Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: google group | github issues

Project: marxls

net.technearts:marxls:0.0.2

Scan Information (show all):

Display: Showing Vulnerable Dependencies (click to show all)

DependencyCPECoordinatesHighest SeverityCVE CountCPE ConfidenceEvidence Count
slf4j-api-1.7.25.jarorg.slf4j:slf4j-api:1.7.25 028
lombok-1.18.0.jarorg.projectlombok:lombok:1.18.0 015
commons-codec-1.10.jarcommons-codec:commons-codec:1.10 035
commons-collections4-4.1.jarcpe:/a:apache:commons_collections:4.1org.apache.commons:commons-collections4:4.1 0Low36
poi-3.17.jarcpe:/a:apache:poi:3.17org.apache.poi:poi:3.17 0Low25
curvesapi-1.04.jarcom.github.virtuald:curvesapi:1.04 018
jsr305-3.0.2.jarcom.google.code.findbugs:jsr305:3.0.2 020
checker-qual-2.5.2.jarorg.checkerframework:checker-qual:2.5.2 018
error_prone_annotations-2.1.3.jarcom.google.errorprone:error_prone_annotations:2.1.3 020
j2objc-annotations-1.1.jarcom.google.j2objc:j2objc-annotations:1.1 020
animal-sniffer-annotations-1.14.jarorg.codehaus.mojo:animal-sniffer-annotations:1.14 021
guava-26.0-jre.jarcpe:/a:google:guava:26.0com.google.guava:guava:26.0-jre 0Low28
stax-api-1.0.1.jarcpe:/a:st_project:st:1.0.1stax:stax-api:1.0.1Medium1Low19
xmlbeans-2.6.0.jarorg.apache.xmlbeans:xmlbeans:2.6.0 021
commons-lang3-3.7.jarorg.apache.commons:commons-lang3:3.7 038
snakeyaml-1.17.jarorg.yaml:snakeyaml:1.17 024
jackson-core-2.9.0.jarcpe:/a:fasterxml:jackson:2.9.0com.fasterxml.jackson.core:jackson-core:2.9.0 0Low36
jackson-databind-2.9.0.jarcpe:/a:fasterxml:jackson-databind:2.9.0
cpe:/a:fasterxml:jackson:2.9.0
com.fasterxml.jackson.core:jackson-databind:2.9.0High11Highest36
commons-logging-1.2.jarcommons-logging:commons-logging:1.2 033
commons-collections-3.2.2.jarcpe:/a:apache:commons_collections:3.2.2commons-collections:commons-collections:3.2.2 0Low37
commons-beanutils-1.9.3.jarcpe:/a:apache:commons_beanutils:1.9.3commons-beanutils:commons-beanutils:1.9.3 0Low37

Dependencies

slf4j-api-1.7.25.jar

Description:

 The slf4j API

File Path: /home/paulo/.m2/repository/org/slf4j/slf4j-api/1.7.25/slf4j-api-1.7.25.jar
MD5: caafe376afb7086dcbee79f780394ca3
SHA1: da76ca59f6a57ee3102f8f9bd9cee742973efa8a
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.slf4j:slf4j-api:1.7.25  Confidence:Highest

lombok-1.18.0.jar

Description:

 Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: /home/paulo/.m2/repository/org/projectlombok/lombok/1.18.0/lombok-1.18.0.jar
MD5: b9e6229086cbbb6ac6fc6ecbc62a6ef4
SHA1: c4647d46f0742746ac07ce4abeeee9b2fb18d147
Referenced In Project/Scope:marxls:provided

Identifiers

  • maven: org.projectlombok:lombok:1.18.0  Confidence:Highest

commons-codec-1.10.jar

Description:

 
     The Apache Commons Codec package contains simple encoder and decoders for
     various formats such as Base64 and Hexadecimal.  In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: commons-codec:commons-codec:1.10  Confidence:Highest

commons-collections4-4.1.jar

Description:

 The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/commons/commons-collections4/4.1/commons-collections4-4.1.jar
MD5: 45af6a8e5b51d5945de6c7411e290bd1
SHA1: a4cf4688fe1c7e3a63aa636cc96d013af537768e
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.apache.commons:commons-collections4:4.1  Confidence:Highest
  • cpe: cpe:/a:apache:commons_collections:4.1  Confidence:Low  

poi-3.17.jar

Description:

 Apache POI - Java API To Access Microsoft Format Files

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/poi/poi/3.17/poi-3.17.jar
MD5: 243bc3d431e4fadb79738719504c64f7
SHA1: 0ae92292a2043888b40d418da97dc0b669fde326
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:apache:poi:3.17  Confidence:Low  
  • maven: org.apache.poi:poi:3.17  Confidence:Highest

curvesapi-1.04.jar

Description:

 Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS.

