Skip to content

Update dependency org.elasticsearch:elasticsearch to v7

8718034
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.elasticsearch:elasticsearch to v7 #273

Update dependency org.elasticsearch:elasticsearch to v7
8718034
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Dec 11, 2025 in 27m 49s

Security Report

You have successfully remediated 61 vulnerabilities, but introduced 4 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-12183

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/lz4/lz4-java/1.8.0/lz4-java-1.8.0.jar

Dependency Hierarchy:

-> elasticsearch-7.17.23.jar (Root Library)

   -> elasticsearch-lz4-7.17.23.jar

     -> ❌ lz4-java-1.8.0.jar (Vulnerable Library)

Critical 9.1 Transitive lz4-java-1.8.0.jar elasticsearch-7.17.23.jar Transitive org.lz4:lz4-java:1.8.1 None

Reachable

CVE-2025-66566

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/lz4/lz4-java/1.8.0/lz4-java-1.8.0.jar

Dependency Hierarchy:

-> elasticsearch-7.17.23.jar (Root Library)

   -> elasticsearch-lz4-7.17.23.jar

     -> ❌ lz4-java-1.8.0.jar (Vulnerable Library)

High 7.5 Transitive lz4-java-1.8.0.jar elasticsearch-7.17.23.jar None

Reachable

CVE-2025-52999

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.14.2/jackson-core-2.14.2.jar

Dependency Hierarchy:

-> spring-rabbit-1.7.1.RELEASE.jar (Root Library)

   -> http-client-1.1.1.RELEASE.jar

     -> jackson-databind-2.8.4.jar

       -> ❌ jackson-core-2.14.2.jar (Vulnerable Library)

High 7.5 Transitive jackson-core-2.14.2.jar spring-rabbit-1.7.1.RELEASE.jar #246

Reachable

CVE-2025-37727

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/elasticsearch/elasticsearch/7.17.23/elasticsearch-7.17.23.jar

Dependency Hierarchy:

-> ❌ elasticsearch-7.17.23.jar (Vulnerable Library)

Medium 5.7 Direct elasticsearch-7.17.23.jar elasticsearch-7.17.23.jar org.elasticsearch:elasticsearch:9.1.5,org.elasticsearch:elasticsearch:9.0.8,org.elasticsearch:elasticsearch:8.18.8,org.elasticsearch:elasticsearch:8.19.5 None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2017-12629 lucene-queryparser-6.6.1.jar
CVE-2020-24750 jackson-databind-2.8.4.jar
CVE-2022-22968 spring-context-4.2.0.RELEASE.jar
CVE-2018-3831 elasticsearch-5.6.4.jar
CVE-2020-36185 jackson-databind-2.8.4.jar
CVE-2020-10650 jackson-databind-2.8.4.jar
CVE-2020-11112 jackson-databind-2.8.4.jar
CVE-2020-14062 jackson-databind-2.8.4.jar
CVE-2018-14718 jackson-databind-2.8.4.jar
CVE-2020-36518 jackson-databind-2.8.4.jar
CVE-2020-36187 jackson-databind-2.8.4.jar
CVE-2020-14195 jackson-databind-2.8.4.jar
CVE-2020-9548 jackson-databind-2.8.4.jar
CVE-2020-36179 jackson-databind-2.8.4.jar
CVE-2018-19361 jackson-databind-2.8.4.jar
CVE-2021-22137 elasticsearch-5.6.4.jar
CVE-2020-36180 jackson-databind-2.8.4.jar
CVE-2020-36181 jackson-databind-2.8.4.jar
CVE-2019-17531 jackson-databind-2.8.4.jar
CVE-2021-20190 jackson-databind-2.8.4.jar
CVE-2018-14721 jackson-databind-2.8.4.jar
CVE-2018-19362 jackson-databind-2.8.4.jar
CVE-2022-38751 snakeyaml-1.15.jar
CVE-2022-38752 snakeyaml-1.15.jar
CVE-2023-49921 elasticsearch-5.6.4.jar
CVE-2022-41854 snakeyaml-1.15.jar
CVE-2022-38750 snakeyaml-1.15.jar
CVE-2022-38749 snakeyaml-1.15.jar
CVE-2019-14540 jackson-databind-2.8.4.jar
CVE-2020-10673 jackson-databind-2.8.4.jar
CVE-2020-36186 jackson-databind-2.8.4.jar
CVE-2024-43709 elasticsearch-5.6.4.jar
CVE-2020-11113 jackson-databind-2.8.4.jar
CVE-2025-52999 jackson-core-2.8.6.jar
CVE-2022-25647 gson-2.8.2.jar
CVE-2020-11619 jackson-databind-2.8.4.jar
CVE-2020-24616 jackson-databind-2.8.4.jar
CVE-2020-36184 jackson-databind-2.8.4.jar
CVE-2020-36182 jackson-databind-2.8.4.jar
CVE-2018-3823 elasticsearch-5.6.4.jar
CVE-2021-22135 elasticsearch-5.6.4.jar
CVE-2017-18640 snakeyaml-1.15.jar
CVE-2020-25638 hibernate-core-4.3.11.Final.jar
CVE-2020-14061 jackson-databind-2.8.4.jar
CVE-2020-11620 jackson-databind-2.8.4.jar
CVE-2019-14893 jackson-databind-2.8.4.jar
CVE-2020-36189 jackson-databind-2.8.4.jar
CVE-2018-14720 jackson-databind-2.8.4.jar
CVE-2019-14892 jackson-databind-2.8.4.jar
CVE-2020-36188 jackson-databind-2.8.4.jar
CVE-2020-11111 jackson-databind-2.8.4.jar
CVE-2021-22144 elasticsearch-5.6.4.jar
CVE-2020-14060 jackson-databind-2.8.4.jar
CVE-2019-14439 jackson-databind-2.8.4.jar
CVE-2018-5968 jackson-databind-2.8.4.jar
CVE-2018-14719 jackson-databind-2.8.4.jar
CVE-2020-36183 jackson-databind-2.8.4.jar
CVE-2024-23444 elasticsearch-5.6.4.jar
CVE-2019-14379 jackson-databind-2.8.4.jar
CVE-2018-3824 elasticsearch-5.6.4.jar
CVE-2020-7019 elasticsearch-5.6.4.jar

Base branch total remaining vulnerabilities: 175
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9


Total libraries scanned: 114

Scan token: 92115d971bba4a98acbddd690716df9b