal/epl-v20.html" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/sisu/org.eclipse.sisu.plexus/0.9.0.M3/org.eclipse.sisu.plexus-0.9.0.M3.jar
MD5: 964e7bc9837b270566f18b87af65f5d7
SHA1: b493c7abcc6e04fa0a6a20d489a3db0395c76f70
SHA256: c99674d3773e26154885661711f0b6d63aa5008f5cc99227a236756d4ad9de5e
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.sisu.plexus High Vendor jar package name eclipse Highest Vendor jar package name plexus Highest Vendor jar package name sisu Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Vendor Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Vendor Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Vendor Manifest bundle-symbolicname org.eclipse.sisu.plexus;singleton:=true Medium Vendor pom artifactid eclipse.sisu.plexus Low Vendor pom groupid org.eclipse.sisu Highest Vendor pom parent-artifactid sisu-inject Low Product file name org.eclipse.sisu.plexus High Product jar package name eclipse Highest Product jar package name plexus Highest Product jar package name sisu Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Product Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Product Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Product Manifest Bundle-Name Sisu-Plexus (Incubation) Medium Product Manifest bundle-symbolicname org.eclipse.sisu.plexus;singleton:=true Medium Product pom artifactid eclipse.sisu.plexus Highest Product pom groupid org.eclipse.sisu Highest Product pom parent-artifactid sisu-inject Medium Version Manifest Bundle-Version 0.9.0.M3 High Version pom version 0.9.0.M3 Highest
pkg:maven/org.eclipse.sisu/org.eclipse.sisu.plexus@0.9.0.M3 (Confidence :High) org.eclipse.sisu.plexus-0.9.0.M4.jarDescription:
Plexus-JSR330 adapter; adds Plexus support to the Sisu-Inject container License:
"Eclipse Public License, Version 2.0";link="https://www.eclipse.org/legal/epl-v20.html" File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/eclipse/sisu/org.eclipse.sisu.plexus/0.9.0.M4/org.eclipse.sisu.plexus-0.9.0.M4.jar
MD5: 51eea54bbc85323fc68f6a79f9b8f179
SHA1: 478f7935e88cd9da7ef01f509e4853e80ede9034
SHA256: b90579bc652eac7331436e0a25533fce14130b9c6e015f2dd3a3d4bb07e942b7
Evidence Type Source Name Value Confidence Vendor file name org.eclipse.sisu.plexus High Vendor jar package name eclipse Highest Vendor jar package name plexus Highest Vendor jar package name sisu Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Vendor Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Vendor Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Vendor Manifest bundle-symbolicname org.eclipse.sisu.plexus;singleton:=true Medium Vendor pom artifactid eclipse.sisu.plexus Low Vendor pom groupid org.eclipse.sisu Highest Vendor pom name : High Vendor pom parent-artifactid sisu-inject Low Product file name org.eclipse.sisu.plexus High Product jar package name eclipse Highest Product jar package name plexus Highest Product jar package name sisu Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-copyright Copyright (c) 2010-present Sonatype, Inc. and others Low Product Manifest bundle-developers mcculls;name="Stuart McCulloch",cstamas;name="Tamas Cservenak",kwin;name="Konrad Windszus" Low Product Manifest bundle-docurl http://www.eclipse.org/sisu/ Low Product Manifest Bundle-Name Sisu-Plexus (Incubation) Medium Product Manifest bundle-symbolicname org.eclipse.sisu.plexus;singleton:=true Medium Product pom artifactid eclipse.sisu.plexus Highest Product pom groupid org.eclipse.sisu Highest Product pom name : High Product pom parent-artifactid sisu-inject Medium Version Manifest Bundle-Version 0.9.0.M4 High Version pom version 0.9.0.M4 Highest
pkg:maven/org.eclipse.sisu/org.eclipse.sisu.plexus@0.9.0.M4 (Confidence :High) org.glassfish.expressly.expressly-6.0.0.jarDescription:
Jakarta Expression Language Implementation License:
https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt, https://www.gnu.org/software/classpath/license.html File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.glassfish.expressly.expressly-6.0.0.jar
MD5: e19bad48904a955072a576f0efea554b
SHA1: 0524fa43fa48fc68fb62604cf14ce71b31caf7c0
SHA256: 86ee67c7040278bac5204b571f738b8b859f014ceb5f896bd935bacbdaf33cb9
Evidence Type Source Name Value Confidence Vendor file name org.glassfish.expressly.expressly High Vendor jar package name expressly Highest Vendor jar package name expressly Low Vendor jar package name glassfish Highest Vendor jar package name glassfish Low Vendor jar package name parser Low Vendor Manifest automatic-module-name org.glassfish.expressly Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.expressly Medium Vendor Manifest extension-name org.glassfish.expressly Medium Vendor Manifest Implementation-Vendor ${vendorName} High Vendor Manifest specification-vendor Eclipse Foundation Low Product file name org.glassfish.expressly.expressly High Product jar package name expressly Highest Product jar package name expressly Low Product jar package name glassfish Highest Product jar package name parser Low Product Manifest automatic-module-name org.glassfish.expressly Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Eclipse Expressly Medium Product Manifest bundle-symbolicname org.glassfish.expressly Medium Product Manifest extension-name org.glassfish.expressly Medium Version file version 6.0.0 High Version Manifest Implementation-Version 6.0.0 High
Related Dependencies expressly-6.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/glassfish/expressly/expressly/6.0.0/expressly-6.0.0.jar MD5: e19bad48904a955072a576f0efea554b SHA1: 0524fa43fa48fc68fb62604cf14ce71b31caf7c0 SHA256: 86ee67c7040278bac5204b571f738b8b859f014ceb5f896bd935bacbdaf33cb9 pkg:maven/org.glassfish.expressly/expressly@6.0.0 org.glassfish.expressly.expressly-6.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.glassfish.expressly.expressly-6.0.0.jar MD5: e19bad48904a955072a576f0efea554b SHA1: 0524fa43fa48fc68fb62604cf14ce71b31caf7c0 SHA256: 86ee67c7040278bac5204b571f738b8b859f014ceb5f896bd935bacbdaf33cb9 CVE-2023-5763 suppress
In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
CWE-20 Improper Input Validation, CWE-913 Improper Control of Dynamically-Managed Code Resources
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2022-2712 suppress
In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to access critical data, such as configuration files and deployed application source code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-9329 suppress
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. CWE-601 URL Redirection to Untrusted Site ('Open Redirect'), CWE-233 Improper Handling of Parameters
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-8646 suppress
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed.
This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code included in GlassFish.
This vulnerability only affects applications that are explicitly deployed to the root context ('/'). CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
org.glassfish.jaxb.jaxb-core-4.0.6.jarDescription:
JAXB Core module. Contains sources required by XJC, JXC and Runtime modules. License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.glassfish.jaxb.jaxb-core-4.0.6.jar
MD5: e36c915cf47342b4fe31ffba3407b928
SHA1: 8e61282303777fc98a00cc3affd0560d68748a75
SHA256: ebbd274207b4860d0dc6e2d44d6dbdb5945cede01222d2e50661d45f5d46c0f7
Evidence Type Source Name Value Confidence Vendor file name org.glassfish.jaxb.jaxb-core High Vendor jar package name core Highest Vendor jar package name core Low Vendor jar package name glassfish Highest Vendor jar package name glassfish Low Vendor jar package name jaxb Highest Vendor jar package name jaxb Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Vendor Manifest git-revision 0dcfdf5 Low Vendor Manifest implementation-build-id 4.0.6 - 0dcfdf5 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest specification-vendor Eclipse Foundation Low Product file name org.glassfish.jaxb.jaxb-core High Product jar package name core Highest Product jar package name core Low Product jar package name glassfish Highest Product jar package name jaxb Highest Product jar package name jaxb Low Product jar package name v2 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Core Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Product Manifest git-revision 0dcfdf5 Low Product Manifest implementation-build-id 4.0.6 - 0dcfdf5 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Version file name org.glassfish.jaxb.jaxb-core Medium Version file version 4.0.6 High Version Manifest build-id 2025-09-22 16:36 Medium Version Manifest build-version 4.0.6 Medium Version Manifest Bundle-Version 4.0.6 High Version Manifest implementation-build-id 4.0.6 Low Version Manifest Implementation-Version 4.0.6 - 0dcfdf5 High
Related Dependencies jaxb-core-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/glassfish/jaxb/jaxb-core/4.0.6/jaxb-core-4.0.6.jar MD5: e36c915cf47342b4fe31ffba3407b928 SHA1: 8e61282303777fc98a00cc3affd0560d68748a75 SHA256: ebbd274207b4860d0dc6e2d44d6dbdb5945cede01222d2e50661d45f5d46c0f7 pkg:maven/org.glassfish.jaxb/jaxb-core@4.0.6 jaxb-runtime-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/glassfish/jaxb/jaxb-runtime/4.0.6/jaxb-runtime-4.0.6.jar MD5: 0e600d639f3a09ddd6fa91623a12b634 SHA1: fb95ebb62564657b2fedfe165b859789ef3a8711 SHA256: 1c0d57f8c25f9605d5a2f7ad0a87581893776ac85b00b101b2651258edaa9118 pkg:maven/org.glassfish.jaxb/jaxb-runtime@4.0.6 org.glassfish.jaxb.jaxb-core-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.glassfish.jaxb.jaxb-core-4.0.6.jar MD5: e36c915cf47342b4fe31ffba3407b928 SHA1: 8e61282303777fc98a00cc3affd0560d68748a75 SHA256: ebbd274207b4860d0dc6e2d44d6dbdb5945cede01222d2e50661d45f5d46c0f7 org.glassfish.jaxb.jaxb-runtime-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.glassfish.jaxb.jaxb-runtime-4.0.6.jar MD5: 0e600d639f3a09ddd6fa91623a12b634 SHA1: fb95ebb62564657b2fedfe165b859789ef3a8711 SHA256: 1c0d57f8c25f9605d5a2f7ad0a87581893776ac85b00b101b2651258edaa9118 org.glassfish.jaxb.txw2-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.glassfish.jaxb.txw2-4.0.6.jar MD5: 0bf7070aee3bb53640d2ea6441e059fb SHA1: 4f4cd53b5ff9a2c5aa1211f15ed2569c57dfb044 SHA256: fcc749785412ef3806fde1ce70f93ef5a0065dcc47fe449bc871db0795cb11af cpe:2.3:a:eclipse:glassfish:4.0.6:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2024-9329 suppress
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. CWE-601 URL Redirection to Untrusted Site ('Open Redirect'), CWE-233 Improper Handling of Parameters
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
org.glassfish.jaxb.txw2-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.glassfish.jaxb.txw2-4.0.6.jarMD5: 0bf7070aee3bb53640d2ea6441e059fbSHA1: 4f4cd53b5ff9a2c5aa1211f15ed2569c57dfb044SHA256: fcc749785412ef3806fde1ce70f93ef5a0065dcc47fe449bc871db0795cb11af
Evidence Type Source Name Value Confidence Vendor file name org.glassfish.jaxb.txw2 High Vendor jar package name sun Low Vendor jar package name txw2 Low Vendor jar package name xml Low Vendor jar (hint) package name oracle Low Vendor Manifest git-revision 0dcfdf5 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest specification-vendor Eclipse Foundation Low Product file name org.glassfish.jaxb.txw2 High Product jar package name txw2 Low Product jar package name xml Highest Product jar package name xml Low Product Manifest git-revision 0dcfdf5 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Version file name org.glassfish.jaxb.txw2 Medium Version file version 4.0.6 High Version Manifest build-id 2025-09-22 16:36 Medium Version Manifest build-version 4.0.6 Medium Version Manifest Implementation-Version 4.0.6 - 0dcfdf5 High
Related Dependencies org.glassfish.jaxb.jaxb-runtime-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.glassfish.jaxb.jaxb-runtime-4.0.6.jar MD5: 0e600d639f3a09ddd6fa91623a12b634 SHA1: fb95ebb62564657b2fedfe165b859789ef3a8711 SHA256: 1c0d57f8c25f9605d5a2f7ad0a87581893776ac85b00b101b2651258edaa9118 org.glassfish.jaxb.txw2-4.0.6.jar (shaded: org.glassfish.jaxb:txw2:4.0.6)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.glassfish.jaxb.txw2-4.0.6.jar/META-INF/maven/org.glassfish.jaxb/txw2/pom.xml MD5: 3b7d081682e20db2ecb3f8e60109bac1 SHA1: be583548df5da9c8e8bb2b9e396296bb5b4124ef SHA256: 6af14a91b3f9e9e317f7a58e80dcbefd3df4f2f205448359ff3a1c5901627374 pkg:maven/org.glassfish.jaxb/txw2@4.0.6 txw2-4.0.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/glassfish/jaxb/txw2/4.0.6/txw2-4.0.6.jar MD5: 0bf7070aee3bb53640d2ea6441e059fb SHA1: 4f4cd53b5ff9a2c5aa1211f15ed2569c57dfb044 SHA256: fcc749785412ef3806fde1ce70f93ef5a0065dcc47fe449bc871db0795cb11af pkg:maven/org.glassfish.jaxb/txw2@4.0.6 cpe:2.3:a:eclipse:glassfish:4.0.6:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2024-9329 suppress
In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint is '/management/domain'. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. CWE-601 URL Redirection to Untrusted Site ('Open Redirect'), CWE-233 Improper Handling of Parameters
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
org.hibernate.models.hibernate-models-1.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.hibernate.models.hibernate-models-1.0.1.jarMD5: 911e7ad11382712f0869328465937718SHA1: 3158c5f9309494b905de62c72f6f02d108aea651SHA256: bdb42c4979001742ebc098f3b206dd1057dc93be55c50a31c3f027d3eed06412
Evidence Type Source Name Value Confidence Vendor file name org.hibernate.models.hibernate-models High Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor jar package name internal Low Vendor jar package name models Highest Vendor jar package name models Low Vendor Manifest automatic-module-name org.hibernate.models Medium Product file name org.hibernate.models.hibernate-models High Product jar package name hibernate Highest Product jar package name internal Low Product jar package name models Highest Product jar package name models Low Product Manifest automatic-module-name org.hibernate.models Medium Version file name org.hibernate.models.hibernate-models Medium Version file version 1.0.1 High
Related Dependencies hibernate-models-1.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hibernate/models/hibernate-models/1.0.1/hibernate-models-1.0.1.jar MD5: 911e7ad11382712f0869328465937718 SHA1: 3158c5f9309494b905de62c72f6f02d108aea651 SHA256: bdb42c4979001742ebc098f3b206dd1057dc93be55c50a31c3f027d3eed06412 pkg:maven/org.hibernate.models/hibernate-models@1.0.1 org.hibernate.models.hibernate-models-1.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.hibernate.models.hibernate-models-1.0.1.jar MD5: 911e7ad11382712f0869328465937718 SHA1: 3158c5f9309494b905de62c72f6f02d108aea651 SHA256: bdb42c4979001742ebc098f3b206dd1057dc93be55c50a31c3f027d3eed06412 org.hibernate.orm.hibernate-core-7.1.11.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.hibernate.orm.hibernate-core-7.1.11.Final.jarMD5: 4e165c298d5f880836185259ce51e942SHA1: 1b07cd175f8999792e1a46f3bba7464164f4dfbeSHA256: de30f99eecedaecc8e3370f418c54b77bb5d2c0862d32d2e1bc4db8a52852eff
Evidence Type Source Name Value Confidence Vendor file name org.hibernate.orm.hibernate-core High Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor Manifest automatic-module-name org.hibernate.orm.core Medium Vendor Manifest bundle-docurl https://hibernate.org/orm/releases/7.1 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.core Medium Vendor Manifest implementation-url https://hibernate.org/orm Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest specification-vendor Hibernate.org Low Product file name org.hibernate.orm.hibernate-core High Product jar package name hibernate Highest Product Manifest automatic-module-name org.hibernate.orm.core Medium Product Manifest bundle-docurl https://hibernate.org/orm/releases/7.1 Low Product Manifest Bundle-Name hibernate-core Medium Product Manifest bundle-symbolicname org.hibernate.orm.core Medium Product Manifest Implementation-Title hibernate-core High Product Manifest implementation-url https://hibernate.org/orm Low Product Manifest specification-title hibernate-core Medium Version file version 7.1.11 High Version Manifest Implementation-Version 7.1.11.Final High
Related Dependencies hibernate-core-7.1.11.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hibernate/orm/hibernate-core/7.1.11.Final/hibernate-core-7.1.11.Final.jar MD5: 4e165c298d5f880836185259ce51e942 SHA1: 1b07cd175f8999792e1a46f3bba7464164f4dfbe SHA256: de30f99eecedaecc8e3370f418c54b77bb5d2c0862d32d2e1bc4db8a52852eff pkg:maven/org.hibernate.orm/hibernate-core@7.1.11.Final hibernate-graalvm-7.1.11.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hibernate/orm/hibernate-graalvm/7.1.11.Final/hibernate-graalvm-7.1.11.Final.jar MD5: 67ce5aa9bd09085f058149dc4641fadf SHA1: f3f7eade70c3914a60b3c74a4d53e770e3cacfa3 SHA256: eeea166a729c82365ecd12259796a14b239286a4833e5a9626a93d48d5096574 pkg:maven/org.hibernate.orm/hibernate-graalvm@7.1.11.Final org.hibernate.orm.hibernate-core-7.1.11.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.hibernate.orm.hibernate-core-7.1.11.Final.jar MD5: 4e165c298d5f880836185259ce51e942 SHA1: 1b07cd175f8999792e1a46f3bba7464164f4dfbe SHA256: de30f99eecedaecc8e3370f418c54b77bb5d2c0862d32d2e1bc4db8a52852eff org.hibernate.orm.hibernate-graalvm-7.1.11.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.hibernate.orm.hibernate-graalvm-7.1.11.Final.jar MD5: 67ce5aa9bd09085f058149dc4641fadf SHA1: f3f7eade70c3914a60b3c74a4d53e770e3cacfa3 SHA256: eeea166a729c82365ecd12259796a14b239286a4833e5a9626a93d48d5096574 org.hibernate.orm.hibernate-graalvm-7.1.11.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.hibernate.orm.hibernate-graalvm-7.1.11.Final.jarMD5: 67ce5aa9bd09085f058149dc4641fadfSHA1: f3f7eade70c3914a60b3c74a4d53e770e3cacfa3SHA256: eeea166a729c82365ecd12259796a14b239286a4833e5a9626a93d48d5096574
Evidence Type Source Name Value Confidence Vendor file name org.hibernate.orm.hibernate-graalvm High Vendor jar package name graalvm Highest Vendor jar package name graalvm Low Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor jar package name internal Low Vendor Manifest automatic-module-name org.hibernate.orm.graalvm Medium Vendor Manifest bundle-docurl https://hibernate.org/orm/releases/7.1 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.graalvm Medium Vendor Manifest implementation-url https://hibernate.org/orm Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest specification-vendor Hibernate.org Low Product file name org.hibernate.orm.hibernate-graalvm High Product jar package name graalvm Highest Product jar package name graalvm Low Product jar package name hibernate Highest Product jar package name internal Low Product Manifest automatic-module-name org.hibernate.orm.graalvm Medium Product Manifest bundle-docurl https://hibernate.org/orm/releases/7.1 Low Product Manifest Bundle-Name hibernate-graalvm Medium Product Manifest bundle-symbolicname org.hibernate.orm.graalvm Medium Product Manifest Implementation-Title hibernate-graalvm High Product Manifest implementation-url https://hibernate.org/orm Low Product Manifest specification-title hibernate-graalvm Medium Version file version 7.1.11 High Version Manifest Implementation-Version 7.1.11.Final High
org.hibernate.quarkus-local-cache-0.3.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.hibernate.quarkus-local-cache-0.3.1.jarMD5: 8e6b3de7a260ef80f279033127757ebdSHA1: a0e9b53ad67b9735cdc320ca1428688d5f777d1dSHA256: a8feb703499dfaf129a364c84e1fb5f6c9738b96b6ac3e59dfc4697652a23d0b
Evidence Type Source Name Value Confidence Vendor file name org.hibernate.quarkus-local-cache High Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor jar package name infinispan Low Vendor jar package name quarkus Low Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor hibernate.org High Vendor Manifest Implementation-Vendor-Id hibernate.org Medium Product file name org.hibernate.quarkus-local-cache High Product jar package name cache Highest Product jar package name cache Low Product jar package name hibernate Highest Product jar package name hibernate Low Product jar package name quarkus Highest Product jar package name quarkus Low Product Manifest Implementation-Title Local-only Hibernate Cache for Quarkus High Product Manifest implementation-url http://hibernate.org Low Version file version 0.3.1 High Version Manifest Implementation-Version 0.3.1 High
Related Dependencies org.hibernate.quarkus-local-cache-0.3.1.jar (shaded: org.hibernate:quarkus-local-cache:0.3.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.hibernate.quarkus-local-cache-0.3.1.jar/META-INF/maven/org.hibernate/quarkus-local-cache/pom.xml MD5: a3ccb42269470c287203cdea58d3305c SHA1: 90c00400ac4e287b951864978cd8303173640d29 SHA256: 1e15bb94a980f76b9fa02c96cfd19160c8ac8ba4a6c892829665acc9e79cd0fa pkg:maven/org.hibernate/quarkus-local-cache@0.3.1 org.hibernate.quarkus-local-cache-0.3.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.hibernate.quarkus-local-cache-0.3.1.jar MD5: 8e6b3de7a260ef80f279033127757ebd SHA1: a0e9b53ad67b9735cdc320ca1428688d5f777d1d SHA256: a8feb703499dfaf129a364c84e1fb5f6c9738b96b6ac3e59dfc4697652a23d0b quarkus-local-cache-0.3.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hibernate/quarkus-local-cache/0.3.1/quarkus-local-cache-0.3.1.jar MD5: 8e6b3de7a260ef80f279033127757ebd SHA1: a0e9b53ad67b9735cdc320ca1428688d5f777d1d SHA256: a8feb703499dfaf129a364c84e1fb5f6c9738b96b6ac3e59dfc4697652a23d0b pkg:maven/org.hibernate/quarkus-local-cache@0.3.1 CVE-2022-21724 suppress
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue. CWE-665 Improper Initialization
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-4116 suppress
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution. NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-6267 suppress
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security. CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-26291 suppress
Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in the legacy behavior, and are unaffected by this vulnerability and change to default behavior. See this link for more information about repository management: https://maven.apache.org/repository-management.html CWE-346 Origin Validation Error
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2020-1714 suppress
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution. CWE-20 Improper Input Validation
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2022-0981 suppress
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended. CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2023-4853 suppress
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service. CWE-148 Improper Neutralization of Input Leaders, CWE-863 Incorrect Authorization
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,MITIGATION,TECHNICAL_DESCRIPTION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MITIGATION,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - EXPLOIT,MITIGATION,TECHNICAL_DESCRIPTION,VENDOR_ADVISORY secalert@redhat.com - ISSUE_TRACKING,VENDOR_ADVISORY secalert@redhat.com - MITIGATION,VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29428 suppress
In Gradle before version 7.0, on Unix-like systems, the system temporary directory can be created with open permissions that allow multiple users to create and delete files within it. Gradle builds could be vulnerable to a local privilege escalation from an attacker quickly deleting and recreating files in the system temporary directory. This vulnerability impacted builds using precompiled script plugins written in Kotlin DSL and tests for Gradle plugins written using ProjectBuilder or TestKit. If you are on Windows or modern versions of macOS, you are not vulnerable. If you are on a Unix-like operating system with the "sticky" bit set on your system temporary directory, you are not vulnerable. The problem has been patched and released with Gradle 7.0. As a workaround, on Unix-like operating systems, ensure that the "sticky" bit is set. This only allows the original user (or root) to delete a file. If you are unable to change the permissions of the system temporary directory, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. For additional details refer to the referenced GitHub Security Advisory. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions
CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.4) Vector: /AV:L/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2020-13692 suppress
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: HIGH (7.7) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2017-18640 suppress
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564. CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - RELEASE_NOTES,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-25649 suppress
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity. CWE-611 Improper Restriction of XML External Entity Reference
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-28491 suppress
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY report@snyk.io - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY report@snyk.io - PATCH,THIRD_PARTY_ADVISORY report@snyk.io - PATCH,THIRD_PARTY_ADVISORY report@snyk.io - PATCH,THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-37136 suppress
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37137 suppress
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk. CWE-400 Uncontrolled Resource Consumption
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-37714 suppress
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw an unexpected exception. This effect may support a denial of service attack. The issue is patched in version 1.14.2. There are a few available workarounds. Users may rate limit input parsing, limit the size of inputs based on system resources, and/or implement thread watchdogs to cap and timeout parse runtimes. CWE-248 Uncaught Exception, CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - RELEASE_NOTES,VENDOR_ADVISORY security-advisories@github.com - RELEASE_NOTES,VENDOR_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-42003 suppress
In FasterXML jackson-databind before versions 2.13.4.1 and 2.12.17.1, resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2022-42004 suppress
In FasterXML jackson-databind before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. An application is vulnerable only with certain customized choices for deserialization. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,MAILING_LIST,PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - EXPLOIT,ISSUE_TRACKING,THIRD_PARTY_ADVISORY cve@mitre.org - MAILING_LIST,THIRD_PARTY_ADVISORY cve@mitre.org - PATCH,THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2023-1584 suppress
A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data from OIDC provider services. Please note that passwords are not stored in access tokens. NVD-CWE-noinfo, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2020-25638 suppress
A flaw was found in hibernate-core in versions prior to and including 5.4.23.Final. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (7.4) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY secalert@redhat.com - MAILING_LIST,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29427 suppress
In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was introduced in the wake of the "A Confusing Dependency" blog post. In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file. This may change how dependencies are resolved for Gradle plugins and build scripts. For builds that are vulnerable, there are two risks: 1) Information disclosure: Gradle could make dependency requests to repositories outside your organization and leak internal package identifiers. 2) Dependency poisoning/Dependency confusion: Gradle could download a malicious binary from a repository outside your organization due to name squatting. For a full example and more details refer to the referenced GitHub Security Advisory. The problem has been patched and released with Gradle 7.0. Users relying on this feature should upgrade their build as soon as possible. As a workaround, users may use a company repository which has the right rules for fetching packages from public repositories, or use project level repository content filtering, inside `buildscript.repositories`. This option is available since Gradle 5.1 when the feature was introduced. CWE-829 Inclusion of Functionality from Untrusted Control Sphere
CVSSv3:
Base Score: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:1.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-20328 suppress
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption. CWE-295 Improper Certificate Validation
CVSSv3:
Base Score: MEDIUM (6.8) Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:1.6/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:A/AC:M/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2022-21363 suppress
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H). NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.6) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2019-14900 suppress
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-43797 suppress
Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are present at the beginning / end of the header name. It should instead fail fast as these are not allowed by the spec and could lead to HTTP request smuggling. Failing to do the validation might cause netty to "sanitize" header names before it forward these to another remote system when used as proxy. This remote system can't see the invalid usage anymore, and therefore does not do the validation itself. Users should upgrade to version 4.1.71.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2023-0044 suppress
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2021-21295 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.60.Final there is a vulnerability that enables request smuggling. If a Content-Length header is present in the original HTTP/2 request, the field is not validated by `Http2MultiplexHandler` as it is propagated up. This is fine as long as the request is not proxied through as HTTP/1.1. If the request comes in as an HTTP/2 stream, gets converted into the HTTP/1.1 domain objects (`HttpRequest`, `HttpContent`, etc.) via `Http2StreamFrameToHttpObjectCodec `and then sent up to the child channel's pipeline and proxied through a remote peer as HTTP/1.1 this may result in request smuggling. In a proxy case, users may assume the content-length is validated somehow, which is not the case. If the request is forwarded to a backend channel that is a HTTP/1.1 connection, the Content-Length now has meaning and needs to be checked. An attacker can smuggle requests inside the body as it gets downgraded from HTTP/2 to HTTP/1.1. For an example attack refer to the linked GitHub Advisory. Users are only affected if all of this is true: `HTTP2MultiplexCodec` or `Http2FrameCodec` is used, `Http2StreamFrameToHttpObjectCodec` is used to convert to HTTP/1.1 objects, and these HTTP/1.1 objects are forwarded to another remote peer. This has been patched in 4.1.60.Final As a workaround, the user can do the validation by themselves by implementing a custom `ChannelInboundHandler` that is put in the `ChannelPipeline` behind `Http2StreamFrameToHttpObjectCodec`. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: LOW (2.6) Vector: /AV:N/AC:H/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-21409 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not correctly validated if the request only uses a single Http2HeaderFrame with the endStream set to to true. This could lead to request smuggling if the request is proxied to a remote peer and translated to HTTP/1.1. This is a followup of GHSA-wm47-8v5p-wjpj/CVE-2021-21295 which did miss to fix this one case. This was fixed as part of 4.1.61.Final. CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-2471 suppress
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H). NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H/E:0.7/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.9) Vector: /AV:N/AC:M/Au:S/C:C/I:N/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2021-38153 suppress
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0. CWE-203 Observable Discrepancy
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-21290 suppress
Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a vulnerability on Unix-like systems involving an insecure temp file. When netty's multipart decoders are used local information disclosure can occur via the local system temporary directory if temporary storing uploads on the disk is enabled. On unix-like systems, the temporary directory is shared between all user. As such, writing to this directory using APIs that do not explicitly set the file/directory permissions can lead to information disclosure. Of note, this does not impact modern MacOS Operating Systems. The method "File.createTempFile" on unix-like systems creates a random file, but, by default will create this file with the permissions "-rw-r--r--". Thus, if sensitive information is written to this file, other local users can read this information. This is the case in netty's "AbstractDiskHttpData" is vulnerable. This has been fixed in version 4.1.59.Final. As a workaround, one may specify your own "java.io.tmpdir" when you start the JVM or use "DefaultHttpDataFactory.setBaseDir(...)" to set the directory to something that is only readable by the current user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-379 Creation of Temporary File in Directory with Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security-advisories@github.com - EXPLOIT,THIRD_PARTY_ADVISORY security-advisories@github.com - MAILING_LIST,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - PATCH,THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY security-advisories@github.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2021-29429 suppress
In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to a local information disclosure. Remote files accessed through TextResourceFactory are downloaded into the system temporary directory first. Sensitive information contained in these files can be exposed to other local users on the same system. If you do not use the `TextResourceFactory` API, you are not vulnerable. As of Gradle 7.0, uses of the system temporary directory have been moved to the Gradle User Home directory. By default, this directory is restricted to the user running the build. As a workaround, set a more restrictive umask that removes read access to other users. When files are created in the system temporary directory, they will not be accessible to other users. If you are unable to change your system's umask, you can move the Java temporary directory by setting the System Property `java.io.tmpdir`. The new path needs to limit permissions to the build user only. CWE-377 Insecure Temporary File
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-1728 suppress
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, yet it might aid attackers in their efforts to exploit other problems. The flaws unnecessarily make the servers more prone to Clickjacking, channel downgrade attacks and other similar client-based attack vectors. CWE-358 Improperly Implemented Security Check for Standard, CWE-1021 Improper Restriction of Rendered UI Layers or Frames
CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-10693 suppress
A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input sanitation (escaping, stripping) controls that developers may have put in place when handling user-controlled data in error messages. CWE-20 Improper Input Validation
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-13956 suppress
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution. NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - MAILING_LIST,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY security@apache.org - MAILING_LIST,VENDOR_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - PATCH,THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY security@apache.org - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2020-25633 suppress
A flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentially sensitive information when the server got WebApplicationException from the RESTEasy client call. The highest threat from this vulnerability is to data confidentiality. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-20289 suppress
A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. The highest threat from this vulnerability is to data confidentiality. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-28170 suppress
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. CWE-20 Improper Input Validation, CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-3642 suppress
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. CWE-203 Observable Discrepancy
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.6/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-25724 suppress
A flaw was found in RESTEasy, where an incorrect response to an HTTP request is provided. This flaw allows an attacker to gain access to privileged information. The highest threat from this vulnerability is to confidentiality and integrity. Versions before resteasy 2.0.0.Alpha3 are affected. CWE-567 Unsynchronized Access to Shared Data in a Multithreaded Context
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-8908 suppress
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to the system). The method in question has been marked @Deprecated in versions 30.0 and later and should not be used. For Android developers, we recommend choosing a temporary directory API provided by Android, such as context.getCacheDir(). For other Java developers, we recommend migrating to the Java 7 API java.nio.file.Files.createTempDirectory() which explicitly configures permissions of 700, or configuring the Java runtime's java.io.tmpdir system property to point to a location whose permissions are appropriately configured.
