Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 8.0.1Report Generated On : Sat, 3 May 2025 18:02:21 GMTDependencies Scanned : 120 (84 unique)Vulnerable Dependencies : 8 Vulnerabilities Found : 18Vulnerabilities Suppressed : 0... CurrentEngineRelease : 12.1.0NVD CVE Checked : 2025-05-03T17:09:51NVD CVE Modified : 2025-05-03T16:00:01VersionCheckOn : 2025-05-01T21:09:43kev.checked : 1746292219Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies amqp-client-5.19.0.jarDescription:
The RabbitMQ Java client library allows Java applications to interface with RabbitMQ. License:
AL 2.0: https://www.apache.org/licenses/LICENSE-2.0.html
GPL v2: https://www.gnu.org/licenses/gpl-2.0.txt
MPL 2.0: https://www.mozilla.org/en-US/MPL/2.0/ File Path: /opt/tomcat/.m2/repository/com/rabbitmq/amqp-client/5.19.0/amqp-client-5.19.0.jar
MD5: 66dd87e201ca617388a786db0edf6be2
SHA1: 6bd68c3cdf2662a9fbff8de5b9ef2b0fb1e6fe57
SHA256: d2c7a35031bf7f101b9cfcb5f58b201201b1f8232b6608171db7befe3a2b860d
Referenced In Project/Scope: Users Admin Web:compile
amqp-client-5.19.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-amqp@3.3.11
Evidence Type Source Name Value Confidence Vendor file name amqp-client High Vendor jar package name amqp Highest Vendor jar package name client Highest Vendor jar package name rabbitmq Highest Vendor Manifest automatic-module-name com.rabbitmq.client Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://www.rabbitmq.com Low Vendor Manifest bundle-symbolicname com.rabbitmq.client Medium Vendor Manifest implementation-url https://www.rabbitmq.com Low Vendor Manifest Implementation-Vendor VMware, Inc. or its affiliates. High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor AMQP Working Group (www.amqp.org) Low Vendor pom artifactid amqp-client Highest Vendor pom artifactid amqp-client Low Vendor pom developer email info@rabbitmq.com Low Vendor pom developer name Team RabbitMQ Medium Vendor pom developer org VMware, Inc. or its affiliates. Medium Vendor pom developer org URL https://rabbitmq.com Medium Vendor pom groupid com.rabbitmq Highest Vendor pom name RabbitMQ Java Client High Vendor pom organization name VMware, Inc. or its affiliates. High Vendor pom organization url https://www.rabbitmq.com Medium Vendor pom url https://www.rabbitmq.com Highest Product file name amqp-client High Product jar package name amqp Highest Product jar package name client Highest Product jar package name rabbitmq Highest Product jar package name version Highest Product Manifest automatic-module-name com.rabbitmq.client Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://www.rabbitmq.com Low Product Manifest Bundle-Name RabbitMQ Java Client Medium Product Manifest bundle-symbolicname com.rabbitmq.client Medium Product Manifest Implementation-Title RabbitMQ Java Client High Product Manifest implementation-url https://www.rabbitmq.com Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title AMQP Medium Product pom artifactid amqp-client Highest Product pom developer email info@rabbitmq.com Low Product pom developer name Team RabbitMQ Low Product pom developer org VMware, Inc. or its affiliates. Low Product pom developer org URL https://rabbitmq.com Low Product pom groupid com.rabbitmq Highest Product pom name RabbitMQ Java Client High Product pom organization name VMware, Inc. or its affiliates. Low Product pom organization url https://www.rabbitmq.com Low Product pom url https://www.rabbitmq.com Medium Version file version 5.19.0 High Version Manifest Bundle-Version 5.19.0 High Version Manifest Implementation-Version 5.19.0 High Version pom version 5.19.0 Highest
angus-activation-2.0.1.jarDescription:
${project.name} Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-activation/2.0.1/angus-activation-2.0.1.jar
MD5: 9a66564224140488f83f645ac32d4169
SHA1: eaafaf4eb71b400e4136fc3a286f50e34a68ecb7
SHA256: b226761815868edf8964c1d71e6d2d54ab238c2788507061b4e0633933b4c131
Referenced In Project/Scope: Users Admin Web:compile
angus-activation-2.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name angus-activation High Vendor jar package name activation Highest Vendor jar package name angus Highest Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname angus-activation Medium Vendor Manifest extension-name org.eclipse.angus Medium Vendor Manifest implementation-build-id 2.0.1-RELEASE-b350e3d Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid angus-activation Highest Vendor pom artifactid angus-activation Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Activation Registries High Vendor pom parent-artifactid angus-activation-project Low Product file name angus-activation High Product jar package name activation Highest Product jar package name angus Highest Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Angus Activation Registries Medium Product Manifest bundle-symbolicname angus-activation Medium Product Manifest extension-name org.eclipse.angus Medium Product Manifest implementation-build-id 2.0.1-RELEASE-b350e3d Low Product Manifest Implementation-Title Angus Activation Registries High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid angus-activation Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Activation Registries High Product pom parent-artifactid angus-activation-project Medium Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version pom version 2.0.1 Highest
angus-mail-2.0.1.jar (shaded: org.eclipse.angus:angus-core:2.0.1)File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-mail/2.0.1/angus-mail-2.0.1.jar/META-INF/maven/org.eclipse.angus/angus-core/pom.xmlMD5: f360e369882e5a0e72c9b8478bb3b89dSHA1: 441ce7c16adde6d27b18f8483bed824de1345ce4SHA256: d14626b21a4173d2cf26168a89f01cd4bb3b49e67077abc6c97a122fc68b061bReferenced In Project/Scope: Users Admin Web:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid angus-core Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Mail Core High Vendor pom parent-artifactid all Low Product pom artifactid angus-core Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Mail Core High Product pom parent-artifactid all Medium Version pom version 2.0.1 Highest
angus-mail-2.0.1.jar (shaded: org.eclipse.angus:imap:2.0.1)File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-mail/2.0.1/angus-mail-2.0.1.jar/META-INF/maven/org.eclipse.angus/imap/pom.xmlMD5: 05102a237edc3b98999ac6d990ccd6bfSHA1: a5b9f48971acc1e6469b3d3c6370f9557d517aa0SHA256: b62ab94e0e77f341653b9546a8ff7e0e42b21bd6668f64762d9bdaf2bf257f48Referenced In Project/Scope: Users Admin Web:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid imap Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Mail imap provider High Vendor pom parent-artifactid providers Low Product pom artifactid imap Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Mail imap provider High Product pom parent-artifactid providers Medium Version pom version 2.0.1 Highest
angus-mail-2.0.1.jar (shaded: org.eclipse.angus:logging-mailhandler:2.0.1)File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-mail/2.0.1/angus-mail-2.0.1.jar/META-INF/maven/org.eclipse.angus/logging-mailhandler/pom.xmlMD5: dbfd0bb62cf7c3787e593b49829a3188SHA1: a3c463c283bff762d132f742266fb6daf9b01d55SHA256: de393af2c75ed62b8d6975886623dbb880d59df5d587f90d309ce82ad16f82c9Referenced In Project/Scope: Users Admin Web:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid logging-mailhandler Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Mail logging handler High Vendor pom parent-artifactid all Low Product pom artifactid logging-mailhandler Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Mail logging handler High Product pom parent-artifactid all Medium Version pom version 2.0.1 Highest
angus-mail-2.0.1.jar (shaded: org.eclipse.angus:pop3:2.0.1)File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-mail/2.0.1/angus-mail-2.0.1.jar/META-INF/maven/org.eclipse.angus/pop3/pom.xmlMD5: 0e0c10ef42056448a3c9d56722891b2dSHA1: c414da9569662c1e964978805045429ea5f0ab51SHA256: 698d9c6b990f311a8bdea17624d307da6356227d95203a5d00a7513327c223d7Referenced In Project/Scope: Users Admin Web:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid pop3 Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Mail pop3 provider High Vendor pom parent-artifactid providers Low Product pom artifactid pop3 Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Mail pop3 provider High Product pom parent-artifactid providers Medium Version pom version 2.0.1 Highest
angus-mail-2.0.1.jar (shaded: org.eclipse.angus:smtp:2.0.1)File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-mail/2.0.1/angus-mail-2.0.1.jar/META-INF/maven/org.eclipse.angus/smtp/pom.xmlMD5: 5c13f420e93a799e77a06a61c9c1dac3SHA1: 45d00fe1ee33ac6dee9cabda854da88c99232bd2SHA256: b88a786ecae5834454ffe1c0ffa067f636bc37ae602e13b221c9f01838d06fffReferenced In Project/Scope: Users Admin Web:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid smtp Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Mail smtp provider High Vendor pom parent-artifactid providers Low Product pom artifactid smtp Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Mail smtp provider High Product pom parent-artifactid providers Medium Version pom version 2.0.1 Highest
angus-mail-2.0.1.jarDescription:
Angus Mail Provider License:
http://www.eclipse.org/legal/epl-2.0, https://www.gnu.org/software/classpath/license.html, http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/org/eclipse/angus/angus-mail/2.0.1/angus-mail-2.0.1.jar
MD5: 8d14ee5ed48e5c25913dec56e9e76f23
SHA1: 7adb247e025999f7bc435415f99ddf3764463d51
SHA256: 130c53932fb205bd3dc965619ae37a82922f3153c1418b2ce0e0ab71bf0c2721
Referenced In Project/Scope: Users Admin Web:compile
angus-mail-2.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name angus-mail High Vendor jar package name angus Highest Vendor jar package name eclipse Highest Vendor jar package name mail Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.eclipse.angus.mail Medium Vendor Manifest provide-capability osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.util.MailStreamProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.util.MailStreamProvider";osgi.serviceloader="org.eclipse.angus.mail.util.MailStreamProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.imap.IMAPProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.imap.IMAPProvider";osgi.serviceloader="org.eclipse.angus.mail.imap.IMAPProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.imap.IMAPSSLProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.imap.IMAPSSLProvider";osgi.serviceloader="org.eclipse.angus.mail.imap.IMAPSSLProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.smtp.SMTPProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.smtp.SMTPProvider";osgi.serviceloader="org.eclipse.angus.mail.smtp.SMTPProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.smtp.SMTPSSLProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.smtp.SMTPSSLProvider";osgi.serviceloader="org.eclipse.angus.mail.smtp.SMTPSSLProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.pop3.POP3Provider",osgi.serviceloader;register:="org.eclipse.angus.mail.pop3.POP3Provider";osgi.serviceloader="org.eclipse.angus.mail.pop3.POP3Provider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.pop3.POP3SSLProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.pop3.POP3SSLProvider";osgi.serviceloader="org.eclipse.angus.mail.pop3.POP3SSLProvider" Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid angus-mail Highest Vendor pom artifactid angus-mail Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Mail Provider High Vendor pom parent-artifactid all Low Product file name angus-mail High Product jar package name angus Highest Product jar package name eclipse Highest Product jar package name imap Highest Product jar package name mail Highest Product jar package name pop3 Highest Product jar package name smtp Highest Product jar package name util Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Angus Mail Provider Medium Product Manifest bundle-symbolicname org.eclipse.angus.mail Medium Product Manifest provide-capability osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.util.MailStreamProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.util.MailStreamProvider";osgi.serviceloader="org.eclipse.angus.mail.util.MailStreamProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.imap.IMAPProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.imap.IMAPProvider";osgi.serviceloader="org.eclipse.angus.mail.imap.IMAPProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.imap.IMAPSSLProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.imap.IMAPSSLProvider";osgi.serviceloader="org.eclipse.angus.mail.imap.IMAPSSLProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.smtp.SMTPProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.smtp.SMTPProvider";osgi.serviceloader="org.eclipse.angus.mail.smtp.SMTPProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.smtp.SMTPSSLProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.smtp.SMTPSSLProvider";osgi.serviceloader="org.eclipse.angus.mail.smtp.SMTPSSLProvider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.pop3.POP3Provider",osgi.serviceloader;register:="org.eclipse.angus.mail.pop3.POP3Provider";osgi.serviceloader="org.eclipse.angus.mail.pop3.POP3Provider",osgi.service;effective:=active;objectClass="org.eclipse.angus.mail.pop3.POP3SSLProvider",osgi.serviceloader;register:="org.eclipse.angus.mail.pop3.POP3SSLProvider";osgi.serviceloader="org.eclipse.angus.mail.pop3.POP3SSLProvider" Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid angus-mail Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Mail Provider High Product pom parent-artifactid all Medium Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version pom version 2.0.1 Highest
apache-mime4j-core-0.8.11.jarDescription:
Java stream based MIME message parser License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/james/apache-mime4j-core/0.8.11/apache-mime4j-core-0.8.11.jar
MD5: 83990269ea1fdba6f423c26963a0440a
SHA1: 6d1eb5f7b84eaa9d38fca13b761f01c693aef3da
SHA256: 62a7853523dff0c382065df82fa280c1bf59bcd9b329180d707b0f6f15ceb903
Referenced In Project/Scope: Users Admin Web:compile
apache-mime4j-core-0.8.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name apache-mime4j-core High Vendor jar package name apache Highest Vendor jar package name james Highest Vendor jar package name mime4j Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid apache-mime4j-core Highest Vendor pom artifactid apache-mime4j-core Low Vendor pom groupid org.apache.james Highest Vendor pom name Apache James :: Mime4j :: Core High Vendor pom parent-artifactid apache-mime4j-project Low Product file name apache-mime4j-core High Product jar package name apache Highest Product jar package name james Highest Product jar package name mime4j Highest Product jar package name parser Highest Product jar package name stream Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache James :: Mime4j :: Core Medium Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-core Medium Product Manifest Implementation-Title Apache James :: Mime4j :: Core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache James :: Mime4j :: Core Medium Product pom artifactid apache-mime4j-core Highest Product pom groupid org.apache.james Highest Product pom name Apache James :: Mime4j :: Core High Product pom parent-artifactid apache-mime4j-project Medium Version file version 0.8.11 High Version Manifest Bundle-Version 0.8.11 High Version Manifest Implementation-Version 0.8.11 High Version pom version 0.8.11 Highest
Related Dependencies apache-mime4j-dom-0.8.11.jarFile Path: /opt/tomcat/.m2/repository/org/apache/james/apache-mime4j-dom/0.8.11/apache-mime4j-dom-0.8.11.jar MD5: 99a0d8c9c024464be1cae9eb5c96757b SHA1: f0d42ab9a5832b5f5d05afc004b31245b838e0fc SHA256: 80b301f08e21a6de6d941bb98ef1361ad816c057b7aa61c95cf6249e90d87183 pkg:maven/org.apache.james/apache-mime4j-dom@0.8.11 apache-mime4j-storage-0.8.11.jarDescription:
Java MIME Document Object Model Storage License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/james/apache-mime4j-storage/0.8.11/apache-mime4j-storage-0.8.11.jar
MD5: 5e9a9c4a751a54de790476f96bf3d152
SHA1: 874a7338051442158412a2734bbb84a8595e1428
SHA256: 70802a28b4f71319da90bc8b5b981d61163aeed7d1ecec083a0e4c49375f8b4f
Referenced In Project/Scope: Users Admin Web:compile
apache-mime4j-storage-0.8.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name apache-mime4j-storage High Vendor jar package name apache Highest Vendor jar package name james Highest Vendor jar package name mime4j Highest Vendor jar package name storage Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.james.apache-mime4j-storage Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid apache-mime4j-storage Highest Vendor pom artifactid apache-mime4j-storage Low Vendor pom groupid org.apache.james Highest Vendor pom name Apache James :: Mime4j :: Storage High Vendor pom parent-artifactid apache-mime4j-project Low Product file name apache-mime4j-storage High Product jar package name apache Highest Product jar package name james Highest Product jar package name mime4j Highest Product jar package name storage Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache James :: Mime4j :: Storage Medium Product Manifest bundle-symbolicname org.apache.james.apache-mime4j-storage Medium Product Manifest Implementation-Title Apache James :: Mime4j :: Storage High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache James :: Mime4j :: Storage Medium Product pom artifactid apache-mime4j-storage Highest Product pom groupid org.apache.james Highest Product pom name Apache James :: Mime4j :: Storage High Product pom parent-artifactid apache-mime4j-project Medium Version file version 0.8.11 High Version Manifest Bundle-Version 0.8.11 High Version Manifest Implementation-Version 0.8.11 High Version pom version 0.8.11 Highest
aspectjweaver-1.9.24.jarDescription:
The AspectJ weaver applies aspects to Java classes. It can be used as a Java agent in order to apply load-time
weaving (LTW) during class-loading and also contains the AspectJ runtime classes. License:
Eclipse Public License - v 2.0: https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt File Path: /opt/tomcat/.m2/repository/org/aspectj/aspectjweaver/1.9.24/aspectjweaver-1.9.24.jar
MD5: d95bb9406a5351d45a02145777b9a241
SHA1: 9b5aeb0cea9f958b9c57fb80e62996e95a3e9379
SHA256: 75e4227fb7dc5f97c3d4689cd1c2439f4db0bd18cea2fa242c4656cd93c599aa
Referenced In Project/Scope: Users Admin Web:compile
aspectjweaver-1.9.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name aspectjweaver High Vendor jar package name agent Highest Vendor jar package name and Highest Vendor jar package name aspectj Highest Vendor jar package name aspects Highest Vendor jar package name ltw Highest Vendor jar package name org Highest Vendor jar package name runtime Highest Vendor jar package name weaver Highest Vendor Manifest automatic-module-name org.aspectj.weaver Medium Vendor Manifest can-redefine-classes true Low Vendor manifest: org/aspectj/weaver/ Implementation-Vendor https://www.eclipse.org/aspectj/ Medium Vendor pom artifactid aspectjweaver Highest Vendor pom artifactid aspectjweaver Low Vendor pom developer email aclement@vmware.com Low Vendor pom developer email kriegaex@aspectj.dev Low Vendor pom developer id aclement Medium Vendor pom developer id kriegaex Medium Vendor pom developer name Alexander Kriegisch Medium Vendor pom developer name Andy Clement Medium Vendor pom groupid org.aspectj Highest Vendor pom name AspectJ Weaver High Vendor pom url https://www.eclipse.org/aspectj/ Highest Product file name aspectjweaver High Product jar package name agent Highest Product jar package name and Highest Product jar package name aspectj Highest Product jar package name aspects Highest Product jar package name ltw Highest Product jar package name org Highest Product jar package name runtime Highest Product jar package name weaver Highest Product Manifest automatic-module-name org.aspectj.weaver Medium Product Manifest can-redefine-classes true Low Product manifest: org/aspectj/weaver/ Implementation-Title org.aspectj.weaver Medium Product manifest: org/aspectj/weaver/ Specification-Title AspectJ Weaver Classes Medium Product pom artifactid aspectjweaver Highest Product pom developer email aclement@vmware.com Low Product pom developer email kriegaex@aspectj.dev Low Product pom developer id aclement Low Product pom developer id kriegaex Low Product pom developer name Alexander Kriegisch Low Product pom developer name Andy Clement Low Product pom groupid org.aspectj Highest Product pom name AspectJ Weaver High Product pom url https://www.eclipse.org/aspectj/ Medium Version file version 1.9.24 High Version manifest: org/aspectj/weaver/ Implementation-Version 1.9.24 Medium Version pom version 1.9.24 Highest
asyncutil-0.1.0.jarDescription:
Utilities for working with CompletionStages License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/ibm/async/asyncutil/0.1.0/asyncutil-0.1.0.jar
MD5: cbf288497b12b8c6c4ca728c57db77fd
SHA1: 440941c382166029a299602e6c9ff5abde1b5143
SHA256: cb80a7a5cd1fef63c7ea4c9abbc5138e84136657c19d148879d22e28e144fe04
Referenced In Project/Scope: Users Admin Web:compile
asyncutil-0.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name asyncutil High Vendor jar package name asyncutil Highest Vendor jar package name asyncutil Low Vendor jar package name ibm Highest Vendor jar package name ibm Low Vendor pom artifactid asyncutil Highest Vendor pom artifactid asyncutil Low Vendor pom developer email rkhadiwa@us.ibm.com Low Vendor pom developer email rnarubin@us.ibm.com Low Vendor pom developer name Ravi Khadiwala Medium Vendor pom developer name Renar Narubin Medium Vendor pom developer org IBM Medium Vendor pom developer org URL http://www.ibm.com Medium Vendor pom groupid com.ibm.async Highest Vendor pom name asyncutil High Vendor pom parent-artifactid asyncutil-aggregator Low Vendor pom url http://github.com/ibm/java-async-util Highest Product file name asyncutil High Product jar package name asyncutil Highest Product jar package name asyncutil Low Product jar package name ibm Highest Product pom artifactid asyncutil Highest Product pom developer email rkhadiwa@us.ibm.com Low Product pom developer email rnarubin@us.ibm.com Low Product pom developer name Ravi Khadiwala Low Product pom developer name Renar Narubin Low Product pom developer org IBM Low Product pom developer org URL http://www.ibm.com Low Product pom groupid com.ibm.async Highest Product pom name asyncutil High Product pom parent-artifactid asyncutil-aggregator Medium Product pom url http://github.com/ibm/java-async-util Medium Version file version 0.1.0 High Version pom version 0.1.0 Highest
btf-1.3.jarDescription:
Generic interfaces to the classical builder pattern and the less classical "freeze/thaw" pattern License:
Lesser General Public License, version 3 or greater: http://www.gnu.org/licenses/lgpl.html
Apache Software License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/com/github/java-json-tools/btf/1.3/btf-1.3.jar
MD5: 884a930eed6ea9212ae61521fa655af3
SHA1: 6cf5405e214cbc83337a107cdef8401fb6aa6383
SHA256: 67c3e462eb50807f4e0a5f4dee304bbf17cd986a42ee5eb0b2f4c9bf64d130d9
