Replace dependency mysql:mysql-connector-java with com.mysql:mysql-connector-j #275
Dev - Mend for GitHub.com / Mend Security Check
failed
Mar 9, 2026 in 20m 37s
Security Report
You have successfully remediated 50 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2024-7254Path to dependency file: /pom.xml Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar Dependency Hierarchy: -> mysql-connector-j-8.0.33.jar (Root Library) -> ❌ protobuf-java-3.21.9.jar (Vulnerable Library) |
7.5 | Transitive protobuf-java-3.21.9.jar |
mysql-connector-j-8.0.33.jar | Transitive com.google.protobuf:protobuf-javalite:3.25.5,com.google.protobuf:protobuf-kotlin:4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-java:3.25.5,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin:4.28.2,google-protobuf - 4.27.5,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-kotlin:3.25.5,google-protobuf - 4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,google-protobuf - 3.25.5,com.google.protobuf:protobuf-kotlin-lite:3.25.5 |
None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2020-24750 | jackson-databind-2.8.4.jar |
| CVE-2020-36185 | jackson-databind-2.8.4.jar |
| CVE-2020-10650 | jackson-databind-2.8.4.jar |
| CVE-2020-11112 | jackson-databind-2.8.4.jar |
| CVE-2019-2692 | mysql-connector-java-5.1.35.jar |
| CVE-2020-14062 | jackson-databind-2.8.4.jar |
| CVE-2018-14718 | jackson-databind-2.8.4.jar |
| CVE-2020-36518 | jackson-databind-2.8.4.jar |
| CVE-2020-36187 | jackson-databind-2.8.4.jar |
| CVE-2018-3258 | mysql-connector-java-5.1.35.jar |
| CVE-2020-14195 | jackson-databind-2.8.4.jar |
| CVE-2020-9548 | jackson-databind-2.8.4.jar |
| CVE-2020-36179 | jackson-databind-2.8.4.jar |
| CVE-2018-19361 | jackson-databind-2.8.4.jar |
| GHSA-257q-pv89-v3xv | jquery-3.2.1.min.js |
| CVE-2020-36180 | jackson-databind-2.8.4.jar |
| CVE-2017-3589 | mysql-connector-java-5.1.35.jar |
| CVE-2020-36181 | jackson-databind-2.8.4.jar |
| CVE-2019-17531 | jackson-databind-2.8.4.jar |
| CVE-2018-14721 | jackson-databind-2.8.4.jar |
| CVE-2018-19362 | jackson-databind-2.8.4.jar |
| CVE-2019-14540 | jackson-databind-2.8.4.jar |
| CVE-2020-10673 | jackson-databind-2.8.4.jar |
| CVE-2020-36186 | jackson-databind-2.8.4.jar |
| CVE-2020-11113 | jackson-databind-2.8.4.jar |
| CVE-2022-25647 | gson-2.8.2.jar |
| CVE-2020-11619 | jackson-databind-2.8.4.jar |
| CVE-2020-2933 | mysql-connector-java-5.1.35.jar |
| CVE-2020-24616 | jackson-databind-2.8.4.jar |
| CVE-2020-36184 | jackson-databind-2.8.4.jar |
| CVE-2020-36182 | jackson-databind-2.8.4.jar |
| CVE-2020-25638 | hibernate-core-4.3.11.Final.jar |
| CVE-2020-2934 | mysql-connector-java-5.1.35.jar |
| CVE-2020-14061 | jackson-databind-2.8.4.jar |
| CVE-2020-11620 | jackson-databind-2.8.4.jar |
| CVE-2019-14893 | jackson-databind-2.8.4.jar |
| CVE-2017-3586 | mysql-connector-java-5.1.35.jar |
| CVE-2020-36189 | jackson-databind-2.8.4.jar |
| CVE-2017-3523 | mysql-connector-java-5.1.35.jar |
| CVE-2018-14720 | jackson-databind-2.8.4.jar |
| CVE-2019-14892 | jackson-databind-2.8.4.jar |
| CVE-2020-36188 | jackson-databind-2.8.4.jar |
| CVE-2020-11111 | jackson-databind-2.8.4.jar |
| CVE-2020-14060 | jackson-databind-2.8.4.jar |
| CVE-2019-14439 | jackson-databind-2.8.4.jar |
| CVE-2018-5968 | jackson-databind-2.8.4.jar |
| CVE-2020-2875 | mysql-connector-java-5.1.35.jar |
| CVE-2018-14719 | jackson-databind-2.8.4.jar |
| CVE-2020-36183 | jackson-databind-2.8.4.jar |
| CVE-2019-14379 | jackson-databind-2.8.4.jar |
Base branch total remaining vulnerabilities: 186
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9
Total libraries scanned: 109
Scan token: 29dd9f0db2fe4aeb81b466b710012ec2
Loading