CWE-378 Creation of Temporary File With Insecure Permissions, CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (2.1) Vector: /AV:L/AC:L/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - EXPLOIT,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY cve-coordination@google.com - EXPLOIT,PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - ISSUE_TRACKING,PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - PATCH,THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY cve-coordination@google.com - THIRD_PARTY_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2023-0481 suppress
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user. CWE-378 Creation of Temporary File With Insecure Permissions, CWE-668 Exposure of Resource to Wrong Sphere
CVSSv3:
Base Score: LOW (3.3) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
org.hibernate.validator.hibernate-validator-9.1.0.Final.jarDescription:
Hibernate's Jakarta Validation reference implementation. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.hibernate.validator.hibernate-validator-9.1.0.Final.jar
MD5: 003c10d00a9700ff8e80098eda4dcb0e
SHA1: 53505ad984428ab42b4a4f3456aab9ec343bf2f2
SHA256: 4dea20c780d12e8ad6e1fe7d695460af74f8668df9eb58910991919194412188
Evidence Type Source Name Value Confidence Vendor file name org.hibernate.validator.hibernate-validator High Vendor jar package name hibernate Highest Vendor jar package name hibernate Low Vendor jar package name internal Low Vendor jar package name validator Highest Vendor jar package name validator Low Vendor Manifest build-jdk-spec 25 Low Vendor Manifest bundle-symbolicname org.hibernate.validator Medium Vendor Manifest implementation-url https://hibernate.org/validator/ Low Vendor Manifest Implementation-Vendor org.hibernate.validator High Vendor Manifest Implementation-Vendor-Id org.hibernate.validator Medium Product file name org.hibernate.validator.hibernate-validator High Product jar package name engine Highest Product jar package name hibernate Highest Product jar package name internal Low Product jar package name validator Highest Product jar package name validator Low Product Manifest build-jdk-spec 25 Low Product Manifest Bundle-Name Hibernate Validator Engine Medium Product Manifest bundle-symbolicname org.hibernate.validator Medium Product Manifest Implementation-Title hibernate-validator High Product Manifest implementation-url https://hibernate.org/validator/ Low Product Manifest specification-title Jakarta Validation Medium Version file version 9.1.0 High Version Manifest Implementation-Version 9.1.0.Final High
Related Dependencies hibernate-validator-9.1.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/hibernate/validator/hibernate-validator/9.1.0.Final/hibernate-validator-9.1.0.Final.jar MD5: 003c10d00a9700ff8e80098eda4dcb0e SHA1: 53505ad984428ab42b4a4f3456aab9ec343bf2f2 SHA256: 4dea20c780d12e8ad6e1fe7d695460af74f8668df9eb58910991919194412188 pkg:maven/org.hibernate.validator/hibernate-validator@9.1.0.Final org.hibernate.validator.hibernate-validator-9.1.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.hibernate.validator.hibernate-validator-9.1.0.Final.jar MD5: 003c10d00a9700ff8e80098eda4dcb0e SHA1: 53505ad984428ab42b4a4f3456aab9ec343bf2f2 SHA256: 4dea20c780d12e8ad6e1fe7d695460af74f8668df9eb58910991919194412188 CVE-2025-15104 suppress
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd). CWE-918 Server-Side Request Forgery (SSRF)
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
org.jacoco.agent-0.8.13-runtime.jar (shaded: org.jacoco:org.jacoco.agent.rt:0.8.13)Description:
JaCoCo Java Agent File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.13/org.jacoco.agent-0.8.13-runtime.jar/META-INF/maven/org.jacoco/org.jacoco.agent.rt/pom.xmlMD5: f605822110446edb8421c5db2d25ac37SHA1: e6061cd2c843a09e2491363afc7e7e0c72174c3cSHA256: 1b58aae6bd8c906f23b9915fd046ab04f38ff25072f21e885bf0fe3fe020b1c4
Evidence Type Source Name Value Confidence Vendor pom artifactid jacoco.agent.rt Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Agent RT High Vendor pom parent-artifactid org.jacoco.build Low Product pom artifactid jacoco.agent.rt Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Agent RT High Product pom parent-artifactid org.jacoco.build Medium Version pom version 0.8.13 Highest
pkg:maven/org.jacoco/org.jacoco.agent.rt@0.8.13 (Confidence :High) org.jacoco.agent-0.8.13-runtime.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.13/org.jacoco.agent-0.8.13-runtime.jarMD5: e5abff18b16682ea4ff4e93b893089daSHA1: 850ba9544f357712728f89fe3e1fd51b265a0192SHA256: 47e700ccb0fdb9e27c5241353f8161938f4e53c3561dd35e063c5fe88dc3349b
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.agent High Vendor jar package name agent Highest Vendor jar package name agent Low Vendor jar package name jacoco Highest Vendor jar package name jacoco Low Vendor jar package name rt Highest Vendor jar package name rt Low Vendor Manifest automatic-module-name org.jacoco.agent.rt Medium Vendor Manifest build-jdk-spec 1.5 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Mountainminds GmbH & Co. KG High Product file name org.jacoco.agent High Product jar package name agent Highest Product jar package name agent Low Product jar package name internal_0e20598 Low Product jar package name jacoco Highest Product jar package name rt Highest Product jar package name rt Low Product Manifest automatic-module-name org.jacoco.agent.rt Medium Product Manifest build-jdk-spec 1.5 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Implementation-Title JaCoCo Java Agent High Version file version 0.8.13 High Version Manifest Implementation-Version 0.8.13 High
org.jacoco.agent-0.8.14-runtime.jar (shaded: org.jacoco:org.jacoco.agent.rt:0.8.14)Description:
JaCoCo Java Agent File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.14/org.jacoco.agent-0.8.14-runtime.jar/META-INF/maven/org.jacoco/org.jacoco.agent.rt/pom.xmlMD5: 8926b54ca2e7cf401672ea548a772642SHA1: a6b7b25d0d1cc2a8d8b7d1a02cc13a4b63614836SHA256: 820171ee970faf8a3ffd92a07ab360cf0ea65e98977d063f35a5990fe9e5781d
Evidence Type Source Name Value Confidence Vendor pom artifactid jacoco.agent.rt Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Agent RT High Vendor pom parent-artifactid org.jacoco.build Low Product pom artifactid jacoco.agent.rt Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Agent RT High Product pom parent-artifactid org.jacoco.build Medium Version pom version 0.8.14 Highest
Related Dependencies org.jacoco.agent-0.8.14.jar: jacocoagent.jar (shaded: org.jacoco:org.jacoco.agent.rt:0.8.14)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.14/org.jacoco.agent-0.8.14.jar/jacocoagent.jar/META-INF/maven/org.jacoco/org.jacoco.agent.rt/pom.xml MD5: 8926b54ca2e7cf401672ea548a772642 SHA1: a6b7b25d0d1cc2a8d8b7d1a02cc13a4b63614836 SHA256: 820171ee970faf8a3ffd92a07ab360cf0ea65e98977d063f35a5990fe9e5781d pkg:maven/org.jacoco/org.jacoco.agent.rt@0.8.14 pkg:maven/org.jacoco/org.jacoco.agent.rt@0.8.14 (Confidence :High) org.jacoco.agent-0.8.14-runtime.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.14/org.jacoco.agent-0.8.14-runtime.jarMD5: 0fc2cdf54086905065f5700cb9250a4aSHA1: 4bb9b49d4e6c5b042fc7e6b4f1e3e808f7441ddeSHA256: 3fb76eea65f81bd9415202bab34b6571728841dff1ab8e6bbe81adc2e299face
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.agent High Vendor jar package name agent Highest Vendor jar package name agent Low Vendor jar package name jacoco Highest Vendor jar package name jacoco Low Vendor jar package name rt Highest Vendor jar package name rt Low Vendor Manifest automatic-module-name org.jacoco.agent.rt Medium Vendor Manifest build-jdk-spec 1.5 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Mountainminds GmbH & Co. KG High Product file name org.jacoco.agent High Product jar package name agent Highest Product jar package name agent Low Product jar package name internal_29a6edd Low Product jar package name jacoco Highest Product jar package name rt Highest Product jar package name rt Low Product Manifest automatic-module-name org.jacoco.agent.rt Medium Product Manifest build-jdk-spec 1.5 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Implementation-Title JaCoCo Java Agent High Version file version 0.8.14 High Version Manifest Implementation-Version 0.8.14 High
Related Dependencies org.jacoco.agent-0.8.14.jar: jacocoagent.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.14/org.jacoco.agent-0.8.14.jar/jacocoagent.jar MD5: 0fc2cdf54086905065f5700cb9250a4a SHA1: 4bb9b49d4e6c5b042fc7e6b4f1e3e808f7441dde SHA256: 3fb76eea65f81bd9415202bab34b6571728841dff1ab8e6bbe81adc2e299face org.jacoco.agent-0.8.14.jarDescription:
JaCoCo Agent License:
https://www.eclipse.org/legal/epl-2.0/ File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.14/org.jacoco.agent-0.8.14.jar
MD5: 80ca49511ad2aaadecb86b631b400f10
SHA1: bca1f6d49506da3eb9d0d3b9acbcfdd1fb22c14e
SHA256: 20be9853385bdfc65a5929643412d09243d14514304b89ba23a265158cc8792b
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.agent High Vendor jar package name agent Highest Vendor jar package name jacoco Highest Vendor Manifest automatic-module-name org.jacoco.agent Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.jacoco.agent Medium Vendor pom artifactid jacoco.agent Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Agent High Vendor pom parent-artifactid org.jacoco.build Low Product file name org.jacoco.agent High Product jar package name agent Highest Product jar package name jacoco Highest Product Manifest automatic-module-name org.jacoco.agent Medium Product Manifest build-jdk-spec 21 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Bundle-Name JaCoCo Agent Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.jacoco.agent Medium Product pom artifactid jacoco.agent Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Agent High Product pom parent-artifactid org.jacoco.build Medium Version file version 0.8.14 High Version pom version 0.8.14 Highest
pkg:maven/org.jacoco/org.jacoco.agent@0.8.14 (Confidence :High) org.jacoco.core-0.8.13.jarDescription:
JaCoCo Core License:
https://www.eclipse.org/legal/epl-2.0/ File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.core/0.8.13/org.jacoco.core-0.8.13.jar
MD5: a744ac46e98efe9ef72e0a2116748b04
SHA1: 4424d689f0738cd4445e948270e3f2f2d0e5cdb8
SHA256: 514c23df6cfd015d7d83c10a792e35ab68a7b7e82f3d6a3a4481762c132e33a9
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.core High Vendor jar package name core Highest Vendor jar package name jacoco Highest Vendor Manifest automatic-module-name org.jacoco.core Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.jacoco.core Medium Vendor pom artifactid jacoco.core Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Core High Vendor pom parent-artifactid org.jacoco.build Low Product file name org.jacoco.core High Product jar package name core Highest Product jar package name jacoco Highest Product Manifest automatic-module-name org.jacoco.core Medium Product Manifest build-jdk-spec 21 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Bundle-Name JaCoCo Core Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.jacoco.core Medium Product pom artifactid jacoco.core Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Core High Product pom parent-artifactid org.jacoco.build Medium Version file version 0.8.13 High Version pom version 0.8.13 Highest
pkg:maven/org.jacoco/org.jacoco.core@0.8.13 (Confidence :High) org.jacoco.core-0.8.14.jarDescription:
JaCoCo Core License:
https://www.eclipse.org/legal/epl-2.0/ File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.core/0.8.14/org.jacoco.core-0.8.14.jar
MD5: 07f7ab938a007b6146aede8407c2b117
SHA1: 5d317827447ab203bb90ecc7597850baae9c8565
SHA256: 28abbf0eea5a08e4f24097f2fbac663ca17c341c25c3a04d90d6cd325943c995
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.core High Vendor jar package name core Highest Vendor jar package name jacoco Highest Vendor Manifest automatic-module-name org.jacoco.core Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.jacoco.core Medium Vendor pom artifactid jacoco.core Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Core High Vendor pom parent-artifactid org.jacoco.build Low Product file name org.jacoco.core High Product jar package name core Highest Product jar package name jacoco Highest Product Manifest automatic-module-name org.jacoco.core Medium Product Manifest build-jdk-spec 21 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Bundle-Name JaCoCo Core Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.jacoco.core Medium Product pom artifactid jacoco.core Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Core High Product pom parent-artifactid org.jacoco.build Medium Version file version 0.8.14 High Version pom version 0.8.14 Highest
Related Dependencies org.jacoco.agent-0.8.14.jar: jacocoagent.jar (shaded: org.jacoco:org.jacoco.core:0.8.14)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.agent/0.8.14/org.jacoco.agent-0.8.14.jar/jacocoagent.jar/META-INF/maven/org.jacoco/org.jacoco.core/pom.xml MD5: 620aa68512219e859412ff2ae2af20fc SHA1: 6dbaed317295aadea76fc848057dc67d99736062 SHA256: 7b75bae2c1779af544369833afe1d68f5a3955e91d166cb19dff886534b1ad6c pkg:maven/org.jacoco/org.jacoco.core@0.8.14 pkg:maven/org.jacoco/org.jacoco.core@0.8.14 (Confidence :High) org.jacoco.report-0.8.13.jarDescription:
JaCoCo Report License:
https://www.eclipse.org/legal/epl-2.0/ File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.report/0.8.13/org.jacoco.report-0.8.13.jar
MD5: e7b18fffabb0ddd7502fd4b76c6e0b00
SHA1: 44d475e169049322b081db376933bad859ec6526
SHA256: 8133280a0aa44358be9d136b52370342f455ccb944aae07438220a77662578a2
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.report High Vendor jar package name jacoco Highest Vendor jar package name report Highest Vendor Manifest automatic-module-name org.jacoco.report Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.jacoco.report Medium Vendor pom artifactid jacoco.report Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Report High Vendor pom parent-artifactid org.jacoco.build Low Product file name org.jacoco.report High Product jar package name jacoco Highest Product jar package name report Highest Product Manifest automatic-module-name org.jacoco.report Medium Product Manifest build-jdk-spec 21 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Bundle-Name JaCoCo Report Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.jacoco.report Medium Product pom artifactid jacoco.report Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Report High Product pom parent-artifactid org.jacoco.build Medium Version file version 0.8.13 High Version pom version 0.8.13 Highest
pkg:maven/org.jacoco/org.jacoco.report@0.8.13 (Confidence :High) org.jacoco.report-0.8.14.jarDescription:
JaCoCo Report License:
https://www.eclipse.org/legal/epl-2.0/ File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.report/0.8.14/org.jacoco.report-0.8.14.jar
MD5: 00cef8f0702d2c26201078f566552014
SHA1: d25b1c200c0c6e82baac3c0ddb8b9e38f13a5f6c
SHA256: a3e2026060ab8b8d5c650706406234bb4c033dfd5376afeb8b1666e8ed27c453
Evidence Type Source Name Value Confidence Vendor file name org.jacoco.report High Vendor jar package name jacoco Highest Vendor jar package name report Highest Vendor Manifest automatic-module-name org.jacoco.report Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest build-tool-jdk-spec 21 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname org.jacoco.report Medium Vendor pom artifactid jacoco.report Low Vendor pom groupid org.jacoco Highest Vendor pom name JaCoCo :: Report High Vendor pom parent-artifactid org.jacoco.build Low Product file name org.jacoco.report High Product jar package name jacoco Highest Product jar package name report Highest Product Manifest automatic-module-name org.jacoco.report Medium Product Manifest build-jdk-spec 21 Low Product Manifest build-tool-jdk-spec 21 Low Product Manifest Bundle-Name JaCoCo Report Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname org.jacoco.report Medium Product pom artifactid jacoco.report Highest Product pom groupid org.jacoco Highest Product pom name JaCoCo :: Report High Product pom parent-artifactid org.jacoco.build Medium Version file version 0.8.14 High Version pom version 0.8.14 Highest
pkg:maven/org.jacoco/org.jacoco.report@0.8.14 (Confidence :High) org.jboss.invocation.jboss-invocation-2.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.invocation.jboss-invocation-2.0.0.Final.jarMD5: fd328a02b76b46dbcf681a6dacd9f708SHA1: a23df3678b4797bffaecff4be013fd9971d0f3a2SHA256: ef9beb3bff85930710b367b6f84d40bf72128898ca6ccdf3775537793b74b067
Evidence Type Source Name Value Confidence Vendor file name org.jboss.invocation.jboss-invocation High Vendor hint analyzer vendor redhat Highest Vendor jar package name invocation Low Vendor jar package name jboss Highest Vendor jar package name jboss Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest implementation-url http://www.jboss.org/jboss-invocation Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.invocation.jboss-invocation High Product jar package name invocation Highest Product jar package name invocation Low Product jar package name jboss Highest Product Manifest build-jdk-spec 11 Low Product Manifest Implementation-Title JBoss Invocation API - Jakarta EE Variant High Product Manifest implementation-url http://www.jboss.org/jboss-invocation Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Invocation API - Jakarta EE Variant Medium Version file version 2.0.0 High Version Manifest Implementation-Version 2.0.0.Final High
Related Dependencies jboss-invocation-2.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/invocation/jboss-invocation/2.0.0.Final/jboss-invocation-2.0.0.Final.jar MD5: fd328a02b76b46dbcf681a6dacd9f708 SHA1: a23df3678b4797bffaecff4be013fd9971d0f3a2 SHA256: ef9beb3bff85930710b367b6f84d40bf72128898ca6ccdf3775537793b74b067 pkg:maven/org.jboss.invocation/jboss-invocation@2.0.0.Final org.jboss.invocation.jboss-invocation-2.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.invocation.jboss-invocation-2.0.0.Final.jar MD5: fd328a02b76b46dbcf681a6dacd9f708 SHA1: a23df3678b4797bffaecff4be013fd9971d0f3a2 SHA256: ef9beb3bff85930710b367b6f84d40bf72128898ca6ccdf3775537793b74b067 org.jboss.jboss-transaction-spi-8.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.jboss-transaction-spi-8.0.0.Final.jarMD5: 218b5e634dfb78d592e2702e8f214dc0SHA1: c9ac775a105f4f7326c3b3052aee9c5ab1b29403SHA256: 07e4e62ceae075a8c11a715d89b19992c879f505b48be6b2727f5be798562ae1
Evidence Type Source Name Value Confidence Vendor file name org.jboss.jboss-transaction-spi High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name jboss Low Vendor jar package name tm Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.jboss-transaction-spi High Product jar package name jboss Highest Product jar package name tm Low Product Manifest build-jdk-spec 11 Low Product Manifest Implementation-Title JBoss Transaction SPI High Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Transaction SPI Medium Version file version 8.0.0 High Version Manifest Implementation-Version 8.0.0.Final High
Related Dependencies jboss-transaction-spi-8.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/jboss-transaction-spi/8.0.0.Final/jboss-transaction-spi-8.0.0.Final.jar MD5: 218b5e634dfb78d592e2702e8f214dc0 SHA1: c9ac775a105f4f7326c3b3052aee9c5ab1b29403 SHA256: 07e4e62ceae075a8c11a715d89b19992c879f505b48be6b2727f5be798562ae1 pkg:maven/org.jboss/jboss-transaction-spi@8.0.0.Final org.jboss.jboss-transaction-spi-8.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.jboss-transaction-spi-8.0.0.Final.jar MD5: 218b5e634dfb78d592e2702e8f214dc0 SHA1: c9ac775a105f4f7326c3b3052aee9c5ab1b29403 SHA256: 07e4e62ceae075a8c11a715d89b19992c879f505b48be6b2727f5be798562ae1 org.jboss.logging.commons-logging-jboss-logging-1.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.logging.commons-logging-jboss-logging-1.0.0.Final.jarMD5: 46328c16f47be35563b73425d456445aSHA1: 27a4e823d661bde67ec103bba2baf33cddde6e75SHA256: f12176263ea25f4e78bb4fa4b36d335a29738dde6a8123e1b6da89a655d150ff
Evidence Type Source Name Value Confidence Vendor file name org.jboss.logging.commons-logging-jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name apache Low Vendor jar package name commons Low Vendor jar package name logging Highest Vendor jar package name logging Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.logging.commons-logging-jboss-logging High Product jar package name commons Highest Product jar package name commons Low Product jar package name impl Low Product jar package name logging Highest Product jar package name logging Low Product Manifest Implementation-Title Commons Logging to JBoss Logging High Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Commons Logging to JBoss Logging Medium Version file version 1.0.0 High Version Manifest Implementation-Version 1.0.0.Final High
Related Dependencies commons-logging-jboss-logging-1.0.0.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/logging/commons-logging-jboss-logging/1.0.0.Final/commons-logging-jboss-logging-1.0.0.Final.jar MD5: 46328c16f47be35563b73425d456445a SHA1: 27a4e823d661bde67ec103bba2baf33cddde6e75 SHA256: f12176263ea25f4e78bb4fa4b36d335a29738dde6a8123e1b6da89a655d150ff pkg:maven/org.jboss.logging/commons-logging-jboss-logging@1.0.0.Final org.jboss.logging.jboss-logging-3.6.1.Final.jarDescription:
The JBoss Logging Framework License:
https://repository.jboss.org/licenses/apache-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/org.jboss.logging.jboss-logging-3.6.1.Final.jar
MD5: acab989faf62db02c092448e95614fab
SHA1: 886afbb445b4016a37c8960a7aef6ebd769ce7e5
SHA256: 5e08a4b092dc85b337f0910a740571d8720cfa565fabd880a8caf94a657ca416
Evidence Type Source Name Value Confidence Vendor file name org.jboss.logging.jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name jboss Low Vendor jar package name logging Highest Vendor jar package name logging Low Vendor Manifest automatic-module-name org.jboss.logging Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.logging.jboss-logging High Product jar package name jboss Highest Product jar package name logging Highest Product jar package name logging Low Product Manifest automatic-module-name org.jboss.logging Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest Implementation-Title JBoss Logging 3 High Product Manifest implementation-url http://www.jboss.org Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Logging 3 Medium Version file version 3.6.1 High Version Manifest Implementation-Version 3.6.1.Final High
Related Dependencies jboss-logging-3.6.1.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/logging/jboss-logging/3.6.1.Final/jboss-logging-3.6.1.Final.jar MD5: acab989faf62db02c092448e95614fab SHA1: 886afbb445b4016a37c8960a7aef6ebd769ce7e5 SHA256: 5e08a4b092dc85b337f0910a740571d8720cfa565fabd880a8caf94a657ca416 pkg:maven/org.jboss.logging/jboss-logging@3.6.1.Final org.jboss.logging.jboss-logging-3.6.1.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/org.jboss.logging.jboss-logging-3.6.1.Final.jar MD5: acab989faf62db02c092448e95614fab SHA1: 886afbb445b4016a37c8960a7aef6ebd769ce7e5 SHA256: 5e08a4b092dc85b337f0910a740571d8720cfa565fabd880a8caf94a657ca416 org.jboss.logmanager.jboss-logmanager-3.1.2.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/boot/org.jboss.logmanager.jboss-logmanager-3.1.2.Final.jarMD5: d68145d81ecd36ebea08b242072d45ecSHA1: 1bef088e3f640c3b1013308ec4d9e44b3371d373SHA256: c1e7de682a4871a8e4eefb26adaf0fcc63cd0913543c50aa6b7f46fa5ec151fe
Evidence Type Source Name Value Confidence Vendor file name org.jboss.logmanager.jboss-logmanager High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name jboss Low Vendor jar package name logmanager Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest multi-release true Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.logmanager.jboss-logmanager High Product jar package name jboss Highest Product jar package name logmanager Low Product jar package name org Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title JBoss Log Manager High Product Manifest implementation-url https://jboss.org Low Product Manifest multi-release true Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Log Manager Medium Version file version 3.1.2 High Version Manifest Implementation-Version 3.1.2.Final High
Related Dependencies jboss-logmanager-3.1.2.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/logmanager/jboss-logmanager/3.1.2.Final/jboss-logmanager-3.1.2.Final.jar MD5: d68145d81ecd36ebea08b242072d45ec SHA1: 1bef088e3f640c3b1013308ec4d9e44b3371d373 SHA256: c1e7de682a4871a8e4eefb26adaf0fcc63cd0913543c50aa6b7f46fa5ec151fe pkg:maven/org.jboss.logmanager/jboss-logmanager@3.1.2.Final org.jboss.logmanager.jboss-logmanager-3.1.2.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/boot/org.jboss.logmanager.jboss-logmanager-3.1.2.Final.jar MD5: d68145d81ecd36ebea08b242072d45ec SHA1: 1bef088e3f640c3b1013308ec4d9e44b3371d373 SHA256: c1e7de682a4871a8e4eefb26adaf0fcc63cd0913543c50aa6b7f46fa5ec151fe org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.arjunacore:arjuna:7.3.3.Final)Description:
Narayana: ArjunaCore Arjuna File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.arjunacore/arjuna/pom.xmlMD5: 064a90cfd5ca4251b852e2e1b4751877SHA1: 1e96b78a76696bb1cb85bab2d64f5dbc18ad8cabSHA256: 9bf72be0cc673822ca9c89244c9f97b2e975d8b5a3583c74381b61671a743c95
Evidence Type Source Name Value Confidence Vendor pom artifactid arjuna Low Vendor pom groupid org.jboss.narayana.arjunacore Highest Vendor pom name Narayana: ArjunaCore arjuna High Vendor pom parent-artifactid arjunacore-all Low Product pom artifactid arjuna Highest Product pom groupid org.jboss.narayana.arjunacore Highest Product pom name Narayana: ArjunaCore arjuna High Product pom parent-artifactid arjunacore-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.arjunacore:arjuna:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.arjunacore/arjuna/pom.xml MD5: 064a90cfd5ca4251b852e2e1b4751877 SHA1: 1e96b78a76696bb1cb85bab2d64f5dbc18ad8cab SHA256: 9bf72be0cc673822ca9c89244c9f97b2e975d8b5a3583c74381b61671a743c95 pkg:maven/org.jboss.narayana.arjunacore/arjuna@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.arjunacore:arjuna:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.arjunacore/arjuna/pom.xml MD5: 064a90cfd5ca4251b852e2e1b4751877 SHA1: 1e96b78a76696bb1cb85bab2d64f5dbc18ad8cab SHA256: 9bf72be0cc673822ca9c89244c9f97b2e975d8b5a3583c74381b61671a743c95 pkg:maven/org.jboss.narayana.arjunacore/arjuna@7.3.3.Final pkg:maven/org.jboss.narayana.arjunacore/arjuna@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.arjunacore:txoj:7.3.3.Final)Description:
ArjunaCore txoj module File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.arjunacore/txoj/pom.xmlMD5: d77b153702af9d2c50e5b38a2b464658SHA1: da5e57bae12d6e94afbf9904fad76664d667cef5SHA256: 3ceebfb28c8565104afeb85aa0c9b72a7be9b6d78c701563ae350828096d30bb
Evidence Type Source Name Value Confidence Vendor pom artifactid txoj Low Vendor pom groupid org.jboss.narayana.arjunacore Highest Vendor pom name Narayana: ArjunaCore txoj High Vendor pom parent-artifactid arjunacore-all Low Product pom artifactid txoj Highest Product pom groupid org.jboss.narayana.arjunacore Highest Product pom name Narayana: ArjunaCore txoj High Product pom parent-artifactid arjunacore-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.arjunacore:txoj:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.arjunacore/txoj/pom.xml MD5: d77b153702af9d2c50e5b38a2b464658 SHA1: da5e57bae12d6e94afbf9904fad76664d667cef5 SHA256: 3ceebfb28c8565104afeb85aa0c9b72a7be9b6d78c701563ae350828096d30bb pkg:maven/org.jboss.narayana.arjunacore/txoj@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.arjunacore:txoj:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.arjunacore/txoj/pom.xml MD5: d77b153702af9d2c50e5b38a2b464658 SHA1: da5e57bae12d6e94afbf9904fad76664d667cef5 SHA256: 3ceebfb28c8565104afeb85aa0c9b72a7be9b6d78c701563ae350828096d30bb pkg:maven/org.jboss.narayana.arjunacore/txoj@7.3.3.Final pkg:maven/org.jboss.narayana.arjunacore/txoj@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:cdi:7.3.3.Final)Description:
Narayana: ArjunaJTA cdi File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/cdi/pom.xmlMD5: 8f78f9fb9affd1e7a999dfc79d1b3415SHA1: e0771e5a9825e52ed5e06fbd38fd338a7cac1598SHA256: abe7251b35f65035d415a941b76eadecfb6a7f9f1230c480058dec631b9df383
Evidence Type Source Name Value Confidence Vendor pom artifactid cdi Low Vendor pom groupid org.jboss.narayana.jta Highest Vendor pom name Narayana: ArjunaJTA cdi High Vendor pom parent-artifactid narayana-jta-all Low Product pom artifactid cdi Highest Product pom groupid org.jboss.narayana.jta Highest Product pom name Narayana: ArjunaJTA cdi High Product pom parent-artifactid narayana-jta-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:cdi:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/cdi/pom.xml MD5: 8f78f9fb9affd1e7a999dfc79d1b3415 SHA1: e0771e5a9825e52ed5e06fbd38fd338a7cac1598 SHA256: abe7251b35f65035d415a941b76eadecfb6a7f9f1230c480058dec631b9df383 pkg:maven/org.jboss.narayana.jta/cdi@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:cdi:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/cdi/pom.xml MD5: 8f78f9fb9affd1e7a999dfc79d1b3415 SHA1: e0771e5a9825e52ed5e06fbd38fd338a7cac1598 SHA256: abe7251b35f65035d415a941b76eadecfb6a7f9f1230c480058dec631b9df383 pkg:maven/org.jboss.narayana.jta/cdi@7.3.3.Final pkg:maven/org.jboss.narayana.jta/cdi@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jdbc:7.3.3.Final)Description:
transactional driver File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jdbc/pom.xmlMD5: 9e0a88821a262c977645905a726c7286SHA1: fbc69107e75aa54eb13184a6dc7da4e19254e4f8SHA256: e13b1934a386dfcc388e97d14d124d3af35d4985b2fff04dbda7eb10c5bb3d17
Evidence Type Source Name Value Confidence Vendor pom artifactid jdbc Low Vendor pom groupid org.jboss.narayana.jta Highest Vendor pom name Narayana: ArjunaJTA jdbc High Vendor pom parent-artifactid narayana-jta-all Low Product pom artifactid jdbc Highest Product pom groupid org.jboss.narayana.jta Highest Product pom name Narayana: ArjunaJTA jdbc High Product pom parent-artifactid narayana-jta-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jdbc:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jdbc/pom.xml MD5: 9e0a88821a262c977645905a726c7286 SHA1: fbc69107e75aa54eb13184a6dc7da4e19254e4f8 SHA256: e13b1934a386dfcc388e97d14d124d3af35d4985b2fff04dbda7eb10c5bb3d17 pkg:maven/org.jboss.narayana.jta/jdbc@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jdbc:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jdbc/pom.xml MD5: 9e0a88821a262c977645905a726c7286 SHA1: fbc69107e75aa54eb13184a6dc7da4e19254e4f8 SHA256: e13b1934a386dfcc388e97d14d124d3af35d4985b2fff04dbda7eb10c5bb3d17 pkg:maven/org.jboss.narayana.jta/jdbc@7.3.3.Final pkg:maven/org.jboss.narayana.jta/jdbc@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jms:7.3.3.Final)Description:
Narayana JMS integration File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jms/pom.xmlMD5: 91ea859a5111414ab39d66e94871b235SHA1: 565dc4d70fb38176b0cea7abaa12acd66e569d0eSHA256: fa08ee50fb5df16b0226f6cf12165d9c3408a877a8ac0b5d5c1472b27c56e6d1
Evidence Type Source Name Value Confidence Vendor pom artifactid jms Low Vendor pom groupid org.jboss.narayana.jta Highest Vendor pom name Narayana: ArjunaJTA JMS High Vendor pom parent-artifactid narayana-jta-all Low Product pom artifactid jms Highest Product pom groupid org.jboss.narayana.jta Highest Product pom name Narayana: ArjunaJTA JMS High Product pom parent-artifactid narayana-jta-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jms:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jms/pom.xml MD5: 91ea859a5111414ab39d66e94871b235 SHA1: 565dc4d70fb38176b0cea7abaa12acd66e569d0e SHA256: fa08ee50fb5df16b0226f6cf12165d9c3408a877a8ac0b5d5c1472b27c56e6d1 pkg:maven/org.jboss.narayana.jta/jms@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jms:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jms/pom.xml MD5: 91ea859a5111414ab39d66e94871b235 SHA1: 565dc4d70fb38176b0cea7abaa12acd66e569d0e SHA256: fa08ee50fb5df16b0226f6cf12165d9c3408a877a8ac0b5d5c1472b27c56e6d1 pkg:maven/org.jboss.narayana.jta/jms@7.3.3.Final pkg:maven/org.jboss.narayana.jta/jms@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jta:7.3.3.Final)Description:
Narayana: ArjunaJTA jta File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jta/pom.xmlMD5: 8e54521c85a762177fe85b1a5c310f04SHA1: fffb5c1ec10004ca1b1441da45c2ce747b6e808fSHA256: e6c61905a17bdfffa9e106fa3d928f457e26c452bca656498bfa10a9ccf52634
Evidence Type Source Name Value Confidence Vendor pom artifactid jta Low Vendor pom groupid org.jboss.narayana.jta Highest Vendor pom name Narayana: ArjunaJTA jta High Vendor pom parent-artifactid narayana-jta-all Low Product pom artifactid jta Highest Product pom groupid org.jboss.narayana.jta Highest Product pom name Narayana: ArjunaJTA jta High Product pom parent-artifactid narayana-jta-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jta:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jta/pom.xml MD5: 8e54521c85a762177fe85b1a5c310f04 SHA1: fffb5c1ec10004ca1b1441da45c2ce747b6e808f SHA256: e6c61905a17bdfffa9e106fa3d928f457e26c452bca656498bfa10a9ccf52634 pkg:maven/org.jboss.narayana.jta/jta@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana.jta:jta:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana.jta/jta/pom.xml MD5: 8e54521c85a762177fe85b1a5c310f04 SHA1: fffb5c1ec10004ca1b1441da45c2ce747b6e808f SHA256: e6c61905a17bdfffa9e106fa3d928f457e26c452bca656498bfa10a9ccf52634 pkg:maven/org.jboss.narayana.jta/jta@7.3.3.Final pkg:maven/org.jboss.narayana.jta/jta@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana:common:7.3.3.Final)Description:
Narayana: common File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana/common/pom.xmlMD5: b0ac38474588a0ec9e0763d59b9b8f3eSHA1: fd685d705ec1fb7f15a6ccb9de07d7f2db1546a6SHA256: 3baf78cab75b7ddbbbcf33c6572014e40ac95767e60ce7fef1bebd07cf9f564b
Evidence Type Source Name Value Confidence Vendor pom artifactid common Low Vendor pom groupid org.jboss.narayana Highest Vendor pom name Narayana: common High Vendor pom parent-artifactid narayana-all Low Product pom artifactid common Highest Product pom groupid org.jboss.narayana Highest Product pom name Narayana: common High Product pom parent-artifactid narayana-all Medium Version pom version 7.3.3.Final Highest
Related Dependencies narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana:common:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana/common/pom.xml MD5: b0ac38474588a0ec9e0763d59b9b8f3e SHA1: fd685d705ec1fb7f15a6ccb9de07d7f2db1546a6 SHA256: 3baf78cab75b7ddbbbcf33c6572014e40ac95767e60ce7fef1bebd07cf9f564b pkg:maven/org.jboss.narayana/common@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar (shaded: org.jboss.narayana:common:7.3.3.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar/META-INF/maven/org.jboss.narayana/common/pom.xml MD5: b0ac38474588a0ec9e0763d59b9b8f3e SHA1: fd685d705ec1fb7f15a6ccb9de07d7f2db1546a6 SHA256: 3baf78cab75b7ddbbbcf33c6572014e40ac95767e60ce7fef1bebd07cf9f564b pkg:maven/org.jboss.narayana/common@7.3.3.Final pkg:maven/org.jboss.narayana/common@7.3.3.Final (Confidence :High) org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jarMD5: a38ef210988d306eaea5697851cc65d1SHA1: 76a860759a6d214607db279e0b68c6dd3a014a5aSHA256: 02acd3d1c8adbf558cba4ab10e816097fa783e1b0f77eef1ce05321e03b4b1dd
Evidence Type Source Name Value Confidence Vendor file name org.jboss.narayana.jta.narayana-jta High Vendor jar package name arjuna Low Vendor jar package name ats Low Vendor jar package name jboss Highest Vendor Manifest arjuna-builder JBoss Inc. [msappegr] Linux 6.16.12-200.fc42.x86_64 2025/Nov/11 11:19 Low Vendor Manifest arjuna-properties-file jbossts-properties.xml Low Vendor Manifest arjuna-scm-revision c2c49 Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://www.jboss.org/ Low Vendor Manifest Implementation-Vendor JBoss by Red Hat, Inc. High Vendor Manifest Implementation-Vendor-Id https://www.jboss.org/ Medium Vendor Manifest specification-vendor Eclipse Foundation Low Product file name org.jboss.narayana.jta.narayana-jta High Product jar package name arjuna Low Product jar package name ats Low Product jar package name jboss Highest Product jar package name narayana Highest Product Manifest arjuna-builder JBoss Inc. [msappegr] Linux 6.16.12-200.fc42.x86_64 2025/Nov/11 11:19 Low Product Manifest arjuna-properties-file jbossts-properties.xml Low Product Manifest arjuna-scm-revision c2c49 Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Narayana: ArjunaJTA narayana-jta High Product Manifest implementation-url https://www.jboss.org/ Low Product Manifest specification-title Jakarta Transactions Medium Version file name org.jboss.narayana.jta.narayana-jta Medium Version file version 7.3.3 High Version jar package name jboss Highest Version Manifest build-jdk-spec 21 Low Version Manifest Implementation-Version 7.3.3.Final (revision: c2c49) High Version Manifest java-version 21.0.8 Medium
Related Dependencies narayana-jta-7.3.3.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jta/narayana-jta/7.3.3.Final/narayana-jta-7.3.3.Final.jar MD5: a38ef210988d306eaea5697851cc65d1 SHA1: 76a860759a6d214607db279e0b68c6dd3a014a5a SHA256: 02acd3d1c8adbf558cba4ab10e816097fa783e1b0f77eef1ce05321e03b4b1dd pkg:maven/org.jboss.narayana.jta/narayana-jta@7.3.3.Final org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jta.narayana-jta-7.3.3.Final.jar MD5: a38ef210988d306eaea5697851cc65d1 SHA1: 76a860759a6d214607db279e0b68c6dd3a014a5a SHA256: 02acd3d1c8adbf558cba4ab10e816097fa783e1b0f77eef1ce05321e03b4b1dd org.jboss.narayana.jts.narayana-jts-integration-7.3.3.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.narayana.jts.narayana-jts-integration-7.3.3.Final.jarMD5: a5a2a8a183396137a8b1552fa77bd780SHA1: eeb902438907920d3527b39a39d7ce3ca86d7d23SHA256: 5a88eead14ad4cd2a2142fe7ab618cda20450de1f7d6e9c4092395fcdde478f5
Evidence Type Source Name Value Confidence Vendor file name org.jboss.narayana.jts.narayana-jts-integration High Vendor jar package name arjuna Low Vendor jar package name ats Low Vendor jar package name jboss Highest Vendor jar package name jbossatx Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://www.jboss.org/ Low Vendor Manifest Implementation-Vendor JBoss by Red Hat, Inc. High Vendor Manifest Implementation-Vendor-Id https://www.jboss.org/ Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.narayana.jts.narayana-jts-integration High Product jar package name ats Low Product jar package name jboss Highest Product jar package name jbossatx Low Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Narayana: ArjunaJTS integration High Product Manifest implementation-url https://www.jboss.org/ Low Product Manifest specification-title Narayana: ArjunaJTS integration Medium Version file version 7.3.3 High Version Manifest Implementation-Version 7.3.3.Final High
Related Dependencies narayana-jts-integration-7.3.3.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/narayana/jts/narayana-jts-integration/7.3.3.Final/narayana-jts-integration-7.3.3.Final.jar MD5: a5a2a8a183396137a8b1552fa77bd780 SHA1: eeb902438907920d3527b39a39d7ce3ca86d7d23 SHA256: 5a88eead14ad4cd2a2142fe7ab618cda20450de1f7d6e9c4092395fcdde478f5 pkg:maven/org.jboss.narayana.jts/narayana-jts-integration@7.3.3.Final org.jboss.narayana.jts.narayana-jts-integration-7.3.3.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.narayana.jts.narayana-jts-integration-7.3.3.Final.jar MD5: a5a2a8a183396137a8b1552fa77bd780 SHA1: eeb902438907920d3527b39a39d7ce3ca86d7d23 SHA256: 5a88eead14ad4cd2a2142fe7ab618cda20450de1f7d6e9c4092395fcdde478f5 org.jboss.slf4j.slf4j-jboss-logmanager-2.0.2.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.slf4j.slf4j-jboss-logmanager-2.0.2.Final.jarMD5: 7f67c53f6697f3968f0faeff408bf72fSHA1: 00ca0dfff7058ba18aa4244a0234c45919f01243SHA256: ba469a975e9d1e79f34a8baa1a0afa8b01bbd8cf080537c0e0899476d31db84b
Evidence Type Source Name Value Confidence Vendor file name org.jboss.slf4j.slf4j-jboss-logmanager High Vendor hint analyzer vendor redhat Highest Vendor jar package name impl Low Vendor jar package name slf4j Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.slf4j.slf4j-jboss-logmanager High Product jar package name impl Low Product jar package name slf4j Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SLF4J: JBoss Log Manager High Product Manifest implementation-url http://www.jboss.org Low Product Manifest specification-title SLF4J: JBoss Log Manager Medium Version file version 2.0.2 High Version Manifest Implementation-Version 2.0.2.Final High