Referenced In Project/Scope: Users Admin Web:compile
btf-1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name btf High Vendor jar package name builder Highest Vendor jar package name github Highest Vendor Manifest bundle-symbolicname com.github.java-json-tools.btf Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid btf Highest Vendor pom artifactid btf Low Vendor pom developer email jhuffaker+java-json-tools@gmail.com Low Vendor pom developer id huggsboson Medium Vendor pom developer name John Huffaker Medium Vendor pom groupid com.github.java-json-tools Highest Vendor pom name btf High Vendor pom url java-json-tools/btf Highest Product file name btf High Product jar package name builder Highest Product jar package name github Highest Product Manifest Bundle-Name btf Medium Product Manifest bundle-symbolicname com.github.java-json-tools.btf Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid btf Highest Product pom developer email jhuffaker+java-json-tools@gmail.com Low Product pom developer id huggsboson Low Product pom developer name John Huffaker Low Product pom groupid com.github.java-json-tools Highest Product pom name btf High Product pom url java-json-tools/btf High Version file version 1.3 High Version Manifest Bundle-Version 1.3 High Version pom version 1.3 Highest
CVE-2022-45688 suppress
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2023-5072 suppress
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
classmate-1.5.1.jarDescription:
Library for introspecting types with full generic information
including resolving of field and method types.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar
MD5: e91fcd30ba329fd1b0b6dc5321fd067c
SHA1: 3fe0bed568c62df5e89f4f174c101eab25345b6c
SHA256: aab4de3006808c09d25dd4ff4a3611cfb63c95463cfd99e73d2e1680d229a33b
Referenced In Project/Scope: Users Admin Web:compile
classmate-1.5.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-validation@3.3.11
Evidence Type Source Name Value Confidence Vendor file name classmate High Vendor jar package name classmate Highest Vendor jar package name fasterxml Highest Vendor jar package name types Highest Vendor Manifest automatic-module-name com.fasterxml.classmate Medium Vendor Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor Manifest implementation-build-date 2019-10-19 22:46:35+0000 Low Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor fasterxml.com Low Vendor pom artifactid classmate Highest Vendor pom artifactid classmate Low Vendor pom developer email blangel@ocheyedan.net Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id blangel Medium Vendor pom developer id tatu Medium Vendor pom developer name Brian Langel Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid com.fasterxml Highest Vendor pom name ClassMate High Vendor pom organization name fasterxml.com High Vendor pom organization url https://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom url FasterXML/java-classmate Highest Product file name classmate High Product jar package name classmate Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product jar package name types Highest Product Manifest automatic-module-name com.fasterxml.classmate Medium Product Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Product Manifest Bundle-Name ClassMate Medium Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product Manifest implementation-build-date 2019-10-19 22:46:35+0000 Low Product Manifest Implementation-Title ClassMate High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title ClassMate Medium Product pom artifactid classmate Highest Product pom developer email blangel@ocheyedan.net Low Product pom developer email tatu@fasterxml.com Low Product pom developer id blangel Low Product pom developer id tatu Low Product pom developer name Brian Langel Low Product pom developer name Tatu Saloranta Low Product pom groupid com.fasterxml Highest Product pom name ClassMate High Product pom organization name fasterxml.com Low Product pom organization url https://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom url FasterXML/java-classmate High Version file version 1.5.1 High Version Manifest Bundle-Version 1.5.1 High Version Manifest Implementation-Version 1.5.1 High Version pom parent-version 1.5.1 Low Version pom version 1.5.1 Highest
codemodel-4.0.3.jarDescription:
The core functionality of the CodeModel java source code generation library License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/codemodel/4.0.3/codemodel-4.0.3.jar
MD5: 1e4f79edf55ab8c0f0e8e8803f511530
SHA1: 04ce3895b414420e7140cd51d52420aaddaccd45
SHA256: 15acc9323d54b14527de229b76f2de13a258f3fe2470c290cd00014cc6641d40
Referenced In Project/Scope: Users Admin Web:compile
codemodel-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name codemodel High Vendor jar package name codemodel Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.codemodel Medium Vendor Manifest implementation-build-id 4.0.3 - ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom artifactid codemodel Highest Vendor pom artifactid codemodel Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name Codemodel Core High Vendor pom parent-artifactid jaxb-codemodel-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name codemodel High Product jar package name codemodel Highest Product jar package name sun Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Codemodel Core Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.codemodel Medium Product Manifest implementation-build-id 4.0.3 - ff66b10 Low Product Manifest Implementation-Title Codemodel Core High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid codemodel Highest Product pom groupid org.glassfish.jaxb Highest Product pom name Codemodel Core High Product pom parent-artifactid jaxb-codemodel-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest Bundle-Version 4.0.3 High Version Manifest implementation-build-id 4.0.3 Low Version Manifest Implementation-Version 4.0.3 High Version pom version 4.0.3 Highest
commons-codec-1.16.1.jarDescription:
The Apache Commons Codec component contains encoder and decoders for
various formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/commons-codec/commons-codec/1.16.1/commons-codec-1.16.1.jar
MD5: 6c5be822d8d3fa61c3b54c4c8978dfdc
SHA1: 47bd4d333fba53406f6c6c51884ddbca435c8862
SHA256: ec87bfb55f22cbd1b21e2190eeda28b2b312ed2a431ee49fbdcc01812d04a5e4
Referenced In Project/Scope: Users Admin Web:compile
commons-codec-1.16.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-codec High Vendor jar package name apache Highest Vendor jar package name codec Highest Vendor jar package name commons Highest Vendor jar package name digest Highest Vendor jar package name encoder Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email mattsicker@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id mattsicker Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Matt Sicker Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product file name commons-codec High Product jar package name apache Highest Product jar package name codec Highest Product jar package name commons Highest Product jar package name digest Highest Product jar package name encoder Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Codec Medium Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email mattsicker@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id mattsicker Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Matt Sicker Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version file version 1.16.1 High Version Manifest Bundle-Version 1.16.1 High Version Manifest Implementation-Version 1.16.1 High Version pom parent-version 1.16.1 Low Version pom version 1.16.1 Highest
commons-collections4-4.4.jarDescription:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/commons/commons-collections4/4.4/commons-collections4-4.4.jar
MD5: 4a37023740719b391f10030362c86be6
SHA1: 62ebe7544cb7164d87e0637a2a6a2bdc981395e8
SHA256: 1df8b9430b5c8ed143d7815e403e33ef5371b2400aadbe9bda0883762e0846d1
Referenced In Project/Scope: Users Admin Web:compile
commons-collections4-4.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-collections4 High Vendor jar package name apache Highest Vendor jar package name collections4 Highest Vendor jar package name commons Highest Vendor Manifest automatic-module-name org.apache.commons.collections4 Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Vendor Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-collections4 Highest Vendor pom artifactid commons-collections4 Low Vendor pom developer id adriannistor Medium Vendor pom developer id amamment Medium Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dlaha Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id luc Medium Vendor pom developer id matth Medium Vendor pom developer id mbenson Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id scolebourne Medium Vendor pom developer id tn Medium Vendor pom developer name Adrian Nistor Medium Vendor pom developer name Arun M. Thomas Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Dipanjan Laha Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Luc Maisonobe Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Collections High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-collections/ Highest Product file name commons-collections4 High Product jar package name apache Highest Product jar package name collections4 Highest Product jar package name commons Highest Product Manifest automatic-module-name org.apache.commons.collections4 Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Product Manifest Bundle-Name Apache Commons Collections Medium Product Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Product Manifest Implementation-Title Apache Commons Collections High Product Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Collections Medium Product pom artifactid commons-collections4 Highest Product pom developer id adriannistor Low Product pom developer id amamment Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id craigmcc Low Product pom developer id dlaha Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id luc Low Product pom developer id matth Low Product pom developer id mbenson Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id scolebourne Low Product pom developer id tn Low Product pom developer name Adrian Nistor Low Product pom developer name Arun M. Thomas Low Product pom developer name Craig McClanahan Low Product pom developer name Dipanjan Laha Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Luc Maisonobe Low Product pom developer name Matt Benson Low Product pom developer name Matthew Hawthorne Low Product pom developer name Morgan Delagrange Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Stephen Colebourne Low Product pom developer name Thomas Neidhart Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Collections High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-collections/ Medium Version file version 4.4 High Version Manifest Implementation-Version 4.4 High Version pom parent-version 4.4 Low Version pom version 4.4 Highest
commons-io-2.15.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/commons-io/commons-io/2.15.0/commons-io-2.15.0.jar
MD5: 125a9d3dc2477b10cc6fa6e89c699e81
SHA1: 5c3c2db10f6f797430a7f9c696b4d1273768c924
SHA256: a328dad730921d197b6a9b195dffa00e41c974c2dac8fe37e84d31706bca7792
Referenced In Project/Scope: Users Admin Web:compile
commons-io-2.15.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Highest Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.15.0 High Version Manifest Bundle-Version 2.15.0 High Version Manifest Implementation-Version 2.15.0 High Version pom parent-version 2.15.0 Low Version pom version 2.15.0 Highest
commons-lang3-3.13.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar
MD5: 3435b913691a5c1b173485a49850b1a8
SHA1: b7263237aa89c1f99b327197c41d0669707a462e
SHA256: 82f528cf718c7a3c2f30fc5bc784e3c6a0a10b17605dadb9e16c82ede11e6064
Referenced In Project/Scope: Users Admin Web:compile
commons-lang3-3.13.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Highest Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version file version 3.13.0 High Version Manifest Bundle-Version 3.13.0 High Version Manifest Implementation-Version 3.13.0 High Version pom parent-version 3.13.0 Low Version pom version 3.13.0 Highest
commons-logging-1.2.jarDescription:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256: daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Project/Scope: Users Admin Web:compile
commons-logging-1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-test@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-logging High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-logging Highest Vendor pom artifactid commons-logging Low Vendor pom developer email baliuka@apache.org Low Vendor pom developer email costin@apache.org Low Vendor pom developer email craigmcc@apache.org Low Vendor pom developer email dennisl@apache.org Low Vendor pom developer email donaldp@apache.org Low Vendor pom developer email morgand@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email rsitze@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer email skitching@apache.org Low Vendor pom developer email tn@apache.org Low Vendor pom developer id baliuka Medium Vendor pom developer id bstansberry Medium Vendor pom developer id costin Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dennisl Medium Vendor pom developer id donaldp Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rsitze Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id skitching Medium Vendor pom developer id tn Medium Vendor pom developer name Brian Stansberry Medium Vendor pom developer name Costin Manolache Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Dennis Lundberg Medium Vendor pom developer name Juozas Baliuka Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Peter Donald Medium Vendor pom developer name Richard Sitze Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Simon Kitching Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer org Apache Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom groupid commons-logging Highest Vendor pom name Apache Commons Logging High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Product file name commons-logging High Product jar package name apache Highest Product jar package name commons Highest Product jar package name logging Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Product Manifest Bundle-Name Apache Commons Logging Medium Product Manifest bundle-symbolicname org.apache.commons.logging Medium Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Product Manifest Implementation-Title Apache Commons Logging High Product Manifest specification-title Apache Commons Logging Medium Product pom artifactid commons-logging Highest Product pom developer email baliuka@apache.org Low Product pom developer email costin@apache.org Low Product pom developer email craigmcc@apache.org Low Product pom developer email dennisl@apache.org Low Product pom developer email donaldp@apache.org Low Product pom developer email morgand@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email rsitze@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer email skitching@apache.org Low Product pom developer email tn@apache.org Low Product pom developer id baliuka Low Product pom developer id bstansberry Low Product pom developer id costin Low Product pom developer id craigmcc Low Product pom developer id dennisl Low Product pom developer id donaldp Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rsitze Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id skitching Low Product pom developer id tn Low Product pom developer name Brian Stansberry Low Product pom developer name Costin Manolache Low Product pom developer name Craig McClanahan Low Product pom developer name Dennis Lundberg Low Product pom developer name Juozas Baliuka Low Product pom developer name Morgan Delagrange Low Product pom developer name Peter Donald Low Product pom developer name Richard Sitze Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Simon Kitching Low Product pom developer name Thomas Neidhart Low Product pom developer org Apache Low Product pom developer org The Apache Software Foundation Low Product pom groupid commons-logging Highest Product pom name Apache Commons Logging High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url http://commons.apache.org/proper/commons-logging/ Medium Version file version 1.2 High Version Manifest Implementation-Version 1.2 High Version pom parent-version 1.2 Low Version pom version 1.2 Highest
commons-logging-jboss-logging-1.0.0.Final.jarDescription:
Apache Commons Logging to JBoss Logging implementation License:
Apache License 2.0: http://repository.jboss.org/licenses/apache-2.0.txt File Path: /opt/tomcat/.m2/repository/org/jboss/logging/commons-logging-jboss-logging/1.0.0.Final/commons-logging-jboss-logging-1.0.0.Final.jar
MD5: 46328c16f47be35563b73425d456445a
SHA1: 27a4e823d661bde67ec103bba2baf33cddde6e75
SHA256: f12176263ea25f4e78bb4fa4b36d335a29738dde6a8123e1b6da89a655d150ff
Referenced In Project/Scope: Users Admin Web:runtime
commons-logging-jboss-logging-1.0.0.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-logging-jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid commons-logging-jboss-logging Highest Vendor pom artifactid commons-logging-jboss-logging Low Vendor pom groupid org.jboss.logging Highest Vendor pom name Commons Logging to JBoss Logging High Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Vendor pom url http://www.jboss.org Highest Product file name commons-logging-jboss-logging High Product jar package name apache Highest Product jar package name commons Highest Product jar package name logging Highest Product Manifest Implementation-Title Commons Logging to JBoss Logging High Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Commons Logging to JBoss Logging Medium Product pom artifactid commons-logging-jboss-logging Highest Product pom groupid org.jboss.logging Highest Product pom name Commons Logging to JBoss Logging High Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Product pom url http://www.jboss.org Medium Version Manifest Implementation-Version 1.0.0.Final High Version pom parent-version 1.0.0.Final Low Version pom version 1.0.0.Final Highest
commons-text-1.11.0.jarDescription:
Apache Commons Text is a library focused on algorithms working on strings. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/commons/commons-text/1.11.0/commons-text-1.11.0.jar
MD5: ebfec4f77cc595c518d655f7e68346be
SHA1: 2bb044b7717ec2eccaf9ea7769c1509054b50e9a
SHA256: 2acf30a070b19163d5a480eae411a281341e870020e3534c6d5d4c8472739e30
Referenced In Project/Scope: Users Admin Web:compile
commons-text-1.11.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name commons-text High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name text Highest Vendor Manifest automatic-module-name org.apache.commons.text Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Vendor Manifest bundle-symbolicname org.apache.commons.text Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-text Highest Vendor pom artifactid commons-text Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email kinow@apache.org Low Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id ggregory Medium Vendor pom developer id kinow Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Bruno P. Kinoshita Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Text High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-text Highest Product file name commons-text High Product jar package name apache Highest Product jar package name commons Highest Product jar package name text Highest Product Manifest automatic-module-name org.apache.commons.text Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Product Manifest Bundle-Name Apache Commons Text Medium Product Manifest bundle-symbolicname org.apache.commons.text Medium Product Manifest Implementation-Title Apache Commons Text High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Commons Text Medium Product pom artifactid commons-text Highest Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email kinow@apache.org Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id ggregory Low Product pom developer id kinow Low Product pom developer name Benedikt Ritter Low Product pom developer name Bruno P. Kinoshita Low Product pom developer name Duncan Jones Low Product pom developer name Gary Gregory Low Product pom developer name Rob Tompkins Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Text High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-text Medium Version file version 1.11.0 High Version Manifest Bundle-Version 1.11.0 High Version Manifest Implementation-Version 1.11.0 High Version pom parent-version 1.11.0 Low Version pom version 1.11.0 Highest
freemarker-2.3.34.jarDescription:
FreeMarker is a "template engine"; a generic tool to generate text output based on templates.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/freemarker/freemarker/2.3.34/freemarker-2.3.34.jar
MD5: 1704fd3c579385ca5fd0ebcdf50df73c
SHA1: c2fa47a1c3b6dcdfca90e952e51211967a4baa54
SHA256: 9a9fb91cd64199232eb1ca9766148a5d30ef8944be5fac051018f96c70c8f6a3
Referenced In Project/Scope: Users Admin Web:compile
freemarker-2.3.34.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name freemarker High Vendor jar package name freemarker Highest Vendor jar package name on Highest Vendor jar package name template Highest Vendor Manifest automatic-module-name freemarker Medium Vendor Manifest bundle-requiredexecutionenvironment JavaSE-16, JavaSE-15, JavaSE-14, JavaSE-13, JavaSE-12, JavaSE-11, JavaSE-10, JavaSE-9, JavaSE-1.8 Low Vendor Manifest bundle-symbolicname org.freemarker.freemarker Medium Vendor Manifest extension-name FreeMarker Medium Vendor Manifest Implementation-Vendor freemarker.org High Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor freemarker.org Low Vendor pom artifactid freemarker Highest Vendor pom artifactid freemarker Low Vendor pom groupid org.freemarker Highest Vendor pom name Apache FreeMarker High Vendor pom organization name Apache Software Foundation High Vendor pom organization url http://apache.org Medium Vendor pom url https://freemarker.apache.org/ Highest Product file name freemarker High Product jar package name 16 Highest Product jar package name 9 Highest Product jar package name freemarker Highest Product jar package name on Highest Product jar package name template Highest Product jar package name version Highest Product Manifest automatic-module-name freemarker Medium Product Manifest Bundle-Name org.freemarker.freemarker Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-16, JavaSE-15, JavaSE-14, JavaSE-13, JavaSE-12, JavaSE-11, JavaSE-10, JavaSE-9, JavaSE-1.8 Low Product Manifest bundle-symbolicname org.freemarker.freemarker Medium Product Manifest extension-name FreeMarker Medium Product Manifest Implementation-Title FreeMarker High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title FreeMarker Medium Product pom artifactid freemarker Highest Product pom groupid org.freemarker Highest Product pom name Apache FreeMarker High Product pom organization name Apache Software Foundation Low Product pom organization url http://apache.org Low Product pom url https://freemarker.apache.org/ Medium Version file version 2.3.34 High Version Manifest Implementation-Version 2.3.34 High Version pom version 2.3.34 Highest
