Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: google group | github issues

Project: rip

net.technearts:rip:0.0.9

Scan Information (show all):

Display: Showing Vulnerable Dependencies (click to show all)

DependencyCPECoordinatesHighest SeverityCVE CountCPE ConfidenceEvidence Count
javax.servlet-api-3.1.0.jarjavax.servlet:javax.servlet-api:3.1.0 033
jetty-io-9.4.8.v20171121.jarorg.eclipse.jetty:jetty-io:9.4.8.v20171121 036
jetty-xml-9.4.8.v20171121.jarcpe:/a:eclipse:jetty:9.4.8.v20171121
cpe:/a:jetty:jetty:9.4.8.v20171121
org.eclipse.jetty:jetty-xml:9.4.8.v20171121 0Low38
websocket-common-9.4.8.v20171121.jarcpe:/a:eclipse:jetty:9.4.8.v20171121
cpe:/a:jetty:jetty:9.4.8.v20171121
org.eclipse.jetty.websocket:websocket-common:9.4.8.v20171121 0Low34
websocket-api-9.4.8.v20171121.jarorg.eclipse.jetty.websocket:websocket-api:9.4.8.v20171121 034
spark-core-2.7.2.jarcpe:/a:sparkjava:spark:2.7.2com.sparkjava:spark-core:2.7.2 0Low22
slf4j-api-1.7.25.jarcpe:/a:slf4j:slf4j:1.7.25org.slf4j:slf4j-api:1.7.25 0Low28
commons-cli-1.4.jarcommons-cli:commons-cli:1.4 037
commons-lang3-3.8.jarorg.apache.commons:commons-lang3:3.8 038
jackson-core-2.9.6.jarcpe:/a:fasterxml:jackson:2.9.6com.fasterxml.jackson.core:jackson-core:2.9.6 0Low38
jsr305-3.0.2.jarcom.google.code.findbugs:jsr305:3.0.2 020
checker-qual-2.5.2.jarorg.checkerframework:checker-qual:2.5.2 018
error_prone_annotations-2.1.3.jarcom.google.errorprone:error_prone_annotations:2.1.3 020
j2objc-annotations-1.1.jarcom.google.j2objc:j2objc-annotations:1.1 020
animal-sniffer-annotations-1.14.jarorg.codehaus.mojo:animal-sniffer-annotations:1.14 021
guava-26.0-jre.jarcom.google.guava:guava:26.0-jre 028
commons-codec-1.10.jarcommons-codec:commons-codec:1.10 035
commons-collections4-4.1.jarcpe:/a:apache:commons_collections:4.1org.apache.commons:commons-collections4:4.1 0Low36
poi-3.17.jarcpe:/a:apache:poi:3.17org.apache.poi:poi:3.17 0Low25
stax-api-1.0.1.jarcpe:/a:st_project:st:1.0.1stax:stax-api:1.0.1Medium1Low19
xmlbeans-2.6.0.jarorg.apache.xmlbeans:xmlbeans:2.6.0 021
curvesapi-1.04.jarcom.github.virtuald:curvesapi:1.04 018
freemarker-2.3.26-incubating.jarorg.freemarker:freemarker:2.3.26-incubating 041
spark-template-freemarker-2.7.1.jarcpe:/a:sparkjava:spark:2.7.1com.sparkjava:spark-template-freemarker:2.7.1 0Low21
commons-logging-1.0.4.jarcommons-logging:commons-logging:1.0.4 023
commons-io-2.1.jarcommons-io:commons-io:2.1 033
jmimemagic-0.1.5.jarnet.sf.jmimemagic:jmimemagic:0.1.5 019
lombok-1.18.0.jarorg.projectlombok:lombok:1.18.0 015

Dependencies

javax.servlet-api-3.1.0.jar

Description:

 Java(TM) Servlet 3.1 API Design Specification

License:

CDDL + GPLv2 with classpath exception: https://glassfish.dev.java.net/nonav/public/CDDL+GPL.html
File Path: /home/paulo/.m2/repository/javax/servlet/javax.servlet-api/3.1.0/javax.servlet-api-3.1.0.jar
MD5: 79de69e9f5ed8c7fcb8342585732bbf7
SHA1: 3cd63d075497751784b2fa84be59432f4905bf7c
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: javax.servlet:javax.servlet-api:3.1.0  Confidence:Highest

jetty-io-9.4.8.v20171121.jar

Description:

 Jetty module for Jetty :: IO Utility

License:

http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/paulo/.m2/repository/org/eclipse/jetty/jetty-io/9.4.8.v20171121/jetty-io-9.4.8.v20171121.jar
MD5: b7cf135927d91368e8813354c1048f43
SHA1: d3fe2dfa62f52ee91ff07cb359f63387e0e30b40
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.eclipse.jetty:jetty-io:9.4.8.v20171121  Confidence:Highest

jetty-xml-9.4.8.v20171121.jar

Description:

 The jetty xml utilities.

