Skip to content

Update dependency org.apache.sling:maven-sling-plugin to v2.2.0

4fe08fd
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.apache.sling:maven-sling-plugin to v2.2.0 #43

Update dependency org.apache.sling:maven-sling-plugin to v2.2.0
4fe08fd
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jun 30, 2025 in 19m 54s

Security Report

You have successfully remediated 12 vulnerabilities, but introduced 14 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue Reachability
WS-2021-0616

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.11.0/jackson-databind-2.11.0.jar

Dependency Hierarchy:

-> spring-boot-starter-web-2.3.1.RELEASE.jar (Root Library)

   -> spring-boot-starter-json-2.3.1.RELEASE.jar

     -> ❌ jackson-databind-2.11.0.jar (Vulnerable Library)

Medium 5.9 jackson-databind-2.11.0.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 #36

Reachable

CVE-2022-29599

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/maven/shared/maven-shared-utils/0.7/maven-shared-utils-0.7.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> ❌ maven-shared-utils-0.7.jar (Vulnerable Library)

Critical 9.8 maven-shared-utils-0.7.jar Upgrade to version: org.apache.maven.shared:maven-shared-utils:3.3.3 None

Unreachable

CVE-2022-4244

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> maven-artifact-2.2.1.jar

       -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library)

High 7.5 plexus-utils-3.0.20.jar Upgrade to version: org.codehaus.plexus:plexus-utils:3.0.24 None

Unreachable

CVE-2021-36090

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> plexus-archiver-2.8.1.jar

       -> ❌ commons-compress-1.9.jar (Vulnerable Library)

High 7.5 commons-compress-1.9.jar Upgrade to version: org.apache.commons:commons-compress:1.21 None

Unreachable

CVE-2021-35517

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> plexus-archiver-2.8.1.jar

       -> ❌ commons-compress-1.9.jar (Vulnerable Library)

High 7.5 commons-compress-1.9.jar Upgrade to version: org.apache.commons:commons-compress:1.21 None

Unreachable

CVE-2021-35516

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> plexus-archiver-2.8.1.jar

       -> ❌ commons-compress-1.9.jar (Vulnerable Library)

High 7.5 commons-compress-1.9.jar Upgrade to version: org.apache.commons:commons-compress:1.21 None

Unreachable

CVE-2021-35515

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> plexus-archiver-2.8.1.jar

       -> ❌ commons-compress-1.9.jar (Vulnerable Library)

High 7.5 commons-compress-1.9.jar Upgrade to version: org.apache.commons:commons-compress:1.21 None

Unreachable

CVE-2015-1833

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/jackrabbit/jackrabbit-webdav/1.5.0/jackrabbit-webdav-1.5.0.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> maven-core-2.2.1.jar

       -> wagon-webdav-jackrabbit-1.0-beta-6.jar

         -> ❌ jackrabbit-webdav-1.5.0.jar (Vulnerable Library)

Medium 6.5 jackrabbit-webdav-1.5.0.jar Upgrade to version: org.apache.jackrabbit:jackrabbit-core:2.8.1 None

Unreachable

WS-2016-7057

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> maven-artifact-2.2.1.jar

       -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library)

Medium 5.9 plexus-utils-3.0.20.jar Upgrade to version: 3.0.24 None

Unreachable

CVE-2016-5725

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/jcraft/jsch/0.1.38/jsch-0.1.38.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> maven-core-2.2.1.jar

       -> wagon-ssh-1.0-beta-6.jar

         -> ❌ jsch-0.1.38.jar (Vulnerable Library)

Medium 5.9 jsch-0.1.38.jar Upgrade to version: 0.1.54 None

Unreachable

CVE-2018-11771

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> plexus-archiver-2.8.1.jar

       -> ❌ commons-compress-1.9.jar (Vulnerable Library)

Medium 5.5 commons-compress-1.9.jar Upgrade to version: 1.18 None

Unreachable

CVE-2018-1002200

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-archiver/2.8.1/plexus-archiver-2.8.1.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> ❌ plexus-archiver-2.8.1.jar (Vulnerable Library)

Medium 5.5 plexus-archiver-2.8.1.jar Upgrade to version: org.codehaus.plexus:plexus-archiver:3.6.0 None

Unreachable

WS-2016-7062

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> maven-artifact-2.2.1.jar

       -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library)

Medium 5.3 plexus-utils-3.0.20.jar Upgrade to version: 3.0.24 None

Unreachable

CVE-2022-4245

Path to dependency file: /app/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar

Dependency Hierarchy:

-> maven-sling-plugin-2.2.0.jar (Root Library)

   -> maven-archiver-2.6.jar

     -> maven-artifact-2.2.1.jar

       -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library)

Medium 4.3 plexus-utils-3.0.20.jar Upgrade to version: org.codehaus.plexus:plexus-utils:3.0.24 None

Unreachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2015-2944 org.apache.sling.api-2.0.2-incubator.jar
GHSA-4xx7-2cx3-x473 keycloak-saml-core-1.8.1.Final.jar
CVE-2017-1000487 plexus-utils-1.0.4.jar
CVE-2022-47937 org.apache.sling.commons.json-2.0.4-incubator.jar
CVE-2022-32549 org.apache.sling.api-2.0.2-incubator.jar
CVE-2022-4245 plexus-utils-1.0.4.jar
GHSA-q2gp-gph3-88x9 keycloak-saml-core-1.8.1.Final.jar
CVE-2018-1002200 plexus-archiver-1.0-alpha-3.jar
CVE-2022-4244 plexus-utils-1.0.4.jar
WS-2016-7062 plexus-utils-1.0.4.jar
CVE-2013-2254 org.apache.sling.api-2.0.2-incubator.jar
WS-2016-7057 plexus-utils-1.0.4.jar

Base branch total remaining vulnerabilities: 93
Base branch commit: f9e0dc6866b5df73561aeec6122e14261d82ab4d


Total libraries scanned: 118

Scan token: fe914853ae7c49c1b9898f73f738cb4d