hibernate-validator-8.0.2.Final.jarDescription:
Hibernate's Jakarta Bean Validation reference implementation. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/hibernate/validator/hibernate-validator/8.0.2.Final/hibernate-validator-8.0.2.Final.jar
MD5: 1adda123292ba2627d03a696d8c7e76a
SHA1: 220e64815dd87535525331de20570017f899eb13
SHA256: 2f2224a5a19bdcfa73540e9ff5c971b6c425ad80415876f305259fe873a15b2f
Referenced In Project/Scope: Users Admin Web:compile
hibernate-validator-8.0.2.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-validation@3.3.11
Evidence Type Source Name Value Confidence Vendor file name hibernate-validator High Vendor hint analyzer vendor redhat Highest Vendor jar package name engine Highest Vendor jar package name hibernate Highest Vendor jar package name validator Highest Vendor Manifest automatic-module-name org.hibernate.validator Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-symbolicname org.hibernate.validator Medium Vendor Manifest implementation-url http://hibernate.org/validator/ Low Vendor Manifest Implementation-Vendor org.hibernate.validator High Vendor Manifest Implementation-Vendor-Id org.hibernate.validator Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom artifactid hibernate-validator Highest Vendor pom artifactid hibernate-validator Low Vendor pom groupid org.hibernate.validator Highest Vendor pom name Hibernate Validator Engine High Vendor pom parent-artifactid hibernate-validator-parent Low Product file name hibernate-validator High Product jar package name engine Highest Product jar package name hibernate Highest Product jar package name validator Highest Product Manifest automatic-module-name org.hibernate.validator Medium Product Manifest build-jdk-spec 17 Low Product Manifest Bundle-Name Hibernate Validator Engine Medium Product Manifest bundle-symbolicname org.hibernate.validator Medium Product Manifest Implementation-Title hibernate-validator High Product Manifest implementation-url http://hibernate.org/validator/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product Manifest specification-title Jakarta Bean Validation Medium Product pom artifactid hibernate-validator Highest Product pom groupid org.hibernate.validator Highest Product pom name Hibernate Validator Engine High Product pom parent-artifactid hibernate-validator-parent Medium Version Manifest Bundle-Version 8.0.2.Final High Version Manifest Implementation-Version 8.0.2.Final High Version pom version 8.0.2.Final Highest
httpclient-4.5.14.jarDescription:
Apache HttpComponents Client
File Path: /opt/tomcat/.m2/repository/org/apache/httpcomponents/httpclient/4.5.14/httpclient-4.5.14.jarMD5: 2cb357c4b763f47e58af6cad47df6ba3SHA1: 1194890e6f56ec29177673f2f12d0b8e627dec98SHA256: c8bc7e1c51a6d4ce72f40d2ebbabf1c4b68bfe76e732104b04381b493478e9d6Referenced In Project/Scope: Users Admin Web:compilehttpclient-4.5.14.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name httpclient High Vendor jar package name apache Highest Vendor jar package name client Highest Vendor jar package name httpclient Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpclient Highest Vendor pom artifactid httpclient Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpClient High Vendor pom parent-artifactid httpcomponents-client Low Vendor pom url http://hc.apache.org/httpcomponents-client-ga Highest Product file name httpclient High Product jar package name apache Highest Product jar package name client Highest Product jar package name http Highest Product jar package name httpclient Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Product Manifest Implementation-Title Apache HttpClient High Product Manifest implementation-url http://hc.apache.org/httpcomponents-client-ga Low Product Manifest specification-title Apache HttpClient Medium Product pom artifactid httpclient Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpClient High Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client-ga Medium Version file version 4.5.14 High Version Manifest Implementation-Version 4.5.14 High Version pom version 4.5.14 Highest
httpcore-4.4.16.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /opt/tomcat/.m2/repository/org/apache/httpcomponents/httpcore/4.4.16/httpcore-4.4.16.jarMD5: 28d2cd9bf8789fd2ec774fb88436ebd1SHA1: 51cf043c87253c9f58b539c9f7e44c8894223850SHA256: 6c9b3dd142a09dc468e23ad39aad6f75a0f2b85125104469f026e52a474e464fReferenced In Project/Scope: Users Admin Web:compilehttpcore-4.4.16.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name httpcore High Vendor jar package name apache Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor pom artifactid httpcore Highest Vendor pom artifactid httpcore Low Vendor pom groupid org.apache.httpcomponents Highest Vendor pom name Apache HttpCore High Vendor pom parent-artifactid httpcomponents-core Low Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Product file name httpcore High Product jar package name apache Highest Product jar package name http Highest Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2022-11-26 09:44:32+0000 Low Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product pom artifactid httpcore Highest Product pom groupid org.apache.httpcomponents Highest Product pom name Apache HttpCore High Product pom parent-artifactid httpcomponents-core Medium Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Version file version 4.4.16 High Version Manifest Implementation-Version 4.4.16 High Version pom version 4.4.16 Highest
istack-commons-tools-4.1.2.jarDescription:
istack common utility code License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/com/sun/istack/istack-commons-tools/4.1.2/istack-commons-tools-4.1.2.jar
MD5: 53590bcdfeafccd31d1d1bc791af1555
SHA1: 585c1af261fbc0b0cccf72f4d6c5ff11c1e596b1
SHA256: 85b4fe7ad6fdfc64a586133f039d3de7b51db2c8111a1aa98a267891e27f386f
Referenced In Project/Scope: Users Admin Web:compile
istack-commons-tools-4.1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name istack-commons-tools High Vendor jar package name istack Highest Vendor jar package name sun Highest Vendor jar package name tools Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-tools Medium Vendor Manifest implementation-build-id 4.1.2 - 343a28e Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom artifactid istack-commons-tools Highest Vendor pom artifactid istack-commons-tools Low Vendor pom groupid com.sun.istack Highest Vendor pom name istack common utility code tools High Vendor pom parent-artifactid istack-commons Low Product file name istack-commons-tools High Product jar package name istack Highest Product jar package name sun Highest Product jar package name tools Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name istack common utility code tools Medium Product Manifest bundle-symbolicname com.sun.istack.commons-tools Medium Product Manifest implementation-build-id 4.1.2 - 343a28e Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid istack-commons-tools Highest Product pom groupid com.sun.istack Highest Product pom name istack common utility code tools High Product pom parent-artifactid istack-commons Medium Version file version 4.1.2 High Version Manifest Bundle-Version 4.1.2 High Version Manifest implementation-build-id 4.1.2 Low Version pom version 4.1.2 Highest
Related Dependencies istack-commons-runtime-4.1.2.jarFile Path: /opt/tomcat/.m2/repository/com/sun/istack/istack-commons-runtime/4.1.2/istack-commons-runtime-4.1.2.jar MD5: 535154ef647af2a52478c4debec93659 SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739 SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee pkg:maven/com.sun.istack/istack-commons-runtime@4.1.2 jackson-annotations-2.17.3.jarDescription:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.17.3/jackson-annotations-2.17.3.jar
MD5: cb80e34a9fa3c0b27560e1562dfdff43
SHA1: 4f30a05d2eee0ab700cdc27aa5967e934d3042b2
SHA256: 2747f60343783a6ec8a68405c7c839fa0bbe30ee4e2459d21a1ac3b7365e1ed5
Referenced In Project/Scope: Users Admin Web:compile
jackson-annotations-2.17.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-annotations High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-annotations Highest Vendor pom artifactid jackson-annotations Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-annotations High Vendor pom parent-artifactid jackson-parent Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-annotations High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name Jackson-annotations Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Product Manifest Implementation-Title Jackson-annotations High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title Jackson-annotations Medium Product pom artifactid jackson-annotations Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-annotations High Product pom parent-artifactid jackson-parent Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.17.3 High Version Manifest Bundle-Version 2.17.3 High Version Manifest Implementation-Version 2.17.3 High Version pom parent-version 2.17.3 Low Version pom version 2.17.3 Highest
Related Dependencies jackson-datatype-jdk8-2.17.3.jarFile Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jdk8/2.17.3/jackson-datatype-jdk8-2.17.3.jar MD5: ae9824e8bd6f39c92e5feaec026bed39 SHA1: 2b8b1894dc9798e761bd565df51ef1fc44c75a2a SHA256: b7207c1df9d89e95efd23793d3a13b1295bec0d9be58b3582ea0dff6cb096fa2 pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.17.3 jackson-datatype-jsr310-2.17.3.jarFile Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jsr310/2.17.3/jackson-datatype-jsr310-2.17.3.jar MD5: 9b733e7f3fa1f7a8fba27de5fb09aec3 SHA1: a25fe2f5607fea9e00ed00cf81b7aa2eaacbbd6e SHA256: b1e3e4be52f69ecf6442d8a07e96ddd200bacb1867cb47460ade87710552a9ee pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.17.3 jackson-module-parameter-names-2.17.3.jar jackson-core-2.17.3.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.17.3/jackson-core-2.17.3.jar
MD5: b38c1cd06ec2b87bd23494962c44da69
SHA1: 1d6eb3e959c737692b720d3492b2f1f34c4c8579
SHA256: 19e03ee71f00a86255fa3c980560b231e1305486f6482c905601209014f5870c
Referenced In Project/Scope: Users Admin Web:compile
jackson-core-2.17.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.17.3
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor jar package name base Highest Vendor jar package name com Highest Vendor jar package name core Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name json Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-core Highest Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-core High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-core Highest Product file name jackson-core High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name base Highest Product jar package name com Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product jar package name jackson Highest Product jar package name json Highest Product jar package name version Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest Implementation-Title Jackson-core High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson-core Medium Product pom artifactid jackson-core Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-core High Version file version 2.17.3 High Version Manifest Bundle-Version 2.17.3 High Version Manifest Implementation-Version 2.17.3 High Version pom version 2.17.3 Highest
CVE-2022-45688 suppress
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2023-5072 suppress
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
jackson-coreutils-2.0.jarDescription:
JSON Pointer (RFC 6901) and numeric equality for Jackson (2.2.x) License:
Lesser General Public License, version 3 or greater: http://www.gnu.org/licenses/lgpl.html
Apache Software License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/com/github/java-json-tools/jackson-coreutils/2.0/jackson-coreutils-2.0.jar
MD5: 7d2699a50f92f6ee224d1d75fbd884ef
SHA1: 6374371261b91b829d10f21256b2feefdf8f0a78
SHA256: 16b3aabd3a9eb25655dda433e35f9bd9c7c1aa7991427702f5f11f000813dbb0
Referenced In Project/Scope: Users Admin Web:compile
jackson-coreutils-2.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-coreutils High Vendor jar package name github Highest Vendor jar package name jackson Highest Vendor Manifest bundle-symbolicname jackson-coreutils Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid jackson-coreutils Highest Vendor pom artifactid jackson-coreutils Low Vendor pom developer email jhuffaker+java-json-tools@gmail.com Low Vendor pom developer id huggsboson Medium Vendor pom developer name John Huffaker Medium Vendor pom groupid com.github.java-json-tools Highest Vendor pom name jackson-coreutils High Vendor pom url java-json-tools/jackson-coreutils Highest Product file name jackson-coreutils High Product jar package name github Highest Product jar package name jackson Highest Product Manifest Bundle-Name jackson-coreutils Medium Product Manifest bundle-symbolicname jackson-coreutils Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid jackson-coreutils Highest Product pom developer email jhuffaker+java-json-tools@gmail.com Low Product pom developer id huggsboson Low Product pom developer name John Huffaker Low Product pom groupid com.github.java-json-tools Highest Product pom name jackson-coreutils High Product pom url java-json-tools/jackson-coreutils High Version file version 2.0 High Version pom version 2.0 Highest
CVE-2022-45688 suppress
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2023-5072 suppress
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
jackson-databind-2.17.3.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.17.3/jackson-databind-2.17.3.jar
MD5: 820811143157937e800b899a4feeb261
SHA1: 42c617beb411ee813bdc39a287424bfb19d99185
SHA256: 93b13e709a0b620de42019180a75bc1fc4885c81fe5b6087a4aa248f91fb9a95
Referenced In Project/Scope: Users Admin Web:compile
jackson-databind-2.17.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-databind High Vendor jar package name databind Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-databind Highest Vendor pom artifactid jackson-databind Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name jackson-databind High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-databind High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name databind Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title jackson-databind Medium Product pom artifactid jackson-databind Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name jackson-databind High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.17.3 High Version Manifest Bundle-Version 2.17.3 High Version Manifest Implementation-Version 2.17.3 High Version pom version 2.17.3 Highest
jackson-jakarta-rs-base-2.17.3.jarDescription:
Pile of code that is shared by all Jackson-based Jakarta-RS
providers.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/jakarta/rs/jackson-jakarta-rs-base/2.17.3/jackson-jakarta-rs-base-2.17.3.jar
MD5: e5e65ccf37efb69f3bddfcce87254c22
SHA1: 686bb983cf901d79d456fa7b12dbf492a250f624
SHA256: c01b46163ee2e639962be14d1e16d18c84e135beff572122f4bce12229ce2113
Referenced In Project/Scope: Users Admin Web:compile
jackson-jakarta-rs-base-2.17.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-jakarta-rs-base High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name jakarta Highest Vendor jar package name rs Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-base Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-base Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.jakarta.rs Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-jakarta-rs-base Highest Vendor pom artifactid jackson-jakarta-rs-base Low Vendor pom groupid com.fasterxml.jackson.jakarta.rs Highest Vendor pom name Jackson Jakarta-RS: base High Vendor pom parent-artifactid jackson-jakarta-rs-providers Low Product file name jackson-jakarta-rs-base High Product jar package name 11 Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jakarta Highest Product jar package name rs Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-base Low Product Manifest Bundle-Name Jackson Jakarta-RS: base Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-base Medium Product Manifest Implementation-Title Jackson Jakarta-RS: base High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson Jakarta-RS: base Medium Product pom artifactid jackson-jakarta-rs-base Highest Product pom groupid com.fasterxml.jackson.jakarta.rs Highest Product pom name Jackson Jakarta-RS: base High Product pom parent-artifactid jackson-jakarta-rs-providers Medium Version file version 2.17.3 High Version Manifest Bundle-Version 2.17.3 High Version Manifest Implementation-Version 2.17.3 High Version pom version 2.17.3 Highest
jackson-jakarta-rs-json-provider-2.17.3.jarDescription:
Functionality to handle JSON input/output for Jakarta-RS implementations
(like Jersey and RESTeasy) using standard Jackson data binding.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/jakarta/rs/jackson-jakarta-rs-json-provider/2.17.3/jackson-jakarta-rs-json-provider-2.17.3.jar
MD5: cfbb0b864f335bb3f7ba47a6c1c8eb56
SHA1: 7caa7f9b3b307cd9de31cc034d55802b224ab8fb
SHA256: 2ecc4a35fad7eed375ef29861291138f6759f0a3af7868effa387af4d14d6c77
Referenced In Project/Scope: Users Admin Web:compile
jackson-jakarta-rs-json-provider-2.17.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-jakarta-rs-json-provider High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name jakarta Highest Vendor jar package name rs Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-json-provider Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-json-provider Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.jakarta.rs Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-jakarta-rs-json-provider Highest Vendor pom artifactid jackson-jakarta-rs-json-provider Low Vendor pom groupid com.fasterxml.jackson.jakarta.rs Highest Vendor pom name Jackson Jakarta-RS: JSON High Vendor pom parent-artifactid jackson-jakarta-rs-providers Low Product file name jackson-jakarta-rs-json-provider High Product jar package name 11 Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jakarta Highest Product jar package name rs Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-jakarta-rs-providers/jackson-jakarta-rs-json-provider Low Product Manifest Bundle-Name Jackson Jakarta-RS: JSON Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.jakarta.rs.jackson-jakarta-rs-json-provider Medium Product Manifest Implementation-Title Jackson Jakarta-RS: JSON High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson Jakarta-RS: JSON Medium Product pom artifactid jackson-jakarta-rs-json-provider Highest Product pom groupid com.fasterxml.jackson.jakarta.rs Highest Product pom name Jackson Jakarta-RS: JSON High Product pom parent-artifactid jackson-jakarta-rs-providers Medium Version file version 2.17.3 High Version Manifest Bundle-Version 2.17.3 High Version Manifest Implementation-Version 2.17.3 High Version pom version 2.17.3 Highest
CVE-2022-45688 suppress
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2023-5072 suppress
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
jackson-module-jakarta-xmlbind-annotations-2.17.3.jarDescription:
Support for using Jakarta XML Bind (aka JAXB 3.0) annotations as an alternative
to "native" Jackson annotations, for configuring data-binding.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/fasterxml/jackson/module/jackson-module-jakarta-xmlbind-annotations/2.17.3/jackson-module-jakarta-xmlbind-annotations-2.17.3.jar
MD5: f999c40ff7777d2e3162ba3f4a5f63c3
SHA1: 93c4f8434820f7581c8905804be34dffc7f2a189
SHA256: 167d7d48ddabe3a3c2941551992832232f61b19d77cafbf9f7080d1293aafcb4
Referenced In Project/Scope: Users Admin Web:compile
jackson-module-jakarta-xmlbind-annotations-2.17.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-module-jakarta-xmlbind-annotations High Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name jakarta Highest Vendor jar package name module Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jakarta-xmlbind-annotations Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-module-jakarta-xmlbind-annotations Highest Vendor pom artifactid jackson-module-jakarta-xmlbind-annotations Low Vendor pom groupid com.fasterxml.jackson.module Highest Vendor pom name Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) High Vendor pom parent-artifactid jackson-modules-base Low Vendor pom url FasterXML/jackson-modules-base Highest Product file name jackson-module-jakarta-xmlbind-annotations High Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name jakarta Highest Product jar package name module Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Product Manifest Bundle-Name Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jakarta-xmlbind-annotations Medium Product Manifest Implementation-Title Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) Medium Product pom artifactid jackson-module-jakarta-xmlbind-annotations Highest Product pom groupid com.fasterxml.jackson.module Highest Product pom name Jackson module: Jakarta XML Bind Annotations (jakarta.xml.bind) High Product pom parent-artifactid jackson-modules-base Medium Product pom url FasterXML/jackson-modules-base High Version file version 2.17.3 High Version Manifest Bundle-Version 2.17.3 High Version Manifest Implementation-Version 2.17.3 High Version pom version 2.17.3 Highest
jakarta.activation-api-2.1.3.jarDescription:
${project.name} ${spec.version} Specification License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/jakarta/activation/jakarta.activation-api/2.1.3/jakarta.activation-api-2.1.3.jar
MD5: 76e7b680375ea9f40f3ddbd702efcd25
SHA1: fa165bd70cda600368eee31555222776a46b881f
SHA256: 01b176d718a169263e78290691fc479977186bcc6b333487325084d6586f4627
Referenced In Project/Scope: Users Admin Web:compile
jakarta.activation-api-2.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@3.3.11
