Skip to content

Replace dependency mysql:mysql-connector-java with com.mysql:mysql-co…

9293fa0
Select commit
Loading
Failed to load commit list.
Open

Replace dependency mysql:mysql-connector-java with com.mysql:mysql-connector-j #275

Replace dependency mysql:mysql-connector-java with com.mysql:mysql-co…
9293fa0
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Mar 9, 2026 in 20m 37s

Security Report

You have successfully remediated 50 vulnerabilities, but introduced 1 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2024-7254

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar

Dependency Hierarchy:

-> mysql-connector-j-8.0.33.jar (Root Library)

   -> ❌ protobuf-java-3.21.9.jar (Vulnerable Library)

High 7.5 Transitive protobuf-java-3.21.9.jar mysql-connector-j-8.0.33.jar Transitive com.google.protobuf:protobuf-javalite:3.25.5,com.google.protobuf:protobuf-kotlin:4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-java:3.25.5,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin:4.28.2,google-protobuf - 4.27.5,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-kotlin:3.25.5,google-protobuf - 4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,google-protobuf - 3.25.5,com.google.protobuf:protobuf-kotlin-lite:3.25.5 None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2020-24750 jackson-databind-2.8.4.jar
CVE-2020-36185 jackson-databind-2.8.4.jar
CVE-2020-10650 jackson-databind-2.8.4.jar
CVE-2020-11112 jackson-databind-2.8.4.jar
CVE-2019-2692 mysql-connector-java-5.1.35.jar
CVE-2020-14062 jackson-databind-2.8.4.jar
CVE-2018-14718 jackson-databind-2.8.4.jar
CVE-2020-36518 jackson-databind-2.8.4.jar
CVE-2020-36187 jackson-databind-2.8.4.jar
CVE-2018-3258 mysql-connector-java-5.1.35.jar
CVE-2020-14195 jackson-databind-2.8.4.jar
CVE-2020-9548 jackson-databind-2.8.4.jar
CVE-2020-36179 jackson-databind-2.8.4.jar
CVE-2018-19361 jackson-databind-2.8.4.jar
GHSA-257q-pv89-v3xv jquery-3.2.1.min.js
CVE-2020-36180 jackson-databind-2.8.4.jar
CVE-2017-3589 mysql-connector-java-5.1.35.jar
CVE-2020-36181 jackson-databind-2.8.4.jar
CVE-2019-17531 jackson-databind-2.8.4.jar
CVE-2018-14721 jackson-databind-2.8.4.jar
CVE-2018-19362 jackson-databind-2.8.4.jar
CVE-2019-14540 jackson-databind-2.8.4.jar
CVE-2020-10673 jackson-databind-2.8.4.jar
CVE-2020-36186 jackson-databind-2.8.4.jar
CVE-2020-11113 jackson-databind-2.8.4.jar
CVE-2022-25647 gson-2.8.2.jar
CVE-2020-11619 jackson-databind-2.8.4.jar
CVE-2020-2933 mysql-connector-java-5.1.35.jar
CVE-2020-24616 jackson-databind-2.8.4.jar
CVE-2020-36184 jackson-databind-2.8.4.jar
CVE-2020-36182 jackson-databind-2.8.4.jar
CVE-2020-25638 hibernate-core-4.3.11.Final.jar
CVE-2020-2934 mysql-connector-java-5.1.35.jar
CVE-2020-14061 jackson-databind-2.8.4.jar
CVE-2020-11620 jackson-databind-2.8.4.jar
CVE-2019-14893 jackson-databind-2.8.4.jar
CVE-2017-3586 mysql-connector-java-5.1.35.jar
CVE-2020-36189 jackson-databind-2.8.4.jar
CVE-2017-3523 mysql-connector-java-5.1.35.jar
CVE-2018-14720 jackson-databind-2.8.4.jar
CVE-2019-14892 jackson-databind-2.8.4.jar
CVE-2020-36188 jackson-databind-2.8.4.jar
CVE-2020-11111 jackson-databind-2.8.4.jar
CVE-2020-14060 jackson-databind-2.8.4.jar
CVE-2019-14439 jackson-databind-2.8.4.jar
CVE-2018-5968 jackson-databind-2.8.4.jar
CVE-2020-2875 mysql-connector-java-5.1.35.jar
CVE-2018-14719 jackson-databind-2.8.4.jar
CVE-2020-36183 jackson-databind-2.8.4.jar
CVE-2019-14379 jackson-databind-2.8.4.jar

Base branch total remaining vulnerabilities: 186
Base branch commit: 80eb1448744dcd3ab7e403f5f4f723c4c6760ae9


Total libraries scanned: 109

Scan token: 29dd9f0db2fe4aeb81b466b710012ec2