Update dependency org.elasticsearch:elasticsearch to v7 #273
Security Report
You have successfully remediated 61 vulnerabilities, but introduced 4 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2025-12183Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/lz4/lz4-java/1.8.0/lz4-java-1.8.0.jar Dependency Hierarchy: -> elasticsearch-7.17.23.jar (Root Library) -> elasticsearch-lz4-7.17.23.jar -> ❌ lz4-java-1.8.0.jar (Vulnerable Library) |
9.1 | Transitive lz4-java-1.8.0.jar |
elasticsearch-7.17.23.jar | Transitive org.lz4:lz4-java:1.8.1 |
None | ||
CVE-2025-66566Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/lz4/lz4-java/1.8.0/lz4-java-1.8.0.jar Dependency Hierarchy: -> elasticsearch-7.17.23.jar (Root Library) -> elasticsearch-lz4-7.17.23.jar -> ❌ lz4-java-1.8.0.jar (Vulnerable Library) |
7.5 | Transitive lz4-java-1.8.0.jar |
elasticsearch-7.17.23.jar | None | |||
CVE-2025-52999Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.14.2/jackson-core-2.14.2.jar Dependency Hierarchy: -> spring-rabbit-1.7.1.RELEASE.jar (Root Library) -> http-client-1.1.1.RELEASE.jar -> jackson-databind-2.8.4.jar -> ❌ jackson-core-2.14.2.jar (Vulnerable Library) |
7.5 | Transitive jackson-core-2.14.2.jar |
spring-rabbit-1.7.1.RELEASE.jar | #246 | |||
CVE-2025-37727Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/org/elasticsearch/elasticsearch/7.17.23/elasticsearch-7.17.23.jar Dependency Hierarchy: -> ❌ elasticsearch-7.17.23.jar (Vulnerable Library) |
5.7 | Direct elasticsearch-7.17.23.jar |
elasticsearch-7.17.23.jar | org.elasticsearch:elasticsearch:9.1.5,org.elasticsearch:elasticsearch:9.0.8,org.elasticsearch:elasticsearch:8.18.8,org.elasticsearch:elasticsearch:8.19.5 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2017-12629 | lucene-queryparser-6.6.1.jar |
| CVE-2020-24750 | jackson-databind-2.8.4.jar |
| CVE-2022-22968 | spring-context-4.2.0.RELEASE.jar |
| CVE-2018-3831 | elasticsearch-5.6.4.jar |
| CVE-2020-36185 | jackson-databind-2.8.4.jar |
| CVE-2020-10650 | jackson-databind-2.8.4.jar |
| CVE-2020-11112 | jackson-databind-2.8.4.jar |
| CVE-2020-14062 | jackson-databind-2.8.4.jar |
| CVE-2018-14718 | jackson-databind-2.8.4.jar |
| CVE-2020-36518 | jackson-databind-2.8.4.jar |
| CVE-2020-36187 | jackson-databind-2.8.4.jar |
| CVE-2020-14195 | jackson-databind-2.8.4.jar |
| CVE-2020-9548 | jackson-databind-2.8.4.jar |
| CVE-2020-36179 | jackson-databind-2.8.4.jar |
| CVE-2018-19361 | jackson-databind-2.8.4.jar |
| CVE-2021-22137 | elasticsearch-5.6.4.jar |
| CVE-2020-36180 | jackson-databind-2.8.4.jar |
| CVE-2020-36181 | jackson-databind-2.8.4.jar |
| CVE-2019-17531 | jackson-databind-2.8.4.jar |
| CVE-2021-20190 | jackson-databind-2.8.4.jar |
| CVE-2018-14721 | jackson-databind-2.8.4.jar |
| CVE-2018-19362 | jackson-databind-2.8.4.jar |
| CVE-2022-38751 | snakeyaml-1.15.jar |
| CVE-2022-38752 | snakeyaml-1.15.jar |
| CVE-2023-49921 | elasticsearch-5.6.4.jar |
| CVE-2022-41854 | snakeyaml-1.15.jar |
| CVE-2022-38750 | snakeyaml-1.15.jar |
| CVE-2022-38749 | snakeyaml-1.15.jar |
| CVE-2019-14540 | jackson-databind-2.8.4.jar |
| CVE-2020-10673 | jackson-databind-2.8.4.jar |
| CVE-2020-36186 | jackson-databind-2.8.4.jar |
| CVE-2024-43709 | elasticsearch-5.6.4.jar |
| CVE-2020-11113 | jackson-databind-2.8.4.jar |
| CVE-2025-52999 | jackson-core-2.8.6.jar |
| CVE-2022-25647 | gson-2.8.2.jar |
| CVE-2020-11619 | jackson-databind-2.8.4.jar |
| CVE-2020-24616 | jackson-databind-2.8.4.jar |
| CVE-2020-36184 | jackson-databind-2.8.4.jar |
| CVE-2020-36182 | jackson-databind-2.8.4.jar |
| CVE-2018-3823 | elasticsearch-5.6.4.jar |
| CVE-2021-22135 | elasticsearch-5.6.4.jar |
| CVE-2017-18640 | snakeyaml-1.15.jar |
| CVE-2020-25638 | hibernate-core-4.3.11.Final.jar |
| CVE-2020-14061 | jackson-databind-2.8.4.jar |
| CVE-2020-11620 | jackson-databind-2.8.4.jar |
| CVE-2019-14893 | jackson-databind-2.8.4.jar |
| CVE-2020-36189 | jackson-databind-2.8.4.jar |
| CVE-2018-14720 | jackson-databind-2.8.4.jar |
| CVE-2019-14892 | jackson-databind-2.8.4.jar |
| CVE-2020-36188 | jackson-databind-2.8.4.jar |
| CVE-2020-11111 | jackson-databind-2.8.4.jar |
| CVE-2021-22144 | elasticsearch-5.6.4.jar |
| CVE-2020-14060 | jackson-databind-2.8.4.jar |
| CVE-2019-14439 | jackson-databind-2.8.4.jar |
| CVE-2018-5968 | jackson-databind-2.8.4.jar |
| CVE-2018-14719 | jackson-databind-2.8.4.jar |
| CVE-2020-36183 | jackson-databind-2.8.4.jar |
| CVE-2024-23444 | elasticsearch-5.6.4.jar |
| CVE-2019-14379 | jackson-databind-2.8.4.jar |
| CVE-2018-3824 | elasticsearch-5.6.4.jar |
| CVE-2020-7019 | elasticsearch-5.6.4.jar |
Base branch total remaining vulnerabilities: 175
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9
Total libraries scanned: 114
Scan token: 92115d971bba4a98acbddd690716df9b