Evidence Type Source Name Value Confidence Vendor file name jakarta.activation-api High Vendor jar package name activation Highest Vendor jar package name jakarta Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest implementation-build-id 7f7d358 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.activation.spi.MailcapRegistryProvider)";osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider";cardinality:=multiple;resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.activation.spi.MimeTypeRegistryProvider)";osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider";cardinality:=multiple;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.activation-api Highest Vendor pom artifactid jakarta.activation-api Low Vendor pom developer email bill.shannon@oracle.com Low Vendor pom developer id shannon Medium Vendor pom developer name Bill Shannon Medium Vendor pom developer org Oracle Medium Vendor pom groupid jakarta.activation Highest Vendor pom name Jakarta Activation API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url jakartaee/jaf-api Highest Vendor pom (hint) developer org sun Medium Product file name jakarta.activation-api High Product jar package name activation Highest Product jar package name jakarta Highest Product jar package name mailcapregistryprovider Highest Product jar package name mimetyperegistryprovider Highest Product jar package name spi Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Activation API Medium Product Manifest bundle-symbolicname jakarta.activation-api Medium Product Manifest extension-name jakarta.activation Medium Product Manifest implementation-build-id 7f7d358 Low Product Manifest Implementation-Title Jakarta Activation API High Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.activation.spi.MailcapRegistryProvider)";osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider";cardinality:=multiple;resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.activation.spi.MimeTypeRegistryProvider)";osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider";cardinality:=multiple;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid jakarta.activation-api Highest Product pom developer email bill.shannon@oracle.com Low Product pom developer id shannon Low Product pom developer name Bill Shannon Low Product pom developer org Oracle Low Product pom groupid jakarta.activation Highest Product pom name Jakarta Activation API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url jakartaee/jaf-api High Version file version 2.1.3 High Version Manifest Bundle-Version 2.1.3 High Version pom parent-version 2.1.3 Low Version pom version 2.1.3 Highest
CVE-2023-4218 suppress
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv3:
Base Score: MEDIUM (5.0) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2008-7271 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2010-4647 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
jakarta.annotation-api-2.1.1.jarDescription:
Jakarta Annotations API License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /opt/tomcat/.m2/repository/jakarta/annotation/jakarta.annotation-api/2.1.1/jakarta.annotation-api-2.1.1.jar
MD5: 5dac2f68e8288d0add4dc92cb161711d
SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3
SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe
Referenced In Project/Scope: Users Admin Web:compile
jakarta.annotation-api-2.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-test@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jakarta.annotation-api High Vendor jar package name annotation Highest Vendor jar package name jakarta Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium Vendor Manifest extension-name jakarta.annotation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.annotation-api Highest Vendor pom artifactid jakarta.annotation-api Low Vendor pom developer name Dmitry Kornilov Medium Vendor pom developer name Linda De Michiel Medium Vendor pom developer org Oracle Corp. Medium Vendor pom groupid jakarta.annotation Highest Vendor pom name Jakarta Annotations API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest Product file name jakarta.annotation-api High Product jar package name annotation Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Annotations API Medium Product Manifest bundle-symbolicname jakarta.annotation-api Medium Product Manifest extension-name jakarta.annotation Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid jakarta.annotation-api Highest Product pom developer name Dmitry Kornilov Low Product pom developer name Linda De Michiel Low Product pom developer org Oracle Corp. Low Product pom groupid jakarta.annotation Highest Product pom name Jakarta Annotations API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium Version file version 2.1.1 High Version Manifest Bundle-Version 2.1.1 High Version Manifest Implementation-Version 2.1.1 High Version pom parent-version 2.1.1 Low Version pom version 2.1.1 Highest
jakarta.mail-api-2.1.3.jarDescription:
${project.name} ${spec.version} Specification API License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/jakarta/mail/jakarta.mail-api/2.1.3/jakarta.mail-api-2.1.3.jar
MD5: 288a687deb06b87602ce14cd03dddff4
SHA1: a327aa5f514ba86e80d54584417d7376ed2bde0e
SHA256: 8051b58d75f982f9a5b963b3765426e824b2a64865ef0af17205e455b98db05c
Referenced In Project/Scope: Users Admin Web:compile
jakarta.mail-api-2.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jakarta.mail-api High Vendor jar package name jakarta Highest Vendor jar package name mail Highest Vendor jar package name version Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.mail-api Medium Vendor Manifest extension-name jakarta.mail Medium Vendor Manifest implementation-build-id 0f448dc Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.mail.Provider)";osgi.serviceloader="jakarta.mail.Provider";cardinality:=multiple;resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.mail.util.StreamProvider)";osgi.serviceloader="jakarta.mail.util.StreamProvider";cardinality:=multiple;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.mail-api Highest Vendor pom artifactid jakarta.mail-api Low Vendor pom groupid jakarta.mail Highest Vendor pom name Jakarta Mail API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Product file name jakarta.mail-api High Product jar package name jakarta Highest Product jar package name mail Highest Product jar package name provider Highest Product jar package name streamprovider Highest Product jar package name util Highest Product jar package name version Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Mail API Medium Product Manifest bundle-symbolicname jakarta.mail-api Medium Product Manifest extension-name jakarta.mail Medium Product Manifest implementation-build-id 0f448dc Low Product Manifest Implementation-Title Jakarta Mail API High Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.mail.Provider)";osgi.serviceloader="jakarta.mail.Provider";cardinality:=multiple;resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.mail.util.StreamProvider)";osgi.serviceloader="jakarta.mail.util.StreamProvider";cardinality:=multiple;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jakarta Mail Specification Medium Product pom artifactid jakarta.mail-api Highest Product pom groupid jakarta.mail Highest Product pom name Jakarta Mail API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Version file version 2.1.3 High Version Manifest Bundle-Version 2.1.3 High Version pom parent-version 2.1.3 Low Version pom version 2.1.3 Highest
CVE-2023-4218 suppress
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
CVSSv3:
Base Score: MEDIUM (5.0) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2008-7271 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2010-4647 suppress
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp. CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv2:
Base Score: MEDIUM (4.3) Vector: /AV:N/AC:M/Au:N/C:N/I:P/A:N References:
Vulnerable Software & Versions: (show all )
jakarta.servlet-api-6.0.0.jarDescription:
Jakarta Servlet 6.0 License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /opt/tomcat/.m2/repository/jakarta/servlet/jakarta.servlet-api/6.0.0/jakarta.servlet-api-6.0.0.jar
MD5: 4bcb3175ed9b7aa3f038d082879ec2a8
SHA1: abecc699286e65035ebba9844c03931357a6a963
SHA256: c034eb1afb158987dbb53a5fea0cadf611c8dae8daadd59c44d9d5ab70129cef
Referenced In Project/Scope: Users Admin Web:provided
jakarta.servlet-api-6.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jakarta.servlet-api High Vendor jar package name jakarta Highest Vendor jar package name servlet Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.servlet-api Medium Vendor Manifest extension-name jakarta.servlet Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.servlet-api Highest Vendor pom artifactid jakarta.servlet-api Low Vendor pom developer id yaminikb Medium Vendor pom developer name Yamini K B Medium Vendor pom developer org Oracle Corporation Medium Vendor pom developer org URL http://www.oracle.com/ Medium Vendor pom groupid jakarta.servlet Highest Vendor pom name Jakarta Servlet High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.servlet Highest Product file name jakarta.servlet-api High Product jar package name filter Highest Product jar package name jakarta Highest Product jar package name servlet Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Servlet Medium Product Manifest bundle-symbolicname jakarta.servlet-api Medium Product Manifest extension-name jakarta.servlet Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid jakarta.servlet-api Highest Product pom developer id yaminikb Low Product pom developer name Yamini K B Low Product pom developer org Oracle Corporation Low Product pom developer org URL http://www.oracle.com/ Low Product pom groupid jakarta.servlet Highest Product pom name Jakarta Servlet High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url https://projects.eclipse.org/projects/ee4j.servlet Medium Version file version 6.0.0 High Version Manifest Bundle-Version 6.0.0 High Version Manifest Implementation-Version 6.0.0 High Version pom parent-version 6.0.0 Low Version pom version 6.0.0 Highest
jakarta.validation-api-3.0.2.jarDescription:
Jakarta Bean Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/jakarta/validation/jakarta.validation-api/3.0.2/jakarta.validation-api-3.0.2.jar
MD5: 3a1ee6efca3e41e3320599790f54c5eb
SHA1: 92b6631659ba35ca09e44874d3eb936edfeee532
SHA256: 291c25e6910cc6a7ebd96d4c6baebf6d7c37676c5482c2d96146e901b62c1fc9
Referenced In Project/Scope: Users Admin Web:compile
jakarta.validation-api-3.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jakarta.validation-api High Vendor jar package name jakarta Highest Vendor jar package name validation Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid jakarta.validation-api Highest Vendor pom artifactid jakarta.validation-api Low Vendor pom developer email emmanuel@hibernate.org Low Vendor pom developer email guillaume.smet@hibernate.org Low Vendor pom developer email gunnar@hibernate.org Low Vendor pom developer email hferents@redhat.com Low Vendor pom developer id emmanuelbernard Medium Vendor pom developer id epbernard Medium Vendor pom developer id guillaume.smet Medium Vendor pom developer id gunnar.morling Medium Vendor pom developer id hardy.ferentschik Medium Vendor pom developer name Emmanuel Bernard Medium Vendor pom developer name Guillaume Smet Medium Vendor pom developer name Gunnar Morling Medium Vendor pom developer name Hardy Ferentschik Medium Vendor pom developer org Red Hat, Inc. Medium Vendor pom groupid jakarta.validation Highest Vendor pom name Jakarta Bean Validation API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://beanvalidation.org Highest Product file name jakarta.validation-api High Product jar package name jakarta Highest Product jar package name validation Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Bean Validation API Medium Product Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid jakarta.validation-api Highest Product pom developer email emmanuel@hibernate.org Low Product pom developer email guillaume.smet@hibernate.org Low Product pom developer email gunnar@hibernate.org Low Product pom developer email hferents@redhat.com Low Product pom developer id emmanuelbernard Low Product pom developer id epbernard Low Product pom developer id guillaume.smet Low Product pom developer id gunnar.morling Low Product pom developer id hardy.ferentschik Low Product pom developer name Emmanuel Bernard Low Product pom developer name Guillaume Smet Low Product pom developer name Gunnar Morling Low Product pom developer name Hardy Ferentschik Low Product pom developer org Red Hat, Inc. Low Product pom groupid jakarta.validation Highest Product pom name Jakarta Bean Validation API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url https://beanvalidation.org Medium Version file version 3.0.2 High Version Manifest Bundle-Version 3.0.2 High Version pom parent-version 3.0.2 Low Version pom version 3.0.2 Highest
jakarta.ws.rs-api-3.1.0.jarDescription:
Jakarta RESTful Web Services License:
EPL-2.0: http://www.eclipse.org/legal/epl-2.0
GPL-2.0-with-classpath-exception: https://www.gnu.org/software/classpath/license.html File Path: /opt/tomcat/.m2/repository/jakarta/ws/rs/jakarta.ws.rs-api/3.1.0/jakarta.ws.rs-api-3.1.0.jar
MD5: 6ce4c6749e048456b2c452c1091689ca
SHA1: 15ce10d249a38865b58fc39521f10f29ab0e3363
SHA256: 6b3b3628b8b4aedda0d24c3354335e985497d8ef3c510b8f3028e920d5b8663d
Referenced In Project/Scope: Users Admin Web:compile
jakarta.ws.rs-api-3.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jakarta.ws.rs-api High Vendor hint analyzer vendor web services Medium Vendor jar package name jakarta Highest Vendor jar package name rs Highest Vendor jar package name ws Highest Vendor Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low Vendor Manifest bundle-symbolicname jakarta.ws.rs-api Medium Vendor Manifest extension-name jakarta.ws.rs Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.ws.rs-api Highest Vendor pom artifactid jakarta.ws.rs-api Low Vendor pom developer email jaxrs-dev@eclipse.org Low Vendor pom developer id developers Medium Vendor pom developer name JAX-RS API Developers Medium Vendor pom groupid jakarta.ws.rs Highest Vendor pom name Jakarta RESTful WS API High Vendor pom organization name Eclipse Foundation High Vendor pom organization url https://www.eclipse.org/org/foundation/ Medium Vendor pom parent-artifactid all Low Vendor pom url eclipse-ee4j/jaxrs-api Highest Product file name jakarta.ws.rs-api High Product hint analyzer product web services Medium Product jar package name jakarta Highest Product jar package name rs Highest Product jar package name ws Highest Product Manifest bundle-docurl https://www.eclipse.org/org/foundation/ Low Product Manifest Bundle-Name Jakarta RESTful WS API Medium Product Manifest bundle-symbolicname jakarta.ws.rs-api Medium Product Manifest extension-name jakarta.ws.rs Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid jakarta.ws.rs-api Highest Product pom developer email jaxrs-dev@eclipse.org Low Product pom developer id developers Low Product pom developer name JAX-RS API Developers Low Product pom groupid jakarta.ws.rs Highest Product pom name Jakarta RESTful WS API High Product pom organization name Eclipse Foundation Low Product pom organization url https://www.eclipse.org/org/foundation/ Low Product pom parent-artifactid all Medium Product pom url eclipse-ee4j/jaxrs-api High Version file version 3.1.0 High Version Manifest Bundle-Version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom version 3.1.0 Highest
jakarta.xml.bind-api-4.0.2.jarDescription:
Jakarta XML Binding API 4.0 Design Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/jakarta/xml/bind/jakarta.xml.bind-api/4.0.2/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: Users Admin Web:compile
jakarta.xml.bind-api-4.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@3.3.11
Evidence Type Source Name Value Confidence Vendor file name jakarta.xml.bind-api High Vendor jar package name bind Highest Vendor jar package name jakarta Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium Vendor Manifest extension-name jakarta.xml.bind Medium Vendor Manifest implementation-build-id ca43d8b Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.xml.bind.JAXBContextFactory)";osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory";cardinality:=multiple;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.xml.bind-api Highest Vendor pom artifactid jakarta.xml.bind-api Low Vendor pom groupid jakarta.xml.bind Highest Vendor pom name Jakarta XML Binding API High Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low Product file name jakarta.xml.bind-api High Product jar package name bind Highest Product jar package name jakarta Highest Product jar package name jaxbcontextfactory Highest Product jar package name xml Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta XML Binding API Medium Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium Product Manifest extension-name jakarta.xml.bind Medium Product Manifest implementation-build-id ca43d8b Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))";resolution:=optional,osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.xml.bind.JAXBContextFactory)";osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory";cardinality:=multiple;resolution:=optional,osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid jakarta.xml.bind-api Highest Product pom groupid jakarta.xml.bind Highest Product pom name Jakarta XML Binding API High Product pom parent-artifactid jakarta.xml.bind-api-parent Medium Version file version 4.0.2 High Version Manifest Bundle-Version 4.0.2 High Version Manifest Implementation-Version 4.0.2 High Version pom version 4.0.2 Highest
jandex-2.4.5.Final.jarDescription:
Parent POM for JBoss projects. Provides default project build configuration. License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/jboss/jandex/2.4.5.Final/jandex-2.4.5.Final.jar
MD5: 81ce0b995162eedcd867f10b3914c517
SHA1: 9b4634d1fa28628549eb986b7c0c73f387090fba
SHA256: 70a283bcf11a82b14c20d1a9be731d301aedfd98be1b4c0f5b35fe60b305caff
Referenced In Project/Scope: Users Admin Web:compile
jandex-2.4.5.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jandex High Vendor hint analyzer vendor redhat Highest Vendor jar package name indexer Highest Vendor jar package name jandex Highest Vendor jar package name jboss Highest Vendor Manifest automatic-module-name org.jboss.jandex Medium Vendor Manifest build-timestamp Tue, 7 May 2024 11:14:46 +0200 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.jandex Medium Vendor Manifest implementation-url http://www.jboss.org/jandex Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jandex Highest Vendor pom artifactid jandex Low Vendor pom groupid org.jboss Highest Vendor pom name Java Annotation Indexer High Vendor pom parent-artifactid jboss-parent Low Product file name jandex High Product jar package name indexer Highest Product jar package name jandex Highest Product jar package name jboss Highest Product Manifest automatic-module-name org.jboss.jandex Medium Product Manifest build-timestamp Tue, 7 May 2024 11:14:46 +0200 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Java Annotation Indexer Medium Product Manifest bundle-symbolicname org.jboss.jandex Medium Product Manifest Implementation-Title Java Annotation Indexer High Product Manifest implementation-url http://www.jboss.org/jandex Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Java Annotation Indexer Medium Product pom artifactid jandex Highest Product pom groupid org.jboss Highest Product pom name Java Annotation Indexer High Product pom parent-artifactid jboss-parent Medium Version Manifest Bundle-Version 2.4.5.Final High Version Manifest Implementation-Version 2.4.5.Final High Version pom parent-version 2.4.5.Final Low Version pom version 2.4.5.Final Highest
jaxb-core-4.0.3.jarDescription:
JAXB Core module. Contains sources required by XJC, JXC and Runtime modules. License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/jaxb-core/4.0.3/jaxb-core-4.0.3.jar
MD5: 8c5d90e32ee3e76972b7d2acf7a49fdf
SHA1: e9093b4a82069a1d78ee9a3233ca387bca88861f
SHA256: d6d75c422752684fbf04dd74a21698feae0e4a406c2892b5af02d23dc97b2ac6
Referenced In Project/Scope: Users Admin Web:compile
jaxb-core-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jaxb-core High Vendor jar package name core Highest Vendor jar package name glassfish Highest Vendor jar package name jaxb Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Vendor Manifest git-revision ff66b10 Low Vendor Manifest implementation-build-id 4.0.3 - ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-core Highest Vendor pom artifactid jaxb-core Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Core High Vendor pom parent-artifactid jaxb-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-core High Product jar package name core Highest Product jar package name glassfish Highest Product jar package name jaxb Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Core Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Product Manifest git-revision ff66b10 Low Product Manifest implementation-build-id 4.0.3 - ff66b10 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-core Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Core High Product pom parent-artifactid jaxb-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest build-version 4.0.3 Medium Version Manifest Bundle-Version 4.0.3 High Version Manifest implementation-build-id 4.0.3 Low Version pom version 4.0.3 Highest
jaxb-jxc-4.0.3.jarDescription:
JAXB schema generator.The *tool* to generate XML schema based on java classes.
File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/jaxb-jxc/4.0.3/jaxb-jxc-4.0.3.jarMD5: 084bf03ab3beb840a96d480b51a1abb3SHA1: ff97bfca3455817a3605bf21289abb4d12e27ff3SHA256: 1ab742bf26e939e87682c32973996cc067a3357ac3b0efb744c3f0d153063a30Referenced In Project/Scope: Users Admin Web:compilejaxb-jxc-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jaxb-jxc High Vendor jar package name jxc Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-jxc Highest Vendor pom artifactid jaxb-jxc Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB JXC High Vendor pom parent-artifactid jaxb-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-jxc High Product jar package name jxc Highest Product jar package name sun Highest Product Manifest git-revision ff66b10 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-jxc Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB JXC High Product pom parent-artifactid jaxb-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest build-version 4.0.3 Medium Version pom version 4.0.3 Highest
jaxb-runtime-4.0.3.jarDescription:
JAXB (JSR 222) Reference Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/jaxb-runtime/4.0.3/jaxb-runtime-4.0.3.jar
MD5: 1e3fe19cc19a1393c48b5116c0e0999f
SHA1: 93af25be25b2c92c83e0ce61cb8b3ed23568f316
SHA256: 795e2dbdd3e64c8ba7e532e35f83136603931a8e9a3b5ffeb05f9f483adab6e0
Referenced In Project/Scope: Users Admin Web:compile
jaxb-runtime-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jaxb-runtime High Vendor jar package name glassfish Highest Vendor jar package name jaxb Highest Vendor jar package name runtime Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Vendor Manifest git-revision ff66b10 Low Vendor Manifest implementation-build-id 4.0.3 - ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-runtime Highest Vendor pom artifactid jaxb-runtime Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-runtime High Product jar package name glassfish Highest Product jar package name jaxb Highest Product jar package name runtime Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Runtime Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Product Manifest git-revision ff66b10 Low Product Manifest implementation-build-id 4.0.3 - ff66b10 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-runtime Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Runtime High Product pom parent-artifactid jaxb-runtime-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest build-version 4.0.3 Medium Version Manifest Bundle-Version 4.0.3 High Version Manifest implementation-build-id 4.0.3 Low Version pom version 4.0.3 Highest
jaxb-xjc-4.0.3.jarDescription:
JAXB Binding Compiler. Contains source code needed for binding customization files into java sources.