Related Dependencies org.jboss.slf4j.slf4j-jboss-logmanager-2.0.2.Final.jar (shaded: org.jboss.slf4j:slf4j-jboss-logmanager:2.0.2.Final)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.slf4j.slf4j-jboss-logmanager-2.0.2.Final.jar/META-INF/maven/org.jboss.slf4j/slf4j-jboss-logmanager/pom.xml MD5: 6b7b95db360d028992742e3ea6a0f10e SHA1: 261dc50c735832660dafb95fcc7f7defd087cfbf SHA256: 1cea6fae5f05c918f0165284959d3dfb0ada88f51e7855a61f00bc97b0e5e874 pkg:maven/org.jboss.slf4j/slf4j-jboss-logmanager@2.0.2.Final org.jboss.slf4j.slf4j-jboss-logmanager-2.0.2.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.slf4j.slf4j-jboss-logmanager-2.0.2.Final.jar MD5: 7f67c53f6697f3968f0faeff408bf72f SHA1: 00ca0dfff7058ba18aa4244a0234c45919f01243 SHA256: ba469a975e9d1e79f34a8baa1a0afa8b01bbd8cf080537c0e0899476d31db84b slf4j-jboss-logmanager-2.0.2.Final.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/slf4j/slf4j-jboss-logmanager/2.0.2.Final/slf4j-jboss-logmanager-2.0.2.Final.jar MD5: 7f67c53f6697f3968f0faeff408bf72f SHA1: 00ca0dfff7058ba18aa4244a0234c45919f01243 SHA256: ba469a975e9d1e79f34a8baa1a0afa8b01bbd8cf080537c0e0899476d31db84b pkg:maven/org.jboss.slf4j/slf4j-jboss-logmanager@2.0.2.Final org.jboss.threads.jboss-threads-3.9.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jboss.threads.jboss-threads-3.9.2.jarMD5: a439cbe3b888adf97682853c2aceddd6SHA1: ee52e069cee3c892de572b0011d80c9c9bd81fd4SHA256: ac0fd044686122014143267d3688245852ca07c6c4474320c9172062a5af6634
Evidence Type Source Name Value Confidence Vendor file name org.jboss.threads.jboss-threads High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name jboss Low Vendor jar package name threads Low Vendor Manifest build-jdk-spec 24 Low Vendor Manifest implementation-url https://github.com/jbossas/jboss-threads Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.jboss.threads.jboss-threads High Product jar package name 24 Highest Product jar package name jboss Highest Product jar package name threads Highest Product jar package name threads Low Product Manifest build-jdk-spec 24 Low Product Manifest Implementation-Title JBoss Threads High Product Manifest implementation-url https://github.com/jbossas/jboss-threads Low Product Manifest multi-release true Low Product Manifest specification-title JBoss Threads Medium Version file version 3.9.2 High Version Manifest Implementation-Version 3.9.2 High
Related Dependencies jboss-threads-3.9.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jboss/threads/jboss-threads/3.9.2/jboss-threads-3.9.2.jar MD5: a439cbe3b888adf97682853c2aceddd6 SHA1: ee52e069cee3c892de572b0011d80c9c9bd81fd4 SHA256: ac0fd044686122014143267d3688245852ca07c6c4474320c9172062a5af6634 pkg:maven/org.jboss.threads/jboss-threads@3.9.2 org.jboss.threads.jboss-threads-3.9.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jboss.threads.jboss-threads-3.9.2.jar MD5: a439cbe3b888adf97682853c2aceddd6 SHA1: ee52e069cee3c892de572b0011d80c9c9bd81fd4 SHA256: ac0fd044686122014143267d3688245852ca07c6c4474320c9172062a5af6634 org.jctools.jctools-core-4.0.5.jarDescription:
Java Concurrency Tools Core Library License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jctools.jctools-core-4.0.5.jar
MD5: 4ec497e79923de658526ef2dcb61a641
SHA1: 9ab38ca19877236986db4894ef1400a7ca23db80
SHA256: d65e5f38bcd0984e26f87187687f1f70dd52740c4d5e046f8d104e01ab5db95f
Evidence Type Source Name Value Confidence Vendor file name org.jctools.jctools-core High Vendor jar package name jctools Highest Vendor jar package name jctools Low Vendor jar package name queues Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname org.jctools.core Medium Product file name org.jctools.jctools-core High Product jar package name jctools Highest Product jar package name queues Low Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Java Concurrency Tools Core Library Medium Product Manifest bundle-symbolicname org.jctools.core Medium Version file name org.jctools.jctools-core Medium Version file version 4.0.5 High Version Manifest build-jdk-spec 1.8 Low Version Manifest Bundle-Version 4.0.5 High
Related Dependencies io.netty.netty-common-4.1.130.Final.jar (shaded: org.jctools:jctools-core:4.0.5)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.netty.netty-common-4.1.130.Final.jar/META-INF/maven/org.jctools/jctools-core/pom.xml MD5: 5d5135397b920a7dcbca5c1fb0576cf2 SHA1: eaa05d6ad937464312a2681a3236c0e06602bbb7 SHA256: a69897b8ff0c2198b4b8cd7d4f93fde6d42b8e9dbfc95553585e27587b24e211 pkg:maven/org.jctools/jctools-core@4.0.5 io.opentelemetry.opentelemetry-sdk-trace-1.55.0.jar (shaded: org.jctools:jctools-core:4.0.5)File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/io.opentelemetry.opentelemetry-sdk-trace-1.55.0.jar/META-INF/maven/org.jctools/jctools-core/pom.xml MD5: 5d5135397b920a7dcbca5c1fb0576cf2 SHA1: eaa05d6ad937464312a2681a3236c0e06602bbb7 SHA256: a69897b8ff0c2198b4b8cd7d4f93fde6d42b8e9dbfc95553585e27587b24e211 pkg:maven/org.jctools/jctools-core@4.0.5 jctools-core-4.0.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jctools/jctools-core/4.0.5/jctools-core-4.0.5.jar MD5: 4ec497e79923de658526ef2dcb61a641 SHA1: 9ab38ca19877236986db4894ef1400a7ca23db80 SHA256: d65e5f38bcd0984e26f87187687f1f70dd52740c4d5e046f8d104e01ab5db95f pkg:maven/org.jctools/jctools-core@4.0.5 org.jctools.jctools-core-4.0.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jctools.jctools-core-4.0.5.jar MD5: 4ec497e79923de658526ef2dcb61a641 SHA1: 9ab38ca19877236986db4894ef1400a7ca23db80 SHA256: d65e5f38bcd0984e26f87187687f1f70dd52740c4d5e046f8d104e01ab5db95f org.jspecify.jspecify-1.0.0.jarDescription:
An artifact of well-specified annotations to power static analysis checks and JVM language interop. License:
https://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.jspecify.jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Evidence Type Source Name Value Confidence Vendor file name org.jspecify.jspecify High Vendor jar package name annotations Low Vendor jar package name jspecify Highest Vendor jar package name jspecify Low Vendor Manifest bundle-docurl https://jspecify.dev/docs/start-here Low Vendor Manifest bundle-symbolicname org.jspecify.jspecify Medium Vendor Manifest multi-release true Low Product file name org.jspecify.jspecify High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name jspecify Highest Product Manifest bundle-docurl https://jspecify.dev/docs/start-here Low Product Manifest Bundle-Name JSpecify annotations Medium Product Manifest bundle-symbolicname org.jspecify.jspecify Medium Product Manifest multi-release true Low Version file version 1.0.0 High Version Manifest Implementation-Version 1.0.0 High
Related Dependencies jspecify-1.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jspecify/jspecify/1.0.0/jspecify-1.0.0.jar MD5: 9133aba420d0ca3b001dbb6ae9992cf6 SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507 SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab pkg:maven/org.jspecify/jspecify@1.0.0 org.jspecify.jspecify-1.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.jspecify.jspecify-1.0.0.jar MD5: 9133aba420d0ca3b001dbb6ae9992cf6 SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507 SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab org.liquibase.liquibase-core-4.33.0.jarLicense:
http://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.liquibase.liquibase-core-4.33.0.jar
MD5: 6f6da4d8541e70a3b0a6d84d6bda5908
SHA1: 25b69ed7cc15e3c5de424ca9f32375f1815dd4e8
SHA256: 729691fdd26761f6264e4332a6a657e907c626863da8b4a0bf3bd22dbeebdc6b
Evidence Type Source Name Value Confidence Vendor file name org.liquibase.liquibase-core High Vendor jar package name core Highest Vendor jar package name liquibase Highest Vendor jar package name liquibase Low Vendor Manifest automatic-module-name liquibase.core Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest build-number 8744 Low Vendor Manifest build-time 2025-07-08 20:43+0000 Low Vendor Manifest bundle-docurl http://www.liquibase.org Low Vendor Manifest bundle-symbolicname org.liquibase.core Medium Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="liquibase.serializer.ChangeLogSerializer",osgi.serviceloader;osgi.serviceloader="liquibase.parser.NamespaceDetails",osgi.serviceloader;osgi.serviceloader="liquibase.database.Database",osgi.serviceloader;osgi.serviceloader="liquibase.change.Change",osgi.serviceloader;osgi.serviceloader="liquibase.database.DatabaseConnection",osgi.serviceloader;osgi.serviceloader="liquibase.precondition.Precondition",osgi.serviceloader;osgi.serviceloader="liquibase.serializer.SnapshotSerializer",osgi.serviceloader;osgi.serviceloader="liquibase.configuration.AutoloadedConfigurations",osgi.serviceloader;osgi.serviceloader="liquibase.diff.DiffGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.lockservice.LockService",osgi.serviceloader;osgi.serviceloader="liquibase.changelog.ChangeLogHistoryService",osgi.serviceloader;osgi.serviceloader="liquibase.datatype.LiquibaseDataType",osgi.serviceloader;osgi.serviceloader="liquibase.configuration.ConfigurationValueProvider",osgi.serviceloader;osgi.serviceloader="liquibase.logging.LogService",osgi.serviceloader;osgi.serviceloader="liquibase.snapshot.SnapshotGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.parser.ChangeLogParser",osgi.serviceloader;osgi.serviceloader="liquibase.servicelocator.ServiceLocator",osgi.serviceloader;osgi.serviceloader="liquibase.diff.compare.DatabaseObjectComparator",osgi.serviceloader;osgi.serviceloader="liquibase.command.LiquibaseCommand",osgi.serviceloader;osgi.serviceloader="liquibase.license.LicenseService",osgi.serviceloader;osgi.serviceloader="liquibase.diff.output.changelog.ChangeGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.executor.Executor",osgi.serviceloader;osgi.serviceloader="liquibase.structure.DatabaseObject",osgi.serviceloader;osgi.serviceloader="liquibase.parser.SnapshotParser",osgi.serviceloader;osgi.serviceloader="liquibase.hub.HubService",osgi.serviceloader;osgi.serviceloader="liquibase.command.CommandStep",osgi.serviceloader;osgi.serviceloader="liquibase.sqlgenerator.SqlGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.logging.mdc.MdcManager",osgi.serviceloader;osgi.serviceloader="liquibase.logging.mdc.CustomMdcObject",osgi.serviceloader;osgi.serviceloader="liquibase.resource.PathHandler",osgi.serviceloader;osgi.serviceloader="liquibase.report.ShowSummaryGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.parser.LiquibaseSqlParser",osgi.serviceloader;osgi.serviceloader="liquibase.changeset.ChangeSetService",osgi.serviceloader;osgi.serviceloader="liquibase.changelog.visitor.ValidatingVisitorGenerator" Low Product file name org.liquibase.liquibase-core High Product jar package name autoloadedconfigurations Highest Product jar package name changeloghistoryservice Highest Product jar package name changelogparser Highest Product jar package name changelogserializer Highest Product jar package name changeset Highest Product jar package name changesetservice Highest Product jar package name command Highest Product jar package name commandstep Highest Product jar package name compare Highest Product jar package name configuration Highest Product jar package name configurationvalueprovider Highest Product jar package name core Highest Product jar package name custommdcobject Highest Product jar package name database Highest Product jar package name databaseconnection Highest Product jar package name databaseobjectcomparator Highest Product jar package name datatype Highest Product jar package name diff Highest Product jar package name diffgenerator Highest Product jar package name executor Highest Product jar package name license Highest Product jar package name licenseservice Highest Product jar package name liquibase Highest Product jar package name liquibasecommand Highest Product jar package name liquibasedatatype Highest Product jar package name liquibasesqlparser Highest Product jar package name lockservice Highest Product jar package name logging Highest Product jar package name logservice Highest Product jar package name mdc Highest Product jar package name mdcmanager Highest Product jar package name namespacedetails Highest Product jar package name osgi Highest Product jar package name output Highest Product jar package name parser Highest Product jar package name pathhandler Highest Product jar package name plugin Highest Product jar package name precondition Highest Product jar package name report Highest Product jar package name resource Highest Product jar package name serializer Highest Product jar package name servicelocator Highest Product jar package name showsummarygenerator Highest Product jar package name snapshotgenerator Highest Product jar package name snapshotparser Highest Product jar package name snapshotserializer Highest Product jar package name sqlgenerator Highest Product jar package name structure Highest Product jar package name validatingvisitorgenerator Highest Product jar package name visitor Highest Product Manifest automatic-module-name liquibase.core Medium Product Manifest build-jdk-spec 17 Low Product Manifest build-number 8744 Low Product Manifest build-time 2025-07-08 20:43+0000 Low Product Manifest bundle-docurl http://www.liquibase.org Low Product Manifest Bundle-Name liquibase-core Medium Product Manifest bundle-symbolicname org.liquibase.core Medium Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="liquibase.serializer.ChangeLogSerializer",osgi.serviceloader;osgi.serviceloader="liquibase.parser.NamespaceDetails",osgi.serviceloader;osgi.serviceloader="liquibase.database.Database",osgi.serviceloader;osgi.serviceloader="liquibase.change.Change",osgi.serviceloader;osgi.serviceloader="liquibase.database.DatabaseConnection",osgi.serviceloader;osgi.serviceloader="liquibase.precondition.Precondition",osgi.serviceloader;osgi.serviceloader="liquibase.serializer.SnapshotSerializer",osgi.serviceloader;osgi.serviceloader="liquibase.configuration.AutoloadedConfigurations",osgi.serviceloader;osgi.serviceloader="liquibase.diff.DiffGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.lockservice.LockService",osgi.serviceloader;osgi.serviceloader="liquibase.changelog.ChangeLogHistoryService",osgi.serviceloader;osgi.serviceloader="liquibase.datatype.LiquibaseDataType",osgi.serviceloader;osgi.serviceloader="liquibase.configuration.ConfigurationValueProvider",osgi.serviceloader;osgi.serviceloader="liquibase.logging.LogService",osgi.serviceloader;osgi.serviceloader="liquibase.snapshot.SnapshotGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.parser.ChangeLogParser",osgi.serviceloader;osgi.serviceloader="liquibase.servicelocator.ServiceLocator",osgi.serviceloader;osgi.serviceloader="liquibase.diff.compare.DatabaseObjectComparator",osgi.serviceloader;osgi.serviceloader="liquibase.command.LiquibaseCommand",osgi.serviceloader;osgi.serviceloader="liquibase.license.LicenseService",osgi.serviceloader;osgi.serviceloader="liquibase.diff.output.changelog.ChangeGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.executor.Executor",osgi.serviceloader;osgi.serviceloader="liquibase.structure.DatabaseObject",osgi.serviceloader;osgi.serviceloader="liquibase.parser.SnapshotParser",osgi.serviceloader;osgi.serviceloader="liquibase.hub.HubService",osgi.serviceloader;osgi.serviceloader="liquibase.command.CommandStep",osgi.serviceloader;osgi.serviceloader="liquibase.sqlgenerator.SqlGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.logging.mdc.MdcManager",osgi.serviceloader;osgi.serviceloader="liquibase.logging.mdc.CustomMdcObject",osgi.serviceloader;osgi.serviceloader="liquibase.resource.PathHandler",osgi.serviceloader;osgi.serviceloader="liquibase.report.ShowSummaryGenerator",osgi.serviceloader;osgi.serviceloader="liquibase.parser.LiquibaseSqlParser",osgi.serviceloader;osgi.serviceloader="liquibase.changeset.ChangeSetService",osgi.serviceloader;osgi.serviceloader="liquibase.changelog.visitor.ValidatingVisitorGenerator" Low Version file name org.liquibase.liquibase-core Medium Version file version 4.33.0 High Version jar package name autoloadedconfigurations Highest Version jar package name changeloghistoryservice Highest Version jar package name changelogparser Highest Version jar package name changelogserializer Highest Version jar package name changeset Highest Version jar package name changesetservice Highest Version jar package name command Highest Version jar package name commandstep Highest Version jar package name compare Highest Version jar package name configuration Highest Version jar package name configurationvalueprovider Highest Version jar package name custommdcobject Highest Version jar package name database Highest Version jar package name databaseconnection Highest Version jar package name databaseobjectcomparator Highest Version jar package name datatype Highest Version jar package name diff Highest Version jar package name diffgenerator Highest Version jar package name executor Highest Version jar package name license Highest Version jar package name licenseservice Highest Version jar package name liquibase Highest Version jar package name liquibasecommand Highest Version jar package name liquibasedatatype Highest Version jar package name liquibasesqlparser Highest Version jar package name lockservice Highest Version jar package name logging Highest Version jar package name logservice Highest Version jar package name mdc Highest Version jar package name mdcmanager Highest Version jar package name namespacedetails Highest Version jar package name osgi Highest Version jar package name output Highest Version jar package name parser Highest Version jar package name pathhandler Highest Version jar package name plugin Highest Version jar package name precondition Highest Version jar package name report Highest Version jar package name resource Highest Version jar package name serializer Highest Version jar package name servicelocator Highest Version jar package name showsummarygenerator Highest Version jar package name snapshotgenerator Highest Version jar package name snapshotparser Highest Version jar package name snapshotserializer Highest Version jar package name sqlgenerator Highest Version jar package name structure Highest Version jar package name validatingvisitorgenerator Highest Version jar package name visitor Highest Version Manifest build-jdk-spec 17 Low Version Manifest build-number 8744 Low Version Manifest Bundle-Version 4.33.0 High Version Manifest liquibase-version 4.33.0 Medium Version Manifest originally-created-by 5.1.9 Low
Related Dependencies liquibase-core-4.33.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/liquibase/liquibase-core/4.33.0/liquibase-core-4.33.0.jar MD5: 6f6da4d8541e70a3b0a6d84d6bda5908 SHA1: 25b69ed7cc15e3c5de424ca9f32375f1815dd4e8 SHA256: 729691fdd26761f6264e4332a6a657e907c626863da8b4a0bf3bd22dbeebdc6b pkg:maven/org.liquibase/liquibase-core@4.33.0 cpe:2.3:a:liquibase:liquibase:4.33.0:*:*:*:*:*:*:* (Confidence :Low) suppress org.mapstruct.mapstruct-1.6.3.jarDescription:
An annotation processor for generating type-safe bean mappers License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.mapstruct.mapstruct-1.6.3.jar
MD5: 3662b4f7a5abfb4f233e6b0dba5d3070
SHA1: 416a2155212286d6a1c4cb3bb553c7dfd6a1a092
SHA256: 00b52467f31d482f8673b0b74306f4be0a305cdce31e587bc1b3d7bf779f1dbf
Evidence Type Source Name Value Confidence Vendor file name org.mapstruct.mapstruct High Vendor jar package name mapstruct Highest Vendor jar package name mapstruct Low Vendor Manifest automatic-module-name org.mapstruct Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.mapstruct Medium Product file name org.mapstruct.mapstruct High Product jar package name mappers Highest Product jar package name mapstruct Highest Product Manifest automatic-module-name org.mapstruct Medium Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name MapStruct Core Medium Product Manifest bundle-symbolicname org.mapstruct Medium Version file name org.mapstruct.mapstruct Medium Version file version 1.6.3 High Version Manifest build-jdk-spec 11 Low Version Manifest Bundle-Version 1.6.3 High
Related Dependencies mapstruct-1.6.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/mapstruct/mapstruct/1.6.3/mapstruct-1.6.3.jar MD5: 3662b4f7a5abfb4f233e6b0dba5d3070 SHA1: 416a2155212286d6a1c4cb3bb553c7dfd6a1a092 SHA256: 00b52467f31d482f8673b0b74306f4be0a305cdce31e587bc1b3d7bf779f1dbf pkg:maven/org.mapstruct/mapstruct@1.6.3 org.mapstruct.mapstruct-1.6.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.mapstruct.mapstruct-1.6.3.jar MD5: 3662b4f7a5abfb4f233e6b0dba5d3070 SHA1: 416a2155212286d6a1c4cb3bb553c7dfd6a1a092 SHA256: 00b52467f31d482f8673b0b74306f4be0a305cdce31e587bc1b3d7bf779f1dbf org.osgi.osgi.core-6.0.0.jarDescription:
OSGi Core Release 6, Interfaces and Classes for use in compiling bundles. License:
http://opensource.org/licenses/apache2.0.php; link="http://www.apache.org/licenses/LICENSE-2.0"; description="Apache License, Version 2.0" File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.osgi.osgi.core-6.0.0.jar
MD5: cae291c61fe8b7a4476d713550c7ff49
SHA1: 0c49acdc9ac62cf69ee49cb6f1905b4fdb79ea5c
SHA256: 1c1bb435eb34cbf1f743653da38f604d45d53fbc95979053768cd3fc293cb931
Evidence Type Source Name Value Confidence Vendor file name org.osgi.osgi.core High Vendor jar package name framework Low Vendor jar package name osgi Highest Vendor jar package name osgi Low Vendor Manifest bundle-copyright Copyright (c) OSGi Alliance (2000, 2014). All Rights Reserved. Low Vendor Manifest bundle-symbolicname osgi.core Medium Product file name org.osgi.osgi.core High Product jar package name framework Low Product jar package name osgi Highest Product Manifest bundle-copyright Copyright (c) OSGi Alliance (2000, 2014). All Rights Reserved. Low Product Manifest Bundle-Name osgi.core Medium Product Manifest bundle-symbolicname osgi.core Medium Version file name org.osgi.osgi.core Medium Version file version 6.0.0 High Version jar package name osgi Highest Version Manifest Bundle-Version 6.0.0.201403061837 High
Related Dependencies osgi.core-6.0.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/osgi/osgi.core/6.0.0/osgi.core-6.0.0.jar MD5: cae291c61fe8b7a4476d713550c7ff49 SHA1: 0c49acdc9ac62cf69ee49cb6f1905b4fdb79ea5c SHA256: 1c1bb435eb34cbf1f743653da38f604d45d53fbc95979053768cd3fc293cb931 pkg:maven/org.osgi/osgi.core@6.0.0 org.postgresql.postgresql-42.7.8.jarDescription:
Java JDBC driver for PostgreSQL database License:
BSD-2-Clause File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.postgresql.postgresql-42.7.8.jar
MD5: d5626352279a40e69e863fcff564e2f1
SHA1: 81b840fbfe0a6c0b7aa14c6bd4856108d36ed780
SHA256: 2a32a9dcbc42d67a50ad3a0de5efd102c8d2be46720045f2cbd6689f160ab7c7
Evidence Type Source Name Value Confidence Vendor file name org.postgresql.postgresql High Vendor jar package name jdbc Highest Vendor jar package name postgresql Highest Vendor jar package name postgresql Low Vendor Manifest automatic-module-name org.postgresql.jdbc Medium Vendor Manifest bundle-copyright Copyright (c) 2003-2024, PostgreSQL Global Development Group Low Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High Vendor Manifest Implementation-Vendor-Id org.postgresql Medium Vendor Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory";osgi.jdbc.driver.class="org.postgresql.Driver";osgi.jdbc.driver.name="PostgreSQL JDBC Driver" Low Vendor Manifest specification-vendor Oracle Corporation Low Product file name org.postgresql.postgresql High Product hint analyzer product pgjdbc Highest Product hint analyzer product postgresql_jdbc_driver Highest Product jar package name driver Highest Product jar package name jdbc Highest Product jar package name osgi Highest Product jar package name postgresql Highest Product Manifest automatic-module-name org.postgresql.jdbc Medium Product Manifest bundle-copyright Copyright (c) 2003-2024, PostgreSQL Global Development Group Low Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium Product Manifest bundle-symbolicname org.postgresql.jdbc Medium Product Manifest Implementation-Title PostgreSQL JDBC Driver High Product Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory";osgi.jdbc.driver.class="org.postgresql.Driver";osgi.jdbc.driver.name="PostgreSQL JDBC Driver" Low Product Manifest specification-title JDBC Medium Version file version 42.7.8 High Version Manifest Implementation-Version 42.7.8 High
Related Dependencies org.postgresql.postgresql-42.7.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.postgresql.postgresql-42.7.8.jar MD5: d5626352279a40e69e863fcff564e2f1 SHA1: 81b840fbfe0a6c0b7aa14c6bd4856108d36ed780 SHA256: 2a32a9dcbc42d67a50ad3a0de5efd102c8d2be46720045f2cbd6689f160ab7c7 postgresql-42.7.8.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/postgresql/postgresql/42.7.8/postgresql-42.7.8.jar MD5: d5626352279a40e69e863fcff564e2f1 SHA1: 81b840fbfe0a6c0b7aa14c6bd4856108d36ed780 SHA256: 2a32a9dcbc42d67a50ad3a0de5efd102c8d2be46720045f2cbd6689f160ab7c7 pkg:maven/org.postgresql/postgresql@42.7.8 org.reactivestreams.reactive-streams-1.0.4.jarDescription:
Reactive Streams API File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.reactivestreams.reactive-streams-1.0.4.jarMD5: eda7978509c32d99166745cc144c99cdSHA1: 3864a1320d97d7b045f729a326e1e077661f31b7SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28
Evidence Type Source Name Value Confidence Vendor file name org.reactivestreams.reactive-streams High Vendor jar package name reactivestreams Highest Vendor jar package name reactivestreams Low Vendor Manifest automatic-module-name org.reactivestreams Medium Vendor Manifest bundle-docurl http://reactive-streams.org Low Vendor Manifest bundle-symbolicname reactive-streams Medium Product file name org.reactivestreams.reactive-streams High Product jar package name reactivestreams Highest Product Manifest automatic-module-name org.reactivestreams Medium Product Manifest bundle-docurl http://reactive-streams.org Low Product Manifest Bundle-Name reactive-streams-jvm Medium Product Manifest bundle-symbolicname reactive-streams Medium Version file name org.reactivestreams.reactive-streams Medium Version file version 1.0.4 High Version Manifest Bundle-Version 1.0.4 High
Related Dependencies org.reactivestreams.reactive-streams-1.0.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.reactivestreams.reactive-streams-1.0.4.jar MD5: eda7978509c32d99166745cc144c99cd SHA1: 3864a1320d97d7b045f729a326e1e077661f31b7 SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28 reactive-streams-1.0.4.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/reactivestreams/reactive-streams/1.0.4/reactive-streams-1.0.4.jar MD5: eda7978509c32d99166745cc144c99cd SHA1: 3864a1320d97d7b045f729a326e1e077661f31b7 SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28 pkg:maven/org.reactivestreams/reactive-streams@1.0.4 org.seleniumhq.selenium.selenium-chromium-driver-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-chromium-driver-4.35.0.jarMD5: dff95e882aba3a88f68ee13c97de3a85SHA1: 8b7fd718ba9c2a74dfe9ed6a4a1008e65e4fc6f6SHA256: de4239ff9e7e22261c7c16b3a60b5afac8754a0c0ea35d8d2b3cc209508dc616
Evidence Type Source Name Value Confidence Vendor file name org.seleniumhq.selenium.selenium-chromium-driver High Vendor jar package name chromium Low Vendor jar package name openqa Low Vendor jar package name selenium Low Product file name org.seleniumhq.selenium.selenium-chromium-driver High Product jar package name chromium Low Product jar package name selenium Low Version file name org.seleniumhq.selenium.selenium-chromium-driver Medium Version file version 4.35.0 High
Related Dependencies selenium-chromium-driver-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-chromium-driver/4.35.0/selenium-chromium-driver-4.35.0.jar MD5: dff95e882aba3a88f68ee13c97de3a85 SHA1: 8b7fd718ba9c2a74dfe9ed6a4a1008e65e4fc6f6 SHA256: de4239ff9e7e22261c7c16b3a60b5afac8754a0c0ea35d8d2b3cc209508dc616 pkg:maven/org.seleniumhq.selenium/selenium-chromium-driver@4.35.0 cpe:2.3:a:chromium:chromium:4.35.0:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:chromium_project:chromium:4.35.0:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:selenium:selenium:4.35.0:*:*:*:*:*:*:* (Confidence :Low) suppress CVE-2011-1797 suppress
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2017-7000 suppress
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2015-1205 suppress
Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-1346 suppress
Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors. NVD-CWE-noinfo
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
org.seleniumhq.selenium.selenium-manager-4.35.0.jar: selenium-manager.exeFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-manager-4.35.0.jar/org/openqa/selenium/manager/windows/selenium-manager.exeMD5: 89e93dd126c7e0792ea6722761ca7f0fSHA1: d466ccb34c533229ad1f9ae57e6ccc89e71ee1fcSHA256: eb6e3b19bb70c3fee7fdb332153d7c7c523034044059900e80b663b8817e720c
Evidence Type Source Name Value Confidence Vendor file name selenium-manager High Product file name selenium-manager High
Related Dependencies selenium-manager-4.35.0.jar: selenium-manager.exeFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-manager/4.35.0/selenium-manager-4.35.0.jar/org/openqa/selenium/manager/windows/selenium-manager.exe MD5: 89e93dd126c7e0792ea6722761ca7f0f SHA1: d466ccb34c533229ad1f9ae57e6ccc89e71ee1fc SHA256: eb6e3b19bb70c3fee7fdb332153d7c7c523034044059900e80b663b8817e720c org.seleniumhq.selenium.selenium-os-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-os-4.35.0.jarMD5: 4f5cb00e405dd8f2bc02202bec09426bSHA1: 50ca14dd91a917fdcd508974ed4fc85b7440b07cSHA256: cb6b750851e04025d8c3f07b434395176355959ce31e32a95c1ecd2dc6e04ae7
Evidence Type Source Name Value Confidence Vendor file name org.seleniumhq.selenium.selenium-os High Vendor jar package name io Low Vendor jar package name openqa Low Vendor jar package name selenium Low Product file name org.seleniumhq.selenium.selenium-os High Product jar package name io Low Product jar package name selenium Low Version file name org.seleniumhq.selenium.selenium-os Medium Version file version 4.35.0 High
Related Dependencies org.seleniumhq.selenium.selenium-api-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-api-4.35.0.jar MD5: 9f4b2d2198a2780a7cba1bbd7a1311a6 SHA1: 379ce2910c60248f9cb79e087d92a3aefa1ffd32 SHA256: dddab2cad799b624220c0bc39567da101cc2cf06c85f309a0706fe8312b5a1e8 org.seleniumhq.selenium.selenium-chrome-driver-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-chrome-driver-4.35.0.jar MD5: cae1ba8d9dcbcc3379de33679b39233d SHA1: 47d3827d984ff3b8c995dba34abf0ac9c72fa07d SHA256: 8ad918907fb381d6448b1b0b639a560ad5180131f93947ee2bdaa7f8dfe884f9 org.seleniumhq.selenium.selenium-devtools-v137-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-devtools-v137-4.35.0.jar MD5: c18b714de2b2443d2667d1087f239656 SHA1: 2d768f1290834e7533aedfc7ff532bc1b3abe96c SHA256: 2bb4643de5b44007418edf4d7440d0bb3f64c9eab016d150459bf74c7d1791d9 org.seleniumhq.selenium.selenium-http-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-http-4.35.0.jar MD5: 776ddfa5786088206e7318d517d05f2a SHA1: 5e3d24b5aac210b8dd9491b53568d3a9d7c7b349 SHA256: fb964eae6286a5328cb1e941ab841818c448532233e84a7d4b4e00deae04b8ba org.seleniumhq.selenium.selenium-json-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-json-4.35.0.jar MD5: 584f1718031a532dcaff98472b88e417 SHA1: afa77140c5b8ca0f56593d5b2eef831a9c00b999 SHA256: e2ffa5f99c7d3964be9b5e060faed2ef0ae22bf67294589ed37e2b8451ad9041 org.seleniumhq.selenium.selenium-manager-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-manager-4.35.0.jar MD5: f4f04a758d716b4cadfaf4c0dd9eb7ab SHA1: 225119476567a605c7a30263a1dd60fdd2de7c7d SHA256: 84b6c86d0d216fad5c3c7880e7a50a8691f063c532781dc079de4320dc4e61ed org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar MD5: 034831196877e016f68a19f4e5f5ca38 SHA1: 92295302036f9227bfb5cc32adbc1c0eb7fb9c09 SHA256: db910d0e24330e386cc153d4192409c80ec152c47ca7d05e5eb90261d8a986ea org.seleniumhq.selenium.selenium-support-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-support-4.35.0.jar MD5: 0f7c599cd1d00263935e604610820bb4 SHA1: ea8078e129aabd5b10cb4588fe4a5c8a3f22f959 SHA256: 5bc0a5732f901f7bb97fc94266a546d537297e403ca12234c1e2cdfd3d0327e7 selenium-os-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-os/4.35.0/selenium-os-4.35.0.jar MD5: 4f5cb00e405dd8f2bc02202bec09426b SHA1: 50ca14dd91a917fdcd508974ed4fc85b7440b07c SHA256: cb6b750851e04025d8c3f07b434395176355959ce31e32a95c1ecd2dc6e04ae7 pkg:maven/org.seleniumhq.selenium/selenium-os@4.35.0 cpe:2.3:a:selenium:selenium:4.35.0:*:*:*:*:*:*:* (Confidence :Low) suppress org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar: bidi-mutation-listener.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar/org/openqa/selenium/remote/bidi-mutation-listener.jsMD5: 7bacd2c61d7926322f2b53fa7441cff8SHA1: fb21cdb0722173264770c5576d576edb51655767SHA256: 15f2cb88147c33b65cc5f81fac99c7629711a90aa2a8e7785f70f69792237967
Evidence Type Source Name Value Confidence
Related Dependencies selenium-remote-driver-4.35.0.jar: bidi-mutation-listener.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-remote-driver/4.35.0/selenium-remote-driver-4.35.0.jar/org/openqa/selenium/remote/bidi-mutation-listener.js MD5: 7bacd2c61d7926322f2b53fa7441cff8 SHA1: fb21cdb0722173264770c5576d576edb51655767 SHA256: 15f2cb88147c33b65cc5f81fac99c7629711a90aa2a8e7785f70f69792237967 org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar: getAttribute.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar/org/openqa/selenium/remote/getAttribute.jsMD5: 232e1624f3d4f2a8f9487a81b9901103SHA1: 527dc161296244e355a5e0f9b1b0218b1f285fc2SHA256: 76674bf5db7e04c72b97ab441c5790cb9b46682fc9dd6109a38342b9be96f274
Evidence Type Source Name Value Confidence
Related Dependencies selenium-remote-driver-4.35.0.jar: getAttribute.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-remote-driver/4.35.0/selenium-remote-driver-4.35.0.jar/org/openqa/selenium/remote/getAttribute.js MD5: 232e1624f3d4f2a8f9487a81b9901103 SHA1: 527dc161296244e355a5e0f9b1b0218b1f285fc2 SHA256: 76674bf5db7e04c72b97ab441c5790cb9b46682fc9dd6109a38342b9be96f274 org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar: isDisplayed.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar/org/openqa/selenium/remote/isDisplayed.jsMD5: 727e11fb186de471c2bbea2999d5ff91SHA1: 7264278c39f16c6881a477b4a1f22bbfae3ac960SHA256: ae26018c01cd27448b250f8e55a094cbfcd2e2cbbe171c78aaa906e1b5c3ed7c
Evidence Type Source Name Value Confidence
Related Dependencies selenium-remote-driver-4.35.0.jar: isDisplayed.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-remote-driver/4.35.0/selenium-remote-driver-4.35.0.jar/org/openqa/selenium/remote/isDisplayed.js MD5: 727e11fb186de471c2bbea2999d5ff91 SHA1: 7264278c39f16c6881a477b4a1f22bbfae3ac960 SHA256: ae26018c01cd27448b250f8e55a094cbfcd2e2cbbe171c78aaa906e1b5c3ed7c org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar: mutation-listener.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-remote-driver-4.35.0.jar/org/openqa/selenium/devtools/mutation-listener.jsMD5: 81f59e36bde07e051c3cb92a4986b327SHA1: 676e0a28a5a1353e89469acaad1b08adc62c795dSHA256: 2c2083c9a49f65c510d68d3620a57d4dfedc8dc0fcc32524c1ccb11c6329ea07
Evidence Type Source Name Value Confidence
Related Dependencies selenium-remote-driver-4.35.0.jar: mutation-listener.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-remote-driver/4.35.0/selenium-remote-driver-4.35.0.jar/org/openqa/selenium/devtools/mutation-listener.js MD5: 81f59e36bde07e051c3cb92a4986b327 SHA1: 676e0a28a5a1353e89469acaad1b08adc62c795d SHA256: 2c2083c9a49f65c510d68d3620a57d4dfedc8dc0fcc32524c1ccb11c6329ea07 org.seleniumhq.selenium.selenium-support-4.35.0.jar: findElements.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.seleniumhq.selenium.selenium-support-4.35.0.jar/org/openqa/selenium/support/locators/findElements.jsMD5: 414fb857f6ff729f9336da3fc3981621SHA1: 9d0511915a5cadb261832d87085cebb37b0478f0SHA256: adc9a973afd2dbc0b24176272096f71fe2a37551ef3262d3973dfd5bc098022b
Evidence Type Source Name Value Confidence
Related Dependencies selenium-support-4.35.0.jar: findElements.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-support/4.35.0/selenium-support-4.35.0.jar/org/openqa/selenium/support/locators/findElements.js MD5: 414fb857f6ff729f9336da3fc3981621 SHA1: 9d0511915a5cadb261832d87085cebb37b0478f0 SHA256: adc9a973afd2dbc0b24176272096f71fe2a37551ef3262d3973dfd5bc098022b org.slf4j.slf4j-api-2.0.17.jarDescription:
The slf4j API License:
https://opensource.org/license/mit File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.slf4j.slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Evidence Type Source Name Value Confidence Vendor file name org.slf4j.slf4j-api High Vendor jar package name slf4j Highest Vendor jar package name slf4j Low Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.slf4j.org Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor Manifest multi-release true Low Product file name org.slf4j.slf4j-api High Product jar package name slf4j Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.slf4j.org Low Product Manifest Bundle-Name SLF4J API Module Medium Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product Manifest multi-release true Low Version file version 2.0.17 High Version Manifest Implementation-Version 2.0.17 High
Related Dependencies org.slf4j.slf4j-api-2.0.17.jar (shaded: org.slf4j:slf4j-api:2.0.17)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.slf4j.slf4j-api-2.0.17.jar/META-INF/maven/org.slf4j/slf4j-api/pom.xml MD5: e3b0304a349d7201df5e8e462ac9d833 SHA1: 0570964f8e6716b09c354c6e334ba1a092464d85 SHA256: 150c40287f7cecdc21b9380caac98e928c4f33c023db6b348df1c5ac977026bf pkg:maven/org.slf4j/slf4j-api@2.0.17 org.slf4j.slf4j-api-2.0.17.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.slf4j.slf4j-api-2.0.17.jar MD5: b6480d114a23683498ac3f746f959d2f SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832 slf4j-api-2.0.17.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar MD5: b6480d114a23683498ac3f746f959d2f SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832 pkg:maven/org.slf4j/slf4j-api@2.0.17 org.wildfly.common.wildfly-common-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.wildfly.common.wildfly-common-2.0.1.jarMD5: b0b9f3faf5b8394fc73e507e0ff4dbbcSHA1: 5db5c5f2d04a1c0a3f7fe678030d3ec3760f81a3SHA256: fa4a710db7ae3e598a5f41639eb54e9f7b09de5fd0f58f56bd6070f21d956374
Evidence Type Source Name Value Confidence Vendor file name org.wildfly.common.wildfly-common High Vendor hint analyzer vendor redhat Highest Vendor jar package name common Low Vendor jar package name wildfly Low Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest specification-vendor JBoss by Red Hat Low Product file name org.wildfly.common.wildfly-common High Product jar package name common Highest Product jar package name common Low Product jar package name wildfly Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title wildfly-common High Product Manifest implementation-url http://www.jboss.org Low Product Manifest specification-title wildfly-common Medium Version file version 2.0.1 High Version Manifest Implementation-Version 2.0.1 High
Related Dependencies org.wildfly.common.wildfly-common-2.0.1.jar (shaded: org.wildfly.common:wildfly-common:2.0.1)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.wildfly.common.wildfly-common-2.0.1.jar/META-INF/maven/org.wildfly.common/wildfly-common/pom.xml MD5: bb6ec84fac7fb36d1a7853be110cc59a SHA1: 7a8fad1ce55f575a278574af60a2a8717c72fce0 SHA256: c96c922497c28c9c66edbada7b8a1d19824926bd41fe1d4b10c27ba6c66c65f3 pkg:maven/org.wildfly.common/wildfly-common@2.0.1 org.wildfly.common.wildfly-common-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.wildfly.common.wildfly-common-2.0.1.jar MD5: b0b9f3faf5b8394fc73e507e0ff4dbbc SHA1: 5db5c5f2d04a1c0a3f7fe678030d3ec3760f81a3 SHA256: fa4a710db7ae3e598a5f41639eb54e9f7b09de5fd0f58f56bd6070f21d956374 wildfly-common-2.0.1.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/wildfly/common/wildfly-common/2.0.1/wildfly-common-2.0.1.jar MD5: b0b9f3faf5b8394fc73e507e0ff4dbbc SHA1: 5db5c5f2d04a1c0a3f7fe678030d3ec3760f81a3 SHA256: fa4a710db7ae3e598a5f41639eb54e9f7b09de5fd0f58f56bd6070f21d956374 pkg:maven/org.wildfly.common/wildfly-common@2.0.1 CVE-2020-10718 suppress
A flaw was found in Wildfly before wildfly-embedded-13.0.0.Final, where the embedded managed process API has an exposed setting of the Thread Context Classloader (TCCL). This setting is exposed as a public method, which can bypass the security manager. The highest threat from this vulnerability is to confidentiality. NVD-CWE-Other
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2020-10740 suppress
A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.6/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions:
CVE-2022-1278 suppress
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. CWE-1188 Insecure Default Initialization of Resource
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2020-25689 suppress
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat from this vulnerability is to system availability. CWE-401 Missing Release of Memory after Effective Lifetime
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2025-23367 suppress
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server.
