Skip to content

Update dependency mysql:mysql-connector-java to v8

c55957f
Select commit
Loading
Failed to load commit list.
Open

Update dependency mysql:mysql-connector-java to v8 #29

Update dependency mysql:mysql-connector-java to v8
c55957f
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jun 30, 2025 in 2m 14s

Security Report

You have successfully remediated 8 vulnerabilities, but introduced 7 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue Reachability
CVE-2022-3510

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

High 7.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-javalite:3.19.6 None

Unreachable

CVE-2022-3509

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

High 7.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-javalite:3.21.7 None

Unreachable

CVE-2021-22569

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

High 7.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-java:3.19.2 None

Unreachable

CVE-2021-22570

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

Medium 6.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-java:3.15.0 None

Unreachable

CVE-2021-2471

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/8.0.16/mysql-connector-java-8.0.16.jar

Dependency Hierarchy:

-> ❌ mysql-connector-java-8.0.16.jar (Vulnerable Library)

Medium 5.9 mysql-connector-java-8.0.16.jar Upgrade to version: mysql:mysql-connector-java:8.0.27 None

Unreachable

CVE-2020-2934

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/8.0.16/mysql-connector-java-8.0.16.jar

Dependency Hierarchy:

-> ❌ mysql-connector-java-8.0.16.jar (Vulnerable Library)

Medium 5.0 mysql-connector-java-8.0.16.jar Upgrade to version: mysql:mysql-connector-java:5.1.49,8.0.20 None

Unreachable

CVE-2022-3171

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

Medium 4.3 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-javalite:3.21.7 None

Unreachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-2875 mysql-connector-java-5.1.24.jar
CVE-2020-2934 mysql-connector-java-5.1.24.jar
CVE-2018-3258 mysql-connector-java-5.1.24.jar
CVE-2017-3586 mysql-connector-java-5.1.24.jar
CVE-2017-3589 mysql-connector-java-5.1.24.jar
CVE-2020-2933 mysql-connector-java-5.1.24.jar
CVE-2017-3523 mysql-connector-java-5.1.24.jar
CVE-2019-2692 mysql-connector-java-5.1.24.jar

Base branch total remaining vulnerabilities: 26
Base branch commit: null


Total libraries scanned: 20

Scan token: 21308bf312e846ccbb43958322f2017f