In other words: the *tool* to generate java classes for the given xml representation.
File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/jaxb-xjc/4.0.3/jaxb-xjc-4.0.3.jarMD5: 877234d80035820c4504868536d83124SHA1: 7420f2fa71646abc584381bc7a6f4ce436d88d15SHA256: 53437669f695d263d7d3632251dca423f4cf87e1f2210a181d6696c7ca753990Referenced In Project/Scope: Users Admin Web:compilejaxb-xjc-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jaxb-xjc High Vendor jar package name sun Highest Vendor jar package name xjc Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-xjc Highest Vendor pom artifactid jaxb-xjc Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB XJC High Vendor pom parent-artifactid jaxb-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-xjc High Product jar package name sun Highest Product jar package name xjc Highest Product Manifest git-revision ff66b10 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-xjc Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB XJC High Product pom parent-artifactid jaxb-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest build-version 4.0.3 Medium Version pom version 4.0.3 Highest
jboss-logging-3.5.3.Final.jarDescription:
The JBoss Logging Framework License:
Apache License 2.0: https://repository.jboss.org/licenses/apache-2.0.txt File Path: /opt/tomcat/.m2/repository/org/jboss/logging/jboss-logging/3.5.3.Final/jboss-logging-3.5.3.Final.jar
MD5: ee7e24e94235c13f53392ecaa53f938c
SHA1: c88fc1d8a96d4c3491f55d4317458ccad53ca663
SHA256: 7b119460de174195aca412dfed52ca0bbef0ece26c2d74301b6172cfadf4ff59
Referenced In Project/Scope: Users Admin Web:compile
jboss-logging-3.5.3.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-validation@3.3.11
Evidence Type Source Name Value Confidence Vendor file name jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name logging Highest Vendor Manifest automatic-module-name org.jboss.logging Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jboss-logging Highest Vendor pom artifactid jboss-logging Low Vendor pom groupid org.jboss.logging Highest Vendor pom name JBoss Logging 3 High Vendor pom parent-artifactid logging-parent Low Vendor pom url http://www.jboss.org Highest Product file name jboss-logging High Product jar package name jboss Highest Product jar package name logging Highest Product Manifest automatic-module-name org.jboss.logging Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest Implementation-Title JBoss Logging 3 High Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product Manifest specification-title JBoss Logging 3 Medium Product pom artifactid jboss-logging Highest Product pom groupid org.jboss.logging Highest Product pom name JBoss Logging 3 High Product pom parent-artifactid logging-parent Medium Product pom url http://www.jboss.org Medium Version Manifest Bundle-Version 3.5.3.Final High Version Manifest Implementation-Version 3.5.3.Final High Version pom parent-version 3.5.3.Final Low Version pom version 3.5.3.Final Highest
jcip-annotations-1.0-1.jarDescription:
A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/github/stephenc/jcip/jcip-annotations/1.0-1/jcip-annotations-1.0-1.jar
MD5: d62dbfa8789378457ada685e2f614846
SHA1: ef31541dd28ae2cefdd17c7ebf352d93e9058c63
SHA256: 4fccff8382aafc589962c4edb262f6aa595e34f1e11e61057d1c6a96e8fc7323
Referenced In Project/Scope: Users Admin Web:compile
jcip-annotations-1.0-1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jcip-annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name jcip Highest Vendor jar package name jcip Low Vendor jar package name net Low Vendor pom artifactid jcip-annotations Highest Vendor pom artifactid jcip-annotations Low Vendor pom developer id stephenc Medium Vendor pom developer name Stephen Connolly Medium Vendor pom groupid com.github.stephenc.jcip Highest Vendor pom name JCIP Annotations under Apache License High Vendor pom url http://stephenc.github.com/jcip-annotations Highest Product file name jcip-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name jcip Highest Product jar package name jcip Low Product pom artifactid jcip-annotations Highest Product pom developer id stephenc Low Product pom developer name Stephen Connolly Low Product pom groupid com.github.stephenc.jcip Highest Product pom name JCIP Annotations under Apache License High Product pom url http://stephenc.github.com/jcip-annotations Medium Version pom version 1.0-1 Highest
json-patch-1.13.jarDescription:
JSON Patch (RFC 6902) and JSON Merge Patch (RFC 7386) implementation in Java License:
Lesser General Public License, version 3 or greater: http://www.gnu.org/licenses/lgpl.html
Apache Software License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/com/github/java-json-tools/json-patch/1.13/json-patch-1.13.jar
MD5: 2cca1a560d862f9d0e74da8cf4d5fca3
SHA1: c8b72249e50fe778e7df223e5b1fed1931a4a688
SHA256: 1f794d256965b53ef37e70b55505e2ed00ddc0184d44e2e8e1fdce5a3cacc7de
Referenced In Project/Scope: Users Admin Web:compile
json-patch-1.13.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name json-patch High Vendor jar package name github Highest Vendor jar package name patch Highest Vendor Manifest bundle-symbolicname json-patch Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid json-patch Highest Vendor pom artifactid json-patch Low Vendor pom developer email jhuffaker+java-json-tools@gmail.com Low Vendor pom developer id huggsboson Medium Vendor pom developer name John Huffaker Medium Vendor pom groupid com.github.java-json-tools Highest Vendor pom name json-patch High Vendor pom url java-json-tools/json-patch Highest Product file name json-patch High Product jar package name github Highest Product jar package name patch Highest Product Manifest Bundle-Name json-patch Medium Product Manifest bundle-symbolicname json-patch Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid json-patch Highest Product pom developer email jhuffaker+java-json-tools@gmail.com Low Product pom developer id huggsboson Low Product pom developer name John Huffaker Low Product pom groupid com.github.java-json-tools Highest Product pom name json-patch High Product pom url java-json-tools/json-patch High Version file version 1.13 High Version pom version 1.13 Highest
CVE-2022-45688 suppress
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2023-5072 suppress
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
keycloak-admin-client-26.0.5.jarFile Path: /opt/tomcat/.m2/repository/org/keycloak/keycloak-admin-client/26.0.5/keycloak-admin-client-26.0.5.jarMD5: a942027d2297bd2df35e2f79e80e05eeSHA1: 5fed495319d1a8addd0f4b54deb1195beac4640fSHA256: fe0f28032634b6b7373e2edd7e3d60d10078801727f8c8d6d530041f38154187Referenced In Project/Scope: Users Admin Web:compilekeycloak-admin-client-26.0.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name keycloak-admin-client High Vendor hint analyzer vendor redhat Highest Vendor jar package name admin Highest Vendor jar package name client Highest Vendor jar package name keycloak Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url https://keycloak.org/keycloak-admin-client Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid keycloak-admin-client Highest Vendor pom artifactid keycloak-admin-client Low Vendor pom groupid org.keycloak Highest Vendor pom name Keycloak Admin REST Client High Vendor pom parent-artifactid keycloak-client-parent Low Product file name keycloak-admin-client High Product jar package name admin Highest Product jar package name client Highest Product jar package name keycloak Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Keycloak Admin REST Client High Product Manifest implementation-url https://keycloak.org/keycloak-admin-client Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Keycloak Admin REST Client Medium Product pom artifactid keycloak-admin-client Highest Product pom groupid org.keycloak Highest Product pom name Keycloak Admin REST Client High Product pom parent-artifactid keycloak-client-parent Medium Version file version 26.0.5 High Version Manifest Implementation-Version 26.0.5 High Version pom version 26.0.5 Highest
Related Dependencies keycloak-client-common-synced-26.0.5.jarFile Path: /opt/tomcat/.m2/repository/org/keycloak/keycloak-client-common-synced/26.0.5/keycloak-client-common-synced-26.0.5.jar MD5: a0840b29103b462adfa0b69057b2929f SHA1: f63cec95c797ef1f3fdcb4bea54397d977c819b5 SHA256: 27d108a252ec66aa6f42b0b9e68ab36061ba52b1ea83e0757ec2abd3f870e4d8 pkg:maven/org.keycloak/keycloak-client-common-synced@26.0.5 keycloak-core-26.1.3.jarFile Path: /opt/tomcat/.m2/repository/org/keycloak/keycloak-core/26.1.3/keycloak-core-26.1.3.jarMD5: 0e4e1fdbdded0470fe86cbb630ba0411SHA1: baf69d73c38f4d6fc5ca469669af225329e877a3SHA256: 224877b24a6d4d634519a90d73d714c7739d0debac2b5d9ac9c9e0293cf6d024Referenced In Project/Scope: Users Admin Web:compilekeycloak-core-26.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name keycloak-core High Vendor hint analyzer vendor redhat Highest Vendor jar package name keycloak Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest implementation-url http://keycloak.org/keycloak-core Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid keycloak-core Highest Vendor pom artifactid keycloak-core Low Vendor pom groupid org.keycloak Highest Vendor pom name Keycloak Core High Vendor pom parent-artifactid keycloak-parent Low Product file name keycloak-core High Product jar package name keycloak Highest Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Keycloak Core High Product Manifest implementation-url http://keycloak.org/keycloak-core Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Keycloak Core Medium Product pom artifactid keycloak-core Highest Product pom groupid org.keycloak Highest Product pom name Keycloak Core High Product pom parent-artifactid keycloak-parent Medium Version file version 26.1.3 High Version Manifest Implementation-Version 26.1.3 High Version pom version 26.1.3 Highest
Related Dependencies keycloak-common-26.1.3.jarFile Path: /opt/tomcat/.m2/repository/org/keycloak/keycloak-common/26.1.3/keycloak-common-26.1.3.jar MD5: 03fd3fe098a10d3e9890c0f6674d796f SHA1: b0ac27742ebb8b050e99793158a14895f718bead SHA256: 7b7e0a477816759ac2b80a8d9744ca55f87bf8c62d877e4695ea18c16aa9fe5d pkg:maven/org.keycloak/keycloak-common@26.1.3 logback-core-1.5.18.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /opt/tomcat/.m2/repository/ch/qos/logback/logback-core/1.5.18/logback-core-1.5.18.jar
MD5: 10bcea83842beead15f072799b9c923d
SHA1: 6c0375624f6f36b4e089e2488ba21334a11ef13f
SHA256: 85139e7b57b464f8e5e36326dd81317648bed199ccc4f98cd42585f8d7571027
Referenced In Project/Scope: Users Admin Web:compile
logback-core-1.5.18.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name logback-core High Vendor jar package name ch Highest Vendor jar package name core Highest Vendor jar package name logback Highest Vendor jar package name qos Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor Manifest Implementation-Vendor QOS.ch High Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor QOS.ch Low Vendor pom artifactid logback-core Highest Vendor pom artifactid logback-core Low Vendor pom groupid ch.qos.logback Highest Vendor pom name Logback Core Module High Vendor pom parent-artifactid logback-parent Low Product file name logback-core High Product jar package name 21 Highest Product jar package name ch Highest Product jar package name core Highest Product jar package name logback Highest Product jar package name qos Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest Bundle-Name Logback Core Module Medium Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest Implementation-Title Logback Core Module High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product Manifest specification-title Logback Core Module Medium Product pom artifactid logback-core Highest Product pom groupid ch.qos.logback Highest Product pom name Logback Core Module High Product pom parent-artifactid logback-parent Medium Version file version 1.5.18 High Version Manifest Bundle-Version 1.5.18 High Version Manifest Implementation-Version 1.5.18 High Version pom version 1.5.18 Highest
Related Dependencies logback-classic-1.5.18.jarFile Path: /opt/tomcat/.m2/repository/ch/qos/logback/logback-classic/1.5.18/logback-classic-1.5.18.jar MD5: 05bd5f5d61a7efe5d5ae362df43377b5 SHA1: fc371f3fc97a639de2d67947cffb7518ec5e3d40 SHA256: 3e1533d0321f8815eef46750aee0111b41554f9a4644c3c4d2d404744b09f60f pkg:maven/ch.qos.logback/logback-classic@1.5.18 mapstruct-1.5.5.Final.jarDescription:
An annotation processor for generating type-safe bean mappers License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/mapstruct/mapstruct/1.5.5.Final/mapstruct-1.5.5.Final.jar
MD5: 9f2f737ffa2496ca5c40dcc323068803
SHA1: 2ca3cbe39b6e9ea8d5ea521965a89bef2a1e8eeb
SHA256: 6391e07982855dd804d825b63a55ab9251003716547216e5f581123c841328d5
Referenced In Project/Scope: Users Admin Web:compile
mapstruct-1.5.5.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name mapstruct High Vendor jar package name mappers Highest Vendor jar package name mapstruct Highest Vendor Manifest automatic-module-name org.mapstruct Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.mapstruct Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid mapstruct Highest Vendor pom artifactid mapstruct Low Vendor pom developer email gunnar@mapstruct.org Low Vendor pom developer id filiphr Medium Vendor pom developer id gunnarmorling Medium Vendor pom developer name Filip Hrisafov Medium Vendor pom developer name Gunnar Morling Medium Vendor pom groupid org.mapstruct Highest Vendor pom name MapStruct Core High Vendor pom parent-artifactid mapstruct-parent Low Vendor pom url https://mapstruct.org/mapstruct/ Highest Product file name mapstruct High Product jar package name mappers Highest Product jar package name mapstruct Highest Product Manifest automatic-module-name org.mapstruct Medium Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name MapStruct Core Medium Product Manifest bundle-symbolicname org.mapstruct Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid mapstruct Highest Product pom developer email gunnar@mapstruct.org Low Product pom developer id filiphr Low Product pom developer id gunnarmorling Low Product pom developer name Filip Hrisafov Low Product pom developer name Gunnar Morling Low Product pom groupid org.mapstruct Highest Product pom name MapStruct Core High Product pom parent-artifactid mapstruct-parent Medium Product pom url https://mapstruct.org/mapstruct/ Medium Version Manifest Bundle-Version 1.5.5.Final High Version pom version 1.5.5.Final Highest
micrometer-commons-1.13.13.jarDescription:
Module containing common code License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/io/micrometer/micrometer-commons/1.13.13/micrometer-commons-1.13.13.jar
MD5: 3a91c7465b7ee9c005e26c3481a636b2
SHA1: 9fa147a70b0fbc237bd0ce9ec2a2fa9b33bc7bd7
SHA256: 8613395fb4914819610d0b24ccf7345b30ee40e7bc08699cfcfb746bb2cb881d
Referenced In Project/Scope: Users Admin Web:compile
micrometer-commons-1.13.13.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework/spring-context@6.1.19
Evidence Type Source Name Value Confidence Vendor file name micrometer-commons High Vendor jar package name common Highest Vendor jar package name io Highest Vendor jar package name micrometer Highest Vendor Manifest automatic-module-name micrometer.commons Medium Vendor Manifest branch HEAD Low Vendor Manifest build-date 2025-04-14_02:10:16 Low Vendor Manifest build-date-utc 2025-04-14T02:10:16.599617231Z Low Vendor Manifest build-host 090f736fee1d Low Vendor Manifest build-job deploy Low Vendor Manifest build-number 46030 Low Vendor Manifest build-timezone Etc/UTC Low Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/46030 Low Vendor Manifest built-os Linux Low Vendor Manifest built-status release Low Vendor Manifest bundle-symbolicname micrometer-commons Medium Vendor Manifest change fa523b1 Low Vendor Manifest full-change fa523b1549ef38f44966c27ac921592196f09d3f Low Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest module-source /micrometer-commons Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid micrometer-commons Highest Vendor pom artifactid micrometer-commons Low Vendor pom developer email tludwig@vmware.com Low Vendor pom developer id shakuzen Medium Vendor pom developer name Tommy Ludwig Medium Vendor pom groupid io.micrometer Highest Vendor pom name micrometer-commons High Vendor pom url micrometer-metrics/micrometer Highest Product file name micrometer-commons High Product jar package name common Highest Product jar package name io Highest Product jar package name micrometer Highest Product Manifest automatic-module-name micrometer.commons Medium Product Manifest branch HEAD Low Product Manifest build-date 2025-04-14_02:10:16 Low Product Manifest build-date-utc 2025-04-14T02:10:16.599617231Z Low Product Manifest build-host 090f736fee1d Low Product Manifest build-job deploy Low Product Manifest build-number 46030 Low Product Manifest build-timezone Etc/UTC Low Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/46030 Low Product Manifest built-os Linux Low Product Manifest built-status release Low Product Manifest Bundle-Name micrometer-commons Medium Product Manifest bundle-symbolicname micrometer-commons Medium Product Manifest change fa523b1 Low Product Manifest full-change fa523b1549ef38f44966c27ac921592196f09d3f Low Product Manifest Implementation-Title io.micrometer#micrometer-commons;1.13.13 High Product Manifest module-email tludwig@vmware.com Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest module-source /micrometer-commons Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid micrometer-commons Highest Product pom developer email tludwig@vmware.com Low Product pom developer id shakuzen Low Product pom developer name Tommy Ludwig Low Product pom groupid io.micrometer Highest Product pom name micrometer-commons High Product pom url micrometer-metrics/micrometer High Version file version 1.13.13 High Version Manifest Bundle-Version 1.13.13 High Version Manifest Implementation-Version 1.13.13 High Version pom version 1.13.13 Highest
micrometer-observation-1.13.13.jarDescription:
Module containing Observation related code License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/io/micrometer/micrometer-observation/1.13.13/micrometer-observation-1.13.13.jar
MD5: 5511e8e9460c294024a0789dbb015948
SHA1: 8f5dcc8e44120ac65f53cf79581ca8894c560c5b
SHA256: 35b40b485eb0514ff57fa15cbcd3c0cc850a1c72421cb7090e97e8e191167b99
Referenced In Project/Scope: Users Admin Web:compile
micrometer-observation-1.13.13.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework/spring-context@6.1.19