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action. CWE-284 Improper Access Control, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2018-14627 suppress
The IIOP OpenJDK Subsystem in WildFly before version 14.0.0 does not honour configuration when SSL transport is required. Servers before this version that are configured with the following setting allow clients to create plaintext connections: <transport-config confidentiality="required" trust-in-target="supported"/> CWE-319 Cleartext Transmission of Sensitive Information
CVSSv3:
Base Score: MEDIUM (5.9) Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2020-1719 suppress
A flaw was found in wildfly. The EJBContext principle is not popped back after invoking another EJB using a different Security Domain. The highest threat from this vulnerability is to data confidentiality and integrity. Versions before wildfly 20.0.0.Final are affected. CWE-270 Privilege Context Switching Error
CVSSv3:
Base Score: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:N References:
Vulnerable Software & Versions:
CVE-2020-25640 suppress
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file. CWE-532 Insertion of Sensitive Information into Log File, CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:1.6/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2021-3536 suppress
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is possible to add a payload in the name field, leading to XSS. This affects Confidentiality and Integrity. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:1.7/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2019-3805 suppress
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root. CWE-269 Improper Privilege Management, CWE-364 Signal Handler Race Condition
CVSSv3:
Base Score: MEDIUM (4.7) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.7) Vector: /AV:L/AC:M/Au:N/C:N/I:N/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2021-3503 suppress
A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat from this vulnerability is to the confidentiality. NVD-CWE-noinfo, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions:
org.yaml.snakeyaml-2.5.jarDescription:
YAML 1.1 parser and emitter for Java License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/lib/main/org.yaml.snakeyaml-2.5.jar
MD5: 8d3b7581db5c7620db55183f33a4f2ad
SHA1: 2d53ddec134280cb384c1e35d094e5f71c1f2316
SHA256: e6682acf1ace77508ef13649cbf4f8d09d2cf5457bdb61d25ffb6ac0233d78dd
Evidence Type Source Name Value Confidence Vendor file name org.yaml.snakeyaml High Vendor jar package name org Highest Vendor jar package name snakeyaml Highest Vendor jar package name snakeyaml Low Vendor jar package name yaml Highest Vendor jar package name yaml Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor Manifest multi-release true Low Product file name org.yaml.snakeyaml High Product jar package name emitter Highest Product jar package name org Highest Product jar package name parser Highest Product jar package name snakeyaml Highest Product jar package name snakeyaml Low Product jar package name yaml Highest Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest multi-release true Low Version file name org.yaml.snakeyaml Medium Version file version 2.5 High Version Manifest build-jdk-spec 11 Low Version Manifest Bundle-Version 2.5.0 High
Related Dependencies org.yaml.snakeyaml-2.5.jar (shaded: org.yaml:snakeyaml:2.5)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.yaml.snakeyaml-2.5.jar/META-INF/maven/org.yaml/snakeyaml/pom.xml MD5: 926aa99fa2dfc8fc3a1ade1b3408f090 SHA1: 5140dd9f7e010f8238025f4535bd17f38e67993f SHA256: ba01ae7a744cb52fe8ecf3b023cbc32e0ccc8c6beef9f26de77a47808239447d pkg:maven/org.yaml/snakeyaml@2.5 org.yaml.snakeyaml-2.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/org.yaml.snakeyaml-2.5.jar MD5: 8d3b7581db5c7620db55183f33a4f2ad SHA1: 2d53ddec134280cb384c1e35d094e5f71c1f2316 SHA256: e6682acf1ace77508ef13649cbf4f8d09d2cf5457bdb61d25ffb6ac0233d78dd snakeyaml-2.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/yaml/snakeyaml/2.5/snakeyaml-2.5.jar MD5: 8d3b7581db5c7620db55183f33a4f2ad SHA1: 2d53ddec134280cb384c1e35d094e5f71c1f2316 SHA256: e6682acf1ace77508ef13649cbf4f8d09d2cf5457bdb61d25ffb6ac0233d78dd pkg:maven/org.yaml/snakeyaml@2.5 cpe:2.3:a:snakeyaml_project:snakeyaml:2.5:*:*:*:*:*:*:* (Confidence :Low) suppress packageurl-java-1.5.0.jarDescription:
The official Java implementation of the PackageURL specification. PackageURL (purl) is a minimal
specification for describing a package via a "mostly universal" URL.
License:
MIT: https://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/github/package-url/packageurl-java/1.5.0/packageurl-java-1.5.0.jar
MD5: 90856d8bb5b17e08fdf03b6a2f93b81c
SHA1: e6bf530f52feab911f4032604ca0b8216f7ff337
SHA256: e45551727707acc0c56ac62d56964332ea0f138d6cc3656d988b9369150f5247
Evidence Type Source Name Value Confidence Vendor file name packageurl-java High Vendor jar package name github Highest Vendor jar package name packageurl Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid packageurl-java Low Vendor pom developer email Steve.Springett@owasp.org Low Vendor pom developer name Steve Springett Medium Vendor pom developer org OWASP Medium Vendor pom developer org URL http://www.owasp.org/ Medium Vendor pom groupid com.github.package-url Highest Vendor pom name Package URL High Vendor pom url package-url/packageurl-java Highest Product file name packageurl-java High Product jar package name github Highest Product jar package name packageurl Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid packageurl-java Highest Product pom developer email Steve.Springett@owasp.org Low Product pom developer name Steve Springett Low Product pom developer org OWASP Low Product pom developer org URL http://www.owasp.org/ Low Product pom groupid com.github.package-url Highest Product pom name Package URL High Product pom url package-url/packageurl-java High Version file version 1.5.0 High Version pom version 1.5.0 Highest
pkg:maven/com.github.package-url/packageurl-java@1.5.0 (Confidence :High) password.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/password/password.module.jsMD5: 157c15d8a5715ec79759fe71fbafacc4SHA1: f4102745ad1d0e169512a85a4d0efaf970840a6fSHA256: 8036d9010f8023b9404e55bc11743fc85113916a75f97d93a7e1c640fe4fd707
Evidence Type Source Name Value Confidence
password.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/password/password.module.min.jsMD5: 35b140d16e946e810022dc6a91be510bSHA1: 521fbacc87fb381dbccad68d2287f5a4c0ea6fdfSHA256: af7eac27a15c3c497910da7c18856d96544b1f7c2342e5f6d9b29461077791ce
Evidence Type Source Name Value Confidence
password.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/password/password.nomodule.jsMD5: 8c19df4a179023b3942ac931ca6e7613SHA1: 726e97684e8f23b769c8c7cf761016516ac06f1cSHA256: 48e2a5a6a74983ba87a3aac0d6dbd1f0e16370486aeb5f9538edff57ae131b32
Evidence Type Source Name Value Confidence
password.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/password/password.nomodule.min.jsMD5: 70885f88c465e7371e8aca0f721224a4SHA1: 29aab4e9b1000b9437f981f63daab698d16bf876SHA256: c16cb07de0ef607ff937bc51cee017aca96be99e744b9cf6e543d0107594475c
Evidence Type Source Name Value Confidence
patch.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/patch/patch.module.jsMD5: 18e4e7f59999c2b3024530d012c1bd7eSHA1: fc0067ea5d543dfd30790f965fe76ac7a8d8d4cbSHA256: 729385a8afa8897d516d187bd27a76131fd46dc410a8ce7bde4885c5ae2b039e
Evidence Type Source Name Value Confidence
patch.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/patch/patch.module.min.jsMD5: 2c5726ee2cf598f9743e8d289dca8445SHA1: bea9aa29eac44254ff41b68014652d7c19313ea3SHA256: d12ff8e50cf0cd44080c3b0c3f7dac06c2ceaae919dc99e49cd7cf7407da799c
Evidence Type Source Name Value Confidence
patch.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/patch/patch.nomodule.jsMD5: feeaa98f3e6a1915eab991dbff486a17SHA1: 30ce1990694d3f7154da06b182df951c61447542SHA256: a4cbf55f0d870d2470de49bb186b14c43a2aa5ab8b2f33fbe47431ccc19be9a9
Evidence Type Source Name Value Confidence
patch.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/patch/patch.nomodule.min.jsMD5: 0ceae623ae794ba5fed88487f14016ffSHA1: 97c4f05021a1d99193164e58179165d6db871addSHA256: 43e0af7c1541efe1ecbc02876066319fa77900aa7b0d82bf41ab2bd3bb35b97e
Evidence Type Source Name Value Confidence
plexus-archiver-4.4.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-archiver/4.4.0/plexus-archiver-4.4.0.jarMD5: 31d86104d3613dab27830f45c9ee9819SHA1: beb1a3813167d15684d6516a272a1ca499cb8b60SHA256: 43c75ef577d610ab77ec2894acbde0c72604416ba8ba8b49e9a740d045a40250
Evidence Type Source Name Value Confidence Vendor file name plexus-archiver High Vendor jar package name archiver Highest Vendor jar package name codehaus Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid plexus-archiver Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Archiver Component High Vendor pom parent-artifactid plexus Low Product file name plexus-archiver High Product jar package name archiver Highest Product jar package name codehaus Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid plexus-archiver Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Archiver Component High Product pom parent-artifactid plexus Medium Version file version 4.4.0 High Version pom parent-version 4.4.0 Low Version pom version 4.4.0 Highest
CVE-2023-37460 suppress
Plexis Archiver is a collection of Plexus components to create archives or extract archives to a directory with a unified `Archiver`/`UnArchiver` API. Prior to version 4.8.0, using AbstractUnArchiver for extracting an archive might lead to an arbitrary file creation and possibly remote code execution. When extracting an archive with an entry that already exists in the destination directory as a symbolic link whose target does not exist - the `resolveFile()` function will return the symlink's source instead of its target, which will pass the verification that ensures the file will not be extracted outside of the destination directory. Later `Files.newOutputStream()`, that follows symlinks by default, will actually write the entry's content to the symlink's target. Whoever uses plexus archiver to extract an untrusted archive is vulnerable to an arbitrary file creation and possibly remote code execution. Version 4.8.0 contains a patch for this issue. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), CWE-61 UNIX Symbolic Link (Symlink) Following
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
plexus-build-api-0.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/sonatype/plexus/plexus-build-api/0.0.7/plexus-build-api-0.0.7.jarMD5: 49f0f8c6bdf2687e358870a4fc1559c6SHA1: e6ba5cd4bfd8de00235af936e7f63eb24ed436e6SHA256: 934171640fbd3d2495c50b79b0d9adb11e2c83e65bad157df8fe34bcac0ff798
Evidence Type Source Name Value Confidence Vendor file name plexus-build-api High Vendor jar package name build Highest Vendor jar package name build Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor jar package name sonatype Highest Vendor jar package name sonatype Low Vendor pom artifactid plexus-build-api Low Vendor pom groupid org.sonatype.plexus Highest Vendor pom parent-artifactid spice-parent Low Vendor pom parent-groupid org.sonatype.spice Medium Product file name plexus-build-api High Product jar package name build Highest Product jar package name build Low Product jar package name incremental Low Product jar package name plexus Highest Product jar package name plexus Low Product jar package name sonatype Highest Product pom artifactid plexus-build-api Highest Product pom groupid org.sonatype.plexus Highest Product pom parent-artifactid spice-parent Medium Product pom parent-groupid org.sonatype.spice Medium Version file version 0.0.7 High Version pom parent-version 0.0.7 Low Version pom version 0.0.7 Highest
pkg:maven/org.sonatype.plexus/plexus-build-api@0.0.7 (Confidence :High) plexus-cipher-2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-cipher/2.0/plexus-cipher-2.0.jarMD5: 55d612839faf248cbe3e273969c002c2SHA1: 425ea8e534716b4bff1ea90f39bd76be951d651bSHA256: 9a7f1b5c5a9effd61eadfd8731452a2f76a8e79111fac391ef75ea801bea203a
Evidence Type Source Name Value Confidence Vendor file name plexus-cipher High Vendor jar package name cipher Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid plexus-cipher Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Cipher: encryption/decryption Component High Vendor pom parent-artifactid plexus Low Product file name plexus-cipher High Product jar package name cipher Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid plexus-cipher Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Cipher: encryption/decryption Component High Product pom parent-artifactid plexus Medium Version file version 2.0 High Version pom parent-version 2.0 Low Version pom version 2.0 Highest
pkg:maven/org.codehaus.plexus/plexus-cipher@2.0 (Confidence :High) plexus-classworlds-2.6.0.jarDescription:
A class loader framework License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-classworlds/2.6.0/plexus-classworlds-2.6.0.jar
MD5: 67e722b27e3a33b33c1b263b99dd7c43
SHA1: 8587e80fcb38e70b70fae8d5914b6376bfad6259
SHA256: 52f77c5ec49f787c9c417ebed5d6efd9922f44a202f217376e4f94c0d74f3549
Evidence Type Source Name Value Confidence Vendor file name plexus-classworlds High Vendor jar package name classworlds Highest Vendor jar package name codehaus Highest Vendor jar package name plexus Highest Vendor Manifest bundle-docurl http://codehaus-plexus.github.io/ Low Vendor Manifest bundle-symbolicname org.codehaus.plexus.classworlds Medium Vendor pom artifactid plexus-classworlds Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Classworlds High Vendor pom parent-artifactid plexus Low Product file name plexus-classworlds High Product jar package name classworlds Highest Product jar package name codehaus Highest Product jar package name plexus Highest Product Manifest bundle-docurl http://codehaus-plexus.github.io/ Low Product Manifest Bundle-Name Plexus Classworlds Medium Product Manifest bundle-symbolicname org.codehaus.plexus.classworlds Medium Product pom artifactid plexus-classworlds Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Classworlds High Product pom parent-artifactid plexus Medium Version file version 2.6.0 High Version Manifest Bundle-Version 2.6.0 High Version pom parent-version 2.6.0 Low Version pom version 2.6.0 Highest
pkg:maven/org.codehaus.plexus/plexus-classworlds@2.6.0 (Confidence :High) plexus-compiler-api-2.15.0.jarDescription:
Plexus Compilers component's API to manipulate compilers. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-compiler-api/2.15.0/plexus-compiler-api-2.15.0.jarMD5: 6e3034fd2c3748665a2f460bc6ae6919SHA1: 1bd59395d358ca695fddc7b9dc594483f4140601SHA256: d31d744eb69f77dffd3722dca4094758e0f90e79918a7b3b9fdc37ce49b60342
Evidence Type Source Name Value Confidence Vendor file name plexus-compiler-api High Vendor jar package name codehaus Highest Vendor jar package name compiler Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-compiler-api Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Compiler Api High Vendor pom parent-artifactid plexus-compiler Low Product file name plexus-compiler-api High Product jar package name codehaus Highest Product jar package name compiler Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus Compiler Api High Product Manifest specification-title Plexus Compiler Api Medium Product pom artifactid plexus-compiler-api Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Compiler Api High Product pom parent-artifactid plexus-compiler Medium Version file version 2.15.0 High Version Manifest Implementation-Version 2.15.0 High Version pom version 2.15.0 Highest
pkg:maven/org.codehaus.plexus/plexus-compiler-api@2.15.0 (Confidence :High) plexus-compiler-javac-2.15.0.jarDescription:
Javac Compiler support for Plexus Compiler component. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-compiler-javac/2.15.0/plexus-compiler-javac-2.15.0.jarMD5: 5def81afaf940f3ca616d2503d23c76bSHA1: 48069fe3c512b09e8aa32d77929c190a6faba790SHA256: 89603334988453b9cf4d7ec404d4b54f140de28b678d6a8e8edc448240dd0e90
Evidence Type Source Name Value Confidence Vendor file name plexus-compiler-javac High Vendor jar package name codehaus Highest Vendor jar package name compiler Highest Vendor jar package name javac Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-compiler-javac Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Javac Component High Vendor pom parent-artifactid plexus-compilers Low Product file name plexus-compiler-javac High Product jar package name codehaus Highest Product jar package name compiler Highest Product jar package name javac Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus Javac Component High Product Manifest specification-title Plexus Javac Component Medium Product pom artifactid plexus-compiler-javac Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Javac Component High Product pom parent-artifactid plexus-compilers Medium Version file version 2.15.0 High Version Manifest Implementation-Version 2.15.0 High Version pom version 2.15.0 Highest
pkg:maven/org.codehaus.plexus/plexus-compiler-javac@2.15.0 (Confidence :High) plexus-compiler-manager-2.15.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-compiler-manager/2.15.0/plexus-compiler-manager-2.15.0.jarMD5: 17484af69415a6b302a3899d56173c45SHA1: 4c6d2fc56063e2c62b953a2da9ad60c19097474dSHA256: c13b12c32a18b00e457de9b93cfc3d5593bfa1fb992b2c46a3498be1a77c4889
Evidence Type Source Name Value Confidence Vendor file name plexus-compiler-manager High Vendor jar package name codehaus Highest Vendor jar package name compiler Highest Vendor jar package name manager Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-compiler-manager Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Compiler Manager High Vendor pom parent-artifactid plexus-compiler Low Product file name plexus-compiler-manager High Product jar package name codehaus Highest Product jar package name compiler Highest Product jar package name manager Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus Compiler Manager High Product Manifest specification-title Plexus Compiler Manager Medium Product pom artifactid plexus-compiler-manager Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Compiler Manager High Product pom parent-artifactid plexus-compiler Medium Version file version 2.15.0 High Version Manifest Implementation-Version 2.15.0 High Version pom version 2.15.0 Highest
pkg:maven/org.codehaus.plexus/plexus-compiler-manager@2.15.0 (Confidence :High) plexus-component-annotations-2.1.0.jarDescription:
Plexus Component "Java 5" Annotations, to describe plexus components properties in java sources with
standard annotations instead of javadoc annotations.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-component-annotations/2.1.0/plexus-component-annotations-2.1.0.jarMD5: 141fd7a2ae613cb17d25ecd54b43eb3fSHA1: 2f2147a6cc6a119a1b51a96f31d45c557f6244b9SHA256: bde3617ce9b5bcf9584126046080043af6a4b3baea40a3b153f02e7bbc32acac
Evidence Type Source Name Value Confidence Vendor file name plexus-component-annotations High Vendor jar package name annotations Highest Vendor jar package name codehaus Highest Vendor jar package name codehaus Low Vendor jar package name component Highest Vendor jar package name component Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor pom artifactid plexus-component-annotations Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus :: Component Annotations High Vendor pom parent-artifactid plexus-containers Low Product file name plexus-component-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name codehaus Highest Product jar package name component Highest Product jar package name component Low Product jar package name plexus Highest Product jar package name plexus Low Product pom artifactid plexus-component-annotations Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus :: Component Annotations High Product pom parent-artifactid plexus-containers Medium Version file version 2.1.0 High Version pom version 2.1.0 Highest
pkg:maven/org.codehaus.plexus/plexus-component-annotations@2.1.0 (Confidence :High) plexus-interactivity-api-1.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-interactivity-api/1.3/plexus-interactivity-api-1.3.jarMD5: 1c388abeb295c9959ff55292cb8e98c4SHA1: e60b726018558aeb86ca9a0299ec952f2d927b65SHA256: c26de0f7a578a82f8116aced2c3c62f5e06dc1815a8fe22b1af0c1467f2edb25
Evidence Type Source Name Value Confidence Vendor file name plexus-interactivity-api High Vendor jar package name codehaus Highest Vendor jar package name interactivity Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid plexus-interactivity-api Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Default Interactivity Handler High Vendor pom parent-artifactid plexus-interactivity Low Product file name plexus-interactivity-api High Product jar package name codehaus Highest Product jar package name interactivity Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product pom artifactid plexus-interactivity-api Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Default Interactivity Handler High Product pom parent-artifactid plexus-interactivity Medium Version file version 1.3 High Version pom version 1.3 Highest
pkg:maven/org.codehaus.plexus/plexus-interactivity-api@1.3 (Confidence :High) plexus-interpolation-1.26.jarDescription:
The Plexus project provides a full software stack for creating and executing software projects. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-interpolation/1.26/plexus-interpolation-1.26.jar
MD5: 1049ae9f5cd8cf618abf5bc5805e6b94
SHA1: 25b919c664b79795ccde0ede5cee0fd68b544197
SHA256: b3b5412ce17889103ea564bcdfcf9fb3dfa540344ffeac6b538a73c9d7182662
Evidence Type Source Name Value Confidence Vendor file name plexus-interpolation High Vendor jar package name codehaus Highest Vendor jar package name interpolation Highest Vendor jar package name plexus Highest Vendor Manifest bundle-docurl http://codehaus-plexus.github.io/ Low Vendor Manifest bundle-symbolicname org.codehaus.plexus.interpolation Medium Vendor pom artifactid plexus-interpolation Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Interpolation API High Vendor pom parent-artifactid plexus Low Product file name plexus-interpolation High Product jar package name codehaus Highest Product jar package name interpolation Highest Product jar package name plexus Highest Product Manifest bundle-docurl http://codehaus-plexus.github.io/ Low Product Manifest Bundle-Name Plexus Interpolation API Medium Product Manifest bundle-symbolicname org.codehaus.plexus.interpolation Medium Product pom artifactid plexus-interpolation Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Interpolation API High Product pom parent-artifactid plexus Medium Version file version 1.26 High Version pom parent-version 1.26 Low Version pom version 1.26 Highest
pkg:maven/org.codehaus.plexus/plexus-interpolation@1.26 (Confidence :High) plexus-io-3.4.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-io/3.4.0/plexus-io-3.4.0.jarMD5: 9d53b13ce81b2aa1544963a08d56cc1eSHA1: de55d9e6f1fd3cadc483f7a8a893b72e2b75403bSHA256: cd4da2ffd9adddfa30878350878286a5cfb332f7aeb08a39f24465c55e0cfb38
Evidence Type Source Name Value Confidence Vendor file name plexus-io High Vendor jar package name codehaus Highest Vendor jar package name components Highest Vendor jar package name io Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 11 Low Vendor pom artifactid plexus-io Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus IO Components High Vendor pom parent-artifactid plexus Low Product file name plexus-io High Product jar package name codehaus Highest Product jar package name components Highest Product jar package name io Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 11 Low Product pom artifactid plexus-io Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus IO Components High Product pom parent-artifactid plexus Medium Version file version 3.4.0 High Version pom parent-version 3.4.0 Low Version pom version 3.4.0 Highest
pkg:maven/org.codehaus.plexus/plexus-io@3.4.0 (Confidence :High) plexus-java-1.2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-java/1.2.0/plexus-java-1.2.0.jarMD5: fc0976d9a939e5afe5c543f72438f290SHA1: 3f161764aac786d64c4cac26511215369250d4fdSHA256: 4d2d63cdcad46feba432110ef64bcdc8f8fad48538fda5cd2253686b45a94304
Evidence Type Source Name Value Confidence Vendor file name plexus-java High Vendor jar package name codehaus Highest Vendor jar package name java Highest Vendor jar package name languages Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest multi-release true Low Vendor pom artifactid plexus-java Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Languages :: Java High Vendor pom parent-artifactid plexus-languages Low Product file name plexus-java High Product jar package name codehaus Highest Product jar package name java Highest Product jar package name languages Highest Product jar package name org Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest multi-release true Low Product pom artifactid plexus-java Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Languages :: Java High Product pom parent-artifactid plexus-languages Medium Version file version 1.2.0 High Version pom version 1.2.0 Highest
pkg:maven/org.codehaus.plexus/plexus-java@1.2.0 (Confidence :High) plexus-java-1.4.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-java/1.4.0/plexus-java-1.4.0.jarMD5: 365258bc1e631844c54f5386e4ea8c2bSHA1: 85efa6e13ef450deb94f6cb0a812a4e7acf74009SHA256: e295f379d7885edec5d9501ee0a9152300359167f875dc7c483305c9799d70d0
Evidence Type Source Name Value Confidence Vendor file name plexus-java High Vendor jar package name codehaus Highest Vendor jar package name java Highest Vendor jar package name languages Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-java Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Languages :: Java High Vendor pom parent-artifactid plexus-languages Low Product file name plexus-java High Product jar package name codehaus Highest Product jar package name java Highest Product jar package name languages Highest Product jar package name org Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus Languages :: Java High Product Manifest multi-release true Low Product Manifest specification-title Plexus Languages :: Java Medium Product pom artifactid plexus-java Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Languages :: Java High Product pom parent-artifactid plexus-languages Medium Version file version 1.4.0 High Version Manifest Implementation-Version 1.4.0 High Version pom version 1.4.0 Highest
pkg:maven/org.codehaus.plexus/plexus-java@1.4.0 (Confidence :High) plexus-sec-dispatcher-2.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-sec-dispatcher/2.0/plexus-sec-dispatcher-2.0.jarMD5: e68635a721630177ac70173e441336b6SHA1: f89c5080614ffd0764e49861895dbedde1b47237SHA256: 873139960c4c780176dda580b003a2c4bf82188bdce5bb99234e224ef7acfceb
Evidence Type Source Name Value Confidence Vendor file name plexus-sec-dispatcher High Vendor jar package name plexus Highest Vendor jar package name sec Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid plexus-sec-dispatcher Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Security Dispatcher Component High Vendor pom parent-artifactid plexus Low Product file name plexus-sec-dispatcher High Product jar package name plexus Highest Product jar package name sec Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid plexus-sec-dispatcher Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Security Dispatcher Component High Product pom parent-artifactid plexus Medium Version file version 2.0 High Version pom parent-version 2.0 Low Version pom version 2.0 Highest
plexus-utils-3.0.24.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines, XML and
more.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.24/plexus-utils-3.0.24.jarMD5: fbefd8983c6bb4928c27c680463ff355SHA1: b4ac9780b37cb1b736eae9fbcef27609b7c911efSHA256: 83ee748b12d06afb0ad4050a591132b3e8025fbb1990f1ed002e8b73293e69b4
Evidence Type Source Name Value Confidence Vendor file name plexus-utils High Vendor jar package name codehaus Highest Vendor jar package name codehaus Low Vendor jar package name plexus Highest Vendor jar package name plexus Low Vendor jar package name util Low Vendor jar package name xml Highest Vendor pom artifactid plexus-utils Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Product file name plexus-utils High Product jar package name codehaus Highest Product jar package name plexus Highest Product jar package name plexus Low Product jar package name util Low Product jar package name xml Highest Product pom artifactid plexus-utils Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Common Utilities High Product pom parent-artifactid plexus Medium Version file version 3.0.24 High Version pom parent-version 3.0.24 Low Version pom version 3.0.24 Highest
plexus-utils-3.4.2.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines, XML and
more.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-utils/3.4.2/plexus-utils-3.4.2.jarMD5: c1c94fdc23c54654c59909136b85cf5fSHA1: 82445e007f9009ac5ba6ae5d6b6898c4ce54dcf6SHA256: f957f13604ea1686de805801862f339dbbb6eab9a66f9cc7e4a5c5b27e4fcecc
Evidence Type Source Name Value Confidence Vendor file name plexus-utils High Vendor jar package name codehaus Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest multi-release true Low Vendor pom artifactid plexus-utils Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Product file name plexus-utils High Product jar package name codehaus Highest Product jar package name org Highest Product jar package name plexus Highest Product jar package name xml Highest Product Manifest build-jdk-spec 11 Low Product Manifest multi-release true Low Product pom artifactid plexus-utils Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Common Utilities High Product pom parent-artifactid plexus Medium Version file version 3.4.2 High Version pom parent-version 3.4.2 Low Version pom version 3.4.2 Highest
plexus-utils-3.5.1.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines, XML and
more.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-utils/3.5.1/plexus-utils-3.5.1.jarMD5: cdec471a77f52e687d0df4c43f392a71SHA1: c6bfb17c97ecc8863e88778ea301be742c62b06dSHA256: 86e0255d4c879c61b4833ed7f13124e8bb679df47debb127326e7db7dd49a07b
Evidence Type Source Name Value Confidence Vendor file name plexus-utils High Vendor jar package name codehaus Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest multi-release true Low Vendor pom artifactid plexus-utils Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Product file name plexus-utils High Product jar package name 11 Highest Product jar package name codehaus Highest Product jar package name org Highest Product jar package name plexus Highest Product jar package name xml Highest Product Manifest build-jdk-spec 11 Low Product Manifest multi-release true Low Product pom artifactid plexus-utils Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Common Utilities High Product pom parent-artifactid plexus Medium Version file version 3.5.1 High Version pom parent-version 3.5.1 Low Version pom version 3.5.1 Highest
plexus-utils-4.0.1.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines and
more. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-utils/4.0.1/plexus-utils-4.0.1.jarMD5: 0fa4c6aabfa676c4a1a1bf0c7473f684SHA1: 2162c639aa9b081ef2a0be9d41643513e284bf99SHA256: 96b9cc44439191d2d0635974e2d44e768736b4fb2abcb65f94cd95e41912fa8b
Evidence Type Source Name Value Confidence Vendor file name plexus-utils High Vendor jar package name codehaus Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-utils Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Vendor pom parent-artifactid plexus Low Vendor pom url https://codehaus-plexus.github.io/plexus-utils/ Highest Product file name plexus-utils High Product jar package name codehaus Highest Product jar package name org Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus Common Utilities High Product Manifest multi-release true Low Product Manifest specification-title Plexus Common Utilities Medium Product pom artifactid plexus-utils Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Common Utilities High Product pom parent-artifactid plexus Medium Product pom url https://codehaus-plexus.github.io/plexus-utils/ Medium Version file version 4.0.1 High Version Manifest Implementation-Version 4.0.1 High Version pom parent-version 4.0.1 Low Version pom version 4.0.1 Highest
plexus-utils-4.0.2.jarDescription:
A collection of various utility classes to ease working with strings, files, command lines and
more. License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-utils/4.0.2/plexus-utils-4.0.2.jar
MD5: 4cfdd73e436702d319d551a44fcea500
SHA1: 9526a9548b302572f23337fcc217fb4cc713b9c3
SHA256: 8957274e75fe2c278b1428dd16a0daeee1dd38152cb6eff816177ac28fccb697
Evidence Type Source Name Value Confidence Vendor file name plexus-utils High Vendor jar package name codehaus Highest Vendor jar package name org Highest Vendor jar package name plexus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-utils Low Vendor pom developer email 1983-01-06@gmx.net Low Vendor pom developer email agudian@apache.org Low Vendor pom developer email andy@handyande.co.uk Low Vendor pom developer email apache@kav.dk Low Vendor pom developer email belingueres@gmail.com Low Vendor pom developer email brett@codehaus.org Low Vendor pom developer email bwalding@codehaus.org Low Vendor pom developer email carlos@codehaus.org Low Vendor pom developer email dan@envoisolutions.com Low Vendor pom developer email evenisse@codehaus.org Low Vendor pom developer email gnodet@apache.org Low Vendor pom developer email hboutemy@apache.org Low Vendor pom developer email james@jamestaylor.org Low Vendor pom developer email jason@maven.org Low Vendor pom developer email jdcasey@codehaus.org Low Vendor pom developer email joakim@erdfelt.com Low Vendor pom developer email kenney@codehaus.org Low Vendor pom developer email khmarbaise@apache.org Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email kwin@apache.org Low Vendor pom developer email mhw@kremvax.net Low Vendor pom developer email mmaczka@interia.pl Low Vendor pom developer email olamy@codehaus.org Low Vendor pom developer email olegy@codehaus.org Low Vendor pom developer email rahul.thakur.xdev@gmail.com Low Vendor pom developer email sjaranowski@apache.org Low Vendor pom developer email slachiewicz@apache.org Low Vendor pom developer email trygvis@codehaus.org Low Vendor pom developer email vsiveton@codehaus.org Low Vendor pom developer id agudian Medium Vendor pom developer id belingueres Medium Vendor pom developer id brett Medium Vendor pom developer id bwalding Medium Vendor pom developer id carlos Medium Vendor pom developer id dandiep Medium Vendor pom developer id evenisse Medium Vendor pom developer id gnodet Medium Vendor pom developer id handyande Medium Vendor pom developer id hboutemy Medium Vendor pom developer id jdcasey Medium Vendor pom developer id joakime Medium Vendor pom developer id jtaylor Medium Vendor pom developer id jvanzyl Medium Vendor pom developer id kasper Medium Vendor pom developer id kaz Medium Vendor pom developer id kenney Medium Vendor pom developer id khmarbaise Medium Vendor pom developer id krosenvold Medium Vendor pom developer id kwin Medium Vendor pom developer id mhw Medium Vendor pom developer id michael-o Medium Vendor pom developer id michal Medium Vendor pom developer id olamy Medium Vendor pom developer id oleg Medium Vendor pom developer id rahul Medium Vendor pom developer id sjaranowski Medium Vendor pom developer id slachiewicz Medium Vendor pom developer id trygvis Medium Vendor pom developer id vsiveton Medium Vendor pom developer name Andreas Gudian Medium Vendor pom developer name Andrew Williams Medium Vendor pom developer name Ben Walding Medium Vendor pom developer name Brett Porter Medium Vendor pom developer name Carlos Sanchez Medium Vendor pom developer name Dan Diephouse Medium Vendor pom developer name Emmanuel Venisse Medium Vendor pom developer name Gabriel Belingueres Medium Vendor pom developer name Guillaume Nodet Medium Vendor pom developer name Hervé Boutemy Medium Vendor pom developer name James Taylor Medium Vendor pom developer name Jason van Zyl Medium Vendor pom developer name Joakim Erdfelt Medium Vendor pom developer name John Casey Medium Vendor pom developer name Karl Heinz Marbaise Medium Vendor pom developer name Kasper Nielsen Medium Vendor pom developer name Kenney Westerhof Medium Vendor pom developer name Konrad Windszus Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Mark Wilkinson Medium Vendor pom developer name Michael Osipov Medium Vendor pom developer name Michal Maczka Medium Vendor pom developer name Oleg Gusakov Medium Vendor pom developer name Olivier Lamy Medium Vendor pom developer name Pete Kazmier Medium Vendor pom developer name Rahul Thakur Medium Vendor pom developer name Slawomir Jaranowski Medium Vendor pom developer name Sylwester Lachiewicz Medium Vendor pom developer name Trygve Laugstøl Medium Vendor pom developer name Vincent Siveton Medium Vendor pom developer org ASF Medium Vendor pom developer org Envoi solutions Medium Vendor pom developer org Walding Consulting Services Medium Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus Common Utilities High Vendor pom organization name Codehaus Plexus High Vendor pom organization url https://codehaus-plexus.github.io/ Medium Vendor pom parent-artifactid plexus Low Vendor pom url https://codehaus-plexus.github.io/plexus-utils/ Highest Product file name plexus-utils High Product jar package name codehaus Highest Product jar package name org Highest Product jar package name plexus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus Common Utilities High Product Manifest multi-release true Low Product Manifest specification-title Plexus Common Utilities Medium Product pom artifactid plexus-utils Highest Product pom developer email 1983-01-06@gmx.net Low Product pom developer email agudian@apache.org Low Product pom developer email andy@handyande.co.uk Low Product pom developer email apache@kav.dk Low Product pom developer email belingueres@gmail.com Low Product pom developer email brett@codehaus.org Low Product pom developer email bwalding@codehaus.org Low Product pom developer email carlos@codehaus.org Low Product pom developer email dan@envoisolutions.com Low Product pom developer email evenisse@codehaus.org Low Product pom developer email gnodet@apache.org Low Product pom developer email hboutemy@apache.org Low Product pom developer email james@jamestaylor.org Low Product pom developer email jason@maven.org Low Product pom developer email jdcasey@codehaus.org Low Product pom developer email joakim@erdfelt.com Low Product pom developer email kenney@codehaus.org Low Product pom developer email khmarbaise@apache.org Low Product pom developer email krosenvold@apache.org Low Product pom developer email kwin@apache.org Low Product pom developer email mhw@kremvax.net Low Product pom developer email mmaczka@interia.pl Low Product pom developer email olamy@codehaus.org Low Product pom developer email olegy@codehaus.org Low Product pom developer email rahul.thakur.xdev@gmail.com Low Product pom developer email sjaranowski@apache.org Low Product pom developer email slachiewicz@apache.org Low Product pom developer email trygvis@codehaus.org Low Product pom developer email vsiveton@codehaus.org Low Product pom developer id agudian Low Product pom developer id belingueres Low Product pom developer id brett Low Product pom developer id bwalding Low Product pom developer id carlos Low Product pom developer id dandiep Low Product pom developer id evenisse Low Product pom developer id gnodet Low Product pom developer id handyande Low Product pom developer id hboutemy Low Product pom developer id jdcasey Low Product pom developer id joakime Low Product pom developer id jtaylor Low Product pom developer id jvanzyl Low Product pom developer id kasper Low Product pom developer id kaz Low Product pom developer id kenney Low Product pom developer id khmarbaise Low Product pom developer id krosenvold Low Product pom developer id kwin Low Product pom developer id mhw Low Product pom developer id michael-o Low Product pom developer id michal Low Product pom developer id olamy Low Product pom developer id oleg Low Product pom developer id rahul Low Product pom developer id sjaranowski Low Product pom developer id slachiewicz Low Product pom developer id trygvis Low Product pom developer id vsiveton Low Product pom developer name Andreas Gudian Low Product pom developer name Andrew Williams Low Product pom developer name Ben Walding Low Product pom developer name Brett Porter Low Product pom developer name Carlos Sanchez Low Product pom developer name Dan Diephouse Low Product pom developer name Emmanuel Venisse Low Product pom developer name Gabriel Belingueres Low Product pom developer name Guillaume Nodet Low Product pom developer name Hervé Boutemy Low Product pom developer name James Taylor Low Product pom developer name Jason van Zyl Low Product pom developer name Joakim Erdfelt Low Product pom developer name John Casey Low Product pom developer name Karl Heinz Marbaise Low Product pom developer name Kasper Nielsen Low Product pom developer name Kenney Westerhof Low Product pom developer name Konrad Windszus Low Product pom developer name Kristian Rosenvold Low Product pom developer name Mark Wilkinson Low Product pom developer name Michael Osipov Low Product pom developer name Michal Maczka Low Product pom developer name Oleg Gusakov Low Product pom developer name Olivier Lamy Low Product pom developer name Pete Kazmier Low Product pom developer name Rahul Thakur Low Product pom developer name Slawomir Jaranowski Low Product pom developer name Sylwester Lachiewicz Low Product pom developer name Trygve Laugstøl Low Product pom developer name Vincent Siveton Low Product pom developer org ASF Low Product pom developer org Envoi solutions Low Product pom developer org Walding Consulting Services Low Product pom groupid org.codehaus.plexus Highest Product pom name Plexus Common Utilities High Product pom organization name Codehaus Plexus Low Product pom organization url https://codehaus-plexus.github.io/ Low Product pom parent-artifactid plexus Medium Product pom url https://codehaus-plexus.github.io/plexus-utils/ Medium Version file version 4.0.2 High Version Manifest Implementation-Version 4.0.2 High Version pom parent-version 4.0.2 Low Version pom version 4.0.2 Highest
