Skip to content

Update dependency mysql:mysql-connector-java to v8

535cccb
Select commit
Loading
Failed to load commit list.
Open

Update dependency mysql:mysql-connector-java to v8 #219

Update dependency mysql:mysql-connector-java to v8
535cccb
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Jun 30, 2025 in 30m 45s

Security Report

You have successfully remediated 9 vulnerabilities, but introduced 7 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Suggested Fix Issue Reachability
CVE-2022-3510

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

High 7.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-javalite:3.19.6 None

Reachable

CVE-2022-3509

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

High 7.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-javalite:3.21.7 None

Reachable

CVE-2021-22569

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

High 7.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-java:3.19.2 None

Reachable

CVE-2021-22570

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

Medium 6.5 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-java:3.15.0 None

Reachable

CVE-2022-3171

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.6.1/protobuf-java-3.6.1.jar

Dependency Hierarchy:

-> mysql-connector-java-8.0.16.jar (Root Library)

   -> ❌ protobuf-java-3.6.1.jar (Vulnerable Library)

Medium 4.3 protobuf-java-3.6.1.jar Upgrade to version: com.google.protobuf:protobuf-javalite:3.21.7 None

Reachable

CVE-2021-2471

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/8.0.16/mysql-connector-java-8.0.16.jar

Dependency Hierarchy:

-> ❌ mysql-connector-java-8.0.16.jar (Vulnerable Library)

Medium 5.9 mysql-connector-java-8.0.16.jar Upgrade to version: mysql:mysql-connector-java:8.0.27 None

Unreachable

CVE-2020-2934

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/mysql/mysql-connector-java/8.0.16/mysql-connector-java-8.0.16.jar

Dependency Hierarchy:

-> ❌ mysql-connector-java-8.0.16.jar (Vulnerable Library)

Medium 5.0 mysql-connector-java-8.0.16.jar Upgrade to version: mysql:mysql-connector-java:5.1.49,8.0.20 #131

Unreachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2019-2692 mysql-connector-java-5.1.35.jar
CVE-2018-3258 mysql-connector-java-5.1.35.jar
CVE-2020-2933 mysql-connector-java-5.1.35.jar
CVE-2020-2934 mysql-connector-java-5.1.35.jar
CVE-2017-3523 mysql-connector-java-5.1.35.jar
CVE-2020-2875 mysql-connector-java-5.1.35.jar
GHSA-wrr7-33fx-rcvj jackson-databind-2.8.4.jar
CVE-2017-3589 mysql-connector-java-5.1.35.jar
CVE-2017-3586 mysql-connector-java-5.1.35.jar

Base branch total remaining vulnerabilities: 207
Base branch commit: 498f371cf2745f3522d79e209a3a246e98a98f3d


Total libraries scanned: 109

Scan token: 087ed1c9b5d44cf4a5b66e6317fc959b