Evidence Type Source Name Value Confidence Vendor file name micrometer-observation High Vendor jar package name io Highest Vendor jar package name micrometer Highest Vendor jar package name observation Highest Vendor Manifest automatic-module-name micrometer.observation Medium Vendor Manifest branch HEAD Low Vendor Manifest build-date 2025-04-14_02:10:16 Low Vendor Manifest build-date-utc 2025-04-14T02:10:16.921236628Z Low Vendor Manifest build-host 090f736fee1d Low Vendor Manifest build-job deploy Low Vendor Manifest build-number 46030 Low Vendor Manifest build-timezone Etc/UTC Low Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/46030 Low Vendor Manifest built-os Linux Low Vendor Manifest built-status release Low Vendor Manifest bundle-symbolicname micrometer-observation Medium Vendor Manifest change fa523b1 Low Vendor Manifest full-change fa523b1549ef38f44966c27ac921592196f09d3f Low Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest module-source /micrometer-observation Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid micrometer-observation Highest Vendor pom artifactid micrometer-observation Low Vendor pom developer email tludwig@vmware.com Low Vendor pom developer id shakuzen Medium Vendor pom developer name Tommy Ludwig Medium Vendor pom groupid io.micrometer Highest Vendor pom name micrometer-observation High Vendor pom url micrometer-metrics/micrometer Highest Product file name micrometer-observation High Product jar package name io Highest Product jar package name micrometer Highest Product jar package name observation Highest Product Manifest automatic-module-name micrometer.observation Medium Product Manifest branch HEAD Low Product Manifest build-date 2025-04-14_02:10:16 Low Product Manifest build-date-utc 2025-04-14T02:10:16.921236628Z Low Product Manifest build-host 090f736fee1d Low Product Manifest build-job deploy Low Product Manifest build-number 46030 Low Product Manifest build-timezone Etc/UTC Low Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/46030 Low Product Manifest built-os Linux Low Product Manifest built-status release Low Product Manifest Bundle-Name micrometer-observation Medium Product Manifest bundle-symbolicname micrometer-observation Medium Product Manifest change fa523b1 Low Product Manifest full-change fa523b1549ef38f44966c27ac921592196f09d3f Low Product Manifest Implementation-Title io.micrometer#micrometer-observation;1.13.13 High Product Manifest module-email tludwig@vmware.com Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest module-source /micrometer-observation Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid micrometer-observation Highest Product pom developer email tludwig@vmware.com Low Product pom developer id shakuzen Low Product pom developer name Tommy Ludwig Low Product pom groupid io.micrometer Highest Product pom name micrometer-observation High Product pom url micrometer-metrics/micrometer High Version file version 1.13.13 High Version Manifest Bundle-Version 1.13.13 High Version Manifest Implementation-Version 1.13.13 High Version pom version 1.13.13 Highest
microprofile-openapi-api-3.1.1.jarDescription:
MicroProfile OpenAPI API :: API License:
Apache License, Version 2.0 File Path: /opt/tomcat/.m2/repository/org/eclipse/microprofile/openapi/microprofile-openapi-api/3.1.1/microprofile-openapi-api-3.1.1.jar
MD5: d49b4088a9b12341dd37b881fbf14d1d
SHA1: 24d319e0caeca078d2bc748d063ba4f7239d44dc
SHA256: b482278365efc155fe8de06aac2e715911df4abc01562391a958cae2ce941814
Referenced In Project/Scope: Users Admin Web:compile
microprofile-openapi-api-3.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name microprofile-openapi-api High Vendor jar package name eclipse Highest Vendor jar package name microprofile Highest Vendor jar package name openapi Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl http://microprofile.io/microprofile-openapi-parent/microprofile-openapi-api Low Vendor Manifest bundle-symbolicname org.eclipse.microprofile.openapi Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid microprofile-openapi-api Highest Vendor pom artifactid microprofile-openapi-api Low Vendor pom groupid org.eclipse.microprofile.openapi Highest Vendor pom name MicroProfile OpenAPI API High Vendor pom parent-artifactid microprofile-openapi-parent Low Product file name microprofile-openapi-api High Product jar package name eclipse Highest Product jar package name microprofile Highest Product jar package name openapi Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl http://microprofile.io/microprofile-openapi-parent/microprofile-openapi-api Low Product Manifest Bundle-Name MicroProfile OpenAPI Bundle Medium Product Manifest bundle-symbolicname org.eclipse.microprofile.openapi Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid microprofile-openapi-api Highest Product pom groupid org.eclipse.microprofile.openapi Highest Product pom name MicroProfile OpenAPI API High Product pom parent-artifactid microprofile-openapi-parent Medium Version file version 3.1.1 High Version Manifest Bundle-Version 3.1.1 High Version pom version 3.1.1 Highest
msg-simple-1.2.jarDescription:
A lightweight, UTF-8 capable, printf() capable alternative to Java's ResourceBundle License:
Lesser General Public License, version 3 or greater: http://www.gnu.org/licenses/lgpl.html
Apache Software License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/com/github/java-json-tools/msg-simple/1.2/msg-simple-1.2.jar
MD5: b0ad6fb398838287f1993c44bafb18e2
SHA1: a06afa2d5d75c98e54ab370107930978fc3f9937
SHA256: bef4111b993a5b3e6148d8f585621cceac2a1889cdbc34448b11632e0d8a9a8f
Referenced In Project/Scope: Users Admin Web:compile
msg-simple-1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name msg-simple High Vendor jar package name github Highest Vendor Manifest bundle-symbolicname com.github.java-json-tools.msg-simple Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid msg-simple Highest Vendor pom artifactid msg-simple Low Vendor pom developer email jhuffaker+java-json-tools@gmail.com Low Vendor pom developer id huggsboson Medium Vendor pom developer name John Huffaker Medium Vendor pom groupid com.github.java-json-tools Highest Vendor pom name msg-simple High Vendor pom url java-json-tools/msg-simple Highest Product file name msg-simple High Product jar package name github Highest Product Manifest Bundle-Name msg-simple Medium Product Manifest bundle-symbolicname com.github.java-json-tools.msg-simple Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid msg-simple Highest Product pom developer email jhuffaker+java-json-tools@gmail.com Low Product pom developer id huggsboson Low Product pom developer name John Huffaker Low Product pom groupid com.github.java-json-tools Highest Product pom name msg-simple High Product pom url java-json-tools/msg-simple High Version file version 1.2 High Version Manifest Bundle-Version 1.2 High Version pom version 1.2 Highest
CVE-2022-45688 suppress
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions: (show all )
CVE-2023-5072 suppress
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used. CWE-770 Allocation of Resources Without Limits or Throttling
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
net.andresbustamante:y-a-foot-commons-api:2.0.0-SNAPSHOTDescription:
Shared API classes and interfaces File Path: /opt/tomcat/.jenkins/workspace/y-a-foot_y-a-foot_build_develop/y-a-foot-commons-api/pom.xmlReferenced In Project/Scope: Users Admin Webnet.andresbustamante:y-a-foot-commons-api:2.0.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid y-a-foot-commons-api Low Vendor project groupid net.andresbustamante Highest Product file name pom High Product project artifactid y-a-foot-commons-api Highest Product project groupid net.andresbustamante Low
net.andresbustamante:y-a-foot-commons-services:2.0.0-SNAPSHOTDescription:
Shared classes and interfaces for the services layer File Path: /opt/tomcat/.jenkins/workspace/y-a-foot_y-a-foot_build_develop/y-a-foot-commons-services/pom.xmlReferenced In Project/Scope: Users Admin Webnet.andresbustamante:y-a-foot-commons-services:2.0.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid y-a-foot-commons-services Low Vendor project groupid net.andresbustamante Highest Product file name pom High Product project artifactid y-a-foot-commons-services Highest Product project groupid net.andresbustamante Low
net.andresbustamante:y-a-foot-commons-web:2.0.0-SNAPSHOTDescription:
Shared classes, interfaces and configurations for the Web layer File Path: /opt/tomcat/.jenkins/workspace/y-a-foot_y-a-foot_build_develop/y-a-foot-commons-web/pom.xmlReferenced In Project/Scope: Users Admin Webnet.andresbustamante:y-a-foot-commons-web:2.0.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid y-a-foot-commons-web Low Vendor project groupid net.andresbustamante Highest Product file name pom High Product project artifactid y-a-foot-commons-web Highest Product project groupid net.andresbustamante Low
net.andresbustamante:y-a-foot-users-api:2.0.0-SNAPSHOTDescription:
Users API classes and interfaces File Path: /opt/tomcat/.jenkins/workspace/y-a-foot_y-a-foot_build_develop/y-a-foot-users-api/pom.xmlReferenced In Project/Scope: Users Admin Webnet.andresbustamante:y-a-foot-users-api:2.0.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid y-a-foot-users-api Low Vendor project groupid net.andresbustamante Highest Product file name pom High Product project artifactid y-a-foot-users-api Highest Product project groupid net.andresbustamante Low
net.andresbustamante:y-a-foot-users-services:2.0.0-SNAPSHOTDescription:
Users services implementations File Path: /opt/tomcat/.jenkins/workspace/y-a-foot_y-a-foot_build_develop/y-a-foot-users-services/pom.xmlReferenced In Project/Scope: Users Admin Webnet.andresbustamante:y-a-foot-users-services:2.0.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name pom High Vendor project artifactid y-a-foot-users-services Low Vendor project groupid net.andresbustamante Highest Product file name pom High Product project artifactid y-a-foot-users-services Highest Product project groupid net.andresbustamante Low
nimbus-jose-jwt-9.37.3.jar (shaded: com.google.code.gson:gson:2.10.1)License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/nimbusds/nimbus-jose-jwt/9.37.3/nimbus-jose-jwt-9.37.3.jar/META-INF/maven/com.google.code.gson/gson/pom.xml
MD5: c13f373086992bab8989b514941891a6
SHA1: ce159faf33c1e665e1f3a785a5d678a2b20151bc
SHA256: d2b115634f5c085db4b9c9ffc2658e89e231fdbfbe2242121a1cd95d4d948dd7
Referenced In Project/Scope: Users Admin Web:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid gson Low Vendor pom groupid com.google.code.gson Highest Vendor pom name Gson High Vendor pom parent-artifactid gson-parent Low Product pom artifactid gson Highest Product pom groupid com.google.code.gson Highest Product pom name Gson High Product pom parent-artifactid gson-parent Medium Version pom version 2.10.1 Highest
nimbus-jose-jwt-9.37.3.jarDescription:
Java library for Javascript Object Signing and Encryption (JOSE) and
JSON Web Tokens (JWT)
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/com/nimbusds/nimbus-jose-jwt/9.37.3/nimbus-jose-jwt-9.37.3.jar
MD5: a2ecba11e197522b7f963cbcf0b59715
SHA1: 700f71ffefd60c16bd8ce711a956967ea9071cec
SHA256: 12ae4a3a260095d7aeba2adea7ae396e8b9570db8b7b409e09a824c219cc0444
Referenced In Project/Scope: Users Admin Web:compile
nimbus-jose-jwt-9.37.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name nimbus-jose-jwt High Vendor jar package name jose Highest Vendor jar package name jwt Highest Vendor jar package name nimbusds Highest Vendor Manifest automatic-module-name com.nimbusds.jose.jwt Medium Vendor Manifest build-date ${timestamp} Low Vendor Manifest build-number ${buildNumber} Low Vendor Manifest build-tag 9.37.3 Low Vendor Manifest bundle-docurl https://connect2id.com Low Vendor Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Vendor Manifest implementation-url https://bitbucket.org/connect2id/nimbus-jose-jwt Low Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor pom artifactid nimbus-jose-jwt Highest Vendor pom artifactid nimbus-jose-jwt Low Vendor pom developer email vladimir@dzhuvinov.com Low Vendor pom developer id vdzhuvinov Medium Vendor pom developer name Vladimir Dzhuvinov Medium Vendor pom groupid com.nimbusds Highest Vendor pom name Nimbus JOSE+JWT High Vendor pom organization name Connect2id Ltd. High Vendor pom organization url https://connect2id.com Medium Vendor pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Highest Product file name nimbus-jose-jwt High Product jar package name jose Highest Product jar package name jwt Highest Product jar package name nimbusds Highest Product Manifest automatic-module-name com.nimbusds.jose.jwt Medium Product Manifest build-date ${timestamp} Low Product Manifest build-number ${buildNumber} Low Product Manifest build-tag 9.37.3 Low Product Manifest bundle-docurl https://connect2id.com Low Product Manifest Bundle-Name Nimbus JOSE+JWT Medium Product Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Product Manifest Implementation-Title Nimbus JOSE+JWT High Product Manifest implementation-url https://bitbucket.org/connect2id/nimbus-jose-jwt Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Nimbus JOSE+JWT Medium Product pom artifactid nimbus-jose-jwt Highest Product pom developer email vladimir@dzhuvinov.com Low Product pom developer id vdzhuvinov Low Product pom developer name Vladimir Dzhuvinov Low Product pom groupid com.nimbusds Highest Product pom name Nimbus JOSE+JWT High Product pom organization name Connect2id Ltd. Low Product pom organization url https://connect2id.com Low Product pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Medium Version file version 9.37.3 High Version Manifest build-tag 9.37.3 Low Version Manifest Bundle-Version 9.37.3 High Version Manifest Implementation-Version 9.37.3 High Version pom version 9.37.3 Highest
reactive-streams-1.0.4.jarDescription:
A Protocol for Asynchronous Non-Blocking Data Sequence License:
MIT-0: https://spdx.org/licenses/MIT-0.html File Path: /opt/tomcat/.m2/repository/org/reactivestreams/reactive-streams/1.0.4/reactive-streams-1.0.4.jar
MD5: eda7978509c32d99166745cc144c99cd
SHA1: 3864a1320d97d7b045f729a326e1e077661f31b7
SHA256: f75ca597789b3dac58f61857b9ac2e1034a68fa672db35055a8fb4509e325f28
Referenced In Project/Scope: Users Admin Web:compile
reactive-streams-1.0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name reactive-streams High Vendor jar package name reactivestreams Highest Vendor Manifest automatic-module-name org.reactivestreams Medium Vendor Manifest bundle-docurl http://reactive-streams.org Low Vendor Manifest bundle-symbolicname reactive-streams Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid reactive-streams Highest Vendor pom artifactid reactive-streams Low Vendor pom developer id reactive-streams-sig Medium Vendor pom developer name Reactive Streams SIG Medium Vendor pom groupid org.reactivestreams Highest Vendor pom name reactive-streams High Vendor pom url http://www.reactive-streams.org/ Highest Product file name reactive-streams High Product jar package name reactivestreams Highest Product Manifest automatic-module-name org.reactivestreams Medium Product Manifest bundle-docurl http://reactive-streams.org Low Product Manifest Bundle-Name reactive-streams-jvm Medium Product Manifest bundle-symbolicname reactive-streams Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom artifactid reactive-streams Highest Product pom developer id reactive-streams-sig Low Product pom developer name Reactive Streams SIG Low Product pom groupid org.reactivestreams Highest Product pom name reactive-streams High Product pom url http://www.reactive-streams.org/ Medium Version file version 1.0.4 High Version Manifest Bundle-Version 1.0.4 High Version pom version 1.0.4 Highest
relaxng-datatype-4.0.3.jarDescription:
RelaxNG Datatype library. License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/com/sun/xml/bind/external/relaxng-datatype/4.0.3/relaxng-datatype-4.0.3.jar
MD5: 809a7974433a9d3a56756ce4431630e7
SHA1: 4959f0b554ac5674c951205077a3adcdf0b03118
SHA256: 4e62f0f16f933c27a80ced4e6b091cea7e3c853704116b40f324e792ce5a2c73
Referenced In Project/Scope: Users Admin Web:compile
relaxng-datatype-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name relaxng-datatype High Vendor jar package name datatype Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.xml.bind.external.relaxng-datatype Medium Vendor Manifest implementation-build-id 4.0.3 - ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom artifactid relaxng-datatype Highest Vendor pom artifactid relaxng-datatype Low Vendor pom groupid com.sun.xml.bind.external Highest Vendor pom name RelaxNG Datatype High Vendor pom parent-artifactid jaxb-external-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name relaxng-datatype High Product jar package name datatype Highest Product jar package name sun Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name RelaxNG Datatype Medium Product Manifest bundle-symbolicname com.sun.xml.bind.external.relaxng-datatype Medium Product Manifest implementation-build-id 4.0.3 - ff66b10 Low Product Manifest Implementation-Title RelaxNG Datatype High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid relaxng-datatype Highest Product pom groupid com.sun.xml.bind.external Highest Product pom name RelaxNG Datatype High Product pom parent-artifactid jaxb-external-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest Bundle-Version 4.0.3 High Version Manifest implementation-build-id 4.0.3 Low Version Manifest Implementation-Version 4.0.3 High Version pom version 4.0.3 Highest
resteasy-core-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-core/6.2.9.Final/resteasy-core-6.2.9.Final.jarMD5: a2def701dea0ec5efbd51fa0da101c1fSHA1: 7731f7881444f757743ced96d00bec7a36117352SHA256: f7802bb92ee0e8d0bdf95cc9964ff02f6c5177232fd62476073c848bb6314c96Referenced In Project/Scope: Users Admin Web:compileresteasy-core-6.2.9.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name resteasy-core High Vendor hint analyzer vendor redhat Highest Vendor jar package name core Highest Vendor jar package name jboss Highest Vendor jar package name resteasy Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest implementation-url https://resteasy.dev Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid resteasy-core Highest Vendor pom artifactid resteasy-core Low Vendor pom groupid org.jboss.resteasy Highest Vendor pom name RESTEasy Core High Vendor pom parent-artifactid resteasy-jaxrs-all Low Product file name resteasy-core High Product jar package name core Highest Product jar package name jboss Highest Product jar package name resteasy Highest Product Manifest build-jdk-spec 11 Low Product Manifest Implementation-Title RESTEasy Core High Product Manifest implementation-url https://resteasy.dev Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title RESTEasy Core Medium Product pom artifactid resteasy-core Highest Product pom groupid org.jboss.resteasy Highest Product pom name RESTEasy Core High Product pom parent-artifactid resteasy-jaxrs-all Medium Version Manifest Implementation-Version 6.2.9.Final High Version pom version 6.2.9.Final Highest
Related Dependencies resteasy-client-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-client/6.2.9.Final/resteasy-client-6.2.9.Final.jar MD5: 6ac863e7c43a4547af632db9bb4d8b61 SHA1: 8fed88fc81a3eeea146814767e8156e29d95ec1e SHA256: f212cf430f40fd6add79bccaff972988159513a85ace829d42a89393d72d9b0c pkg:maven/org.jboss.resteasy/resteasy-client@6.2.9.Final resteasy-client-api-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-client-api/6.2.9.Final/resteasy-client-api-6.2.9.Final.jar MD5: 851326a08a1b5c653c81d4aca0c30ab7 SHA1: 453ac63298295d5fa38033b1b12ba6d1c0bac3f0 SHA256: 5e719229536c8b516d17083a83956b7813914708b4574c1cfc3b347287fa994b pkg:maven/org.jboss.resteasy/resteasy-client-api@6.2.9.Final resteasy-core-spi-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-core-spi/6.2.9.Final/resteasy-core-spi-6.2.9.Final.jar MD5: 3d0e457b679a7d4b550f1d0f1d641ec2 SHA1: 604ebd1200935e9db48a51e743e75b13107e1824 SHA256: 0fdded02b6100f664e7b892cdb203f15b14a3d39df4c225ec994f5014ada4c6a pkg:maven/org.jboss.resteasy/resteasy-core-spi@6.2.9.Final resteasy-jackson2-provider-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-jackson2-provider/6.2.9.Final/resteasy-jackson2-provider-6.2.9.Final.jar MD5: 35631388bd760a9f0dad9ce4b0c31bc2 SHA1: 2d2edec868b945acb153ad9474efce084e6a0a8d SHA256: 76129a7722a343456bf799ee48dc4f227979d9e88dae1d9fada2fdf623eda6ba pkg:maven/org.jboss.resteasy/resteasy-jackson2-provider@6.2.9.Final resteasy-jaxb-provider-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-jaxb-provider/6.2.9.Final/resteasy-jaxb-provider-6.2.9.Final.jar MD5: 203db61396eab135b26bd76d5d0b755e SHA1: 4eb6feb795448da7e2c1929ecb8eefaf2a6d8177 SHA256: 036d1c7cd398435ec187cf102c8664b5833a17edc2c139616e3703bef88d79da pkg:maven/org.jboss.resteasy/resteasy-jaxb-provider@6.2.9.Final resteasy-multipart-provider-6.2.9.Final.jarFile Path: /opt/tomcat/.m2/repository/org/jboss/resteasy/resteasy-multipart-provider/6.2.9.Final/resteasy-multipart-provider-6.2.9.Final.jar MD5: 03507927cf164f382364f42679b4d3cf SHA1: c447ec8d1dcdd16ca08087d8fd99c94238470f10 SHA256: 936abb0df91ee8bef694b61271666b37daaf35f57fdb25b5d506ecdc37bae3da pkg:maven/org.jboss.resteasy/resteasy-multipart-provider@6.2.9.Final rngom-4.0.3.jarDescription:
RNGOM is a RelaxNG Object model library (XSOM for RelaxNG).