plexus-xml-3.0.1.jarDescription:
A collection of various utility classes to ease working with XML in Maven 3. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-xml/3.0.1/plexus-xml-3.0.1.jarMD5: cd868918ebc742350840124ea4422ab0SHA1: b0e73c21402f03c2765674b8dede21673b3288cfSHA256: c1a510a87a62bd2d74ac1472dd31c3f9e9b0b8b8568f37d77c0f135415bebd05
Evidence Type Source Name Value Confidence Vendor file name plexus-xml High Vendor jar package name codehaus Highest Vendor jar package name plexus Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest Implementation-Vendor Codehaus Plexus High Vendor Manifest specification-vendor Codehaus Plexus Low Vendor pom artifactid plexus-xml Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus XML Utilities High Vendor pom parent-artifactid plexus Low Vendor pom url https://codehaus-plexus.github.io/plexus-xml/ Highest Product file name plexus-xml High Product jar package name codehaus Highest Product jar package name plexus Highest Product jar package name xml Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Plexus XML Utilities High Product Manifest specification-title Plexus XML Utilities Medium Product pom artifactid plexus-xml Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus XML Utilities High Product pom parent-artifactid plexus Medium Product pom url https://codehaus-plexus.github.io/plexus-xml/ Medium Version file version 3.0.1 High Version Manifest Implementation-Version 3.0.1 High Version pom parent-version 3.0.1 Low Version pom version 3.0.1 Highest
pkg:maven/org.codehaus.plexus/plexus-xml@3.0.1 (Confidence :High) plexus-xml-4.0.2.jarDescription:
A collection of various utility classes to ease working with XML. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/plexus/plexus-xml/4.0.2/plexus-xml-4.0.2.jarMD5: b3b3361793dd7ece137750fabb1dc4b5SHA1: 5a4af48449edfd559edf6a52be3ae1e632d1ff3cSHA256: e55f26425ad1ce948e4fca7b0fde5ecc9b0ba90d326c6ecc25a8e0e56ccfb6fd
Evidence Type Source Name Value Confidence Vendor file name plexus-xml High Vendor jar package name codehaus Highest Vendor jar package name plexus Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 20 Low Vendor pom artifactid plexus-xml Low Vendor pom groupid org.codehaus.plexus Highest Vendor pom name Plexus XML Utilities High Vendor pom parent-artifactid plexus Low Vendor pom url https://codehaus-plexus.github.io/plexus-xml/ Highest Product file name plexus-xml High Product jar package name codehaus Highest Product jar package name plexus Highest Product jar package name xml Highest Product Manifest build-jdk-spec 20 Low Product pom artifactid plexus-xml Highest Product pom groupid org.codehaus.plexus Highest Product pom name Plexus XML Utilities High Product pom parent-artifactid plexus Medium Product pom url https://codehaus-plexus.github.io/plexus-xml/ Medium Version file version 4.0.2 High Version pom parent-version 4.0.2 Low Version pom version 4.0.2 Highest
pkg:maven/org.codehaus.plexus/plexus-xml@4.0.2 (Confidence :High) postgresql-1.21.3.jarDescription:
Isolated container management for Java code testing License:
MIT: http://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/testcontainers/postgresql/1.21.3/postgresql-1.21.3.jar
MD5: 080a2eee3872efcbd7e201a775554fde
SHA1: db5a90e4999db85e0c22fc8503075c0af7c3c644
SHA256: cbcc9e5b40a5d1c4203e6fcda7a578c607d47f4197bf489d5e0d0e7e844f44fc
Evidence Type Source Name Value Confidence Vendor file name postgresql High Vendor jar package name containers Low Vendor jar package name testcontainers Highest Vendor jar package name testcontainers Low Vendor pom artifactid postgresql Low Vendor pom developer email rich.north@gmail.com Low Vendor pom developer id rnorth Medium Vendor pom developer name Richard North Medium Vendor pom groupid org.testcontainers Highest Vendor pom name Testcontainers :: JDBC :: PostgreSQL High Vendor pom url https://java.testcontainers.org Highest Product file name postgresql High Product jar package name containers Low Product jar package name testcontainers Highest Product pom artifactid postgresql Highest Product pom developer email rich.north@gmail.com Low Product pom developer id rnorth Low Product pom developer name Richard North Low Product pom groupid org.testcontainers Highest Product pom name Testcontainers :: JDBC :: PostgreSQL High Product pom url https://java.testcontainers.org Medium Version file version 1.21.3 High Version pom version 1.21.3 Highest
prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/jacoco-report/jacoco-resources/prettify.jsMD5: 4b337aaa3c606cfc1a6ff1986db2c8cbSHA1: 290093755739da933c180ae7e7ebf283724dad1dSHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68
Evidence Type Source Name Value Confidence
Related Dependencies org.jacoco.report-0.8.13.jar: prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.report/0.8.13/org.jacoco.report-0.8.13.jar/org/jacoco/report/internal/html/resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 org.jacoco.report-0.8.14.jar: prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.report/0.8.14/org.jacoco.report-0.8.14.jar/org/jacoco/report/internal/html/resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/site/jacoco/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/tests/target/jacoco-aggregate/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/jacoco-report/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 prettify.jsFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/site/jacoco/jacoco-resources/prettify.js MD5: 4b337aaa3c606cfc1a6ff1986db2c8cb SHA1: 290093755739da933c180ae7e7ebf283724dad1d SHA256: 743c6c4cab9499cd0bfe18a5a62281eccce843f47ec75eedb32eeb29c755aa68 qdox-2.0.3.jarDescription:
QDox is a high speed, small footprint parser for extracting class/interface/method definitions from source files
complete with JavaDoc @tags. It is designed to be used by active code generators or documentation tools.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/thoughtworks/qdox/qdox/2.0.3/qdox-2.0.3.jar
MD5: 1a599568ea16556d01a008d9e062ac89
SHA1: d70143d2a58e7b16a8ec73a495508d43a085d83b
SHA256: ff70c10165714fe9546c418a65d74ecd5d57623ba408cecde9428f0a609b5d1c
Evidence Type Source Name Value Confidence Vendor file name qdox High Vendor jar package name parser Highest Vendor jar package name qdox Highest Vendor jar package name thoughtworks Highest Vendor jar package name tools Highest Vendor Manifest automatic-module-name com.thoughtworks.qdox Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid qdox Low Vendor pom developer id joe Medium Vendor pom developer id mauro Medium Vendor pom developer id mdub Medium Vendor pom developer id paul Medium Vendor pom developer id rfscholte Medium Vendor pom developer id rinkrank Medium Vendor pom developer name Aslak Hellesoy Medium Vendor pom developer name Joe Walnes Medium Vendor pom developer name Mauro Talevi Medium Vendor pom developer name Mike Williams Medium Vendor pom developer name Paul Hammant Medium Vendor pom developer name Robert Scholte Medium Vendor pom groupid com.thoughtworks.qdox Highest Vendor pom name QDox High Vendor pom url paul-hammant/qdox Highest Product file name qdox High Product jar package name parser Highest Product jar package name qdox Highest Product jar package name thoughtworks Highest Product jar package name tools Highest Product Manifest automatic-module-name com.thoughtworks.qdox Medium Product Manifest build-jdk-spec 1.8 Low Product pom artifactid qdox Highest Product pom developer id joe Low Product pom developer id mauro Low Product pom developer id mdub Low Product pom developer id paul Low Product pom developer id rfscholte Low Product pom developer id rinkrank Low Product pom developer name Aslak Hellesoy Low Product pom developer name Joe Walnes Low Product pom developer name Mauro Talevi Low Product pom developer name Mike Williams Low Product pom developer name Paul Hammant Low Product pom developer name Robert Scholte Low Product pom groupid com.thoughtworks.qdox Highest Product pom name QDox High Product pom url paul-hammant/qdox High Version file version 2.0.3 High Version pom version 2.0.3 Highest
pkg:maven/com.thoughtworks.qdox/qdox@2.0.3 (Confidence :High) qdox-2.2.0.jarDescription:
QDox is a high speed, small footprint parser for extracting class/interface/method definitions from source files
complete with JavaDoc @tags. It is designed to be used by active code generators or documentation tools.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/thoughtworks/qdox/qdox/2.2.0/qdox-2.2.0.jar
MD5: 1585e7fc441f9d256cdd965718836152
SHA1: 39651eb3ce73d6e506490ea352e1e13eab6b55e8
SHA256: c260c3230b2340af97d54bf01f7f67ebc57c901922736c881bb11cb981302be2
Evidence Type Source Name Value Confidence Vendor file name qdox High Vendor jar package name parser Highest Vendor jar package name qdox Highest Vendor jar package name thoughtworks Highest Vendor jar package name tools Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid qdox Low Vendor pom developer id joe Medium Vendor pom developer id mauro Medium Vendor pom developer id mdub Medium Vendor pom developer id paul Medium Vendor pom developer id rfscholte Medium Vendor pom developer id rinkrank Medium Vendor pom developer name Aslak Hellesoy Medium Vendor pom developer name Joe Walnes Medium Vendor pom developer name Mauro Talevi Medium Vendor pom developer name Mike Williams Medium Vendor pom developer name Paul Hammant Medium Vendor pom developer name Robert Scholte Medium Vendor pom groupid com.thoughtworks.qdox Highest Vendor pom name QDox High Vendor pom url paul-hammant/qdox Highest Product file name qdox High Product jar package name parser Highest Product jar package name qdox Highest Product jar package name thoughtworks Highest Product jar package name tools Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid qdox Highest Product pom developer id joe Low Product pom developer id mauro Low Product pom developer id mdub Low Product pom developer id paul Low Product pom developer id rfscholte Low Product pom developer id rinkrank Low Product pom developer name Aslak Hellesoy Low Product pom developer name Joe Walnes Low Product pom developer name Mauro Talevi Low Product pom developer name Mike Williams Low Product pom developer name Paul Hammant Low Product pom developer name Robert Scholte Low Product pom groupid com.thoughtworks.qdox Highest Product pom name QDox High Product pom url paul-hammant/qdox High Version file version 2.2.0 High Version pom version 2.2.0 Highest
pkg:maven/com.thoughtworks.qdox/qdox@2.2.0 (Confidence :High) quarkus-agroal-deployment-3.30.6.jar: qwc-agroal-datasource.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-agroal-deployment/3.30.6/quarkus-agroal-deployment-3.30.6.jar/dev-ui/qwc-agroal-datasource.jsMD5: 009047e55c30127b12a94af2229173abSHA1: 5dc54b72c8c8f4dca4f2cc3bce506bfab7f01707SHA256: dd8973d49e9c530d574b0164a5f71914b36cd11e7deb1e7a7b05e02eb6297ab7
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-bean-graph.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-bean-graph.jsMD5: c9e6db609eacbbddc722ceabfa29bae6SHA1: d0c1a5d1ee2f652784a2528709cb4684531a120eSHA256: 091f37876637d71a879e81a86108f15116c845c779a46a824f9901b11d4cb8e7
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-beans.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-beans.jsMD5: 8c114dd2077b862c5fd0869865a6a74bSHA1: 1d751ce83e65678229b580a2137e04635e09be00SHA256: ff91e4100e476e889cc2959fae3a13724e75864c5ebcc9f587c52365a17741c1
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-decorators.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-decorators.jsMD5: 8e249bb483e9ed9dacbd0ac09b06ba8eSHA1: 7c45d6ab15708c9e662e052460d5076031c2e36dSHA256: a3710bf6217dd4bc3229d1b71d77f0d9244fe3816024a2fcbd7b8e426d2c6c69
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-fired-events.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-fired-events.jsMD5: 396c7dbc25f000a01fa3675528cb8e20SHA1: 0ad1e62a7d1d2a0edda71d8944f2ce056432760bSHA256: 1ad96c3b0c963a23e72af43155f5d9285d85f81a382b0ba1761959f34b4fb3d1
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-interceptors.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-interceptors.jsMD5: f2bc57b1b0b28fcdb6bb1ddea4ce4c87SHA1: dbe166bd840a7de390ff0370961386c63541b75bSHA256: 29f74fd5479dfab448dd7bf8b6ef010f1ef4c71675be64730c5f22635db7662c
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-invocation-trees.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-invocation-trees.jsMD5: 1ab5c76aa17b6f1ef9ee4ba4fb502908SHA1: 4c252712a227eed6a75084114e9ad739583f19f2SHA256: 0d9ce23d7475180e455188f44c36c7da9724090d6aded89a61074df6d486c195
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-observers.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-observers.jsMD5: 94ca62e780dbfe46eeae19678e13966dSHA1: eb020be57b868757bf4618def16731407c395465SHA256: def457f2e2791b05b0abdb3cb85667834463849d77d46f83fd7c2bc43e3f29bf
Evidence Type Source Name Value Confidence
quarkus-arc-deployment-3.30.6.jar: qwc-arc-removed-components.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar/dev-ui/qwc-arc-removed-components.jsMD5: 2ad8dff203ff526dc96d1f4b9552810aSHA1: 7567807968faef410652d9d4c8f1a4dceeeb5016SHA256: ce3a22776c1e30a945d34547a0e91d4480e7a7fcc0dfe08ad16acd3f4d607b2a
Evidence Type Source Name Value Confidence
quarkus-arc-dev-3.30.6.jarDescription:
Build time CDI dependency injection - Dev mode only License:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-dev/3.30.6/quarkus-arc-dev-3.30.6.jar
MD5: 2e3f7aa88371add821178b6d55e0f529
SHA1: 6f070be9465fcf6496f80accbb622bd0dbf83877
SHA256: 01e5ea60062d7e1be6dd43f24e95902970e4ae16f586e05e63bbdf337a054fc1
Evidence Type Source Name Value Confidence Vendor file name quarkus-arc-dev High Vendor jar package name arc Highest Vendor jar package name io Highest Vendor jar package name quarkus Highest Vendor jar package name runtime Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid quarkus-arc-dev Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus - ArC - Runtime Dev mode High Vendor pom parent-artifactid quarkus-arc-parent Low Product file name quarkus-arc-dev High Product jar package name arc Highest Product jar package name io Highest Product jar package name quarkus Highest Product jar package name runtime Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - ArC - Runtime Dev mode High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - ArC - Runtime Dev mode Medium Product pom artifactid quarkus-arc-dev Highest Product pom groupid io.quarkus Highest Product pom name Quarkus - ArC - Runtime Dev mode High Product pom parent-artifactid quarkus-arc-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
Related Dependencies quarkus-arc-deployment-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-arc-deployment/3.30.6/quarkus-arc-deployment-3.30.6.jar MD5: e840bb6deb13293c874ad0f593574907 SHA1: 1fc6ceb85a0acb3673efe8c9242a99686436971c SHA256: 182307ffcc82b7355bad22817fd6daa8ab17459a3414ab434ea3d85580cb5a44 pkg:maven/io.quarkus/quarkus-arc-deployment@3.30.6 quarkus-container-image-deployment-3.30.6.jar: qwc-container-image-build.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-container-image-deployment/3.30.6/quarkus-container-image-deployment-3.30.6.jar/dev-ui/qwc-container-image-build.jsMD5: e04515564dd31c6ab40909c683872b5cSHA1: b555e9d6e8de8d1c0272d29cc001b7ab9deff44aSHA256: 31597f38c2619913392148790ef7fae2e2efb0ba86fe441f8abcd7dc23443750
Evidence Type Source Name Value Confidence
quarkus-datasource-deployment-3.30.6.jar: qwc-datasources-reset.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-datasource-deployment/3.30.6/quarkus-datasource-deployment-3.30.6.jar/dev-ui/qwc-datasources-reset.jsMD5: ecd12861dcd8cfd038377dbcff6e5976SHA1: b7fbfca17e3e65b8ce8696c702a02730ec0e4471SHA256: 80500db4acf496fcf8e2e26da5b96623d83fb2a38ee6b15f296f1d573b573496
Evidence Type Source Name Value Confidence
quarkus-devservices-keycloak-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-devservices-keycloak/3.30.6/quarkus-devservices-keycloak-3.30.6.jar
MD5: e58ae7abcef3521c9f2ac6381e3bf00f
SHA1: 8bcd30db6257e845fe7fc3df382cebfebdf0fb21
SHA256: a1dceacd10f34dd59c4db299c205b90f6e1fafc42c267e8b812d15523c5e8894
Evidence Type Source Name Value Confidence Vendor file name quarkus-devservices-keycloak High Vendor jar package name devservices Highest Vendor jar package name io Highest Vendor jar package name keycloak Highest Vendor jar package name quarkus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid quarkus-devservices-keycloak Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus - DevServices - Keycloak High Vendor pom parent-artifactid quarkus-devservices-parent Low Product file name quarkus-devservices-keycloak High Product jar package name devservices Highest Product jar package name io Highest Product jar package name keycloak Highest Product jar package name quarkus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - DevServices - Keycloak High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - DevServices - Keycloak Medium Product pom artifactid quarkus-devservices-keycloak Highest Product pom groupid io.quarkus Highest Product pom name Quarkus - DevServices - Keycloak High Product pom parent-artifactid quarkus-devservices-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
quarkus-devservices-postgresql-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-devservices-postgresql/3.30.6/quarkus-devservices-postgresql-3.30.6.jar
MD5: 13b7f4cc5b1a1fe49833b9d040ee4d16
SHA1: c158ef5df5ea3828baaddb99460f20a3b415af62
SHA256: c0783d9d335e3d91c75015747ca2a42446c2b0391abc609383e95c2f9b7e6674
Evidence Type Source Name Value Confidence Vendor file name quarkus-devservices-postgresql High Vendor jar package name devservices Highest Vendor jar package name io Highest Vendor jar package name postgresql Highest Vendor jar package name quarkus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid quarkus-devservices-postgresql Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus - DevServices - Postgresql High Vendor pom parent-artifactid quarkus-devservices-parent Low Product file name quarkus-devservices-postgresql High Product jar package name devservices Highest Product jar package name io Highest Product jar package name postgresql Highest Product jar package name quarkus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - DevServices - Postgresql High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - DevServices - Postgresql Medium Product pom artifactid quarkus-devservices-postgresql Highest Product pom groupid io.quarkus Highest Product pom name Quarkus - DevServices - Postgresql High Product pom parent-artifactid quarkus-devservices-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
CVE-2015-0244 suppress
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-3166 suppress
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-10211 suppress
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. CWE-94 Improper Control of Generation of Code ('Code Injection'), NVD-CWE-noinfo
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2018-1115 suppress
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation. CWE-732 Incorrect Permission Assignment for Critical Resource
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-0241 suppress
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read, or (2) crafted timestamp formatting template, which triggers a buffer overflow. CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-0242 suppress
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a floating point number with a large precision, as demonstrated by using the to_char function. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-0243 suppress
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2019-10127 suppress
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:2.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:L/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2020-25695 suppress
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.8) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2016-5423 suppress
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types. CWE-476 NULL Pointer Dereference
CVSSv3:
Base Score: HIGH (8.3) Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - ISSUE_TRACKING,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - ISSUE_TRACKING,THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - PATCH,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2016-7048 suppress
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: HIGH (9.3) Vector: /AV:N/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions: (show all )
CVE-2020-25694 suppress
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while dropping security-relevant parameters, an opportunity for a man-in-the-middle attack, or the ability to observe clear-text transmissions, could exist. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. CWE-327 Use of a Broken or Risky Cryptographic Algorithm
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.8) Vector: /AV:N/AC:M/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-23214 suppress
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv3:
Base Score: HIGH (8.1) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:2.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.1) Vector: /AV:N/AC:H/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2019-10128 suppress
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (7.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.1) Vector: /AV:L/AC:M/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-3167 suppress
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack. CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2016-0768 suppress
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. CWE-284 Improper Access Control
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions:
CVE-2016-0773 suppress
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2017-7484 suppress
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access. CWE-285 Improper Authorization, CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (5.0) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2016-5424 suppress
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation. CWE-94 Improper Control of Generation of Code ('Code Injection')
CVSSv3:
Base Score: HIGH (7.1) Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:1.2/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:N/AC:H/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH,THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - PATCH,THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY secalert@redhat.com - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2017-14798 suppress
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. CWE-61 UNIX Symbolic Link (Symlink) Following, CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (6.9) Vector: /AV:L/AC:M/Au:N/C:C/I:C/A:C References:
Vulnerable Software & Versions:
CVE-2019-10210 suppress
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. CWE-522 Insufficiently Protected Credentials
CVSSv3:
Base Score: HIGH (7.0) Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:1.0/RC:R/MAV:A CVSSv2:
Base Score: LOW (1.9) Vector: /AV:L/AC:M/Au:N/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0061 suppress
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0063 suppress
Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0064 suppress
Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector. CWE-189 Numeric Errors
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-0065 suppress
Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, a different vulnerability than CVE-2014-0063. CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:S/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2015-5288 suppress
The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt. CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:P/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2007-2138 suppress
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner, related to "search_path settings." CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - BROKEN_LINK af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - PATCH,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - BROKEN_LINK cve@mitre.org - BROKEN_LINK cve@mitre.org - BROKEN_LINK cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - PATCH,VENDOR_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY cve@mitre.org - THIRD_PARTY_ADVISORY,VDB_ENTRY Vulnerable Software & Versions: (show all )
CVE-2014-0062 suppress
Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window. CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv2:
Base Score: MEDIUM (4.9) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0067 suppress
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2014-8161 suppress
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:P/I:N/A:N References:
af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - RELEASE_NOTES,VENDOR_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - THIRD_PARTY_ADVISORY af854a3a-2127-422b-91ae-364da2661108 - VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - RELEASE_NOTES,VENDOR_ADVISORY secalert@redhat.com - THIRD_PARTY_ADVISORY secalert@redhat.com - VENDOR_ADVISORY Vulnerable Software & Versions: (show all )
CVE-2015-3165 suppress
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence. NVD-CWE-Other
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2021-3393 suppress
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclose values from that column in error messages. An attacker could use this flaw to obtain information stored in a column they are allowed to write but not read. CWE-209 Generation of Error Message Containing Sensitive Information
CVSSv3:
Base Score: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:2.8/RC:R/MAV:A CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:P/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0060 suppress
PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command. CWE-264 Permissions, Privileges, and Access Controls
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2014-0066 suppress
The chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.0) Vector: /AV:N/AC:L/Au:S/C:N/I:N/A:P References:
Vulnerable Software & Versions: (show all )
CVE-2010-0733 suppress
Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size calculations. CWE-189 Numeric Errors
CVSSv2:
Base Score: LOW (3.5) Vector: /AV:N/AC:M/Au:S/C:N/I:N/A:P References:
af854a3a-2127-422b-91ae-364da2661108 - PATCH secalert@redhat.com - PATCH Vulnerable Software & Versions: (show all )
quarkus-devtools-base-codestarts-3.30.6.jar: gradle-wrapper.jarLicense:
Apache-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-devtools-base-codestarts/3.30.6/quarkus-devtools-base-codestarts-3.30.6.jar/codestarts/quarkus/tooling/gradle-wrapper/base/gradle/wrapper/gradle-wrapper.jar
MD5: 00fbfe071a292b2cf0bf1613035eef10
SHA1: 9b90d32f1e62028b17ed508b43a9f7056bc0356b
SHA256: 76805e32c009c0cf0dd5d206bddc9fb22ea42e84db904b764f3047de095493f3
Evidence Type Source Name Value Confidence Vendor file name gradle-wrapper High Vendor jar package name gradle Low Vendor Manifest enable-native-access ALL-UNNAMED Low Product file name gradle-wrapper High Product jar package name gradle Highest Product jar package name wrapper Highest Product Manifest enable-native-access ALL-UNNAMED Low Product Manifest Implementation-Title Gradle Wrapper High
quarkus-hibernate-orm-deployment-3.30.6.jar: hibernate-orm-entity-types.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-orm-deployment/3.30.6/quarkus-hibernate-orm-deployment-3.30.6.jar/dev-ui/hibernate-orm-entity-types.jsMD5: c674265941c7833d6ef596b56ef6a45dSHA1: 98a40b1c5a61662828f73cf4a2ad693ebf185a7eSHA256: eeea3cb65fc4547c2220108360ba03e112a9f4ec59e4eb7c4d4c6aa02fb5d256
Evidence Type Source Name Value Confidence
quarkus-hibernate-orm-deployment-3.30.6.jar: hibernate-orm-hql-console.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-orm-deployment/3.30.6/quarkus-hibernate-orm-deployment-3.30.6.jar/dev-ui/hibernate-orm-hql-console.jsMD5: 6adb88dae1cbdeb43b27f30d5c8d3442SHA1: 29b08f2fdc5796227a8f6df8baca41c50c14d158SHA256: 79ada30980cbda16a6dae82d77bb77575d5af08021622a50fcf00b91b4c9fdc6
Evidence Type Source Name Value Confidence
quarkus-hibernate-orm-deployment-3.30.6.jar: hibernate-orm-named-queries.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-orm-deployment/3.30.6/quarkus-hibernate-orm-deployment-3.30.6.jar/dev-ui/hibernate-orm-named-queries.jsMD5: 81385953d36c911ed7ac84f4e9d66b5eSHA1: 855037e167664eaa19955134e25562a099db6e7cSHA256: bf6320c27c0719524b6c41396b5848666b1f0b3fb6a3bf99130a1738f1175828
Evidence Type Source Name Value Confidence
quarkus-hibernate-orm-deployment-3.30.6.jar: hibernate-orm-persistence-units.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-orm-deployment/3.30.6/quarkus-hibernate-orm-deployment-3.30.6.jar/dev-ui/hibernate-orm-persistence-units.jsMD5: 7f03fd2f08e1026f76f1b5d78f014cc5SHA1: aeedc32b1236e09ce898f603dce60d97de85d35fSHA256: 9724a82876404afd57e6229ade31a4f2d26ce930e2d80723461160d048559980
Evidence Type Source Name Value Confidence
quarkus-hibernate-validator-spi-3.30.6.jarDescription:
Artifact that provides BuildItems specific to Hibernate Validator License:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-validator-spi/3.30.6/quarkus-hibernate-validator-spi-3.30.6.jar
MD5: b53d11964f0ec87c4eeeea51f06ef422
SHA1: 68c9320571c1f332e8bc220f1ba9d5982f493bf2
SHA256: 40387b8f4eefaac785bba6bae6b9b6e331b1c6a57fa847c37a6322206ef0d2da
Evidence Type Source Name Value Confidence Vendor file name quarkus-hibernate-validator-spi High Vendor jar package name hibernate Highest Vendor jar package name io Highest Vendor jar package name quarkus Highest Vendor jar package name validator Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid quarkus-hibernate-validator-spi Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus - Hibernate Validator - SPI High Vendor pom parent-artifactid quarkus-hibernate-validator-parent Low Product file name quarkus-hibernate-validator-spi High Product jar package name hibernate Highest Product jar package name io Highest Product jar package name quarkus Highest Product jar package name validator Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - Hibernate Validator - SPI High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - Hibernate Validator - SPI Medium Product pom artifactid quarkus-hibernate-validator-spi Highest Product pom groupid io.quarkus Highest Product pom name Quarkus - Hibernate Validator - SPI High Product pom parent-artifactid quarkus-hibernate-validator-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
Related Dependencies quarkus-hibernate-validator-deployment-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-hibernate-validator-deployment/3.30.6/quarkus-hibernate-validator-deployment-3.30.6.jar MD5: 7bab4824ebaad215cf8ceaaacf8437a8 SHA1: 40f0eefd486017cb9c2677e5b671edc651609d50 SHA256: 2f1bc5c3598ad65557b82ec064083fe495c307f86859f5f4a5077d7a3ab4372f pkg:maven/io.quarkus/quarkus-hibernate-validator-deployment@3.30.6 CVE-2025-15104 suppress
Nu Html Checker (validator.nu) contains a restriction bypass that allows remote attackers to make the server perform arbitrary HTTP/HTTPS requests to internal resources, including localhost services. While the validator implements hostname-based protections to block direct access to localhost and 127.0.0.1, these controls can be bypassed using DNS rebinding techniques or domains that resolve to loopback addresses.This issue affects The Nu Html Checker (vnu): latest (commit 23f090a11bab8d0d4e698f1ffc197a4fe226a9cd). CWE-918 Server-Side Request Forgery (SSRF)
CVSSv4:
Base Score: MEDIUM (6.9) Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2023-1932 suppress
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv3:
Base Score: MEDIUM (6.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:2.8/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
quarkus-junit4-mock-3.30.6.jarDescription:
Module with some empty JUnit4 classes to allow Testcontainers
to run without needing to include JUnit4 on the class path License:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-junit4-mock/3.30.6/quarkus-junit4-mock-3.30.6.jar
MD5: b6428a75121d27b4cfe14f6f9edaef2c
SHA1: 370ddbbc9c892c4f29b2f5a4b526f5a60c936530
SHA256: ad32fc7eda137ec070a0aee7937ae2758ef6978aef664346af2baf5a44ca9158
Evidence Type Source Name Value Confidence Vendor file name quarkus-junit4-mock High Vendor jar package name junit Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid quarkus-junit4-mock Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus - JUnit 4 Mock High Vendor pom parent-artifactid quarkus-core-parent Low Product file name quarkus-junit4-mock High Product jar package name junit Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - JUnit 4 Mock High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - JUnit 4 Mock Medium Product pom artifactid quarkus-junit4-mock Highest Product pom groupid io.quarkus Highest Product pom name Quarkus - JUnit 4 Mock High Product pom parent-artifactid quarkus-core-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
quarkus-liquibase-deployment-3.30.6.jar: qwc-liquibase-datasources.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-liquibase-deployment/3.30.6/quarkus-liquibase-deployment-3.30.6.jar/dev-ui/qwc-liquibase-datasources.jsMD5: 3754b824efb276eda9a4a068480f3c0bSHA1: dffce7d45456d475d3d56052e962be8cbc061124SHA256: 6f32ffd4167c445b2f6a710f91fdbe3f729aa90e1c406a47a70b9a769887ced2
Evidence Type Source Name Value Confidence
quarkus-maven-plugin-3.30.6.jar: jansi.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-maven-plugin/3.30.6/quarkus-maven-plugin-3.30.6.jar/org/fusesource/jansi/internal/native/Windows/x86/jansi.dllMD5: 0e396db1f1371448be55ad0b1542dc0bSHA1: 492bd09333e536e51d17caffcf6b7b56c4afcdbfSHA256: 1d6314da4b3a7a5e9dded6b0cc1b83f15f8f603897ae00cfe98ef171285620f3
Evidence Type Source Name Value Confidence Vendor file name jansi High Product file name jansi High
Related Dependencies jansi-2.4.0.jar: jansi.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/fusesource/jansi/jansi/2.4.0/jansi-2.4.0.jar/org/fusesource/jansi/internal/native/Windows/x86/jansi.dll MD5: 0e396db1f1371448be55ad0b1542dc0b SHA1: 492bd09333e536e51d17caffcf6b7b56c4afcdbf SHA256: 1d6314da4b3a7a5e9dded6b0cc1b83f15f8f603897ae00cfe98ef171285620f3 quarkus-maven-plugin-3.30.6.jar: jansi.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-maven-plugin/3.30.6/quarkus-maven-plugin-3.30.6.jar/org/fusesource/jansi/internal/native/Windows/x86_64/jansi.dllMD5: a7a3efd305c910cd0850f24f17acec86SHA1: 6303f154edeaa18a7aeb3997e9ef3634e5ee1171SHA256: d23fc9293b68781d43314403048d6dc655fa4620b6b4db3dcd345c52c332a2f4
Evidence Type Source Name Value Confidence Vendor file name jansi High Product file name jansi High
Related Dependencies jansi-2.4.0.jar: jansi.dllFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/fusesource/jansi/jansi/2.4.0/jansi-2.4.0.jar/org/fusesource/jansi/internal/native/Windows/x86_64/jansi.dll MD5: a7a3efd305c910cd0850f24f17acec86 SHA1: 6303f154edeaa18a7aeb3997e9ef3634e5ee1171 SHA256: d23fc9293b68781d43314403048d6dc655fa4620b6b4db3dcd345c52c332a2f4 quarkus-messaging-deployment-3.30.6.jar: qwc-smallrye-reactive-messaging-channels.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-messaging-deployment/3.30.6/quarkus-messaging-deployment-3.30.6.jar/dev-ui/qwc-smallrye-reactive-messaging-channels.jsMD5: e338726277b448c2a7ac2dc63eed6266SHA1: 2bf15556ef5f10207609e92d5a21352ccd4713bbSHA256: 6780b8b0013e2cc55d309751cf56378374578044e1a2b64045f4cde896934a75
Evidence Type Source Name Value Confidence
quarkus-messaging-rabbitmq-deployment-3.30.6.jar: qwc-rabbitmq-card.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-messaging-rabbitmq-deployment/3.30.6/quarkus-messaging-rabbitmq-deployment-3.30.6.jar/dev-ui/qwc-rabbitmq-card.jsMD5: fba02c564e9c3c0cd5e61dc55ea49ef6SHA1: a1d9c645ff93333ad901322955825a4f2b3f8323SHA256: 07832c137d3a96d1618f94e2075b571ca21659d129158d73710ce269e8001651
Evidence Type Source Name Value Confidence
quarkus-oidc-deployment-3.30.6.jar: qwc-oidc-provider.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-oidc-deployment/3.30.6/quarkus-oidc-deployment-3.30.6.jar/dev-ui/qwc-oidc-provider.jsMD5: 7099f8f0577bbf8c136e2f47dcf0f6e1SHA1: dfa4c7ab0677faa55d9660ad11d95f5dba1a1493SHA256: 12917bca94abf97e5bf3e0972e3ccdd3101da393de31542fee11b524b1f08acc
Evidence Type Source Name Value Confidence
quarkus-project-core-extension-codestarts-3.30.6.jar: gradle-wrapper.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-project-core-extension-codestarts/3.30.6/quarkus-project-core-extension-codestarts-3.30.6.jar/codestarts/quarkus/tooling/gradle-wrapper/base/gradle/wrapper/gradle-wrapper.jarMD5: 365e8981fbb8626c5235f955b3b92f0fSHA1: 44f8eda0fb915aa0ab56996d808baafa6d3f107aSHA256: ed2c26eba7cfb93cc2b7785d05e534f07b5b48b5e7fc941921cd098628abca58
Evidence Type Source Name Value Confidence Vendor file name gradle-wrapper High Vendor jar package name cli Low Vendor jar package name gradle Low Product file name gradle-wrapper High Product jar package name cli Low Product jar package name gradle Highest Product jar package name wrapper Highest Product Manifest Implementation-Title Gradle Wrapper High
quarkus-rest-deployment-3.30.6.jar: qwc-resteasy-reactive-card.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-rest-deployment/3.30.6/quarkus-rest-deployment-3.30.6.jar/dev-ui/qwc-resteasy-reactive-card.jsMD5: be27014ecb3622cb42d1daae868c1948SHA1: f0d1746bb205c24ade7664035aa4b8ec8958e883SHA256: ee7f2f1d99e5b6b604c056bd28900ae02a8e948035dc97c5196f2ecd81d38e45
Evidence Type Source Name Value Confidence
quarkus-rest-deployment-3.30.6.jar: qwc-resteasy-reactive-endpoint-scores.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-rest-deployment/3.30.6/quarkus-rest-deployment-3.30.6.jar/dev-ui/qwc-resteasy-reactive-endpoint-scores.jsMD5: 171671fe81691f337249d38c506bb199SHA1: 68d590b02e11b7f1073d7bc18ceb208c2da4bf91SHA256: 9df44d006f19b996682afba09cb59e74941e78a62aef5e950f0fdd998db1ad09
Evidence Type Source Name Value Confidence
quarkus-rest-deployment-3.30.6.jar: qwc-resteasy-reactive-endpoints.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-rest-deployment/3.30.6/quarkus-rest-deployment-3.30.6.jar/dev-ui/qwc-resteasy-reactive-endpoints.jsMD5: 9b53d1d657b4b5eecc50bcdbfe36b0a8SHA1: 811d633f6a27ca106f7b7a7fb988ae6b28a38ab6SHA256: 977fcb123eb2023136565d5466b0cd01ed8d8e912e31ddc52ad9494e6bd029f3
Evidence Type Source Name Value Confidence
quarkus-rest-deployment-3.30.6.jar: qwc-resteasy-reactive-exception-mappers.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-rest-deployment/3.30.6/quarkus-rest-deployment-3.30.6.jar/dev-ui/qwc-resteasy-reactive-exception-mappers.jsMD5: 6c8215b3931c2ec3e35098e7e6b1e1beSHA1: 8c22904f74f1c0655ed0157ec9c3e917205f6711SHA256: 8925c6a983513819194c532bc07aed722dc1946f178047c7e07f2c5ce603da71