License:

BSD License: http://opensource.org/licenses/BSD-3-Clause
File Path: /home/paulo/.m2/repository/com/github/virtuald/curvesapi/1.04/curvesapi-1.04.jar
MD5: 0dcbd9b7e498d1118c920d1d55046743
SHA1: 3386abf821719bc89c7685f9eaafaf4a842f0199
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: com.github.virtuald:curvesapi:1.04  Confidence:Highest

jsr305-3.0.2.jar

Description:

 JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: com.google.code.findbugs:jsr305:3.0.2  Confidence:Highest

checker-qual-2.5.2.jar

Description:

 
        Checker Qual is the set of annotations (qualifiers) and supporting classes
        used by the Checker Framework to type check Java source code.  Please
        see artifact:
        org.checkerframework:checker
    

License:

The MIT License: http://opensource.org/licenses/MIT
File Path: /home/paulo/.m2/repository/org/checkerframework/checker-qual/2.5.2/checker-qual-2.5.2.jar
MD5: 04acc78b24bbd365423da357da003cf0
SHA1: cea74543d5904a30861a61b4643a5f2bb372efc4
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.checkerframework:checker-qual:2.5.2  Confidence:Highest

error_prone_annotations-2.1.3.jar

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/errorprone/error_prone_annotations/2.1.3/error_prone_annotations-2.1.3.jar
MD5: 97504b36cf871722d81a4b9e114f2a16
SHA1: 39b109f2cd352b2d71b52a3b5a1a9850e1dc304b
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: com.google.errorprone:error_prone_annotations:2.1.3  Confidence:Highest

j2objc-annotations-1.1.jar

Description:

 
    A set of annotations that provide additional information to the J2ObjC
    translator to modify the result of translation.
  

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/j2objc/j2objc-annotations/1.1/j2objc-annotations-1.1.jar
MD5: 49ae3204bb0bb9b2ac77062641f4a6d7
SHA1: ed28ded51a8b1c6b112568def5f4b455e6809019
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: com.google.j2objc:j2objc-annotations:1.1  Confidence:Highest

animal-sniffer-annotations-1.14.jar

File Path: /home/paulo/.m2/repository/org/codehaus/mojo/animal-sniffer-annotations/1.14/animal-sniffer-annotations-1.14.jar
MD5: 9d42e46845c874f1710a9f6a741f6c14
SHA1: 775b7e22fb10026eed3f86e8dc556dfafe35f2d5
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.codehaus.mojo:animal-sniffer-annotations:1.14  Confidence:Highest

guava-26.0-jre.jar

Description:

 
    Guava is a suite of core and expanded libraries that include
    utility classes, google's collections, io classes, and much
    much more.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/guava/guava/26.0-jre/guava-26.0-jre.jar
MD5: db2d6eae3ec08b0fd752ef0c5672aab7
SHA1: 6a806eff209f36f635f943e16d97491f00f6bfab
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:google:guava:26.0  Confidence:Low  
  • maven: com.google.guava:guava:26.0-jre  Confidence:Highest

stax-api-1.0.1.jar

Description:

 StAX API is the standard java XML processing API defined by JSR-173

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/stax/stax-api/1.0.1/stax-api-1.0.1.jar
MD5: 7d436a53c64490bee564c576babb36b4
SHA1: 49c100caf72d658aca8e58bd74a4ba90fa2b0d70
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:st_project:st:1.0.1  Confidence:Low  
  • maven: stax:stax-api:1.0.1  Confidence:Highest

CVE-2017-16224  

Severity:Medium
CVSS Score: 5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N)
CWE: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").

