Update dependency org.apache.sling:maven-sling-plugin to v2.2.0 #43
Security Report
You have successfully remediated 12 vulnerabilities, but introduced 14 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|
WS-2021-0616Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.11.0/jackson-databind-2.11.0.jar Dependency Hierarchy: -> spring-boot-starter-web-2.3.1.RELEASE.jar (Root Library) -> spring-boot-starter-json-2.3.1.RELEASE.jar -> ❌ jackson-databind-2.11.0.jar (Vulnerable Library) |
5.9 | jackson-databind-2.11.0.jar | Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 | #36 | ||
CVE-2022-29599Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/maven/shared/maven-shared-utils/0.7/maven-shared-utils-0.7.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> ❌ maven-shared-utils-0.7.jar (Vulnerable Library) |
9.8 | maven-shared-utils-0.7.jar | Upgrade to version: org.apache.maven.shared:maven-shared-utils:3.3.3 | None | ||
CVE-2022-4244Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> maven-artifact-2.2.1.jar -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library) |
7.5 | plexus-utils-3.0.20.jar | Upgrade to version: org.codehaus.plexus:plexus-utils:3.0.24 | None | ||
CVE-2021-36090Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> plexus-archiver-2.8.1.jar -> ❌ commons-compress-1.9.jar (Vulnerable Library) |
7.5 | commons-compress-1.9.jar | Upgrade to version: org.apache.commons:commons-compress:1.21 | None | ||
CVE-2021-35517Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> plexus-archiver-2.8.1.jar -> ❌ commons-compress-1.9.jar (Vulnerable Library) |
7.5 | commons-compress-1.9.jar | Upgrade to version: org.apache.commons:commons-compress:1.21 | None | ||
CVE-2021-35516Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> plexus-archiver-2.8.1.jar -> ❌ commons-compress-1.9.jar (Vulnerable Library) |
7.5 | commons-compress-1.9.jar | Upgrade to version: org.apache.commons:commons-compress:1.21 | None | ||
CVE-2021-35515Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> plexus-archiver-2.8.1.jar -> ❌ commons-compress-1.9.jar (Vulnerable Library) |
7.5 | commons-compress-1.9.jar | Upgrade to version: org.apache.commons:commons-compress:1.21 | None | ||
CVE-2015-1833Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/jackrabbit/jackrabbit-webdav/1.5.0/jackrabbit-webdav-1.5.0.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> maven-core-2.2.1.jar -> wagon-webdav-jackrabbit-1.0-beta-6.jar -> ❌ jackrabbit-webdav-1.5.0.jar (Vulnerable Library) |
6.5 | jackrabbit-webdav-1.5.0.jar | Upgrade to version: org.apache.jackrabbit:jackrabbit-core:2.8.1 | None | ||
WS-2016-7057Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> maven-artifact-2.2.1.jar -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library) |
5.9 | plexus-utils-3.0.20.jar | Upgrade to version: 3.0.24 | None | ||
CVE-2016-5725Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/jcraft/jsch/0.1.38/jsch-0.1.38.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> maven-core-2.2.1.jar -> wagon-ssh-1.0-beta-6.jar -> ❌ jsch-0.1.38.jar (Vulnerable Library) |
5.9 | jsch-0.1.38.jar | Upgrade to version: 0.1.54 | None | ||
CVE-2018-11771Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-compress/1.9/commons-compress-1.9.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> plexus-archiver-2.8.1.jar -> ❌ commons-compress-1.9.jar (Vulnerable Library) |
5.5 | commons-compress-1.9.jar | Upgrade to version: 1.18 | None | ||
CVE-2018-1002200Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-archiver/2.8.1/plexus-archiver-2.8.1.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> ❌ plexus-archiver-2.8.1.jar (Vulnerable Library) |
5.5 | plexus-archiver-2.8.1.jar | Upgrade to version: org.codehaus.plexus:plexus-archiver:3.6.0 | None | ||
WS-2016-7062Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> maven-artifact-2.2.1.jar -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library) |
5.3 | plexus-utils-3.0.20.jar | Upgrade to version: 3.0.24 | None | ||
CVE-2022-4245Path to dependency file: /app/pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/codehaus/plexus/plexus-utils/3.0.20/plexus-utils-3.0.20.jar Dependency Hierarchy: -> maven-sling-plugin-2.2.0.jar (Root Library) -> maven-archiver-2.6.jar -> maven-artifact-2.2.1.jar -> ❌ plexus-utils-3.0.20.jar (Vulnerable Library) |
4.3 | plexus-utils-3.0.20.jar | Upgrade to version: org.codehaus.plexus:plexus-utils:3.0.24 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2015-2944 | org.apache.sling.api-2.0.2-incubator.jar |
| GHSA-4xx7-2cx3-x473 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2017-1000487 | plexus-utils-1.0.4.jar |
| CVE-2022-47937 | org.apache.sling.commons.json-2.0.4-incubator.jar |
| CVE-2022-32549 | org.apache.sling.api-2.0.2-incubator.jar |
| CVE-2022-4245 | plexus-utils-1.0.4.jar |
| GHSA-q2gp-gph3-88x9 | keycloak-saml-core-1.8.1.Final.jar |
| CVE-2018-1002200 | plexus-archiver-1.0-alpha-3.jar |
| CVE-2022-4244 | plexus-utils-1.0.4.jar |
| WS-2016-7062 | plexus-utils-1.0.4.jar |
| CVE-2013-2254 | org.apache.sling.api-2.0.2-incubator.jar |
| WS-2016-7057 | plexus-utils-1.0.4.jar |
Base branch total remaining vulnerabilities: 93
Base branch commit: f9e0dc6866b5df73561aeec6122e14261d82ab4d
Total libraries scanned: 118
Scan token: fe914853ae7c49c1b9898f73f738cb4d