Evidence Type Source Name Value Confidence
quarkus-rest-deployment-3.30.6.jar: qwc-resteasy-reactive-parameter-converter-providers.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-rest-deployment/3.30.6/quarkus-rest-deployment-3.30.6.jar/dev-ui/qwc-resteasy-reactive-parameter-converter-providers.jsMD5: 85525a2623ef16c4d0cfccc94bdfdaddSHA1: fce705af9afc128663999e755c9acc4bfb98d56dSHA256: d04e54fd74661f35da230eb166c76c9637a20d902a74378bd5f5c183d0901698
Evidence Type Source Name Value Confidence
quarkus-rest-server-spi-deployment-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-rest-server-spi-deployment/3.30.6/quarkus-rest-server-spi-deployment-3.30.6.jar
MD5: 735631729b4bd3e7fccd86c7a2690717
SHA1: 3b00c1f6bb795d6119880fd2df45461d9c24c603
SHA256: ea48e3af7d33110f279258ca51417f953155f7b2d2b3bc770f166239852b0846
Evidence Type Source Name Value Confidence Vendor file name quarkus-rest-server-spi-deployment High Vendor jar package name io Highest Vendor jar package name quarkus Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid quarkus-rest-server-spi-deployment Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus - REST - Server - SPI - Deployment High Vendor pom parent-artifactid quarkus-rest-parent Low Product file name quarkus-rest-server-spi-deployment High Product jar package name io Highest Product jar package name quarkus Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Quarkus - REST - Server - SPI - Deployment High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Quarkus - REST - Server - SPI - Deployment Medium Product pom artifactid quarkus-rest-server-spi-deployment Highest Product pom groupid io.quarkus Highest Product pom name Quarkus - REST - Server - SPI - Deployment High Product pom parent-artifactid quarkus-rest-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
Related Dependencies quarkus-run.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/quarkus-run.jarMD5: cd8b534ef7528656a9fe51deb0150604SHA1: 30e1deb64d2dc1636b6ebac1c9c7ff069034f4dbSHA256: 283f4770b2f9d5c8cac08d8827145eda1372204ba87dcd86d84806a95f100066
Evidence Type Source Name Value Confidence Vendor file name quarkus-run High Vendor Manifest add-opens java.base/java.lang Low Product file name quarkus-run High Product Manifest add-opens java.base/java.lang Low Product Manifest Implementation-Title analyzer High Version Manifest Implementation-Version 3.0.7 High
CVE-2023-6267 suppress
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security. CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2023-5720 suppress
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application. CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable, NVD-CWE-noinfo
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
quarkus-run.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/quarkus-run.jarMD5: 4e2e79b68507f84660df774bd54bebc2SHA1: 5aa87b2bf929b975b4d25e69b3a47172ecf8b9d9SHA256: f98b0f96514c55422e5814defdf939ef39fae1930f6b0504c157a67a0c2de3ec
Evidence Type Source Name Value Confidence Vendor file name quarkus-run High Vendor Manifest add-opens java.base/java.lang Low Product file name quarkus-run High Product Manifest add-opens java.base/java.lang Low Product Manifest Implementation-Title webapp High Version Manifest Implementation-Version 3.0.7 High
CVE-2023-6267 suppress
A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with configuration based security. CWE-755 Improper Handling of Exceptional Conditions
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2023-6394 suppress
A flaw was found in Quarkus. This issue occurs when receiving a request over websocket with no role-based permission specified on the GraphQL operation, Quarkus processes the request without authentication despite the endpoint being secured. This can allow an attacker to access information and functionality outside of normal granted API permissions. CWE-862 Missing Authorization
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
CVE-2024-12225 suppress
A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes default REST endpoints for registering and logging users in while allowing developers to provide custom REST endpoints. When developers provide custom REST endpoints, the default endpoints remain accessible, potentially allowing attackers to obtain a login cookie that has no corresponding user in the Quarkus application or, depending on how the application is written, could correspond to an existing user that has no relation with the current attacker, allowing anyone to log in as an existing user by just knowing that user's user name. CWE-288 Authentication Bypass Using an Alternate Path or Channel
CVSSv3:
Base Score: CRITICAL (9.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2023-5720 suppress
A flaw was found in Quarkus, where it does not properly sanitize artifacts created using the Gradle plugin, allowing certain build system information to remain. This flaw allows an attacker to access potentially sensitive information from the build system within the application. CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable, NVD-CWE-noinfo
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
quarkus-scheduler-deployment-3.30.6.jar: qwc-scheduler-cron-builder.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-scheduler-deployment/3.30.6/quarkus-scheduler-deployment-3.30.6.jar/dev-ui/qwc-scheduler-cron-builder.jsMD5: 8f320e5fd8f351fbec644d6d2a6333f6SHA1: 0ba5bc860d85a5bebad6b8df7131f12e3a7ac951SHA256: 97fa3551f1a4896750cebaeb83d4821481c66dbb75e10d6c05a6e4a2e2a24ea4
Evidence Type Source Name Value Confidence
quarkus-scheduler-deployment-3.30.6.jar: qwc-scheduler-log.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-scheduler-deployment/3.30.6/quarkus-scheduler-deployment-3.30.6.jar/dev-ui/qwc-scheduler-log.jsMD5: 819efae663c24becafd7a422b5bec138SHA1: cbe71cba92a5b7535b75683c846d13760d814fafSHA256: 911527b1fb8128ce7cc40dba4d2df46257e191afa3d14411b6e0b3d028bde53e
Evidence Type Source Name Value Confidence
quarkus-scheduler-deployment-3.30.6.jar: qwc-scheduler-scheduled-methods.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-scheduler-deployment/3.30.6/quarkus-scheduler-deployment-3.30.6.jar/dev-ui/qwc-scheduler-scheduled-methods.jsMD5: f363398be0a2dc04d3e7c7c7d7dcb188SHA1: 7265596765caddd3096a864fe32b581a67107eafSHA256: 78af2e055453419236c261627a7f1679c5a6cb90c41a8590e943b33c9b84c118
Evidence Type Source Name Value Confidence
quarkus-smallrye-openapi-deployment-3.30.6.jar: qwc-openapi-generate-client.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-smallrye-openapi-deployment/3.30.6/quarkus-smallrye-openapi-deployment-3.30.6.jar/dev-ui/qwc-openapi-generate-client.jsMD5: 4b0993bb23e67be49ee65fdd13739539SHA1: 1472b3eabfa84a7ef3713c17828f20c142f6d182SHA256: 2cfb3722cd98badb52742561f49027976f2f7a019b34ad9b75b5aa753bac4f32
Evidence Type Source Name Value Confidence
quarkus-spring-data-commons-api-3.5.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/quarkus-spring-data-commons-api/3.5/quarkus-spring-data-commons-api-3.5.jarMD5: 7b54fabbc37472f92053d03bb7908023SHA1: f1e658fbf96440c30f8a7ed2c954b52e768a8e48SHA256: 21352eabee9afa085e744addd4b3bb51a7acca29f788be5826b7264543d99bb7
Evidence Type Source Name Value Confidence Vendor file name quarkus-spring-data-commons-api High Vendor jar package name data Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid quarkus-spring-data-commons-api Low Vendor pom groupid io.quarkus Highest Vendor pom name Quarkus Spring Data Commons API High Vendor pom parent-artifactid quarkus-spring-data-api Low Product file name quarkus-spring-data-commons-api High Product jar package name data Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid quarkus-spring-data-commons-api Highest Product pom groupid io.quarkus Highest Product pom name Quarkus Spring Data Commons API High Product pom parent-artifactid quarkus-spring-data-api Medium Version file version 3.5 High Version pom version 3.5 Highest
Related Dependencies io.quarkus.quarkus-spring-data-commons-api-3.5.jar (shaded: io.quarkus:quarkus-spring-data-commons-api:3.5)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.quarkus.quarkus-spring-data-commons-api-3.5.jar/META-INF/maven/io.quarkus/quarkus-spring-data-commons-api/pom.xml MD5: abeb1856c334d3632f3fe4c220823dd7 SHA1: caad0a44256e9db846b7286fea05bbec8a44165f SHA256: bdd470534687fe68d1c397b45b28ba7da19aa2eb65b355f209918b22a6066d5b pkg:maven/io.quarkus/quarkus-spring-data-commons-api@3.5 pkg:maven/io.quarkus/quarkus-spring-data-commons-api@3.5 (Confidence :High) qute-core-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/qute/qute-core/3.30.6/qute-core-3.30.6.jar
MD5: a92b83b5973b51cf7b5ba3fb5f0a5a6f
SHA1: 1efb67a8de00e23d9bc1f1faf8d96a1d28310988
SHA256: 20c774b2f6d7ecbff0fea85cfd7c01cd58d4bdd4a21f2bd12c6ab450e0e514c9
Evidence Type Source Name Value Confidence Vendor file name qute-core High Vendor jar package name io Highest Vendor jar package name quarkus Highest Vendor jar package name qute Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid qute-core Low Vendor pom groupid io.quarkus.qute Highest Vendor pom name Qute - Core High Vendor pom parent-artifactid qute-parent Low Product file name qute-core High Product jar package name io Highest Product jar package name quarkus Highest Product jar package name qute Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title Qute - Core High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Qute - Core Medium Product pom artifactid qute-core Highest Product pom groupid io.quarkus.qute Highest Product pom name Qute - Core High Product pom parent-artifactid qute-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
rabbitmq-1.21.3.jarDescription:
Isolated container management for Java code testing License:
MIT: http://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/testcontainers/rabbitmq/1.21.3/rabbitmq-1.21.3.jar
MD5: b41c1072cd2fb496934c725e2ec1c40c
SHA1: 5c30d10d1ac5aa662d5c1661182de4b2e53f6938
SHA256: 908038097e5eab14a01e918bcbbcf2c5727eff127f5dcaeb815b744b179524f7
Evidence Type Source Name Value Confidence Vendor file name rabbitmq High Vendor jar package name containers Low Vendor jar package name testcontainers Highest Vendor jar package name testcontainers Low Vendor pom artifactid rabbitmq Low Vendor pom developer email rich.north@gmail.com Low Vendor pom developer id rnorth Medium Vendor pom developer name Richard North Medium Vendor pom groupid org.testcontainers Highest Vendor pom name Testcontainers :: RabbitMQ High Vendor pom url https://java.testcontainers.org Highest Product file name rabbitmq High Product jar package name containers Low Product jar package name testcontainers Highest Product pom artifactid rabbitmq Highest Product pom developer email rich.north@gmail.com Low Product pom developer id rnorth Low Product pom developer name Richard North Low Product pom groupid org.testcontainers Highest Product pom name Testcontainers :: RabbitMQ High Product pom url https://java.testcontainers.org Medium Version file version 1.21.3 High Version pom version 1.21.3 Highest
pkg:maven/org.testcontainers/rabbitmq@1.21.3 (Confidence :High) range.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/range/range.module.jsMD5: 06a963f69dc19e1df8e41d4e1ce9a1bbSHA1: c1abb82bcd6d2d7c12819ed6f6799ef641e2135dSHA256: 66c9b81aba6c09a4f1c05241cf25a60101c64b4c3960165717ebf79d617441d7
Evidence Type Source Name Value Confidence
range.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/range/range.module.min.jsMD5: 31d652e61402f83f15cee6d7a7e1d09dSHA1: afc730d5f0bb36d8063d01d5e2ff109c53765ffbSHA256: 39b89f5b9e859db8a52d5a2bccfa40b5082cb0bd35e966bbb2c8dc3a4edffff7
Evidence Type Source Name Value Confidence
range.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/range/range.nomodule.jsMD5: acb9f1bf80b671c54041af1e89483255SHA1: e07821e841c6bafefbcc79efaf24fdefe8717916SHA256: a5249b4cef59476c962aa7ac119219653f22adf646d0e3bd8bddae227d160e65
Evidence Type Source Name Value Confidence
range.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/range/range.nomodule.min.jsMD5: 211028515b1929749e3551728f35357dSHA1: dad11393a14abf7bd7c41316625b9ca9d454d412SHA256: a835e5c38ae33a5dc329cad03b0f13b8d0f45ab1f662e674f45f82a0f15d673a
Evidence Type Source Name Value Confidence
readline-2.6.jar (shaded: org.aesh:terminal-api:2.6)Description:
Æsh (Another Extendable SHell) Terminal API License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/aesh/readline/2.6/readline-2.6.jar/META-INF/maven/org.aesh/terminal-api/pom.xml
MD5: ae31cd7c7a4467d7e7abaa952ffe745b
SHA1: 441dcb2fd4ce3735cdab0c864bbc906592eb9fdb
SHA256: a4a1b3fd10568ec0f64574130d7fc105c67a4f7eb59eb2e53f0d91d3b9871a4e
Evidence Type Source Name Value Confidence Vendor pom artifactid terminal-api Low Vendor pom developer email jdenise@redhat.com Low Vendor pom developer email spederse@redhat.com Low Vendor pom developer name Jean-Francois Denise Medium Vendor pom developer name Ståle Pedersen Medium Vendor pom developer org Red Hat Medium Vendor pom developer org URL http://www.redhat.com Medium Vendor pom groupid org.aesh Highest Vendor pom name Æsh Terminal API High Vendor pom parent-artifactid readline-all Low Product pom artifactid terminal-api Highest Product pom developer email jdenise@redhat.com Low Product pom developer email spederse@redhat.com Low Product pom developer name Jean-Francois Denise Low Product pom developer name Ståle Pedersen Low Product pom developer org Red Hat Low Product pom developer org URL http://www.redhat.com Low Product pom groupid org.aesh Highest Product pom name Æsh Terminal API High Product pom parent-artifactid readline-all Medium Version pom version 2.6 Highest
pkg:maven/org.aesh/terminal-api@2.6 (Confidence :High) readline-2.6.jarDescription:
Æsh (Another Extendable SHell) Readline API License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/aesh/readline/2.6/readline-2.6.jar
MD5: 8990317539a9100bad19fc89f1c7c44e
SHA1: c34fc8145017c4dd5967dc4053d5b100631e6f3c
SHA256: 601eb6cbc77a8b07b8014ba89cf3fbdda20fcdb96493e57466d3753fa26accde
Evidence Type Source Name Value Confidence Vendor file name readline High Vendor hint analyzer vendor redhat Highest Vendor jar package name aesh Highest Vendor jar package name readline Highest Vendor Manifest automatic-module-name org.aesh.readline Medium Vendor Manifest implementation-url http://www.jboss.org/readline-all/readline Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.aesh Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid readline Low Vendor pom developer email jdenise@redhat.com Low Vendor pom developer email spederse@redhat.com Low Vendor pom developer name Jean-Francois Denise Medium Vendor pom developer name Ståle Pedersen Medium Vendor pom developer org Red Hat Medium Vendor pom developer org URL http://www.redhat.com Medium Vendor pom groupid org.aesh Highest Vendor pom name Æsh Readline High Vendor pom parent-artifactid readline-all Low Product file name readline High Product jar package name aesh Highest Product jar package name readline Highest Product Manifest automatic-module-name org.aesh.readline Medium Product Manifest Implementation-Title Æsh Readline High Product Manifest implementation-url http://www.jboss.org/readline-all/readline Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Æsh Readline Medium Product pom artifactid readline Highest Product pom developer email jdenise@redhat.com Low Product pom developer email spederse@redhat.com Low Product pom developer name Jean-Francois Denise Low Product pom developer name Ståle Pedersen Low Product pom developer org Red Hat Low Product pom developer org URL http://www.redhat.com Low Product pom groupid org.aesh Highest Product pom name Æsh Readline High Product pom parent-artifactid readline-all Medium Version file version 2.6 High Version Manifest Implementation-Version 2.6 High Version pom version 2.6 Highest
pkg:maven/org.aesh/readline@2.6 (Confidence :High) rest-assured-5.5.6.jarDescription:
Java DSL for easy testing of REST services License:
https://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/rest-assured/rest-assured/5.5.6/rest-assured-5.5.6.jar
MD5: d2e14d4382e9c6b8861819f609499a68
SHA1: a1253f89315e8141ee9b8432b4f3b7ba8a83f98a
SHA256: 52a7014328070bbeb47457b4c1f79f63812191d37a28d4d7f5ee43fab724e5d1
Evidence Type Source Name Value Confidence Vendor file name rest-assured High Vendor jar package name io Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname io.rest-assured Medium Vendor pom artifactid rest-assured Low Vendor pom groupid io.rest-assured Highest Vendor pom name REST Assured High Vendor pom parent-artifactid rest-assured-parent Low Vendor pom url https://rest-assured.io/ Highest Product file name rest-assured High Product jar package name io Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name REST Assured Medium Product Manifest bundle-symbolicname io.rest-assured Medium Product pom artifactid rest-assured Highest Product pom groupid io.rest-assured Highest Product pom name REST Assured High Product pom parent-artifactid rest-assured-parent Medium Product pom url https://rest-assured.io/ Medium Version file version 5.5.6 High Version Manifest Bundle-Version 5.5.6 High Version pom version 5.5.6 Highest
pkg:maven/io.rest-assured/rest-assured@5.5.6 (Confidence :High) rest-assured-common-5.5.6.jarDescription:
Java DSL for easy testing of REST services License:
https://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/rest-assured/rest-assured-common/5.5.6/rest-assured-common-5.5.6.jar
MD5: 15e5f530e9af2278210900181a602921
SHA1: 4f83b9a3e71e8f0ffeeeff60f91825e8d70ff260
SHA256: bfd0e0fd61e86be103772a03b045462439ea38e9ac5693ceefbe90c708902339
Evidence Type Source Name Value Confidence Vendor file name rest-assured-common High Vendor jar package name common Highest Vendor jar package name io Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname io.rest-assured.common Medium Vendor pom artifactid rest-assured-common Low Vendor pom groupid io.rest-assured Highest Vendor pom name rest-assured-common High Vendor pom parent-artifactid rest-assured-parent Low Vendor pom url https://rest-assured.io/ Highest Product file name rest-assured-common High Product jar package name common Highest Product jar package name io Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name rest-assured-common Medium Product Manifest bundle-symbolicname io.rest-assured.common Medium Product pom artifactid rest-assured-common Highest Product pom groupid io.rest-assured Highest Product pom name rest-assured-common High Product pom parent-artifactid rest-assured-parent Medium Product pom url https://rest-assured.io/ Medium Version file version 5.5.6 High Version Manifest Bundle-Version 5.5.6 High Version pom version 5.5.6 Highest
pkg:maven/io.rest-assured/rest-assured-common@5.5.6 (Confidence :High) resteasy-reactive-3.30.6.jarLicense:
Apache License 2.0 File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive/3.30.6/resteasy-reactive-3.30.6.jar
MD5: b0217afb288013ee87189f629dbf6344
SHA1: 48a7823bd6dde32e74284f4b23ce12e40c8991f5
SHA256: 3ba5933379500e491b75c8340dc98502505ce13ea2c8f7576bfe4978e66b5a84
Evidence Type Source Name Value Confidence Vendor file name resteasy-reactive High Vendor jar package name reactive Highest Vendor jar package name resteasy Highest Vendor jar package name server Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://github.com/quarkusio/quarkus Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor pom artifactid resteasy-reactive Low Vendor pom groupid io.quarkus.resteasy.reactive Highest Vendor pom name RESTEasy Reactive - Runtime High Vendor pom parent-artifactid resteasy-reactive-server-parent Low Product file name resteasy-reactive High Product jar package name reactive Highest Product jar package name resteasy Highest Product jar package name server Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title RESTEasy Reactive - Runtime High Product Manifest implementation-url https://github.com/quarkusio/quarkus Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title RESTEasy Reactive - Runtime Medium Product pom artifactid resteasy-reactive Highest Product pom groupid io.quarkus.resteasy.reactive Highest Product pom name RESTEasy Reactive - Runtime High Product pom parent-artifactid resteasy-reactive-server-parent Medium Version file version 3.30.6 High Version Manifest Implementation-Version 3.30.6 High Version pom version 3.30.6 Highest
Related Dependencies resteasy-reactive-common-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive-common/3.30.6/resteasy-reactive-common-3.30.6.jar MD5: 2534cafd2be3b8d86a7cc640655eec18 SHA1: 722e7485f6fc92b8ad4bfdd69dbbbad6842268a2 SHA256: 2a032fabb82f849ffbe079b52e67e3a5fe2561fcf36d7dad7e23eda2932ca2e5 pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive-common@3.30.6 resteasy-reactive-common-processor-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive-common-processor/3.30.6/resteasy-reactive-common-processor-3.30.6.jar MD5: f22ad0e5ae8df044691db863eeb52537 SHA1: 755da6b9b2167e678f6456dc128c7cc06d3b18f0 SHA256: 9f8a30f4af92888f353f8954557778c0022f81f8f4bd9aaa6afee10d2b084455 pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive-common-processor@3.30.6 resteasy-reactive-common-types-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive-common-types/3.30.6/resteasy-reactive-common-types-3.30.6.jar MD5: 69937378c91482872795d58dfbb0e2e0 SHA1: 42a22a36b83d85e4d08fe4c157a45c35fdf2af5e SHA256: 783f439e8d69da44c5f25f24d23d331915349203fc5108736b362c63d298d5a9 pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive-common-types@3.30.6 resteasy-reactive-jackson-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive-jackson/3.30.6/resteasy-reactive-jackson-3.30.6.jar MD5: fb672d8e9243dc4aac7904c4ccccfb6c SHA1: 5998d3a3b4966242726bb02d9b9ca891b24287aa SHA256: a47c77b77aa5e00d67221c2fd700aa18bba3c18738a11168178fefbbcbfa1d65 pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive-jackson@3.30.6 resteasy-reactive-processor-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive-processor/3.30.6/resteasy-reactive-processor-3.30.6.jar MD5: dab8b779e929637745543dbf266e441a SHA1: a677c8d80fea81aa46ce419d823a269ecac7dbec SHA256: a46a0654b1d9b8e124362b30d8eb57636da521ecfa6500beed07c708ff34d429 pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive-processor@3.30.6 resteasy-reactive-vertx-3.30.6.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/quarkus/resteasy/reactive/resteasy-reactive-vertx/3.30.6/resteasy-reactive-vertx-3.30.6.jar MD5: d5c1e1295bc3d193ec5d3483680ba9a9 SHA1: 6a9db75047a29f7a3078e8b9dc7c981366a915de SHA256: 69c3d2450fb3fdf88ff6926b8e73f84f8d1e1ed79d12aa9febba0fc5b757506e pkg:maven/io.quarkus.resteasy.reactive/resteasy-reactive-vertx@3.30.6 scheme.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/scheme/scheme.module.jsMD5: 3792021f092fd56512ab5e0c9666783bSHA1: 266c2da21106d88b462e1009cceb64dd7b78ba62SHA256: ccd756f0b4322fc323e623e4ae31dfda0bc8438f8cd707c97473e6d36d51bd72
Evidence Type Source Name Value Confidence
scheme.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/scheme/scheme.module.min.jsMD5: 152163209e711018e41e9b3b128fc427SHA1: ce8fce321012271c2942444dd0914499dc8d1d8eSHA256: 831a7ebfc8f1d5d36d835215fb1e9043996e9f71d3b9664dabfd98d94d4d491b
Evidence Type Source Name Value Confidence
segmented.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/segmented/segmented.module.jsMD5: 6a47dff31322aee98a6d8e07b6baa0f4SHA1: 952765ecf9cfce81bad0edd8b546fff9a8c0864eSHA256: c8a1c9514a409a821a81a73ae0cba4a8c997db966c2dba55daff3ccb42f518ec
Evidence Type Source Name Value Confidence
segmented.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/segmented/segmented.module.min.jsMD5: a515a7cd2f9dc9c23282a7bd13258f47SHA1: d0ecff5a6eb0bc809413fd790af968d02288fbf8SHA256: ea2a4c26c76c959d1768ff4bc519d0a871572e1563fd3e6604e73b65693261f6
Evidence Type Source Name Value Confidence
segmented.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/segmented/segmented.nomodule.jsMD5: e03df7eb9b82eadd2de0fe30a5d18e55SHA1: 8d972c5f8e12b7b5a076974d41b903a31f63c48bSHA256: f2f59846707d63029dc0507320e4896aff770cbb78945267794ed989e566f437
Evidence Type Source Name Value Confidence
segmented.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/segmented/segmented.nomodule.min.jsMD5: d0166d2fcfabc290980e5ceecca47563SHA1: 0e316f31de585adec55a8a414f764ccf98cadbe7SHA256: 6752e6e11f19c8420520fe2a2ccb735fc1f6fd8330f1f28b5b38a556a6d46dcb
Evidence Type Source Name Value Confidence
selenium-support-4.35.0.jarDescription:
Selenium automates browsers. That's it! What you do with that power is entirely up to you. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-support/4.35.0/selenium-support-4.35.0.jar
MD5: 0f7c599cd1d00263935e604610820bb4
SHA1: ea8078e129aabd5b10cb4588fe4a5c8a3f22f959
SHA256: 5bc0a5732f901f7bb97fc94266a546d537297e403ca12234c1e2cdfd3d0327e7
Evidence Type Source Name Value Confidence Vendor file name selenium-support High Vendor jar package name openqa Low Vendor jar package name selenium Highest Vendor jar package name selenium Low Vendor jar package name support Highest Vendor jar package name support Low Vendor pom artifactid selenium-support Low Vendor pom developer id barancev Medium Vendor pom developer id diemol Medium Vendor pom developer id james.h.evans.jr Medium Vendor pom developer id simon.m.stewart Medium Vendor pom developer id theautomatedtester Medium Vendor pom developer id titusfortner Medium Vendor pom developer name Alexei Barantsev Medium Vendor pom developer name David Burns Medium Vendor pom developer name Diego Molina Medium Vendor pom developer name Jim Evans Medium Vendor pom developer name Simon Stewart Medium Vendor pom developer name Titus Fortner Medium Vendor pom groupid org.seleniumhq.selenium Highest Vendor pom name org.seleniumhq.selenium:selenium-support High Vendor pom url https://selenium.dev/ Highest Product file name selenium-support High Product jar package name selenium Highest Product jar package name selenium Low Product jar package name support Highest Product jar package name support Low Product jar package name ui Low Product pom artifactid selenium-support Highest Product pom developer id barancev Low Product pom developer id diemol Low Product pom developer id james.h.evans.jr Low Product pom developer id simon.m.stewart Low Product pom developer id theautomatedtester Low Product pom developer id titusfortner Low Product pom developer name Alexei Barantsev Low Product pom developer name David Burns Low Product pom developer name Diego Molina Low Product pom developer name Jim Evans Low Product pom developer name Simon Stewart Low Product pom developer name Titus Fortner Low Product pom groupid org.seleniumhq.selenium Highest Product pom name org.seleniumhq.selenium:selenium-support High Product pom url https://selenium.dev/ Medium Version file version 4.35.0 High Version pom version 4.35.0 Highest
Related Dependencies selenium-remote-driver-4.35.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/seleniumhq/selenium/selenium-remote-driver/4.35.0/selenium-remote-driver-4.35.0.jar MD5: 034831196877e016f68a19f4e5f5ca38 SHA1: 92295302036f9227bfb5cc32adbc1c0eb7fb9c09 SHA256: db910d0e24330e386cc153d4192409c80ec152c47ca7d05e5eb90261d8a986ea pkg:maven/org.seleniumhq.selenium/selenium-remote-driver@4.35.0 sidemenu.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/sidemenu/sidemenu.module.jsMD5: c7b6abc1915c39bbc77b6efe1fdc8dd3SHA1: 4018f2e8c12a39f3a49649c94ce5fd2926f936c8SHA256: 96ab2e8ef4d15030ea33bf19c478bddb0a2a5e4c15561dbd77a180577cfa6b34
Evidence Type Source Name Value Confidence
sidemenu.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/sidemenu/sidemenu.module.min.jsMD5: 0576f86bb1d6f3351ef66b25b397c74fSHA1: 85afb3a0083de2abe7bea5d05a90545d6e5e5f20SHA256: d45091d75258bfb89e9f3379dc16fecd5445d98e0aa5f99fd0f2dbebd11aec3a
Evidence Type Source Name Value Confidence
sidemenu.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/sidemenu/sidemenu.nomodule.jsMD5: c32fb2fda483ccd204a6a83a5d1b428cSHA1: 2e08fc2fa05e44897b53054bbc0206083bf3289aSHA256: 758e13e257cd4ded69c00c4f2fd04f34fdcb9588737b08708c445ffc5d845d41
Evidence Type Source Name Value Confidence
sidemenu.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/sidemenu/sidemenu.nomodule.min.jsMD5: 572d7b88a1eea76f52056a62d6b2792bSHA1: 8eb0d76a69e3b78e24eeb0bffea6f14960d61225SHA256: 912d25138e9523b749f0ac6e6d382c8435ccf0d7453691092184cde2af64fbd4
Evidence Type Source Name Value Confidence
slf4j-api-1.7.36.jarDescription:
The slf4j API File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jarMD5: 872da51f5de7f3923da4de871d57fd85SHA1: 6c62681a2f655b49963a5983b8b0950a6120ae14SHA256: d3ef575e3e4979678dc01bf1dcce51021493b4d11fb7f1be8ad982877c16a1c0
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor jar package name slf4j Highest Vendor Manifest automatic-module-name org.slf4j Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor pom artifactid slf4j-api Low Vendor pom groupid org.slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name slf4j-api High Product jar package name slf4j Highest Product Manifest automatic-module-name org.slf4j Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name slf4j-api Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product pom artifactid slf4j-api Highest Product pom groupid org.slf4j Highest Product pom name SLF4J API Module High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 1.7.36 High Version Manifest Bundle-Version 1.7.36 High Version Manifest Implementation-Version 1.7.36 High Version pom version 1.7.36 Highest
pkg:maven/org.slf4j/slf4j-api@1.7.36 (Confidence :High) smallrye-beanbag-1.5.3.jarDescription:
A trivial programmatic bean container implementation File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/beanbag/smallrye-beanbag/1.5.3/smallrye-beanbag-1.5.3.jarMD5: 96bb0e7728b61a0a2076a5af7f3a92c1SHA1: e879a4cd6eaeb8ca82241740bdf104d343834b26SHA256: a98a1df267cdef1b7f305fbeacfa7d51e423fe2d02596314877196f5ce29a578
Evidence Type Source Name Value Confidence Vendor file name smallrye-beanbag High Vendor jar package name bean Highest Vendor jar package name beanbag Highest Vendor jar package name io Highest Vendor jar package name smallrye Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor pom artifactid smallrye-beanbag Low Vendor pom groupid io.smallrye.beanbag Highest Vendor pom name SmallRye BeanBag High Vendor pom parent-artifactid smallrye-beanbag-parent Low Product file name smallrye-beanbag High Product jar package name bean Highest Product jar package name beanbag Highest Product jar package name io Highest Product jar package name smallrye Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye BeanBag High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye BeanBag Medium Product pom artifactid smallrye-beanbag Highest Product pom groupid io.smallrye.beanbag Highest Product pom name SmallRye BeanBag High Product pom parent-artifactid smallrye-beanbag-parent Medium Version file version 1.5.3 High Version Manifest Implementation-Version 1.5.3 High Version pom version 1.5.3 Highest
pkg:maven/io.smallrye.beanbag/smallrye-beanbag@1.5.3 (Confidence :High) smallrye-beanbag-maven-1.5.3.jarDescription:
A supplier of Maven Resolver components using SmallRye BeanBag File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/beanbag/smallrye-beanbag-maven/1.5.3/smallrye-beanbag-maven-1.5.3.jarMD5: 2c695f7788af101ad9ed9bf8dd7cd515SHA1: 8ccc4a1c72372508614d92abc648c4f0c28b4d70SHA256: 8cc96b5a16bd7d99d8a933b74626d2abe71b0b629ace250f6e95201bdb9a80c5
Evidence Type Source Name Value Confidence Vendor file name smallrye-beanbag-maven High Vendor jar package name beanbag Highest Vendor jar package name io Highest Vendor jar package name maven Highest Vendor jar package name smallrye Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor pom artifactid smallrye-beanbag-maven Low Vendor pom groupid io.smallrye.beanbag Highest Vendor pom name SmallRye BeanBag: Maven High Vendor pom parent-artifactid smallrye-beanbag-parent Low Product file name smallrye-beanbag-maven High Product jar package name beanbag Highest Product jar package name io Highest Product jar package name maven Highest Product jar package name smallrye Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye BeanBag: Maven High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye BeanBag: Maven Medium Product pom artifactid smallrye-beanbag-maven Highest Product pom groupid io.smallrye.beanbag Highest Product pom name SmallRye BeanBag: Maven High Product pom parent-artifactid smallrye-beanbag-parent Medium Version file version 1.5.3 High Version Manifest Implementation-Version 1.5.3 High Version pom version 1.5.3 Highest
pkg:maven/io.smallrye.beanbag/smallrye-beanbag-maven@1.5.3 (Confidence :High) smallrye-beanbag-sisu-1.5.3.jarDescription:
Basic integration for SmallRye BeanBag and Eclipse SISU File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/beanbag/smallrye-beanbag-sisu/1.5.3/smallrye-beanbag-sisu-1.5.3.jarMD5: 12afb6f156040d5a0a1cd0c9a60d9022SHA1: 62a4255474eeb74a6dfd076e89945a6b390f6e83SHA256: 5b709a4e0e62ce613550f3c9edaf7b2663fa797d5312eda7491f6837cd2fefad
Evidence Type Source Name Value Confidence Vendor file name smallrye-beanbag-sisu High Vendor jar package name beanbag Highest Vendor jar package name io Highest Vendor jar package name sisu Highest Vendor jar package name smallrye Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io Low Vendor pom artifactid smallrye-beanbag-sisu Low Vendor pom groupid io.smallrye.beanbag Highest Vendor pom name SmallRye BeanBag: SISU High Vendor pom parent-artifactid smallrye-beanbag-parent Low Product file name smallrye-beanbag-sisu High Product jar package name beanbag Highest Product jar package name io Highest Product jar package name sisu Highest Product jar package name smallrye Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye BeanBag: SISU High Product Manifest implementation-url https://smallrye.io Low Product Manifest specification-title SmallRye BeanBag: SISU Medium Product pom artifactid smallrye-beanbag-sisu Highest Product pom groupid io.smallrye.beanbag Highest Product pom name SmallRye BeanBag: SISU High Product pom parent-artifactid smallrye-beanbag-parent Medium Version file version 1.5.3 High Version Manifest Implementation-Version 1.5.3 High Version pom version 1.5.3 Highest
pkg:maven/io.smallrye.beanbag/smallrye-beanbag-sisu@1.5.3 (Confidence :High) smallrye-common-process-2.14.0.jarDescription:
Process management utilities File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-process/2.14.0/smallrye-common-process-2.14.0.jarMD5: 941fd7bbf66eded39f4f2fbc678e885fSHA1: d9fcf609a78492d5d38fa88072426195eb7b3177SHA256: b4a82442371f9bce3ccbf4966718887d4b4552044801c7465bf3e95d56084564
Evidence Type Source Name Value Confidence Vendor file name smallrye-common-process High Vendor jar package name common Highest Vendor jar package name io Highest Vendor jar package name process Highest Vendor jar package name smallrye Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-common-process Low Vendor pom groupid io.smallrye.common Highest Vendor pom name SmallRye Common: Process High Vendor pom parent-artifactid smallrye-common-parent Low Product file name smallrye-common-process High Product jar package name common Highest Product jar package name io Highest Product jar package name process Highest Product jar package name smallrye Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Process High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Process Medium Product pom artifactid smallrye-common-process Highest Product pom groupid io.smallrye.common Highest Product pom name SmallRye Common: Process High Product pom parent-artifactid smallrye-common-parent Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High Version pom version 2.14.0 Highest
pkg:maven/io.smallrye.common/smallrye-common-process@2.14.0 (Confidence :High) smallrye-common-resource-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-resource/2.14.0/smallrye-common-resource-2.14.0.jarMD5: bce024036ead6b1e683c2621869bfdb5SHA1: 291a0047e35e6a33e51919cfcdd1f32872d27ebdSHA256: 57a4d2caec4de965dfee67a1a349acce76ad74832ce865f740d742e630eda49a
Evidence Type Source Name Value Confidence Vendor file name smallrye-common-resource High Vendor jar package name common Highest Vendor jar package name io Highest Vendor jar package name resource Highest Vendor jar package name smallrye Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-common-resource Low Vendor pom groupid io.smallrye.common Highest Vendor pom name SmallRye Common: Resources High Vendor pom parent-artifactid smallrye-common-parent Low Product file name smallrye-common-resource High Product jar package name common Highest Product jar package name io Highest Product jar package name resource Highest Product jar package name smallrye Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Resources High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Resources Medium Product pom artifactid smallrye-common-resource Highest Product pom groupid io.smallrye.common Highest Product pom name SmallRye Common: Resources High Product pom parent-artifactid smallrye-common-parent Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High Version pom version 2.14.0 Highest
pkg:maven/io.smallrye.common/smallrye-common-resource@2.14.0 (Confidence :High) smallrye-common-version-2.14.0.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/common/smallrye-common-version/2.14.0/smallrye-common-version-2.14.0.jarMD5: 89aac81104302d6cd51d11cc830a9d0bSHA1: 9aa30faed3423c83c290b70e60ac619ba0942985SHA256: a7d4765982c00d5e247d5019844e0971cd7a23195a8defe29639d13e5a0e7731
Evidence Type Source Name Value Confidence Vendor file name smallrye-common-version High Vendor jar package name common Highest Vendor jar package name io Highest Vendor jar package name smallrye Highest Vendor jar package name version Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-common-version Low Vendor pom groupid io.smallrye.common Highest Vendor pom name SmallRye Common: Version High Vendor pom parent-artifactid smallrye-common-parent Low Product file name smallrye-common-version High Product jar package name common Highest Product jar package name io Highest Product jar package name smallrye Highest Product jar package name version Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Common: Version High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye Common: Version Medium Product pom artifactid smallrye-common-version Highest Product pom groupid io.smallrye.common Highest Product pom name SmallRye Common: Version High Product pom parent-artifactid smallrye-common-parent Medium Version file version 2.14.0 High Version Manifest Implementation-Version 2.14.0 High Version pom version 2.14.0 Highest
pkg:maven/io.smallrye.common/smallrye-common-version@2.14.0 (Confidence :High) smallrye-mutiny-vertx-auth-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-auth-common/3.21.3/smallrye-mutiny-vertx-auth-common-3.21.3.jarMD5: 3a314ccfc2fc5249098b72c899d0ba38SHA1: a8ff5660a3af96f20ba6d40b3a6456c002320612SHA256: cdfc220728c203f111c8897802a9844cff70796ad5269fc8009bf4177d65103f
Evidence Type Source Name Value Confidence Vendor file name smallrye-mutiny-vertx-auth-common High Vendor jar package name io Highest Vendor jar package name mutiny Highest Vendor jar package name vertx Highest Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.auth.common Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Vendor pom artifactid smallrye-mutiny-vertx-auth-common Low Vendor pom groupid io.smallrye.reactive Highest Vendor pom name SmallRye Mutiny - Vert.x Auth Common High Vendor pom parent-artifactid vertx-mutiny-clients Low Product file name smallrye-mutiny-vertx-auth-common High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name vertx Highest Product Manifest automatic-module-name io.smallrye.mutiny.vertx.auth.common Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x Auth Common High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x Auth Common Medium Product pom artifactid smallrye-mutiny-vertx-auth-common Highest Product pom groupid io.smallrye.reactive Highest Product pom name SmallRye Mutiny - Vert.x Auth Common High Product pom parent-artifactid vertx-mutiny-clients Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High Version pom version 3.21.3 Highest
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-auth-common-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-auth-common:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-auth-common-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-auth-common/pom.xml MD5: ce2e60d00619f06dbbd5765bc8f0cfd3 SHA1: e77e970005aa27c247b4a990eb19ef2bb9c93952 SHA256: 91b2d3b50716d40b768b9bce9d63350881c06ad94594fb8628f42fe0e16687c5 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-auth-common@3.21.3 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-auth-common@3.21.3 (Confidence :High) smallrye-mutiny-vertx-bridge-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-bridge-common/3.21.3/smallrye-mutiny-vertx-bridge-common-3.21.3.jarMD5: 4ea9045872070a9b835004b4bd157808SHA1: 94a81c66ebe187a9bbac43361f8f843bbbfecaf1SHA256: 7be0b77f9f8dc0c298796db8de7a25859c77c64e948c3a31f702fcaf234d9ec2