Vulnerable Software & Versions:

xmlbeans-2.6.0.jar

Description:

 XmlBeans main jar

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/xmlbeans/xmlbeans/2.6.0/xmlbeans-2.6.0.jar
MD5: 6591c08682d613194dacb01e95c78c2c
SHA1: 29e80d2dd51f9dcdef8f9ffaee0d4dc1c9bbfc87
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.apache.xmlbeans:xmlbeans:2.6.0  Confidence:Highest

commons-lang3-3.7.jar

Description:

 
  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/commons/commons-lang3/3.7/commons-lang3-3.7.jar
MD5: f1df5623d78c432b7c3d58ff491e1801
SHA1: 557edd918fd41f9260963583ebf5a61a43a6b423
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.apache.commons:commons-lang3:3.7  Confidence:Highest

snakeyaml-1.17.jar

Description:

 YAML 1.1 parser and emitter for Java

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/yaml/snakeyaml/1.17/snakeyaml-1.17.jar
MD5: ab621c3cee316236ad04a6f0fe4dd17c
SHA1: 7a27ea250c5130b2922b86dea63cbb1cc10a660c
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: org.yaml:snakeyaml:1.17  Confidence:Highest

jackson-core-2.9.0.jar

Description:

 Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.9.0/jackson-core-2.9.0.jar
MD5: 2db8443005d095a6c7464b56324a738f
SHA1: 88e7c6220be3b3497b3074d3fc7754213289b987
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:fasterxml:jackson:2.9.0  Confidence:Low  
  • maven: com.fasterxml.jackson.core:jackson-core:2.9.0  Confidence:Highest

jackson-databind-2.9.0.jar

Description:

 General data-binding functionality for Jackson: works on core streaming API

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.9.0/jackson-databind-2.9.0.jar
MD5: bc9eddd751df7dbe30d4c68a1662c3de
SHA1: 14fb5f088cc0b0dc90a73ba745bcade4961a3ee3
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:fasterxml:jackson-databind:2.9.0  Confidence:Highest  
  • maven: com.fasterxml.jackson.core:jackson-databind:2.9.0  Confidence:Highest
  • cpe: cpe:/a:fasterxml:jackson:2.9.0  Confidence:Low  

CVE-2017-15095  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

Vulnerable Software & Versions: (show all)

CVE-2018-1000873  

Severity:Medium
CVSS Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
CWE: CWE-20 Improper Input Validation

Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.

Vulnerable Software & Versions: (show all)

CVE-2018-12022  

Severity:Medium
CVSS Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

Vulnerable Software & Versions: (show all)

CVE-2018-12023  

Severity:Medium
CVSS Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

Vulnerable Software & Versions: (show all)

CVE-2018-14719  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

Vulnerable Software & Versions: (show all)

CVE-2018-14720  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-611 Improper Restriction of XML External Entity Reference ('XXE')

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

Vulnerable Software & Versions: (show all)

CVE-2018-14721  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-918 Server-Side Request Forgery (SSRF)

FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

Vulnerable Software & Versions: (show all)

CVE-2018-19360  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

Vulnerable Software & Versions: (show all)

CVE-2018-19361  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

Vulnerable Software & Versions: (show all)

CVE-2018-19362  

Severity:High
CVSS Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
CWE: CWE-502 Deserialization of Untrusted Data

FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

Vulnerable Software & Versions: (show all)

CVE-2018-5968  

Severity:Medium
CVSS Score: 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)
CWE: CWE-184 Incomplete Blacklist

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

Vulnerable Software & Versions: (show all)

commons-logging-1.2.jar

Description:

 Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
Referenced In Project/Scope:marxls:compile

Identifiers

  • maven: commons-logging:commons-logging:1.2  Confidence:Highest

commons-collections-3.2.2.jar

Description:

 Types that extend and augment the Java Collections Framework.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:apache:commons_collections:3.2.2  Confidence:Low  
  • maven: commons-collections:commons-collections:3.2.2  Confidence:Highest

commons-beanutils-1.9.3.jar

Description:

 Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-beanutils/commons-beanutils/1.9.3/commons-beanutils-1.9.3.jar
MD5: 4a105c9d029a7edc6f2b16567d37eab6
SHA1: c845703de334ddc6b4b3cd26835458cb1cba1f3d
Referenced In Project/Scope:marxls:compile

Identifiers

  • cpe: cpe:/a:apache:commons_beanutils:1.9.3  Confidence:Low  
  • maven: commons-beanutils:commons-beanutils:1.9.3  Confidence:Highest


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the Node Security Platform.