License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/com/sun/xml/bind/external/rngom/4.0.3/rngom-4.0.3.jar
MD5: 460a0926da0591f50b09ec85d3c65774
SHA1: 4d240e2341114dcef812c8e572011df44648f4af
SHA256: e86474b30f9ef547d55bf5c035f4a1e3f2fddc28a393c9cfb1c315bb94dbd3fd
Referenced In Project/Scope: Users Admin Web:compile
rngom-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name rngom High Vendor jar package name rngom Highest Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.xml.bind.external.rngom Medium Vendor Manifest implementation-build-id 4.0.3 - ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom artifactid rngom Highest Vendor pom artifactid rngom Low Vendor pom groupid com.sun.xml.bind.external Highest Vendor pom name RNGOM High Vendor pom parent-artifactid jaxb-external-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name rngom High Product jar package name rngom Highest Product jar package name sun Highest Product jar package name xml Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name RNGOM Medium Product Manifest bundle-symbolicname com.sun.xml.bind.external.rngom Medium Product Manifest implementation-build-id 4.0.3 - ff66b10 Low Product Manifest Implementation-Title RNGOM High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid rngom Highest Product pom groupid com.sun.xml.bind.external Highest Product pom name RNGOM High Product pom parent-artifactid jaxb-external-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest Bundle-Version 4.0.3 High Version Manifest implementation-build-id 4.0.3 Low Version Manifest Implementation-Version 4.0.3 High Version pom version 4.0.3 Highest
slf4j-api-2.0.17.jarDescription:
The slf4j API License:
https://opensource.org/license/mit File Path: /opt/tomcat/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Project/Scope: Users Admin Web:compile
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.slf4j.org Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.slf4j.spi.SLF4JServiceProvider)";osgi.serviceloader="org.slf4j.spi.SLF4JServiceProvider",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid slf4j-api Highest Vendor pom artifactid slf4j-api Low Vendor pom groupid org.slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name slf4j-api High Product jar package name slf4j Highest Product jar package name slf4jserviceprovider Highest Product jar package name spi Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.slf4j.org Low Product Manifest Bundle-Name SLF4J API Module Medium Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product Manifest multi-release true Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.slf4j.spi.SLF4JServiceProvider)";osgi.serviceloader="org.slf4j.spi.SLF4JServiceProvider",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid slf4j-api Highest Product pom groupid org.slf4j Highest Product pom name SLF4J API Module High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 2.0.17 High Version Manifest Bundle-Version 2.0.17 High Version Manifest Implementation-Version 2.0.17 High Version pom version 2.0.17 Highest
snakeyaml-2.2.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/yaml/snakeyaml/2.2/snakeyaml-2.2.jar
MD5: d78aacf5f2de5b52f1a327470efd1ad7
SHA1: 3af797a25458550a16bf89acc8e4ab2b7f2bfce0
SHA256: 1467931448a0817696ae2805b7b8b20bfb082652bf9c4efaed528930dc49389b
Referenced In Project/Scope: Users Admin Web:compile
snakeyaml-2.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.3.11
Evidence Type Source Name Value Confidence Vendor file name snakeyaml High Vendor jar package name emitter Highest Vendor jar package name org Highest Vendor jar package name parser Highest Vendor jar package name snakeyaml Highest Vendor jar package name yaml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid snakeyaml Highest Vendor pom artifactid snakeyaml Low Vendor pom developer email alexander.maslov@gmail.com Low Vendor pom developer email public.somov@gmail.com Low Vendor pom developer id asomov Medium Vendor pom developer id maslovalex Medium Vendor pom developer name Alexander Maslov Medium Vendor pom developer name Andrey Somov Medium Vendor pom groupid org.yaml Highest Vendor pom name SnakeYAML High Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest Product file name snakeyaml High Product jar package name emitter Highest Product jar package name org Highest Product jar package name parser Highest Product jar package name snakeyaml Highest Product jar package name yaml Highest Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid snakeyaml Highest Product pom developer email alexander.maslov@gmail.com Low Product pom developer email public.somov@gmail.com Low Product pom developer id asomov Low Product pom developer id maslovalex Low Product pom developer name Alexander Maslov Low Product pom developer name Andrey Somov Low Product pom groupid org.yaml Highest Product pom name SnakeYAML High Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium Version file version 2.2 High Version pom version 2.2 Highest
spring-amqp-3.1.11.jarDescription:
Spring AMQP Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/springframework/amqp/spring-amqp/3.1.11/spring-amqp-3.1.11.jar
MD5: a783fffa27f1fd15a7e6f94b6ee4555f
SHA1: 878a936dda58b32eb08913fe1d3543dd158e38aa
SHA256: c8f866734524bed1a486653f424daf586fec7a1559171534efaef515878cef3e
Referenced In Project/Scope: Users Admin Web:compile
spring-amqp-3.1.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-amqp@3.3.11
Evidence Type Source Name Value Confidence Vendor file name spring-amqp High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name amqp Highest Vendor jar package name core Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.amqp Medium Vendor Manifest implementation-url https://projects.spring.io/spring-amqp Low Vendor Manifest Implementation-Vendor Broadcom Inc. High Vendor Manifest Implementation-Vendor-Id org.springframework.amqp Medium Vendor pom artifactid spring-amqp Highest Vendor pom artifactid spring-amqp Low Vendor pom developer email artem.bilan@broadcom.com Low Vendor pom developer email david.syer@broadcom.com Low Vendor pom developer email github@gprussell.net Low Vendor pom developer email mark.pollack@broadcom.com Low Vendor pom developer email mark.ryan.fisher@gmail.com Low Vendor pom developer email soby.chacko@broadcom.com Low Vendor pom developer id artembilan Medium Vendor pom developer id dsyer Medium Vendor pom developer id garyrussell Medium Vendor pom developer id markfisher Medium Vendor pom developer id markpollack Medium Vendor pom developer id sobychacko Medium Vendor pom developer name Artem Bilan Medium Vendor pom developer name Dave Syer Medium Vendor pom developer name Gary Russell Medium Vendor pom developer name Mark Fisher Medium Vendor pom developer name Mark Pollack Medium Vendor pom developer name Soby Chacko Medium Vendor pom groupid org.springframework.amqp Highest Vendor pom name Spring AMQP Core High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-amqp Medium Vendor pom url spring-projects/spring-amqp Highest Product file name spring-amqp High Product hint analyzer product spring_advanced_message_queuing_protocol Highest Product jar package name amqp Highest Product jar package name core Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.amqp Medium Product Manifest Implementation-Title spring-amqp High Product Manifest implementation-url https://projects.spring.io/spring-amqp Low Product pom artifactid spring-amqp Highest Product pom developer email artem.bilan@broadcom.com Low Product pom developer email david.syer@broadcom.com Low Product pom developer email github@gprussell.net Low Product pom developer email mark.pollack@broadcom.com Low Product pom developer email mark.ryan.fisher@gmail.com Low Product pom developer email soby.chacko@broadcom.com Low Product pom developer id artembilan Low Product pom developer id dsyer Low Product pom developer id garyrussell Low Product pom developer id markfisher Low Product pom developer id markpollack Low Product pom developer id sobychacko Low Product pom developer name Artem Bilan Low Product pom developer name Dave Syer Low Product pom developer name Gary Russell Low Product pom developer name Mark Fisher Low Product pom developer name Mark Pollack Low Product pom developer name Soby Chacko Low Product pom groupid org.springframework.amqp Highest Product pom name Spring AMQP Core High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-amqp Low Product pom url spring-projects/spring-amqp High Version file version 3.1.11 High Version Manifest Implementation-Version 3.1.11 High Version pom version 3.1.11 Highest
Related Dependencies spring-rabbit-3.1.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/amqp/spring-rabbit/3.1.11/spring-rabbit-3.1.11.jar MD5: 23b63b8d9024253fadb5f7aa86f7f050 SHA1: 0d24defe4decb7d85fd2040dfca3ef1cdca7f98a SHA256: 69455352ca4ea7475e2ba69513dfc3775dbd90a75234c4ebcd490d854196ea8b pkg:maven/org.springframework.amqp/spring-rabbit@3.1.11 pkg:maven/org.springframework.amqp/spring-amqp@3.1.11 (Confidence :High)cpe:2.3:a:pivotal_software:spring_advanced_message_queuing_protocol:3.1.11:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:vmware:spring_advanced_message_queuing_protocol:3.1.11:*:*:*:*:*:*:* (Confidence :Low) suppress spring-boot-3.3.11.jarDescription:
Spring Boot License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot/3.3.11/spring-boot-3.3.11.jar
MD5: cb3ffb9e07a9d8d0140466e583958f8b
SHA1: b1f0b53e38e2bf45eae8f5bd27983a07bdeaac30
SHA256: 272efd80096c864ad93edb9c08f450cc37f7f997505a1b0c458587b71a3e6268
Referenced In Project/Scope: Users Admin Web:compile
spring-boot-3.3.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-boot High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name boot Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.boot Medium Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid spring-boot Highest Vendor pom artifactid spring-boot Low Vendor pom developer email ask@spring.io Low Vendor pom developer name Spring Medium Vendor pom developer org VMware, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.boot Highest Vendor pom name spring-boot High Vendor pom organization name VMware, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-boot Highest Product file name spring-boot High Product jar package name boot Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.boot Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Boot High Product pom artifactid spring-boot Highest Product pom developer email ask@spring.io Low Product pom developer name Spring Low Product pom developer org VMware, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.boot Highest Product pom name spring-boot High Product pom organization name VMware, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-boot Medium Version file version 3.3.11 High Version Manifest Implementation-Version 3.3.11 High Version pom version 3.3.11 Highest
Related Dependencies spring-boot-autoconfigure-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/3.3.11/spring-boot-autoconfigure-3.3.11.jar MD5: fcc7d556ea8c112ad385d1aa78a7c27f SHA1: 322a02cfbd787e408aa122c4e76b79e12e830a0e SHA256: 1208dc518180e167fa88ec446b884c83e34dd725710d99a74f641b9365a18c06 pkg:maven/org.springframework.boot/spring-boot-autoconfigure@3.3.11 spring-boot-starter-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter/3.3.11/spring-boot-starter-3.3.11.jar MD5: 2c65aa28379f7e70f2ec9b79197a8e4e SHA1: 8ae992c2c40c454b1ac8887046d6202893e18b25 SHA256: b291bc2f379336f694dffed5ce336e8edce9da8a15219db06a11f09320c5dc55 pkg:maven/org.springframework.boot/spring-boot-starter@3.3.11 spring-boot-starter-amqp-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter-amqp/3.3.11/spring-boot-starter-amqp-3.3.11.jar MD5: 0a2d6b49590c6ca20519cb6b60a8c923 SHA1: fcd1c90ab0773cf614a234ef2abc02a5c688bd57 SHA256: e45189d9323c633afedf56f1913cf4c33a2c65695ebf61dcee815be9ee8e5546 pkg:maven/org.springframework.boot/spring-boot-starter-amqp@3.3.11 spring-boot-starter-json-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter-json/3.3.11/spring-boot-starter-json-3.3.11.jar MD5: 827ec2234b7d6cb807bdf9eff13c976a SHA1: 61bcbbf63cbaeb35f8dda102f78d32e299d078b7 SHA256: 92ba33d0391aa614374908b20d1f36d6f1c0f4f826653f3ee3a2aacfbe9f49f1 pkg:maven/org.springframework.boot/spring-boot-starter-json@3.3.11 spring-boot-starter-security-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter-security/3.3.11/spring-boot-starter-security-3.3.11.jar MD5: 3635a3ac4038d15a42b713d309a7fb86 SHA1: 0c0af554254dd55e34ef91e80040ecf5fd9b5cb7 SHA256: 5bf38ff034ab0ba4bc0dbd283b179d891d5474de589023fa4353573bde7465a1 pkg:maven/org.springframework.boot/spring-boot-starter-security@3.3.11 spring-boot-starter-tomcat-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat/3.3.11/spring-boot-starter-tomcat-3.3.11.jar MD5: c6836822e81f0b1b1f71c4279e5d440a SHA1: 8bd6bf37b59c7855a62b1b7699ea9014aa41761d SHA256: 3ae524fde550bc9a623f53cd264dcc5590fca43b59de24958f03249d7a6d47eb pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@3.3.11 spring-boot-starter-validation-3.3.11.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter-validation/3.3.11/spring-boot-starter-validation-3.3.11.jar MD5: 5b9226d52d6fcce14f601953e3e93b37 SHA1: a27f446896ce5906bc66460b898261087e015cd7 SHA256: 36bdcecd71a06ddbbeb3ca77c358ed851025126fc59408045383444ea97c925b pkg:maven/org.springframework.boot/spring-boot-starter-validation@3.3.11 spring-boot-starter-web-3.3.11.jarDescription:
Starter for building web, including RESTful, applications using Spring MVC. Uses Tomcat as the default embedded container License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/boot/spring-boot-starter-web/3.3.11/spring-boot-starter-web-3.3.11.jar
MD5: dce8a00363ffc8a242d86d0ba59e4a20
SHA1: a447c26f78b6023366143c13d8836082462fb5ed
SHA256: 3343bbca057aa530b72e59788625c26fdec43c8cdaa42836cedae183db20b526
Referenced In Project/Scope: Users Admin Web:compile
spring-boot-starter-web-3.3.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-boot-starter-web High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.boot.starter.web Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom artifactid spring-boot-starter-web Highest Vendor pom artifactid spring-boot-starter-web Low Vendor pom developer email ask@spring.io Low Vendor pom developer name Spring Medium Vendor pom developer org VMware, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.boot Highest Vendor pom name spring-boot-starter-web High Vendor pom organization name VMware, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-boot Highest Product file name spring-boot-starter-web High Product Manifest automatic-module-name spring.boot.starter.web Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Starter for building web, including RESTful, applications using Spring MVC. Uses Tomcat as the default embedded container High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom artifactid spring-boot-starter-web Highest Product pom developer email ask@spring.io Low Product pom developer name Spring Low Product pom developer org VMware, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.boot Highest Product pom name spring-boot-starter-web High Product pom organization name VMware, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-boot Medium Version file version 3.3.11 High Version Manifest Implementation-Version 3.3.11 High Version pom version 3.3.11 Highest
spring-core-6.1.19.jarDescription:
Spring Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/spring-core/6.1.19/spring-core-6.1.19.jar
MD5: c7b7de19a43581b1f22d87fbfa192cd5
SHA1: 85718bafdeda6c6b4b0782afda2002299c3f918a
SHA256: a46e9b693d6be2cce3bc3f2b6ed144c4a7198dcc5c355ca3c63b383d8e911800
Referenced In Project/Scope: Users Admin Web:compile
spring-core-6.1.19.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-test@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name io Highest Vendor jar package name org Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.core Medium Vendor Manifest multi-release true Low Vendor pom artifactid spring-core Highest Vendor pom artifactid spring-core Low Vendor pom developer email juergen.hoeller@broadcom.com Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Core High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-core High Product hint analyzer product springsource_spring_framework Highest Product jar package name core Highest Product jar package name io Highest Product jar package name org Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.core Medium Product Manifest Implementation-Title spring-core High Product Manifest multi-release true Low Product pom artifactid spring-core Highest Product pom developer email juergen.hoeller@broadcom.com Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Core High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 6.1.19 High Version Manifest Implementation-Version 6.1.19 High Version pom version 6.1.19 Highest
Related Dependencies spring-aop-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-aop/6.1.19/spring-aop-6.1.19.jar MD5: b38a285dd96a006d15f0ed36534998b0 SHA1: c18d675301d0e03ecc6253384deafb6ad01824d6 SHA256: 82bf739839ef60d10562958d7dc087380429845eeeef054315c2efe7b54f2483 pkg:maven/org.springframework/spring-aop@6.1.19 spring-beans-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-beans/6.1.19/spring-beans-6.1.19.jar MD5: 4713232688bd4edc3df68a898b22bf3b SHA1: 5350f570eb1a31a42a4afa31ff1292b0c61e2b25 SHA256: 84150f8f35ddbf8369a64b657657778486bdae3286557be54b8b3d9f010fad06 pkg:maven/org.springframework/spring-beans@6.1.19 spring-context-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-context/6.1.19/spring-context-6.1.19.jar MD5: 528d38a917bb7054ed265549428b5b7d SHA1: 00929524186bc9c5997e4a1d8f563c7ca4ae60a7 SHA256: 656af67029d5ba799cfe30b24446645e91c8cf13b5ca726f12c184c5fe78bf74 pkg:maven/org.springframework/spring-context@6.1.19 spring-context-support-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-context-support/6.1.19/spring-context-support-6.1.19.jar MD5: f9055c68c6edb537609d95e4a555dbee SHA1: bc0ef5461669252723df58b73329f618c810f15c SHA256: 94a662eda5607c101e1467c9737dc54458082d413073c00fe60098db62efe452 pkg:maven/org.springframework/spring-context-support@6.1.19 spring-expression-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-expression/6.1.19/spring-expression-6.1.19.jar MD5: b523eafc3c54b1adf2c069230407d289 SHA1: 8ee244869051ec640e1cdbf94b7138273535d528 SHA256: b7e3261e447920172dbfa6e9d82f69be084ebed7e156274564b729a0fa2e61ae pkg:maven/org.springframework/spring-expression@6.1.19 spring-jcl-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-jcl/6.1.19/spring-jcl-6.1.19.jar MD5: c9398ecd33fd294278d74fb8dad48238 SHA1: 98241467bb50cedcb94cccd540002349499dc3ac SHA256: 076ebc259dd90ee15bf5f971dc97a04d0432a134178bd7c9d6cf5f15b6085291 pkg:maven/org.springframework/spring-jcl@6.1.19 spring-messaging-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-messaging/6.1.19/spring-messaging-6.1.19.jar MD5: 886bbee2597906f52371be2d6e8a249d SHA1: abaddcb0300500087e0bf92c16313bc13f2bdd3d SHA256: f7886a6c74df6fba65e104bac744b30d08abd5b19d9a66bf1d1e7d1a2a9ce556 pkg:maven/org.springframework/spring-messaging@6.1.19 spring-tx-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-tx/6.1.19/spring-tx-6.1.19.jar MD5: 5021a07929759b5b06e20ecb4e70e319 SHA1: ae8b4bfa105406d4902481b1a5ab0742f8027d97 SHA256: 1885574985d8c15c87dbdeb1fc75216dc57e648cc803ac576a53dc8d614a2c2d pkg:maven/org.springframework/spring-tx@6.1.19 spring-retry-2.0.11.jarDescription:
Spring Retry provides an abstraction around retrying failed operations, with an
emphasis on declarative control of the process and policy-based behaviour that is
easy to extend and customize. For instance, you can configure a plain POJO
operation to retry if it fails, based on the type of exception, and with a fixed
or exponential backoff.