Evidence Type Source Name Value Confidence Vendor file name smallrye-mutiny-vertx-bridge-common High Vendor jar package name io Highest Vendor jar package name mutiny Highest Vendor jar package name vertx Highest Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.bridge.common Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Vendor pom artifactid smallrye-mutiny-vertx-bridge-common Low Vendor pom groupid io.smallrye.reactive Highest Vendor pom name SmallRye Mutiny - Vert.x Bridge Common High Vendor pom parent-artifactid vertx-mutiny-clients Low Product file name smallrye-mutiny-vertx-bridge-common High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name vertx Highest Product Manifest automatic-module-name io.smallrye.mutiny.vertx.bridge.common Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x Bridge Common High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x Bridge Common Medium Product pom artifactid smallrye-mutiny-vertx-bridge-common Highest Product pom groupid io.smallrye.reactive Highest Product pom name SmallRye Mutiny - Vert.x Bridge Common High Product pom parent-artifactid vertx-mutiny-clients Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High Version pom version 3.21.3 Highest
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-bridge-common-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-bridge-common:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-bridge-common-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-bridge-common/pom.xml MD5: 581e3334426e2d7e7ff98bc77d46f1ad SHA1: 49b5435179d026ecff090c4bde66e2cab01fe953 SHA256: 17a03f631fa661e213cf5b227eeca985508b4ed1559f4de35772177ed006fbde pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-bridge-common@3.21.3 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-bridge-common@3.21.3 (Confidence :High) smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-rabbitmq-client/3.21.3/smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jarMD5: 7d2bf2eaa4bb08877a1e76b8595607cbSHA1: 0c43a3e6a567abf6d87887593c7bb32d94c6d792SHA256: 5e2005164b8e1c9e3cb6ee4de432eb6c58ceb3f8ab98fefa1432d3852c2bf00a
Evidence Type Source Name Value Confidence Vendor file name smallrye-mutiny-vertx-rabbitmq-client High Vendor jar package name io Highest Vendor jar package name mutiny Highest Vendor jar package name rabbitmq Highest Vendor jar package name vertx Highest Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.rabbitmq.client Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Vendor pom artifactid smallrye-mutiny-vertx-rabbitmq-client Low Vendor pom groupid io.smallrye.reactive Highest Vendor pom name SmallRye Mutiny - Vert.x RabbitMQ Client High Vendor pom parent-artifactid vertx-mutiny-clients Low Product file name smallrye-mutiny-vertx-rabbitmq-client High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name rabbitmq Highest Product jar package name vertx Highest Product Manifest automatic-module-name io.smallrye.mutiny.vertx.rabbitmq.client Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x RabbitMQ Client High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x RabbitMQ Client Medium Product pom artifactid smallrye-mutiny-vertx-rabbitmq-client Highest Product pom groupid io.smallrye.reactive Highest Product pom name SmallRye Mutiny - Vert.x RabbitMQ Client High Product pom parent-artifactid vertx-mutiny-clients Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High Version pom version 3.21.3 Highest
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-rabbitmq-client:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-rabbitmq-client-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-rabbitmq-client/pom.xml MD5: ea8468c0627f7a89c4b7e91986ea229a SHA1: 3ea542a3cc23653941c2dc1b9692feb16a33ebc9 SHA256: 34a03ced7a71acd10a28c22f3e4cdbd6d3805f86b0b23297b8a98ce61d29e782 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-rabbitmq-client@3.21.3 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-rabbitmq-client@3.21.3 (Confidence :High) smallrye-mutiny-vertx-runtime-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-runtime/3.21.3/smallrye-mutiny-vertx-runtime-3.21.3.jarMD5: 3e308d0f504219aad672231bec0d1036SHA1: 0b4b36261641dbd4e130fb22d2ba4b3b28693689SHA256: 047c540d6d4b9e65569048d964525f8d306d43726d6ae9427ddb0395c9b457bb
Evidence Type Source Name Value Confidence Vendor file name smallrye-mutiny-vertx-runtime High Vendor jar package name io Highest Vendor jar package name mutiny Highest Vendor jar package name smallrye Highest Vendor jar package name vertx Highest Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.runtime Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Vendor pom artifactid smallrye-mutiny-vertx-runtime Low Vendor pom groupid io.smallrye.reactive Highest Vendor pom name SmallRye Mutiny - Runtime Helpers High Vendor pom parent-artifactid vertx-mutiny-clients Low Product file name smallrye-mutiny-vertx-runtime High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name smallrye Highest Product jar package name vertx Highest Product Manifest automatic-module-name io.smallrye.mutiny.vertx.runtime Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Runtime Helpers High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Runtime Helpers Medium Product pom artifactid smallrye-mutiny-vertx-runtime Highest Product pom groupid io.smallrye.reactive Highest Product pom name SmallRye Mutiny - Runtime Helpers High Product pom parent-artifactid vertx-mutiny-clients Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High Version pom version 3.21.3 Highest
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-runtime-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-runtime:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-runtime-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-runtime/pom.xml MD5: e259ed0c9970132c74e8455e46bae52b SHA1: 4fd78180a23c4401efb98470b2973333fb900888 SHA256: c78f9fee14a41c214121bab75cc595fa31c4ef01a55e130d3ae9cc84d1d1f127 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-runtime@3.21.3 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-runtime@3.21.3 (Confidence :High) smallrye-mutiny-vertx-uri-template-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-uri-template/3.21.3/smallrye-mutiny-vertx-uri-template-3.21.3.jarMD5: d301b06de44f0fccf67686dd1c642e36SHA1: b6669b4320339aefce224625aaeaf1ee57387158SHA256: 847f3650e5fce6de00ca58e31665270a084ec6b283a039fe8848447e8d5a3be9
Evidence Type Source Name Value Confidence Vendor file name smallrye-mutiny-vertx-uri-template High Vendor jar package name io Highest Vendor jar package name mutiny Highest Vendor jar package name vertx Highest Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.uri.template Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Vendor pom artifactid smallrye-mutiny-vertx-uri-template Low Vendor pom groupid io.smallrye.reactive Highest Vendor pom name SmallRye Mutiny - Vert.x URI Template High Vendor pom parent-artifactid vertx-mutiny-clients Low Product file name smallrye-mutiny-vertx-uri-template High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name vertx Highest Product Manifest automatic-module-name io.smallrye.mutiny.vertx.uri.template Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x URI Template High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x URI Template Medium Product pom artifactid smallrye-mutiny-vertx-uri-template Highest Product pom groupid io.smallrye.reactive Highest Product pom name SmallRye Mutiny - Vert.x URI Template High Product pom parent-artifactid vertx-mutiny-clients Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High Version pom version 3.21.3 Highest
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-uri-template-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-uri-template:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-uri-template-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-uri-template/pom.xml MD5: e8ffebb11dd46cb840f13570d3d1e59e SHA1: 30a27c531901b5a2a5d894aefd001ffb7f1aece3 SHA256: bff3e3e3c836bb6896341faf1b9249b30574d1486df377356627e77763d1ca2a pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-uri-template@3.21.3 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-uri-template@3.21.3 (Confidence :High) smallrye-mutiny-vertx-web-client-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-web-client/3.21.3/smallrye-mutiny-vertx-web-client-3.21.3.jarMD5: c461a025f29d76d549e1835a723df143SHA1: a30e2ba3dddfda43688053fe1a38e12ed28ccba8SHA256: 705f35b208c87f50b8401cec24af04c94a5e1e8943b421071f278b8a98c0082f
Evidence Type Source Name Value Confidence Vendor file name smallrye-mutiny-vertx-web-client High Vendor jar package name io Highest Vendor jar package name mutiny Highest Vendor jar package name vertx Highest Vendor Manifest automatic-module-name io.smallrye.mutiny.vertx.web.client Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Vendor Manifest Implementation-Vendor SmallRye High Vendor Manifest specification-vendor SmallRye Low Vendor pom artifactid smallrye-mutiny-vertx-web-client Low Vendor pom groupid io.smallrye.reactive Highest Vendor pom name SmallRye Mutiny - Vert.x Web Client High Vendor pom parent-artifactid vertx-mutiny-clients Low Product file name smallrye-mutiny-vertx-web-client High Product jar package name io Highest Product jar package name mutiny Highest Product jar package name vertx Highest Product Manifest automatic-module-name io.smallrye.mutiny.vertx.web.client Medium Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye Mutiny - Vert.x Web Client High Product Manifest implementation-url https://smallrye.io/smallrye-mutiny-vertx-bindings Low Product Manifest specification-title SmallRye Mutiny - Vert.x Web Client Medium Product pom artifactid smallrye-mutiny-vertx-web-client Highest Product pom groupid io.smallrye.reactive Highest Product pom name SmallRye Mutiny - Vert.x Web Client High Product pom parent-artifactid vertx-mutiny-clients Medium Version file version 3.21.3 High Version Manifest Implementation-Version 3.21.3 High Version pom version 3.21.3 Highest
Related Dependencies io.smallrye.reactive.smallrye-mutiny-vertx-web-common-3.21.3.jar (shaded: io.smallrye.reactive:smallrye-mutiny-vertx-web-common:3.21.3)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.smallrye.reactive.smallrye-mutiny-vertx-web-common-3.21.3.jar/META-INF/maven/io.smallrye.reactive/smallrye-mutiny-vertx-web-common/pom.xml MD5: c9546c687282c09ef74b767f0d8a3f01 SHA1: 5f3d47d2a1031dda75fc9ad13c55de73dd4807bb SHA256: 467fcd2bcafa0b51e2f0bd9efe55ab208f9245d41d471c80b2166e8c08b111fc pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-web-common@3.21.3 smallrye-mutiny-vertx-web-common-3.21.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/reactive/smallrye-mutiny-vertx-web-common/3.21.3/smallrye-mutiny-vertx-web-common-3.21.3.jar MD5: 47c969c198c1653b062e5a56d95c99fc SHA1: cfcdec164e8b3d98556eec6051b16c88e00b935c SHA256: 10c297b7d68d04343e2548c0814962b39123af69804f9f4da3e522b005f99db5 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-web-common@3.21.3 pkg:maven/io.smallrye.reactive/smallrye-mutiny-vertx-web-client@3.21.3 (Confidence :High) cpe:2.3:a:xweb:xweb:3.21.3:*:*:*:*:*:*:* (Confidence :Low) suppress smallrye-open-api-jaxrs-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-jaxrs/4.2.3/smallrye-open-api-jaxrs-4.2.3.jarMD5: ac97c1c5a2e2dc53c462a0df00ea6fdeSHA1: 05b05bb9f3d8aad29f1616278be9f09cf496681aSHA256: 13ea651d3ddc2900dd4725b776f9236146d40ee67cd77b7e1b6d5d5048742aad
Evidence Type Source Name Value Confidence Vendor file name smallrye-open-api-jaxrs High Vendor jar package name io Highest Vendor jar package name jaxrs Highest Vendor jar package name openapi Highest Vendor jar package name smallrye Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-open-api-jaxrs Low Vendor pom groupid io.smallrye Highest Vendor pom name SmallRye: OpenAPI extension - JAX-RS High Vendor pom parent-artifactid smallrye-open-api-parent Low Product file name smallrye-open-api-jaxrs High Product jar package name io Highest Product jar package name jaxrs Highest Product jar package name openapi Highest Product jar package name smallrye Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: OpenAPI extension - JAX-RS High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: OpenAPI extension - JAX-RS Medium Product pom artifactid smallrye-open-api-jaxrs Highest Product pom groupid io.smallrye Highest Product pom name SmallRye: OpenAPI extension - JAX-RS High Product pom parent-artifactid smallrye-open-api-parent Medium Version file version 4.2.3 High Version Manifest Implementation-Version 4.2.3 High Version pom version 4.2.3 Highest
pkg:maven/io.smallrye/smallrye-open-api-jaxrs@4.2.3 (Confidence :High) smallrye-open-api-spring-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-spring/4.2.3/smallrye-open-api-spring-4.2.3.jarMD5: 20f257e76329def7a03e11edc3d8c093SHA1: 4aff6448989ba033fa736a4bab9e92fd63dceeb3SHA256: 9d72a1e1d444cc32d062478705d01a4fa89e6370dc591f0d42e3998f5bd02c60
Evidence Type Source Name Value Confidence Vendor file name smallrye-open-api-spring High Vendor jar package name io Highest Vendor jar package name openapi Highest Vendor jar package name smallrye Highest Vendor jar package name spring Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-open-api-spring Low Vendor pom groupid io.smallrye Highest Vendor pom name SmallRye: OpenAPI extension - Spring High Vendor pom parent-artifactid smallrye-open-api-parent Low Product file name smallrye-open-api-spring High Product jar package name io Highest Product jar package name openapi Highest Product jar package name smallrye Highest Product jar package name spring Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: OpenAPI extension - Spring High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: OpenAPI extension - Spring Medium Product pom artifactid smallrye-open-api-spring Highest Product pom groupid io.smallrye Highest Product pom name SmallRye: OpenAPI extension - Spring High Product pom parent-artifactid smallrye-open-api-parent Medium Version file version 4.2.3 High Version Manifest Implementation-Version 4.2.3 High Version pom version 4.2.3 Highest
pkg:maven/io.smallrye/smallrye-open-api-spring@4.2.3 (Confidence :High) smallrye-open-api-ui-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-ui/4.2.3/smallrye-open-api-ui-4.2.3.jarMD5: 0f8b26cf9ba1b64b55e17b2bb7d065bcSHA1: 43b1f817b567e1b2242a972ee299d6d969195285SHA256: e0424bddf30019fac0b239db9cb6e389629deb598f0c240a108bb6a9d1d3afd8
Evidence Type Source Name Value Confidence Vendor file name smallrye-open-api-ui High Vendor jar package name io Highest Vendor jar package name openapi Highest Vendor jar package name smallrye Highest Vendor jar package name ui Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-open-api-ui Low Vendor pom groupid io.smallrye Highest Vendor pom name SmallRye: OpenAPI UI High Vendor pom parent-artifactid smallrye-open-api-ui-parent Low Product file name smallrye-open-api-ui High Product jar package name io Highest Product jar package name openapi Highest Product jar package name smallrye Highest Product jar package name ui Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: OpenAPI UI High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: OpenAPI UI Medium Product pom artifactid smallrye-open-api-ui Highest Product pom groupid io.smallrye Highest Product pom name SmallRye: OpenAPI UI High Product pom parent-artifactid smallrye-open-api-ui-parent Medium Version file version 4.2.3 High Version Manifest Implementation-Version 4.2.3 High Version pom version 4.2.3 Highest
pkg:maven/io.smallrye/smallrye-open-api-ui@4.2.3 (Confidence :High) smallrye-open-api-ui-4.2.3.jar: swagger-ui-bundle.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-ui/4.2.3/smallrye-open-api-ui-4.2.3.jar/META-INF/resources/openapi-ui/swagger-ui-bundle.jsMD5: 22865a74c584fc10cc97333b3f29095cSHA1: 20da294e6108a68dfd7ce1cb64ab4ca96df9421cSHA256: dcbaefeb09685d45fae31a52758c3028be783f49a6070cc4408618012a13d2a2
Evidence Type Source Name Value Confidence
smallrye-open-api-ui-4.2.3.jar: swagger-ui-standalone-preset.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-ui/4.2.3/smallrye-open-api-ui-4.2.3.jar/META-INF/resources/openapi-ui/swagger-ui-standalone-preset.jsMD5: c52d69e3948ac5fdffc432e95fc737a3SHA1: 97ad64329b79e88fea9bc861766cd5ffbc959d5cSHA256: 8710b6d90ece7113dd467500fa14ed33b5848b68b8695ad075f8d5c6c9af3b01
Evidence Type Source Name Value Confidence
smallrye-open-api-vertx-4.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/smallrye/smallrye-open-api-vertx/4.2.3/smallrye-open-api-vertx-4.2.3.jarMD5: e2e6296593de62659fa61e113a9ce489SHA1: fedd612660d004d25dbea20ccba9cc604874c481SHA256: d706a1c45bdb25458b8290ce692c687ff091f37f98536641c4fc9d11b1751a82
Evidence Type Source Name Value Confidence Vendor file name smallrye-open-api-vertx High Vendor jar package name io Highest Vendor jar package name openapi Highest Vendor jar package name smallrye Highest Vendor jar package name vertx Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest implementation-url http://smallrye.io Low Vendor pom artifactid smallrye-open-api-vertx Low Vendor pom groupid io.smallrye Highest Vendor pom name SmallRye: OpenAPI extension - Vert.x High Vendor pom parent-artifactid smallrye-open-api-parent Low Product file name smallrye-open-api-vertx High Product jar package name io Highest Product jar package name openapi Highest Product jar package name smallrye Highest Product jar package name vertx Highest Product Manifest build-jdk-spec 21 Low Product Manifest Implementation-Title SmallRye: OpenAPI extension - Vert.x High Product Manifest implementation-url http://smallrye.io Low Product Manifest specification-title SmallRye: OpenAPI extension - Vert.x Medium Product pom artifactid smallrye-open-api-vertx Highest Product pom groupid io.smallrye Highest Product pom name SmallRye: OpenAPI extension - Vert.x High Product pom parent-artifactid smallrye-open-api-parent Medium Version file version 4.2.3 High Version Manifest Implementation-Version 4.2.3 High Version pom version 4.2.3 Highest
pkg:maven/io.smallrye/smallrye-open-api-vertx@4.2.3 (Confidence :High) snappy-0.4.jarDescription:
Port of Snappy to Java License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/iq80/snappy/snappy/0.4/snappy-0.4.jar
MD5: f0792d1dbe7f90d8b34c7c19961e0073
SHA1: a42b2d92a89efd35bb14738000dabcac6bd07a8d
SHA256: 46a0c87d504ce9d6063e1ff6e4d20738feb49d8abf85b5071a7d18df4f11bac9
Evidence Type Source Name Value Confidence Vendor file name snappy High Vendor jar package name iq80 Highest Vendor jar package name iq80 Low Vendor jar package name snappy Highest Vendor jar package name snappy Low Vendor pom artifactid snappy Low Vendor pom developer email dain@iq80.com Low Vendor pom developer email david@acz.org Low Vendor pom developer id dain Medium Vendor pom developer id electrum Medium Vendor pom developer name Dain Sundstrom Medium Vendor pom developer name David Phillips Medium Vendor pom groupid org.iq80.snappy Highest Vendor pom name snappy High Vendor pom url http://github.com/dain/snappy Highest Product file name snappy High Product jar package name iq80 Highest Product jar package name snappy Highest Product jar package name snappy Low Product pom artifactid snappy Highest Product pom developer email dain@iq80.com Low Product pom developer email david@acz.org Low Product pom developer id dain Low Product pom developer id electrum Low Product pom developer name Dain Sundstrom Low Product pom developer name David Phillips Low Product pom groupid org.iq80.snappy Highest Product pom name snappy High Product pom url http://github.com/dain/snappy Medium Version file version 0.4 High Version pom version 0.4 Highest
CVE-2024-36124 suppress
iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class `sun.misc.Unsafe` to speed up memory access, no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++, namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.
CWE-125 Out-of-bounds Read
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions:
sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/jacoco-report/jacoco-resources/sort.jsMD5: af6dc76a8d5e0653f66eb57f2757327dSHA1: 03380a84c61514f773a503de39d517e1bb2d72bbSHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043
Evidence Type Source Name Value Confidence
Related Dependencies org.jacoco.report-0.8.13.jar: sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.report/0.8.13/org.jacoco.report-0.8.13.jar/org/jacoco/report/internal/html/resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 org.jacoco.report-0.8.14.jar: sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/jacoco/org.jacoco.report/0.8.14/org.jacoco.report-0.8.14.jar/org/jacoco/report/internal/html/resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/site/jacoco/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/tests/target/jacoco-aggregate/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/jacoco-report/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 sort.jsFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/site/jacoco/jacoco-resources/sort.js MD5: af6dc76a8d5e0653f66eb57f2757327d SHA1: 03380a84c61514f773a503de39d517e1bb2d72bb SHA256: 64407e72c5097000e41f9da4ac9a04131b8ec9479ca8987a5f5d5f2ad6383043 stax2-api-4.2.2.jarDescription:
Stax2 API is an extension to basic Stax 1.0 API that adds significant new functionality, such as full-featured bi-direction validation interface and high-performance Typed Access API.
License:
The BSD 2-Clause License: http://www.opensource.org/licenses/bsd-license.php File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/codehaus/woodstox/stax2-api/4.2.2/stax2-api-4.2.2.jar
MD5: 6949cace015c0f408f0b846e3735d301
SHA1: b0d746cadea928e5264f2ea294ea9a1bf815bbde
SHA256: a61c48d553efad78bc01fffc4ac528bebbae64cbaec170b2a5e39cf61eb51abe
Evidence Type Source Name Value Confidence Vendor file name stax2-api High Vendor jar package name codehaus Highest Vendor jar package name stax2 Highest Vendor jar package name typed Highest Vendor jar package name validation Highest Vendor Manifest automatic-module-name org.codehaus.stax2 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl http://github.com/FasterXML/stax2-api Low Vendor Manifest bundle-symbolicname stax2-api Medium Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id org.codehaus.woodstox Medium Vendor Manifest specification-vendor fasterxml.com Low Vendor pom artifactid stax2-api Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id tatu Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid org.codehaus.woodstox Highest Vendor pom name Stax2 API High Vendor pom organization name fasterxml.com High Vendor pom organization url http://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom parent-groupid com.fasterxml Medium Vendor pom url http://github.com/FasterXML/stax2-api Highest Product file name stax2-api High Product jar package name codehaus Highest Product jar package name stax2 Highest Product jar package name typed Highest Product jar package name validation Highest Product Manifest automatic-module-name org.codehaus.stax2 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl http://github.com/FasterXML/stax2-api Low Product Manifest Bundle-Name Stax2 API Medium Product Manifest bundle-symbolicname stax2-api Medium Product Manifest Implementation-Title Stax2 API High Product Manifest specification-title Stax2 API Medium Product pom artifactid stax2-api Highest Product pom developer email tatu@fasterxml.com Low Product pom developer id tatu Low Product pom developer name Tatu Saloranta Low Product pom groupid org.codehaus.woodstox Highest Product pom name Stax2 API High Product pom organization name fasterxml.com Low Product pom organization url http://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom parent-groupid com.fasterxml Medium Product pom url http://github.com/FasterXML/stax2-api Medium Version file version 4.2.2 High Version Manifest Bundle-Version 4.2.2 High Version Manifest Implementation-Version 4.2.2 High Version pom parent-version 4.2.2 Low Version pom version 4.2.2 Highest
pkg:maven/org.codehaus.woodstox/stax2-api@4.2.2 (Confidence :High) surefire-api-3.2.2.jarDescription:
API used in Surefire and Failsafe MOJO, Booter, Common and test framework providers. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-api/3.2.2/surefire-api-3.2.2.jarMD5: 3cb063ebb9b66116d5b8bd3593bad059SHA1: 243c4e6def8efd0915ed9e3d49298507e8394529SHA256: cf3de8d5b3ea31b410be4957a3b2e9d0aba00ac4c321a8794d7eb5e3d548d705
Evidence Type Source Name Value Confidence Vendor file name surefire-api High Vendor jar package name apache Highest Vendor jar package name api Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-api Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire API High Vendor pom parent-artifactid surefire Low Product file name surefire-api High Product jar package name apache Highest Product jar package name api Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title SureFire API High Product Manifest specification-title SureFire API Medium Product pom artifactid surefire-api Highest Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire API High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/surefire-api@3.2.2 (Confidence :High) surefire-api-3.2.3.jarDescription:
API used in Surefire and Failsafe MOJO, Booter, Common and test framework providers. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-api/3.2.3/surefire-api-3.2.3.jarMD5: e9160f6b26fe2ba9e84bc7760217e1d7SHA1: 385fb784ecf415fd8c85eecaf528d752b639fc97SHA256: a8de90dfd4e82505776587a233bc539f2edf319582b0331cdbb3779e54b52834
Evidence Type Source Name Value Confidence Vendor file name surefire-api High Vendor jar package name apache Highest Vendor jar package name api Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-api Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire API High Vendor pom parent-artifactid surefire Low Product file name surefire-api High Product jar package name apache Highest Product jar package name api Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title SureFire API High Product Manifest specification-title SureFire API Medium Product pom artifactid surefire-api Highest Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire API High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/surefire-api@3.2.3 (Confidence :High) surefire-booter-3.2.2.jarDescription:
API and Facilities used by forked tests running in JVM sub-process. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-booter/3.2.2/surefire-booter-3.2.2.jarMD5: c10b372221f641888eedbb5aefb623b5SHA1: b8c37b5f5d7675ed15b512109abf4ce19005e116SHA256: 57b6d9d56b9b48d767b87c43d3e8d673026c0181ff7cc30b96880779c5fdb74c
Evidence Type Source Name Value Confidence Vendor file name surefire-booter High Vendor jar package name apache Highest Vendor jar package name booter Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-booter Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire Booter High Vendor pom parent-artifactid surefire Low Product file name surefire-booter High Product jar package name apache Highest Product jar package name booter Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title SureFire Booter High Product Manifest specification-title SureFire Booter Medium Product pom artifactid surefire-booter Highest Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire Booter High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/surefire-booter@3.2.2 (Confidence :High) surefire-booter-3.2.3.jarDescription:
API and Facilities used by forked tests running in JVM sub-process. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-booter/3.2.3/surefire-booter-3.2.3.jarMD5: a01310ed0619acc78ddf54d926bab1edSHA1: 148fb18fe910ab3e69fbb7cb507d48f5dd970f3bSHA256: 8e17fb7515a968eebae8e4a41ead220a7fffd7a884b4f44fdef0e5a781294482
Evidence Type Source Name Value Confidence Vendor file name surefire-booter High Vendor jar package name apache Highest Vendor jar package name booter Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-booter Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire Booter High Vendor pom parent-artifactid surefire Low Product file name surefire-booter High Product jar package name apache Highest Product jar package name booter Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title SureFire Booter High Product Manifest specification-title SureFire Booter Medium Product pom artifactid surefire-booter Highest Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire Booter High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/surefire-booter@3.2.3 (Confidence :High) surefire-extensions-api-3.2.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-extensions-api/3.2.2/surefire-extensions-api-3.2.2.jarMD5: 358d2fba67dc8bab448061fdad31b24aSHA1: f514ede3901c2266b6ab9eb6cd9457250fedd6a5SHA256: c17a663985b0cac17eb978488d3f0e62bfa649f0eff1c6411c25f5cda0a11cdc
Evidence Type Source Name Value Confidence Vendor file name surefire-extensions-api High Vendor jar package name apache Highest Vendor jar package name extensions Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-extensions-api Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Surefire Extensions API High Vendor pom parent-artifactid surefire Low Product file name surefire-extensions-api High Product jar package name apache Highest Product jar package name extensions Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Surefire Extensions API High Product Manifest specification-title Surefire Extensions API Medium Product pom artifactid surefire-extensions-api Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Surefire Extensions API High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/surefire-extensions-api@3.2.2 (Confidence :High) surefire-extensions-api-3.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-extensions-api/3.2.3/surefire-extensions-api-3.2.3.jarMD5: 18f612793ba07291c6751299dbab3be3SHA1: 90b4e7f82f52f153734e6342afa1a0ebcc2fce40SHA256: 8c34ca976444685605784dc4c5cb3ac8b838b2b475310a9fcd2b3e2a545de16a
Evidence Type Source Name Value Confidence Vendor file name surefire-extensions-api High Vendor jar package name apache Highest Vendor jar package name extensions Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-extensions-api Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Surefire Extensions API High Vendor pom parent-artifactid surefire Low Product file name surefire-extensions-api High Product jar package name apache Highest Product jar package name extensions Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Surefire Extensions API High Product Manifest specification-title Surefire Extensions API Medium Product pom artifactid surefire-extensions-api Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Surefire Extensions API High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/surefire-extensions-api@3.2.3 (Confidence :High) surefire-extensions-spi-3.2.2.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-extensions-spi/3.2.2/surefire-extensions-spi-3.2.2.jarMD5: d11607221665c37100c9323d5eac6d22SHA1: 4e01d4a8dd2b8f0842750096a6d0069678151987SHA256: 38282f5e09ba6a129b22f5586c2d35c133461c0aa172d97e2f3a7c29293d1410
Evidence Type Source Name Value Confidence Vendor file name surefire-extensions-spi High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name spi Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-extensions-spi Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Surefire Extensions SPI High Vendor pom parent-artifactid surefire Low Product file name surefire-extensions-spi High Product jar package name apache Highest Product jar package name maven Highest Product jar package name spi Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Surefire Extensions SPI High Product Manifest specification-title Surefire Extensions SPI Medium Product pom artifactid surefire-extensions-spi Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Surefire Extensions SPI High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/surefire-extensions-spi@3.2.2 (Confidence :High) surefire-extensions-spi-3.2.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-extensions-spi/3.2.3/surefire-extensions-spi-3.2.3.jarMD5: 5bf8611d8c865c945af236c667c47bd6SHA1: 70f26226daf70aaeff7f8d39e7c577e62eca1d96SHA256: 5eae9d42b9da855b005adc385a35ddd62659aefbe0a3ebeab4dff2c56762c56f
Evidence Type Source Name Value Confidence Vendor file name surefire-extensions-spi High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name spi Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-extensions-spi Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Surefire Extensions SPI High Vendor pom parent-artifactid surefire Low Product file name surefire-extensions-spi High Product jar package name apache Highest Product jar package name maven Highest Product jar package name spi Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Surefire Extensions SPI High Product Manifest specification-title Surefire Extensions SPI Medium Product pom artifactid surefire-extensions-spi Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Surefire Extensions SPI High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/surefire-extensions-spi@3.2.3 (Confidence :High) surefire-junit-platform-3.2.2.jarDescription:
SureFire JUnit Platform Runner File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-junit-platform/3.2.2/surefire-junit-platform-3.2.2.jarMD5: 2250d4f65a1f9c74675f9139512ba61bSHA1: 491d42efd2cc77994d6ab4974793109ead85402fSHA256: 06aef500a1a19ba394411cb352066e3ea9e0e7fbc2e15821ce9c01cb5f583666
Evidence Type Source Name Value Confidence Vendor file name surefire-junit-platform High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-junit-platform Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire JUnit Platform Runner High Vendor pom parent-artifactid surefire-providers Low Product file name surefire-junit-platform High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title SureFire JUnit Platform Runner High Product Manifest specification-title SureFire JUnit Platform Runner Medium Product pom artifactid surefire-junit-platform Highest Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire JUnit Platform Runner High Product pom parent-artifactid surefire-providers Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/surefire-junit-platform@3.2.2 (Confidence :High) surefire-junit-platform-3.2.3.jarDescription:
SureFire JUnit Platform Runner File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-junit-platform/3.2.3/surefire-junit-platform-3.2.3.jarMD5: 65887ddc1dc9b01ba84e77d94ca8f328SHA1: 7c9372a5ba0ee6d83b84887d4c268eab8fc84bb1SHA256: fdafaebb80ec6246efcdb11b61b4270635188a5e820b82306035d65900710fb5
Evidence Type Source Name Value Confidence Vendor file name surefire-junit-platform High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-junit-platform Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire JUnit Platform Runner High Vendor pom parent-artifactid surefire-providers Low Product file name surefire-junit-platform High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title SureFire JUnit Platform Runner High Product Manifest specification-title SureFire JUnit Platform Runner Medium Product pom artifactid surefire-junit-platform Highest Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire JUnit Platform Runner High Product pom parent-artifactid surefire-providers Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/surefire-junit-platform@3.2.3 (Confidence :High) surefire-logger-api-3.2.2.jarDescription:
Interfaces and Utilities related only to internal SureFire Logger API. Free of dependencies. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-logger-api/3.2.2/surefire-logger-api-3.2.2.jarMD5: 0b1c74f7f68092b5ea07669de044dc65SHA1: ad1cf68646e60276dc44df451d2ab107231f1c04SHA256: 34ea28b6f8a822402b6bfa7046341c6258cc44a6f071b6066a3de926180c06b9
Evidence Type Source Name Value Confidence Vendor file name surefire-logger-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-logger-api Low Vendor pom developer email tibordigana@apache.org Low Vendor pom developer id tibordigana Medium Vendor pom developer name Tibor Digaňa (tibor17) Medium Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire Logger API High Vendor pom parent-artifactid surefire Low Product file name surefire-logger-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title SureFire Logger API High Product Manifest specification-title SureFire Logger API Medium Product pom artifactid surefire-logger-api Highest Product pom developer email tibordigana@apache.org Low Product pom developer id tibordigana Low Product pom developer name Tibor Digaňa (tibor17) Low Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire Logger API High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
pkg:maven/org.apache.maven.surefire/surefire-logger-api@3.2.2 (Confidence :High) surefire-logger-api-3.2.3.jarDescription:
Interfaces and Utilities related only to internal SureFire Logger API. Free of dependencies. File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-logger-api/3.2.3/surefire-logger-api-3.2.3.jarMD5: 4583078b93a152321ed99fc889a48684SHA1: 963ab0611235695673656c42e56e9d88e38b4ec3SHA256: b77ad337f49661dbc87c26f791009a591791598d63046b5bfbff0d7eec7e1efe
Evidence Type Source Name Value Confidence Vendor file name surefire-logger-api High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-logger-api Low Vendor pom developer email tibordigana@apache.org Low Vendor pom developer id tibordigana Medium Vendor pom developer name Tibor Digaňa (tibor17) Medium Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name SureFire Logger API High Vendor pom parent-artifactid surefire Low Product file name surefire-logger-api High Product jar package name apache Highest Product jar package name maven Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title SureFire Logger API High Product Manifest specification-title SureFire Logger API Medium Product pom artifactid surefire-logger-api Highest Product pom developer email tibordigana@apache.org Low Product pom developer id tibordigana Low Product pom developer name Tibor Digaňa (tibor17) Low Product pom groupid org.apache.maven.surefire Highest Product pom name SureFire Logger API High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
pkg:maven/org.apache.maven.surefire/surefire-logger-api@3.2.3 (Confidence :High) surefire-shared-utils-3.2.2.jar (shaded: org.apache.commons:commons-compress:1.23.0)Description:
Apache Commons Compress software defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
lzma, xz, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-shared-utils/3.2.2/surefire-shared-utils-3.2.2.jar/META-INF/maven/org.apache.commons/commons-compress/pom.xmlMD5: d3b5ceab5b35e740311012b5b096176aSHA1: 1459c307e78823562355649fd2af3b6b84c4858aSHA256: 59dc121406ba9e8b5b512bcef4571351fed1f902b939cf527d893b7f729454c9
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email peterlee at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id peterlee Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Peter Alfred Lee Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email peterlee at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id peterlee Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Peter Alfred Lee Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version pom parent-version 1.23.0 Low Version pom version 1.23.0 Highest
CVE-2023-42503 suppress
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.
Users are recommended to upgrade to version 1.24.0, which fixes the issue.
A third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.
In version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subsecond precision (for example “1647221103.5998539”). The impacted fields are “atime”, “ctime”, “mtime” and “LIBARCHIVE.creationtime”. No input validation is performed prior to the parsing of header values.
Parsing of these numbers uses the BigDecimal [3] class from the JDK which has a publicly known algorithmic complexity issue when doing operations on large numbers, causing denial of service (see issue # JDK-6560193 [4]). A third party can manipulate file time headers in a TAR file by placing a number with a very long fraction (300,000 digits) or a number with exponent notation (such as “9e9999999”) within a file modification time header, and the parsing of files with these headers will take hours instead of seconds, leading to a denial of service via exhaustion of CPU resources. This issue is similar to CVE-2012-2098 [5].