License:
Apache 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/springframework/retry/spring-retry/2.0.11/spring-retry-2.0.11.jar
MD5: 24fe2b3e01091f9fb1c6038a8f3e57d9
SHA1: 0bd4fae67445baf330b69b6b786748a308ab31f6
SHA256: 1be1d42bb1ae33813f84557b0e419d3471e35850269c749dab8610e521a82567
Referenced In Project/Scope: Users Admin Web:compile
spring-retry-2.0.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-amqp@3.3.11
Evidence Type Source Name Value Confidence Vendor file name spring-retry High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name backoff Highest Vendor jar package name policy Highest Vendor jar package name retry Highest Vendor jar package name springframework Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid spring-retry Highest Vendor pom artifactid spring-retry Low Vendor pom developer email artem.bilan@broadcom.com Low Vendor pom developer email david.syer@broadcom.com Low Vendor pom developer email github@gprussell.net Low Vendor pom developer id artembilan Medium Vendor pom developer id dsyer Medium Vendor pom developer id garyrussell Medium Vendor pom developer name Artem Bilan Medium Vendor pom developer name Dave Syer Medium Vendor pom developer name Gary Russell Medium Vendor pom groupid org.springframework.retry Highest Vendor pom name Spring Retry High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io Medium Vendor pom url spring-projects/spring-retry Highest Product file name spring-retry High Product jar package name backoff Highest Product jar package name policy Highest Product jar package name retry Highest Product jar package name springframework Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid spring-retry Highest Product pom developer email artem.bilan@broadcom.com Low Product pom developer email david.syer@broadcom.com Low Product pom developer email github@gprussell.net Low Product pom developer id artembilan Low Product pom developer id dsyer Low Product pom developer id garyrussell Low Product pom developer name Artem Bilan Low Product pom developer name Dave Syer Low Product pom developer name Gary Russell Low Product pom groupid org.springframework.retry Highest Product pom name Spring Retry High Product pom organization name Spring IO Low Product pom organization url https://spring.io Low Product pom url spring-projects/spring-retry High Version file version 2.0.11 High Version pom version 2.0.11 Highest
spring-security-core-6.3.9.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-core/6.3.9/spring-security-core-6.3.9.jar
MD5: 119f8471a5db75c043d52e8539b735c6
SHA1: 70dd35fe2c70fe78c3f431647b2fc492f0912120
SHA256: c3b06c4c7e4cc437363785b94d5ac57af5a08ff54046bfecf4c387220660be06
Referenced In Project/Scope: Users Admin Web:compile
spring-security-core-6.3.9.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-security-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.security.core Medium Vendor pom artifactid spring-security-core Highest Vendor pom artifactid spring-security-core Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-core High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-core High Product jar package name core Highest Product jar package name security Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.core Medium Product Manifest Implementation-Title spring-security-core High Product pom artifactid spring-security-core Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-core High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 6.3.9 High Version Manifest Implementation-Version 6.3.9 High Version pom version 6.3.9 Highest
Related Dependencies spring-security-config-6.3.9.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-config/6.3.9/spring-security-config-6.3.9.jar MD5: 17cbb0bc25523b3c52752c04810a2e5a SHA1: df93baca5028e34b8f493ca02d0798ba792e020d SHA256: c2b2eb838107c4f6f06a26ae4d6bf895d8661b82299bf382d7fa8aeb23540c88 pkg:maven/org.springframework.security/spring-security-config@6.3.9 spring-security-crypto-6.3.9.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-crypto/6.3.9/spring-security-crypto-6.3.9.jar MD5: ae914be1d97e2fce0e2384411d3e668c SHA1: 5bccf0319e5167a58fa64caba898959cbe3110fe SHA256: 73487877b5a8254800e659a42c0311fe5c26fe9cb780d8ff9d4bca04fd10c1e8 pkg:maven/org.springframework.security/spring-security-crypto@6.3.9 spring-security-oauth2-resource-server-6.3.9.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-oauth2-resource-server/6.3.9/spring-security-oauth2-resource-server-6.3.9.jar
MD5: 2354be71eebe2c9ad68266579cd2b7e0
SHA1: 517b1e3c296869335a3abf6f775ceeba8184d3a8
SHA256: 41037e11206a5e9453e9890c859ca5fed82d1cf79f2ece61d9fd23296390c123
Referenced In Project/Scope: Users Admin Web:compile
spring-security-oauth2-resource-server-6.3.9.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-commons-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-security-oauth2-resource-server High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name oauth2 Highest Vendor jar package name security Highest Vendor jar package name server Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.security.oauth2.resource.server Medium Vendor pom artifactid spring-security-oauth2-resource-server Highest Vendor pom artifactid spring-security-oauth2-resource-server Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-oauth2-resource-server High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-oauth2-resource-server High Product jar package name oauth2 Highest Product jar package name security Highest Product jar package name server Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.oauth2.resource.server Medium Product Manifest Implementation-Title spring-security-oauth2-resource-server High Product pom artifactid spring-security-oauth2-resource-server Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-oauth2-resource-server High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 6.3.9 High Version Manifest Implementation-Version 6.3.9 High Version pom version 6.3.9 Highest
Related Dependencies spring-security-oauth2-core-6.3.9.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-oauth2-core/6.3.9/spring-security-oauth2-core-6.3.9.jar MD5: e7759eb095c973f30ec0cb02afa3edb3 SHA1: af55f3b1bfa70ea6ab0d49cec043b31f40477cff SHA256: 01ea819beeea787b7811b219044a4267bf68752661b3d5342714ff2fab01b4a2 pkg:maven/org.springframework.security/spring-security-oauth2-core@6.3.9 spring-security-oauth2-jose-6.3.9.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-oauth2-jose/6.3.9/spring-security-oauth2-jose-6.3.9.jar MD5: a64633d24cd9bd69180ad417a4b8c64e SHA1: bbcd94afc2880f97bcc71d5bb88882450eb1eb28 SHA256: c907f67c092fda877a6293201b46f8a324fcb3ed0e1c27de7035622e12f99303 pkg:maven/org.springframework.security/spring-security-oauth2-jose@6.3.9 spring-security-web-6.3.9.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/security/spring-security-web/6.3.9/spring-security-web-6.3.9.jar
MD5: d2ffe936d52fc7c438007c14e59641a6
SHA1: 172d00cd128561a0acd2ca81fe7ee508ba489ada
SHA256: 0d452463f5a860da963873842e72dbb96c0198513d19d186cd15fadb111344ab
Referenced In Project/Scope: Users Admin Web:compile
spring-security-web-6.3.9.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-security-web High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name spring.security.web Medium Vendor pom artifactid spring-security-web Highest Vendor pom artifactid spring-security-web Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-web High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-web High Product jar package name security Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest automatic-module-name spring.security.web Medium Product Manifest Implementation-Title spring-security-web High Product pom artifactid spring-security-web Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-web High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 6.3.9 High Version Manifest Implementation-Version 6.3.9 High Version pom version 6.3.9 Highest
spring-web-6.1.19.jarDescription:
Spring Web License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /opt/tomcat/.m2/repository/org/springframework/spring-web/6.1.19/spring-web-6.1.19.jar
MD5: 0dc2be1ade9148172e2c76546eaa6418
SHA1: 86ee75c9042bff1c1e59e35ad15a8f9385b45f0f
SHA256: 163d2155b9ac25eb56b26fd5bf667192c4290992bc0444f90033a81f5f6e887e
Referenced In Project/Scope: Users Admin Web:compile
spring-web-6.1.19.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-web High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name spring.web Medium Vendor pom artifactid spring-web Highest Vendor pom artifactid spring-web Low Vendor pom developer email juergen.hoeller@broadcom.com Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Web High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-web High Product hint analyzer product springsource_spring_framework Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest automatic-module-name spring.web Medium Product Manifest Implementation-Title spring-web High Product pom artifactid spring-web Highest Product pom developer email juergen.hoeller@broadcom.com Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Web High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 6.1.19 High Version Manifest Implementation-Version 6.1.19 High Version pom version 6.1.19 Highest
Related Dependencies spring-webmvc-6.1.19.jarFile Path: /opt/tomcat/.m2/repository/org/springframework/spring-webmvc/6.1.19/spring-webmvc-6.1.19.jar MD5: e882d9efcfb6763889ff053421f91360 SHA1: 30945e1ae7512aef8b10f035e59df758c0808458 SHA256: 757abd1f74626519964e7e06c04d2f1496ac983cf9b7a32db05193323e272b89 pkg:maven/org.springframework/spring-webmvc@6.1.19 swagger-annotations-2.2.18.jarDescription:
swagger-annotations License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html" File Path: /opt/tomcat/.m2/repository/io/swagger/core/v3/swagger-annotations/2.2.18/swagger-annotations-2.2.18.jar
MD5: 89fdf32376651c2a5f1d6ba6ee92c4e9
SHA1: 72ed83a368c13d8963e986bdc82f7105a1439c49
SHA256: 436eb3cea261c770be1a37eb6b4752bb08b776228f8480890763df38390a227d
Referenced In Project/Scope: Users Admin Web:compile
swagger-annotations-2.2.18.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-admin-web@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name swagger-annotations High Vendor jar package name io Highest Vendor jar package name oas Highest Vendor jar package name swagger Highest Vendor jar package name v3 Highest Vendor Manifest automatic-module-name io.swagger.v3.oas.annotations Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-annotations Medium Vendor Manifest mode development Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Vendor pom artifactid swagger-annotations Highest Vendor pom artifactid swagger-annotations Low Vendor pom groupid io.swagger.core.v3 Highest Vendor pom name swagger-annotations High Vendor pom parent-artifactid swagger-project Low Product file name swagger-annotations High Product jar package name io Highest Product jar package name oas Highest Product jar package name swagger Highest Product jar package name v3 Highest Product Manifest automatic-module-name io.swagger.v3.oas.annotations Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-developers frantuma;email="frantuma@yahoo.com";name="Francesco Tumanischvili",fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Product Manifest Bundle-Name swagger-annotations Medium Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-annotations Medium Product Manifest mode development Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Product pom artifactid swagger-annotations Highest Product pom groupid io.swagger.core.v3 Highest Product pom name swagger-annotations High Product pom parent-artifactid swagger-project Medium Version file version 2.2.18 High Version Manifest Bundle-Version 2.2.18 High Version Manifest implementation-version 2.2.18 High Version pom version 2.2.18 Highest
tomcat-embed-core-10.1.40.jarDescription:
Core Tomcat implementation License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/10.1.40/tomcat-embed-core-10.1.40.jar
MD5: 469a77d350935dc68e88be91bc337ee1
SHA1: fc1c09b726336dc6f7dde0408cebb1a56a3a28d3
SHA256: a837da48929985b35a489265bc4d6250b7209a2eaf646de7597ed22a028c610c
Referenced In Project/Scope: Users Admin Web:compile
tomcat-embed-core-10.1.40.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@3.3.11
Evidence Type Source Name Value Confidence Vendor file name tomcat-embed-core High Vendor jar package name apache Highest Vendor jar package name core Highest Vendor jar package name tomcat Highest Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.0";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.0";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.apache.juli.logging.Log)";osgi.serviceloader="org.apache.juli.logging.Log",osgi.contract;osgi.contract=JakartaAnnotations;filter:="(&(osgi.contract=JakartaAnnotations)(version=2.1.0))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor Manifest specification-vendor Apache Software Foundation Low Vendor manifest: jakarta/security/auth/message/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/security/auth/message/callback/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/security/auth/message/config/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/security/auth/message/module/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/servlet/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/servlet/annotation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/servlet/descriptor/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/servlet/http/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: jakarta/servlet/resources/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid tomcat-embed-core Highest Vendor pom artifactid tomcat-embed-core Low Vendor pom groupid org.apache.tomcat.embed Highest Vendor pom url https://tomcat.apache.org/ Highest Product file name tomcat-embed-core High Product jar package name annotation Highest Product jar package name apache Highest Product jar package name auth Highest Product jar package name core Highest Product jar package name descriptor Highest Product jar package name filter Highest Product jar package name http Highest Product jar package name jakarta Highest Product jar package name juli Highest Product jar package name logging Highest Product jar package name message Highest Product jar package name processor Highest Product jar package name security Highest Product jar package name servlet Highest Product jar package name tomcat Highest Product Manifest Bundle-Name tomcat-embed-core Medium Product Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium Product Manifest Implementation-Title Apache Tomcat High Product Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.0";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.0";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.apache.juli.logging.Log)";osgi.serviceloader="org.apache.juli.logging.Log",osgi.contract;osgi.contract=JakartaAnnotations;filter:="(&(osgi.contract=JakartaAnnotations)(version=2.1.0))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product Manifest specification-title Apache Tomcat Medium Product manifest: jakarta/security/auth/message/ Implementation-Title jakarta.security.auth.message Medium Product manifest: jakarta/security/auth/message/ Specification-Title Jakarta Authentication SPI for Containers Medium Product manifest: jakarta/security/auth/message/callback/ Implementation-Title jakarta.security.auth.message Medium Product manifest: jakarta/security/auth/message/callback/ Specification-Title Jakarta Authentication SPI for Containers Medium Product manifest: jakarta/security/auth/message/config/ Implementation-Title jakarta.security.auth.message Medium Product manifest: jakarta/security/auth/message/config/ Specification-Title Jakarta Authentication SPI for Containers Medium Product manifest: jakarta/security/auth/message/module/ Implementation-Title jakarta.security.auth.message Medium Product manifest: jakarta/security/auth/message/module/ Specification-Title Jakarta Authentication SPI for Containers Medium Product manifest: jakarta/servlet/ Implementation-Title jakarta.servlet Medium Product manifest: jakarta/servlet/ Specification-Title Jakarta Servlet Medium Product manifest: jakarta/servlet/annotation/ Implementation-Title jakarta.servlet Medium Product manifest: jakarta/servlet/annotation/ Specification-Title Jakarta Servlet Medium Product manifest: jakarta/servlet/descriptor/ Implementation-Title jakarta.servlet Medium Product manifest: jakarta/servlet/descriptor/ Specification-Title Jakarta Servlet Medium Product manifest: jakarta/servlet/http/ Implementation-Title jakarta.servlet Medium Product manifest: jakarta/servlet/http/ Specification-Title Jakarta Servlet Medium Product manifest: jakarta/servlet/resources/ Implementation-Title jakarta.servlet Medium Product manifest: jakarta/servlet/resources/ Specification-Title Jakarta Servlet Medium Product pom artifactid tomcat-embed-core Highest Product pom groupid org.apache.tomcat.embed Highest Product pom url https://tomcat.apache.org/ Medium Version file version 10.1.40 High Version Manifest Bundle-Version 10.1.40 High Version Manifest Implementation-Version 10.1.40 High Version pom version 10.1.40 Highest
Related Dependencies tomcat-embed-websocket-10.1.40.jarFile Path: /opt/tomcat/.m2/repository/org/apache/tomcat/embed/tomcat-embed-websocket/10.1.40/tomcat-embed-websocket-10.1.40.jar MD5: 12b369d0c90e9f876928e11518a0eb85 SHA1: ffdcf96aa28e77858644f4db100e8de896ba58e3 SHA256: e40a64d119891c66e185a1da753cccce12d55937c8df01f9f45463eb06e91f55 pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@10.1.40 tomcat-embed-el-10.1.40.jarDescription:
Core Tomcat implementation License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /opt/tomcat/.m2/repository/org/apache/tomcat/embed/tomcat-embed-el/10.1.40/tomcat-embed-el-10.1.40.jar
MD5: c80cb09246e057b85dfa5c25deb562ba
SHA1: 1b321790508c1d410689b4f496dae18a97fa6ae9
SHA256: 138e1b8bcb06890b38408b0801d2f4c2a5a375947aa8d3fc12ac2f98573d5385
Referenced In Project/Scope: Users Admin Web:compile
tomcat-embed-el-10.1.40.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-validation@3.3.11
Evidence Type Source Name Value Confidence Vendor file name tomcat-embed-el High Vendor jar package name apache Highest Vendor jar package name el Highest Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="5.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.el.ExpressionFactory)";osgi.serviceloader="jakarta.el.ExpressionFactory",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))",osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))" Low Vendor Manifest specification-vendor Apache Software Foundation Low Vendor manifest: jakarta/el/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid tomcat-embed-el Highest Vendor pom artifactid tomcat-embed-el Low Vendor pom groupid org.apache.tomcat.embed Highest Vendor pom url https://tomcat.apache.org/ Highest Product file name tomcat-embed-el High Product jar package name apache Highest Product jar package name el Highest Product jar package name expression Highest Product jar package name expressionfactory Highest Product jar package name expressionfactoryimpl Highest Product jar package name jakarta Highest Product Manifest Bundle-Name tomcat-embed-jasper-el Medium Product Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium Product Manifest Implementation-Title Apache Tomcat High Product Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="5.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=jakarta.el.ExpressionFactory)";osgi.serviceloader="jakarta.el.ExpressionFactory",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))",osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))" Low Product Manifest specification-title Apache Tomcat Medium Product manifest: jakarta/el/ Implementation-Title jakarta.annotation Medium Product manifest: jakarta/el/ Specification-Title Jakarta Expression Language Medium Product pom artifactid tomcat-embed-el Highest Product pom groupid org.apache.tomcat.embed Highest Product pom url https://tomcat.apache.org/ Medium Version file version 10.1.40 High Version Manifest Bundle-Version 10.1.40 High Version Manifest Implementation-Version 10.1.40 High Version pom version 10.1.40 Highest
txw2-4.0.3.jarDescription:
TXW is a library that allows you to write XML documents.
File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/txw2/4.0.3/txw2-4.0.3.jarMD5: b95e92bbc4dd7183916a11ed210b6169SHA1: 47b8fe31c6d1a3382203af919400527389e01e9cSHA256: df07a51801b995e44aec9a95ef875d95fbb8de2874417de6066d84f731cb9e9cReferenced In Project/Scope: Users Admin Web:compiletxw2-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name txw2 High Vendor jar package name sun Highest Vendor jar package name txw Highest Vendor jar package name txw2 Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid txw2 Highest Vendor pom artifactid txw2 Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name TXW2 Runtime High Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name txw2 High Product jar package name sun Highest Product jar package name txw Highest Product jar package name txw2 Highest Product jar package name xml Highest Product Manifest git-revision ff66b10 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid txw2 Highest Product pom groupid org.glassfish.jaxb Highest Product pom name TXW2 Runtime High Product pom parent-artifactid jaxb-txw-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest build-version 4.0.3 Medium Version pom version 4.0.3 Highest
xsom-4.0.3.jarDescription:
XML Schema Object Model (XSOM) is a Java library that allows applications to easily parse XML Schema
documents and inspect information in them. It is expected to be useful for applications that need to take XML
Schema as an input.
License:
Eclipse Distribution License - v 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /opt/tomcat/.m2/repository/org/glassfish/jaxb/xsom/4.0.3/xsom-4.0.3.jar
MD5: 050161218c72a27c4191e9e6e6f33122
SHA1: 4406ab2fd87b18abfa996870000ff88119de7c6d
SHA256: 247a2348fcfd983ef38d9ada0827d0684630e9018b3839c91df3f56a10a9b01a
Referenced In Project/Scope: Users Admin Web:compile
xsom-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/net.andresbustamante/y-a-foot-users-services@2.0.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name xsom High Vendor jar package name xml Highest Vendor jar package name xsom Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.xsom Medium Vendor Manifest implementation-build-id 4.0.3 - ff66b10 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Vendor pom artifactid xsom Highest Vendor pom artifactid xsom Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name XSOM High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name xsom High Product jar package name xml Highest Product jar package name xsom Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name XSOM Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.xsom Medium Product Manifest implementation-build-id 4.0.3 - ff66b10 Low Product Manifest Implementation-Title XSOM High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=11))" Low Product pom artifactid xsom Highest Product pom groupid org.glassfish.jaxb Highest Product pom name XSOM High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.3 High Version Manifest Bundle-Version 4.0.3 High Version Manifest implementation-build-id 4.0.3 Low Version Manifest Implementation-Version 4.0.3 High Version pom parent-version 4.0.3 Low Version pom version 4.0.3 Highest