[1]: https://issues.apache.org/jira/browse/COMPRESS-612
[2]: https://pubs.opengroup.org/onlinepubs/9699919799/utilities/pax.html#tag_20_92_13_05
[3]: https://docs.oracle.com/javase/8/docs/api/java/math/BigDecimal.html
[4]: https://bugs.openjdk.org/browse/JDK-6560193
[5]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2098
Only applications using CompressorStreamFactory class (with auto-detection of file types), TarArchiveInputStream and TarFile classes to parse TAR files are impacted. Since this code was introduced in v1.22, only that version and later versions are impacted. CWE-400 Uncontrolled Resource Consumption, CWE-20 Improper Input Validation, NVD-CWE-noinfo
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-25710 suppress
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-26308 suppress
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommended to upgrade to version 1.26, which fixes the issue. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
surefire-shared-utils-3.2.2.jarDescription:
Relocated Java packages of maven-shared-utils and several Apache Commons utilities in Surefire. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-shared-utils/3.2.2/surefire-shared-utils-3.2.2.jar
MD5: 0fdf4fe69c8bea86a52229d2d4bd27da
SHA1: ba20712df8e0f43832361428e9189705e1a50927
SHA256: f51e0ff777d36dd567cb7d129f8579ea7c2da03b4e81ef983e608bb4e11a200e
Evidence Type Source Name Value Confidence Vendor file name surefire-shared-utils High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-shared-utils Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Surefire Shared Utils High Vendor pom parent-artifactid surefire Low Product file name surefire-shared-utils High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Surefire Shared Utils High Product Manifest specification-title Surefire Shared Utils Medium Product pom artifactid surefire-shared-utils Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Surefire Shared Utils High Product pom parent-artifactid surefire Medium Version file version 3.2.2 High Version Manifest Implementation-Version 3.2.2 High Version pom version 3.2.2 Highest
CVE-2022-29599 suppress
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. CWE-116 Improper Encoding or Escaping of Output
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions:
surefire-shared-utils-3.2.3.jar (shaded: org.apache.commons:commons-compress:1.25.0)Description:
Apache Commons Compress defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
LZMA, XZ, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-shared-utils/3.2.3/surefire-shared-utils-3.2.3.jar/META-INF/maven/org.apache.commons/commons-compress/pom.xmlMD5: b9908114f28f6b709e5cc096d5038cbbSHA1: 334a8fd9c3120b359be7d70490cd6500bd35f7f8SHA256: ba5cda496643a906fcb77b1f13c5c7de817133c977a417e8a835fe28a6518ece
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email peterlee at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id peterlee Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Peter Alfred Lee Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email peterlee at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id peterlee Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Peter Alfred Lee Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version pom parent-version 1.25.0 Low Version pom version 1.25.0 Highest
CVE-2024-25710 suppress
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue. CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
CVE-2024-26308 suppress
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommended to upgrade to version 1.26, which fixes the issue. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:1.8/RC:R/MAV:A References:
Vulnerable Software & Versions:
surefire-shared-utils-3.2.3.jar (shaded: org.apache.commons:commons-lang3:3.14.0)Description:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-shared-utils/3.2.3/surefire-shared-utils-3.2.3.jar/META-INF/maven/org.apache.commons/commons-lang3/pom.xmlMD5: 05164a1ea756fd8307e72aeaf0f4097cSHA1: 063304d0daef2181ff359107bc29fb865a04d3cfSHA256: 110438863bad37c28f906bf87016e38c7a8c758ba321e09d11dc5a2363a8e79e
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version pom parent-version 3.14.0 Low Version pom version 3.14.0 Highest
CVE-2025-48924 suppress
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue. CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
surefire-shared-utils-3.2.3.jarDescription:
Relocated Java packages of maven-shared-utils and several Apache Commons utilities in Surefire. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/surefire/surefire-shared-utils/3.2.3/surefire-shared-utils-3.2.3.jar
MD5: 0fdeabc9106cfd1ccb237dbd506cb985
SHA1: eb6095975873d98dfbb16e768307f3bc1cc16617
SHA256: b63df8785c206268c7ea094aaa63869f0f78d64080eaf8695558818e05008468
Evidence Type Source Name Value Confidence Vendor file name surefire-shared-utils High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name shared Highest Vendor jar package name surefire Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid surefire-shared-utils Low Vendor pom groupid org.apache.maven.surefire Highest Vendor pom name Surefire Shared Utils High Vendor pom parent-artifactid surefire Low Product file name surefire-shared-utils High Product jar package name apache Highest Product jar package name maven Highest Product jar package name shared Highest Product jar package name surefire Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Surefire Shared Utils High Product Manifest specification-title Surefire Shared Utils Medium Product pom artifactid surefire-shared-utils Highest Product pom groupid org.apache.maven.surefire Highest Product pom name Surefire Shared Utils High Product pom parent-artifactid surefire Medium Version file version 3.2.3 High Version Manifest Implementation-Version 3.2.3 High Version pom version 3.2.3 Highest
CVE-2022-29599 suppress
In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. CWE-116 Improper Encoding or Escaping of Output
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:3.9/RC:R/MAV:A CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P References:
Vulnerable Software & Versions:
tab.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tab/tab.module.jsMD5: 166d2c2b882fdc1a78ca4cc9401b06c9SHA1: 9d791653303758ca503daacbf47ff2b704f7c74bSHA256: d60a7e778a06bef2513f8ea96e66fe1149076bf4a50a59a541ca61d4691a98cb
Evidence Type Source Name Value Confidence
tab.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tab/tab.module.min.jsMD5: 6c17ce001fa7987f74c9cf5cf4efeeabSHA1: 4a6cbcfa7b0f9a814fe04091c5a77ab6fcd03037SHA256: b1b6be5b1180f35989fc0e9c7453a1ce8c310012dc79c479dc35f88adf27f767
Evidence Type Source Name Value Confidence
tab.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tab/tab.nomodule.jsMD5: 360bdd00ec65e441c1966313e91bd3c2SHA1: c39eda551f22a20b3490b02da6a6660dbf0c8d66SHA256: 49883719b3f0eed83854ce966848999f72cf782ce9f21a626b1434224fda4262
Evidence Type Source Name Value Confidence
tab.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tab/tab.nomodule.min.jsMD5: ed8ce73857424ec57088a884b60dce74SHA1: 356e3bd3c9ec63e9183ed22c58f78f8a16585bf4SHA256: 175bbaa3d0eef8c7f9d40815d91f6d43f316c9d9c88ca7f5849dbb6a6cc25a2e
Evidence Type Source Name Value Confidence
table.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/table/table.module.jsMD5: 7af0e32ac6a8f4a121011554e80850a2SHA1: 213437ccbbc0e14219a5f5ca38570535eca94186SHA256: 09394fb0eebf4a7aab82a33499548310cf5dd154a5ff915141606e37620a5cf8
Evidence Type Source Name Value Confidence
table.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/table/table.module.min.jsMD5: fa718f3aa592203edfd3ed8b1fe9e003SHA1: f97ce313b1cb2031344352382300247dc829f7ccSHA256: f4f1fcd7f0331899345376d9fd308b83ef7ab44b21bbe6c54ba286d1df373085
Evidence Type Source Name Value Confidence
table.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/table/table.nomodule.jsMD5: aaca3692d72eaf36d1016c6bd88e7784SHA1: 840e7dcde9ea0c26bcfbc08e3d58cee9713dcc77SHA256: 41590e0798d0954728646e5d07bac106d1cc027cd2336e2fc303794d3dc631ae
Evidence Type Source Name Value Confidence
table.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/table/table.nomodule.min.jsMD5: 86e4b6815fa2f6fd9000c9a8ae47baeaSHA1: 98639b9a3fdfa96ef58f0c0feed933c940158e75SHA256: 900c1902e52d0e35bcf059afbb02ff4daec75c870a8d0157d0b434290c6c00fa
Evidence Type Source Name Value Confidence
tag.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tag/tag.module.jsMD5: ffaaa6aebbd9c16c500e3ce31daaacacSHA1: f22e01605a473078a0ac681bca9d70ac22e4b7b4SHA256: 8027a03832cc077668691590087fce0eb90eff619adb5903ff8d71a5a83a9392
Evidence Type Source Name Value Confidence
tag.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tag/tag.module.min.jsMD5: d60f432b009f1c7f52bce6368d6a7f45SHA1: eca97edbc28d14e733cc09eef67d986afd2adc8eSHA256: b3edf47b39beeafd1c1cf44dcaa4d3e2a81e27a8e43549ccd12ab640c4f10fef
Evidence Type Source Name Value Confidence
tag.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tag/tag.nomodule.jsMD5: 672fe28cbba7e813d5ec804092b0b00eSHA1: c964c6447664be4a5deb2ed52e555ecd819aba1cSHA256: c5ef0637c8d9b8938acda762ed418f15de219d7fc5992362486950bf1df918f7
Evidence Type Source Name Value Confidence
tag.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tag/tag.nomodule.min.jsMD5: 490ba66719c124aee172166dc5798436SHA1: 02f73764e8283f3ed8433a71b321a61409c45f95SHA256: de2556b125dda71411a443a2e365eff2444ac4f4b4f454c51043c02d6481f902
Evidence Type Source Name Value Confidence
tagsoup-1.2.1.jarDescription:
TagSoup is a SAX-compliant parser written in Java that, instead of parsing well-formed or valid XML, parses HTML as it is found in the wild: poor, nasty and brutish, though quite often far from short. TagSoup is designed for people who have to process this stuff using some semblance of a rational application design. By providing a SAX interface, it allows standard XML tools to be applied to even the worst HTML. TagSoup also includes a command-line processor that reads HTML files and can generate either clean HTML or well-formed XML that is a close approximation to XHTML. License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/ccil/cowan/tagsoup/tagsoup/1.2.1/tagsoup-1.2.1.jar
MD5: ae73a52cdcbec10cd61d9ef22fab5936
SHA1: 5584627487e984c03456266d3f8802eb85a9ce97
SHA256: ac97f7b4b1d8e9337edfa0e34044f8d0efe7223f6ad8f3a85d54cc1018ea2e04
Evidence Type Source Name Value Confidence Vendor file name tagsoup High Vendor jar package name ccil Highest Vendor jar package name cowan Highest Vendor jar package name parser Highest Vendor jar package name tagsoup Highest Vendor pom artifactid tagsoup Low Vendor pom developer name John Cowan Medium Vendor pom groupid org.ccil.cowan.tagsoup Highest Vendor pom name TagSoup High Vendor pom url http://home.ccil.org/~cowan/XML/tagsoup/ Highest Product file name tagsoup High Product jar package name ccil Highest Product jar package name cowan Highest Product jar package name parser Highest Product jar package name tagsoup Highest Product pom artifactid tagsoup Highest Product pom developer name John Cowan Low Product pom groupid org.ccil.cowan.tagsoup Highest Product pom name TagSoup High Product pom url http://home.ccil.org/~cowan/XML/tagsoup/ Medium Version file version 1.2.1 High Version Manifest version 1.2.1 Medium Version pom version 1.2.1 Highest
pkg:maven/org.ccil.cowan.tagsoup/tagsoup@1.2.1 (Confidence :High) testcontainers-1.21.3.jarDescription:
Isolated container management for Java code testing License:
MIT: http://opensource.org/licenses/MIT File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/testcontainers/testcontainers/1.21.3/testcontainers-1.21.3.jar
MD5: d7c7e2994e324e29f981fad6e18e8e61
SHA1: aa3e792d2cf4598019933c42f1cfa55bd608ce8b
SHA256: ef934ddac6f42759d71c303a2844544a56cf381b33437149955d3d8c992bec5d
Evidence Type Source Name Value Confidence Vendor file name testcontainers High Vendor jar package name container Highest Vendor jar package name core Highest Vendor jar package name org Highest Vendor jar package name testcontainers Highest Vendor pom artifactid testcontainers Low Vendor pom developer email rich.north@gmail.com Low Vendor pom developer id rnorth Medium Vendor pom developer name Richard North Medium Vendor pom groupid org.testcontainers Highest Vendor pom name Testcontainers Core High Vendor pom url https://java.testcontainers.org Highest Product file name testcontainers High Product jar package name container Highest Product jar package name core Highest Product jar package name org Highest Product jar package name testcontainers Highest Product pom artifactid testcontainers Highest Product pom developer email rich.north@gmail.com Low Product pom developer id rnorth Low Product pom developer name Richard North Low Product pom groupid org.testcontainers Highest Product pom name Testcontainers Core High Product pom url https://java.testcontainers.org Medium Version file version 1.21.3 High Version Manifest Implementation-Version 1.21.3 High Version pom version 1.21.3 Highest
pkg:maven/org.testcontainers/testcontainers@1.21.3 (Confidence :High) tests-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/tests/target/tests-3.0.7.jarMD5: b3e812ab1e11e2e2f89caee2a1792affSHA1: 6a1b680c7ca31813cf1654fd64e1ded41afc8b50SHA256: c9e5ccc3fc1bf83dc326041c3be71b07dc29397fa6427d4d93417e527a8d9246
Evidence Type Source Name Value Confidence Vendor file name tests High Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid tests Low Vendor pom groupid fr.numeco Highest Vendor pom parent-artifactid misis-backend-parent Low Vendor pom parent-groupid fr.gouv.misis Medium Product file name tests High Product Manifest build-jdk-spec 21 Low Product pom artifactid tests Highest Product pom groupid fr.numeco Highest Product pom parent-artifactid misis-backend-parent Medium Product pom parent-groupid fr.gouv.misis Medium Version file version 3.0.7 High Version pom version 3.0.7 Highest
pkg:maven/fr.numeco/tests@3.0.7 (Confidence :High) tile.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tile/tile.module.jsMD5: a90ff1a5c2651a4b688cef62711261feSHA1: f64d5fa083985fd48ea08d9ec6c86d6f2edbbfbcSHA256: 8a8feca0b64b5500b45dd49a0adf446906e452200d5a9fd8d41a3042e2361f8f
Evidence Type Source Name Value Confidence
tile.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tile/tile.module.min.jsMD5: 196e651c43c9d74db5e3ff2af60e1fe1SHA1: b645e760b28ba0c330ac31f0f40af2b5791a4e3dSHA256: 746035acda40737902f48f97663f3b300dd4e889d1858f82b5f02d2085435877
Evidence Type Source Name Value Confidence
tile.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tile/tile.nomodule.jsMD5: 8299e602102b4510919acc7e4b55e759SHA1: f17a10cbffce3a8e84fbb4d20f561d02b131671eSHA256: d22a22169c4326dd038dd78f85c4bc1004b9f4990817894b8f0d79d292c8a2e1
Evidence Type Source Name Value Confidence
tile.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tile/tile.nomodule.min.jsMD5: 8ae366ae585a037c17212311720cba8fSHA1: 3e19d9fb65da55849b7611a17207f2a495dbe55dSHA256: 8819c5ecde62e1517f62db48d9a327308aec00f791698b5b87a3be43111498f3
Evidence Type Source Name Value Confidence
toggle.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/toggle/toggle.module.jsMD5: 309b96f0531d9b68beadb0f36e126ec9SHA1: a66101d0dfdfa5f4ea75d266eef4b5bc722b936aSHA256: 74be836fdce6505d5ae00137a7494ede882704e47a7870554abf36c86e342c31
Evidence Type Source Name Value Confidence
toggle.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/toggle/toggle.module.min.jsMD5: 05daf10ced1279054d6a1038e10d03beSHA1: a49cb75f884b9a2049885ccad33da0b79f326fd8SHA256: 0f0ebe597afb615ff1bcbb08430422a662ca46aa14e0f7e7df0f82a4e005c90d
Evidence Type Source Name Value Confidence
toggle.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/toggle/toggle.nomodule.jsMD5: 493ac25331aac8ce44bf3aa3021ead05SHA1: 7a23d187b81540dae63c118a39cfc382d13331a4SHA256: 38db368b2c549a02cdfbb1dc72e9483ba25e64f948f239f41b9338d87c467517
Evidence Type Source Name Value Confidence
toggle.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/toggle/toggle.nomodule.min.jsMD5: 4353ad2393606bf4ee1d204868129f58SHA1: 45f14b0b4bb9251a1f939212308d4e280c85cc21SHA256: 9eae528d6e8f9e6f6747afca5aad1e76530ed512b20c4edd79b825722eb81cd8
Evidence Type Source Name Value Confidence
tooltip.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tooltip/tooltip.module.jsMD5: abf7b9a8b1d12313c33b2224ad69f51bSHA1: 86a1582b2863fff63f11bb3868a190492b167efeSHA256: 1bfecbbe795beedf23c1ad50a6e60d7d75893f7e85515273afc28279bbdbdb97
Evidence Type Source Name Value Confidence
tooltip.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tooltip/tooltip.module.min.jsMD5: ee98fd691b8824ee46887391d9d58600SHA1: 956f74a634489a82a0629e640d7d0e4146a5d49eSHA256: 4ee88286a5163fa4721ace24313c30794524064f1f389e23f2029cc2b969579b
Evidence Type Source Name Value Confidence
tooltip.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tooltip/tooltip.nomodule.jsMD5: 08f124639c6c4780c69949d2907e974dSHA1: cf86d82b6d4fa5420df76b5b573669cc8be62932SHA256: 9e58e026935ed3d52bf781ba1e5f4d11b93426691f6a8266e31ab1fc610f85f6
Evidence Type Source Name Value Confidence
tooltip.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/tooltip/tooltip.nomodule.min.jsMD5: 778b39643d4763d6e7ca07c14e231edcSHA1: 530aef30cb38cd8da9a792ebf11cc6fa0ab29893SHA256: a91db422bfe089979858a75bcb8ea109a9d3b622f07eaaba45a2ed6fece76848
Evidence Type Source Name Value Confidence
transcription.module.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/transcription/transcription.module.jsMD5: 0eb8a2e872e4ba2fd208a1b4e52a816dSHA1: b2d5eb569980cda34dc1832dcbaccbfab8014501SHA256: cb3bd78b9814a15712e5c571d8d9d17830ebc878d1a299ad7447f56e47d24d10
Evidence Type Source Name Value Confidence
transcription.module.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/transcription/transcription.module.min.jsMD5: e7eaf33855668f1480995d3512144ed8SHA1: 69ced78f8659c290ee8f341d08b83fb6c390c79eSHA256: 8782b14ba29e90c3669f04c2d6bf912517354813a44ca78d80b618fbd8021185
Evidence Type Source Name Value Confidence
transcription.nomodule.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/transcription/transcription.nomodule.jsMD5: 9e3348cbc67f1a3893f2ace3527ad9fcSHA1: 2de45ca31a9635679371ff7cc3eb792a2745353fSHA256: 898da4772e73898a247fa9fa14e7ffd03bb6d28d91348878176eb23cebf49f3a
Evidence Type Source Name Value Confidence
transcription.nomodule.min.jsFile Path: /builds/pub/numeco/misis/misis-backend/keycloak-init/misis/login/resources/css/component/transcription/transcription.nomodule.min.jsMD5: 2ac0b8af0e6489b8e0340993da380604SHA1: 6b8c6586a2ae752c19d16e2c0dc7dd1a8f9be52eSHA256: 05e2a1c08b3e9bb5e2dfbf22f31042d525971610f0dbeea06927ee97a5e72c17
Evidence Type Source Name Value Confidence
transformed-bytecode.jarFile Path: /builds/pub/numeco/misis/misis-backend/analyzer/target/quarkus-app/quarkus/transformed-bytecode.jarMD5: c265e44fd6be1384954567116828760aSHA1: f022310aa51e49ef7654a709a169ac7283ccbfbcSHA256: ba359e2afa9ee00bebb78ee0ad2fe4628571ac04b979ecad721a27b0ecb6ebd7
Evidence Type Source Name Value Confidence Vendor file name transformed-bytecode High Vendor jar package name fr Low Vendor jar package name misis Low Vendor jar package name numeco Low Product file name transformed-bytecode High Product jar package name core Low Product jar package name misis Low Product jar package name numeco Low
transformed-bytecode.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/quarkus/transformed-bytecode.jarMD5: 257df51b879e2da9b4577fb13b9e1abdSHA1: f8e1ffabde300f65b8b4643247d0b5085962d687SHA256: f55775dbebdada072e636a798f83584d05e5e83b7128c051b9b7a8d7945eceed
Evidence Type Source Name Value Confidence Vendor file name transformed-bytecode High Vendor jar package name fr Low Vendor jar package name misis Low Vendor jar package name numeco Low Product file name transformed-bytecode High Product jar package name core Low Product jar package name misis Low Product jar package name numeco Low
vertx-web-common-4.5.23.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/vertx/vertx-web-common/4.5.23/vertx-web-common-4.5.23.jarMD5: 36f7bd7a0281881b446101e5f4d21474SHA1: 8f043782d643441ad50f4cfd3aa0e71728d6dbd2SHA256: e2c04fc9a4914af93e50728878c3b59afcacba2365fa92adf193e33ece44e51a
Evidence Type Source Name Value Confidence Vendor file name vertx-web-common High Vendor jar package name io Highest Vendor jar package name vertx Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name io.vertx.web.common Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor Eclipse High Vendor Manifest maven-artifact-id vertx-web-common Low Vendor Manifest specification-vendor Eclipse Low Vendor pom artifactid vertx-web-common Low Vendor pom groupid io.vertx Highest Vendor pom name Vert.x Web Common High Vendor pom parent-artifactid vertx-web-parent Low Product file name vertx-web-common High Product jar package name io Highest Product jar package name vertx Highest Product jar package name web Highest Product Manifest automatic-module-name io.vertx.web.common Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Vert.x Web Common High Product Manifest maven-artifact-id vertx-web-common Low Product Manifest specification-title Vert.x Web Common Medium Product pom artifactid vertx-web-common Highest Product pom groupid io.vertx Highest Product pom name Vert.x Web Common High Product pom parent-artifactid vertx-web-parent Medium Version file version 4.5.23 High Version Manifest Implementation-Version 4.5.23 High Version Manifest maven-version 4.5.23 Medium Version pom version 4.5.23 Highest
Related Dependencies io.vertx.vertx-web-common-4.5.23.jar (shaded: io.vertx:vertx-web-common:4.5.23)File Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/lib/main/io.vertx.vertx-web-common-4.5.23.jar/META-INF/maven/io.vertx/vertx-web-common/pom.xml MD5: 2334763770ac0162f3b53a475f6e34ad SHA1: 9be1eb99322f24455463fd4197d16450a8770976 SHA256: adae90613fa0f8bcc39cfe727a9eff9b19633bb3d6718c7615a1186ba554609b pkg:maven/io.vertx/vertx-web-common@4.5.23 wagon-file-3.5.3.jarDescription:
Wagon provider that gets and puts artifacts using file system protocol
File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/wagon/wagon-file/3.5.3/wagon-file-3.5.3.jarMD5: 49ed6c95eb28e434ea5c3c9b0ea0fde4SHA1: a09f59be3767dbff0401828463d1752a9cb0c551SHA256: afc9216fa97b78dad227b4a8d4d67b9897bf113a57f80598d62993841113e103
Evidence Type Source Name Value Confidence Vendor file name wagon-file High Vendor jar package name apache Highest Vendor jar package name maven Highest Vendor jar package name providers Highest Vendor jar package name wagon Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid wagon-file Low Vendor pom groupid org.apache.maven.wagon Highest Vendor pom name Apache Maven Wagon :: Providers :: File Provider High Vendor pom parent-artifactid wagon-providers Low Product file name wagon-file High Product jar package name apache Highest Product jar package name maven Highest Product jar package name providers Highest Product jar package name wagon Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache Maven Wagon :: Providers :: File Provider High Product Manifest specification-title Apache Maven Wagon :: Providers :: File Provider Medium Product pom artifactid wagon-file Highest Product pom groupid org.apache.maven.wagon Highest Product pom name Apache Maven Wagon :: Providers :: File Provider High Product pom parent-artifactid wagon-providers Medium Version file version 3.5.3 High Version Manifest Implementation-Version 3.5.3 High Version pom version 3.5.3 Highest
Related Dependencies wagon-http-3.5.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/wagon/wagon-http/3.5.3/wagon-http-3.5.3.jar MD5: 1b072be9b74336ec923d533c4370e1f4 SHA1: 673d54e78f83c4700c8250a48c61f4c70eef9bc3 SHA256: d2b6e48c9fcbe579e1858c622d14464011ff265fa6e28e794004a6882154a509 pkg:maven/org.apache.maven.wagon/wagon-http@3.5.3 wagon-http-shared-3.5.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/wagon/wagon-http-shared/3.5.3/wagon-http-shared-3.5.3.jar MD5: 68b5b8fd16b284b9c7001fc151025c80 SHA1: 635c3d5718a70e3ecfd78f2fef99bb6e0abaed58 SHA256: 8e7da766f55164fde8779aaaa125832506c2848cab4876b5305138873e28037f pkg:maven/org.apache.maven.wagon/wagon-http-shared@3.5.3 wagon-provider-api-3.5.3.jarFile Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/apache/maven/wagon/wagon-provider-api/3.5.3/wagon-provider-api-3.5.3.jar MD5: 55a4be47ca51799ae3c18ed521f296df SHA1: 39c44ebb3945dee359665272d8acb83f9460491b SHA256: 5e72000338945ed3e96f8e4f578d1d0672e1af7e19c0e9014197ae5b31af3ef4 pkg:maven/org.apache.maven.wagon/wagon-provider-api@3.5.3 webapp-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/quarkus-app/app/webapp-3.0.7.jarMD5: 5a5b703abf1a5d0207fa3268dacd7bb1SHA1: 8834c33a32725b198b8e6292f576ffc735155395SHA256: fcd00d5d34161250207230973c131bce430f3ade8ac2676a9fa08d6c70725950
Evidence Type Source Name Value Confidence Vendor file name webapp High Vendor jar package name fr Low Vendor jar package name misis Low Vendor jar package name numeco Low Product file name webapp High Product jar package name misis Low Product jar package name numeco Low Version file name webapp Medium Version file version 3.0.7 High
webapp-3.0.7.jarFile Path: /builds/pub/numeco/misis/misis-backend/webapp/target/webapp-3.0.7.jarMD5: 88e985d8a80ac8ad853961ccd901460eSHA1: a16627984a41b5d1707b1477b75f055879c64ba7SHA256: 2d8259e49e231c820c688f9b1759396bcb37421582e1d986898fd460a395412c
Evidence Type Source Name Value Confidence Vendor file name webapp High Vendor jar package name fr Highest Vendor jar package name misis Highest Vendor Manifest build-jdk-spec 21 Low Vendor pom artifactid webapp Low Vendor pom groupid fr.gouv.misis Highest Vendor pom parent-artifactid misis-backend-parent Low Product file name webapp High Product jar package name fr Highest Product jar package name misis Highest Product Manifest build-jdk-spec 21 Low Product pom artifactid webapp Highest Product pom groupid fr.gouv.misis Highest Product pom parent-artifactid misis-backend-parent Medium Version file version 3.0.7 High Version pom version 3.0.7 Highest
pkg:maven/fr.gouv.misis/webapp@3.0.7 (Confidence :High) woodstox-core-7.1.1.jar (shaded: com.sun.xml.bind.jaxb:isorelax:20090621)Description:
Unknown version of isorelax library used in JAXB project File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/woodstox/woodstox-core/7.1.1/woodstox-core-7.1.1.jar/META-INF/maven/com.sun.xml.bind.jaxb/isorelax/pom.xmlMD5: 6fbb4bc95fbf2072bc6e3b790553fe81SHA1: 314ec72948d5c1fc71d553cbbd7a130caa6f9f13SHA256: cda6451d0231a973352b592ff950e39224ba6ba1a2f35eeab66511b5c225dff1
Evidence Type Source Name Value Confidence Vendor pom artifactid isorelax Low Vendor pom groupid com.sun.xml.bind.jaxb Highest Vendor pom name JAXB isorelax library High Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Product pom artifactid isorelax Highest Product pom groupid com.sun.xml.bind.jaxb Highest Product pom name JAXB isorelax library High Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Version pom parent-version 20090621 Low Version pom version 20090621 Highest
pkg:maven/com.sun.xml.bind.jaxb/isorelax@20090621 (Confidence :High) woodstox-core-7.1.1.jar (shaded: net.java.dev.msv:xsdlib:2022.7)Description:
XML Schema datatypes library License:
BSD File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/woodstox/woodstox-core/7.1.1/woodstox-core-7.1.1.jar/META-INF/maven/net.java.dev.msv/xsdlib/pom.xml
MD5: f82c4c4c46c8a27ee68f031373064bf9
SHA1: 1b9b8fe3901f3556ed99a477af66f0f645c16cf0
SHA256: 8649b880ac5dbb3549022c40eff4053930ea209c4aaf998925fb3d6dd75fb6c3
Evidence Type Source Name Value Confidence Vendor pom artifactid xsdlib Low Vendor pom groupid net.java.dev.msv Highest Vendor pom name MSV XML Schema Datatype Library High Vendor pom parent-artifactid msv Low Product pom artifactid xsdlib Highest Product pom groupid net.java.dev.msv Highest Product pom name MSV XML Schema Datatype Library High Product pom parent-artifactid msv Medium Version pom version 2022.7 Highest
pkg:maven/net.java.dev.msv/xsdlib@2022.7 (Confidence :High) cpe:2.3:a:xml_library_project:xml_library:2022.7:*:*:*:*:*:*:* (Confidence :Low) suppress woodstox-core-7.1.1.jarDescription:
Woodstox is a high-performance XML processor that implements Stax (JSR-173),
SAX2 and Stax2 APIs
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/fasterxml/woodstox/woodstox-core/7.1.1/woodstox-core-7.1.1.jar
MD5: 971ff236679f7b35a7c13c0d02c0170e
SHA1: 76baad1b94513ea896e0a17388890a4c81edd0e0
SHA256: 02b9d022e9d47704ff8a7a859a0dbfd3b2882a8311eb7ff1e180f760ccda2712
Evidence Type Source Name Value Confidence Vendor file name woodstox-core High Vendor jar package name stax Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/woodstox Low Vendor Manifest bundle-symbolicname com.fasterxml.woodstox.woodstox-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.woodstox Medium Vendor Manifest provide-capability osgi.service;objectClass:List="javax.xml.stream.XMLEventFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLInputFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLOutputFactory";effective:=active,osgi.service;objectClass:List="org.codehaus.stax2.validation.XMLValidationSchemaFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLEventFactory";register:="com.ctc.wstx.stax.WstxEventFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLInputFactory";register:="com.ctc.wstx.stax.WstxInputFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLOutputFactory";register:="com.ctc.wstx.stax.WstxOutputFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.dtd.DTDSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.RelaxNGSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.W3CSchemaFactory" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid woodstox-core Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id cowtowncoder Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid com.fasterxml.woodstox Highest Vendor pom name Woodstox High Vendor pom organization name FasterXML High Vendor pom organization url http://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom parent-groupid com.fasterxml Medium Vendor pom url FasterXML/woodstox Highest Product file name woodstox-core High Product jar package name dtd Highest Product jar package name dtdschemafactory Highest Product jar package name msv Highest Product jar package name osgi Highest Product jar package name relaxngschemafactory Highest Product jar package name stax Highest Product jar package name w3cschemafactory Highest Product jar package name wstx Highest Product jar package name wstxeventfactory Highest Product jar package name wstxinputfactory Highest Product jar package name wstxoutputfactory Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://github.com/FasterXML/woodstox Low Product Manifest Bundle-Name Woodstox Medium Product Manifest bundle-symbolicname com.fasterxml.woodstox.woodstox-core Medium Product Manifest Implementation-Title Woodstox High Product Manifest provide-capability osgi.service;objectClass:List="javax.xml.stream.XMLEventFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLInputFactory";effective:=active,osgi.service;objectClass:List="javax.xml.stream.XMLOutputFactory";effective:=active,osgi.service;objectClass:List="org.codehaus.stax2.validation.XMLValidationSchemaFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLEventFactory";register:="com.ctc.wstx.stax.WstxEventFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLInputFactory";register:="com.ctc.wstx.stax.WstxInputFactory",osgi.serviceloader;osgi.serviceloader="javax.xml.stream.XMLOutputFactory";register:="com.ctc.wstx.stax.WstxOutputFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.dtd.DTDSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.RelaxNGSchemaFactory",osgi.serviceloader;osgi.serviceloader="org.codehaus.stax2.validation.XMLValidationSchemaFactory";register:="com.ctc.wstx.msv.W3CSchemaFactory" Low Product Manifest specification-title Woodstox Medium Product pom artifactid woodstox-core Highest Product pom developer email tatu@fasterxml.com Low Product pom developer id cowtowncoder Low Product pom developer name Tatu Saloranta Low Product pom groupid com.fasterxml.woodstox Highest Product pom name Woodstox High Product pom organization name FasterXML Low Product pom organization url http://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom parent-groupid com.fasterxml Medium Product pom url FasterXML/woodstox High Version file version 7.1.1 High Version Manifest Bundle-Version 7.1.1 High Version Manifest Implementation-Version 7.1.1 High Version pom parent-version 7.1.1 Low Version pom version 7.1.1 Highest
word-23.1.2.jarDescription:
A low-level framework for machine-word-sized values in Java. License:
Universal Permissive License, Version 1.0: http://opensource.org/licenses/UPL File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/graalvm/sdk/word/23.1.2/word-23.1.2.jar
MD5: c850fa025977c8e3561fdcee911dbd9e
SHA1: 9dfd386a63750f33e848086317e19a01e9ed7eb8
SHA256: 2ae7a71ff3f53f61d1d7360a6152f67ce3902ae86ca22b30b70208dc0cf4e039
Evidence Type Source Name Value Confidence Vendor file name word High Vendor jar package name graalvm Highest Vendor jar package name graalvm Low Vendor jar package name word Highest Vendor jar package name word Low Vendor pom artifactid word Low Vendor pom developer email graalvm-dev@oss.oracle.com Low Vendor pom developer name GraalVM Development Medium Vendor pom developer org Oracle Corporation Medium Vendor pom developer org URL http://www.graalvm.org/ Medium Vendor pom groupid org.graalvm.sdk Highest Vendor pom name Word High Vendor pom url oracle/graal Highest Product file name word High Product jar package name graalvm Highest Product jar package name word Highest Product jar package name word Low Product pom artifactid word Highest Product pom developer email graalvm-dev@oss.oracle.com Low Product pom developer name GraalVM Development Low Product pom developer org Oracle Corporation Low Product pom developer org URL http://www.graalvm.org/ Low Product pom groupid org.graalvm.sdk Highest Product pom name Word High Product pom url oracle/graal High Version file version 23.1.2 High Version pom version 23.1.2 Highest
pkg:maven/org.graalvm.sdk/word@23.1.2 (Confidence :High) xml-path-5.5.6.jarDescription:
Java DSL for easy testing of REST services License:
https://www.apache.org/licenses/LICENSE-2.0.html File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/io/rest-assured/xml-path/5.5.6/xml-path-5.5.6.jar
MD5: de8d4f799784e42058e798a389fd56e1
SHA1: 0f05b964e3a2eea738a254f1c44d5dbba0ca57b1
SHA256: 7e87fea7d7e51fc033052d72d08150ad46fcaffdf3ed7558a62c3e2c95e89585
Evidence Type Source Name Value Confidence Vendor file name xml-path High Vendor jar package name io Highest Vendor jar package name path Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname io.rest-assured.xml-path Medium Vendor pom artifactid xml-path Low Vendor pom groupid io.rest-assured Highest Vendor pom name xml-path High Vendor pom parent-artifactid rest-assured-parent Low Product file name xml-path High Product jar package name io Highest Product jar package name path Highest Product jar package name xml Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name xml-path Medium Product Manifest bundle-symbolicname io.rest-assured.xml-path Medium Product pom artifactid xml-path Highest Product pom groupid io.rest-assured Highest Product pom name xml-path High Product pom parent-artifactid rest-assured-parent Medium Version file version 5.5.6 High Version Manifest Bundle-Version 5.5.6 High Version pom version 5.5.6 Highest
pkg:maven/io.rest-assured/xml-path@5.5.6 (Confidence :High) xmlpull-1.1.3.1.jarLicense:
Public Domain: http://www.xmlpull.org/v1/download/unpacked/LICENSE.txt File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/xmlpull/xmlpull/1.1.3.1/xmlpull-1.1.3.1.jar
MD5: cc57dacc720eca721a50e78934b822d2
SHA1: 2b8e230d2ab644e4ecaa94db7cdedbc40c805dfa
SHA256: 34e08ee62116071cbb69c0ed70d15a7a5b208d62798c59f2120bb8929324cb63
Evidence Type Source Name Value Confidence Vendor file name xmlpull High Vendor jar package name v1 Low Vendor jar package name xmlpull Highest Vendor jar package name xmlpull Low Vendor pom artifactid xmlpull Low Vendor pom groupid xmlpull Highest Vendor pom name XML Pull Parsing API High Vendor pom url http://www.xmlpull.org Highest Product file name xmlpull High Product jar package name v1 Low Product jar package name xmlpull Highest Product pom artifactid xmlpull Highest Product pom groupid xmlpull Highest Product pom name XML Pull Parsing API High Product pom url http://www.xmlpull.org Medium Version file version 1.1.3.1 High Version pom version 1.1.3.1 Highest
pkg:maven/xmlpull/xmlpull@1.1.3.1 (Confidence :High) xstream-1.4.20.jarDescription:
XStream is a serialization library from Java objects to XML and back. License:
BSD-3-Clause File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/com/thoughtworks/xstream/xstream/1.4.20/xstream-1.4.20.jar
MD5: 1e816f33b1eb780a309789478051faeb
SHA1: 0e2315b8b2e95e9f21697833c8e56cdd9c98a5ee
SHA256: 87df0f0be57c92037d0110fbb225a30b651702dc275653d285afcfef31bc2e81
Evidence Type Source Name Value Confidence Vendor file name xstream High Vendor jar package name core Highest Vendor jar package name thoughtworks Highest Vendor jar package name xstream Highest Vendor Manifest bundle-docurl http://x-stream.github.io Low Vendor Manifest bundle-symbolicname xstream Medium Vendor Manifest Implementation-Vendor XStream High Vendor Manifest Implementation-Vendor-Id com.thoughtworks.xstream Medium Vendor Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Vendor Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Vendor Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Vendor Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Vendor Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Vendor Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Vendor Manifest specification-vendor XStream Low Vendor Manifest x-build-os Linux Low Vendor Manifest x-build-time 2022-12-23T23:21:05Z Low Vendor Manifest x-builder Maven 3.8.6 Low Vendor Manifest x-compile-source 1.4 Low Vendor Manifest x-compile-target 1.4 Low Vendor pom artifactid xstream Low Vendor pom groupid com.thoughtworks.xstream Highest Vendor pom name XStream Core High Vendor pom parent-artifactid xstream-parent Low Product file name xstream High Product jar package name core Highest Product jar package name io Highest Product jar package name thoughtworks Highest Product jar package name xml Highest Product jar package name xstream Highest Product Manifest bundle-docurl http://x-stream.github.io Low Product Manifest Bundle-Name XStream Core Medium Product Manifest bundle-symbolicname xstream Medium Product Manifest Implementation-Title XStream Core High Product Manifest java_1_4_home /opt/blackdown-jdk-1.4.2.03 Low Product Manifest java_1_5_home /opt/sun-jdk-1.5.0.22 Low Product Manifest java_1_6_home /opt/sun-jdk-1.6.0.45 Low Product Manifest java_1_7_home /opt/oracle-jdk-bin-1.7.0.80 Low Product Manifest java_1_8_home /opt/oracle-jdk-bin-1.8.0.202 Low Product Manifest java_9_home /opt/oracle-jdk-bin-9.0.4 Low Product Manifest specification-title XStream Core Medium Product Manifest x-build-os Linux Low Product Manifest x-build-time 2022-12-23T23:21:05Z Low Product Manifest x-builder Maven 3.8.6 Low Product Manifest x-compile-source 1.4 Low Product Manifest x-compile-target 1.4 Low Product pom artifactid xstream Highest Product pom groupid com.thoughtworks.xstream Highest Product pom name XStream Core High Product pom parent-artifactid xstream-parent Medium Version file version 1.4.20 High Version Manifest Bundle-Version 1.4.20 High Version Manifest Implementation-Version 1.4.20 High Version pom version 1.4.20 Highest
xz-1.9.jarDescription:
XZ data compression License:
Public Domain File Path: /builds/pub/numeco/misis/misis-backend/.m2/repository/org/tukaani/xz/1.9/xz-1.9.jar
MD5: 57c2fbfeb55e307ccae52e5322082e02
SHA1: 1ea4bec1a921180164852c65006d928617bd2caf
SHA256: 211b306cfc44f8f96df3a0a3ddaf75ba8c5289eed77d60d72f889bb855f535e5
Evidence Type Source Name Value Confidence Vendor file name xz High Vendor jar package name tukaani Highest Vendor jar package name xz Highest Vendor Manifest bundle-docurl https://tukaani.org/xz/java.html Low Vendor Manifest bundle-symbolicname org.tukaani.xz Medium Vendor Manifest implementation-url https://tukaani.org/xz/java.html Low Vendor Manifest multi-release true Low Vendor pom artifactid xz Low Vendor pom developer email lasse.collin@tukaani.org Low Vendor pom developer name Lasse Collin Medium Vendor pom groupid org.tukaani Highest Vendor pom name XZ for Java High Vendor pom url https://tukaani.org/xz/java.html Highest Product file name xz High Product jar package name tukaani Highest Product jar package name xz Highest Product Manifest bundle-docurl https://tukaani.org/xz/java.html Low Product Manifest Bundle-Name XZ data compression Medium Product Manifest bundle-symbolicname org.tukaani.xz Medium Product Manifest Implementation-Title XZ data compression High Product Manifest implementation-url https://tukaani.org/xz/java.html Low Product Manifest multi-release true Low Product pom artifactid xz Highest Product pom developer email lasse.collin@tukaani.org Low Product pom developer name Lasse Collin Low Product pom groupid org.tukaani Highest Product pom name XZ for Java High Product pom url https://tukaani.org/xz/java.html Medium Version file version 1.9 High Version Manifest Bundle-Version 1.9 High Version Manifest Implementation-Version 1.9 High Version pom version 1.9 Highest
pkg:maven/org.tukaani/xz@1.9 (Confidence :High)