License:

http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/paulo/.m2/repository/org/eclipse/jetty/jetty-xml/9.4.8.v20171121/jetty-xml-9.4.8.v20171121.jar
MD5: 2389d2577916fc18a3c1e0e1af668b92
SHA1: b0d6f87f580a9bd7fa9aaf9b7448bf63cf0ac34f
Referenced In Project/Scope:rip:compile

Identifiers

  • cpe: cpe:/a:eclipse:jetty:9.4.8.v20171121  Confidence:Low  
  • cpe: cpe:/a:jetty:jetty:9.4.8.v20171121  Confidence:Low  
  • maven: org.eclipse.jetty:jetty-xml:9.4.8.v20171121  Confidence:Highest

websocket-common-9.4.8.v20171121.jar

Description:

 Jetty module for Jetty :: Websocket :: Common

License:

http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/paulo/.m2/repository/org/eclipse/jetty/websocket/websocket-common/9.4.8.v20171121/websocket-common-9.4.8.v20171121.jar
MD5: 866abae06fcf8d1a5e90ce636c7e8d12
SHA1: 82cd6d9caa68baf6557176159e6e5c37faed0e9b
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.eclipse.jetty.websocket:websocket-common:9.4.8.v20171121  Confidence:Highest
  • cpe: cpe:/a:eclipse:jetty:9.4.8.v20171121  Confidence:Low  
  • cpe: cpe:/a:jetty:jetty:9.4.8.v20171121  Confidence:Low  

websocket-api-9.4.8.v20171121.jar

Description:

 Jetty module for Jetty :: Websocket :: API

License:

http://www.apache.org/licenses/LICENSE-2.0, http://www.eclipse.org/org/documents/epl-v10.php
File Path: /home/paulo/.m2/repository/org/eclipse/jetty/websocket/websocket-api/9.4.8.v20171121/websocket-api-9.4.8.v20171121.jar
MD5: a982aafeda9238f41b8fa87ac787fd23
SHA1: 6d889f9a8b5fd2a573c6d1d518c7e119a6d8c170
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.eclipse.jetty.websocket:websocket-api:9.4.8.v20171121  Confidence:Highest

spark-core-2.7.2.jar

Description:

 A Sinatra inspired java web framework

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/sparkjava/spark-core/2.7.2/spark-core-2.7.2.jar
MD5: 1c59a69913622d25d39efe91ddbe264a
SHA1: b832cca2704a96c027424efafec3fe39392f5aab
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: com.sparkjava:spark-core:2.7.2  Confidence:Highest
  • cpe: cpe:/a:sparkjava:spark:2.7.2  Confidence:Low  

slf4j-api-1.7.25.jar

Description:

 The slf4j API

File Path: /home/paulo/.m2/repository/org/slf4j/slf4j-api/1.7.25/slf4j-api-1.7.25.jar
MD5: caafe376afb7086dcbee79f780394ca3
SHA1: da76ca59f6a57ee3102f8f9bd9cee742973efa8a
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.slf4j:slf4j-api:1.7.25  Confidence:Highest
  • cpe: cpe:/a:slf4j:slf4j:1.7.25  Confidence:Low  

commons-cli-1.4.jar

Description:

 
    Apache Commons CLI provides a simple API for presenting, processing and validating a command line interface.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-cli/commons-cli/1.4/commons-cli-1.4.jar
MD5: c966d7e03507c834d5b09b848560174e
SHA1: c51c00206bb913cd8612b24abd9fa98ae89719b1
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: commons-cli:commons-cli:1.4  Confidence:Highest

commons-lang3-3.8.jar

Description:

 
  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/commons/commons-lang3/3.8/commons-lang3-3.8.jar
MD5: 0e9023b7d40f09a8f7bdb32889ef4449
SHA1: 222fc4cf714a63f27cbdafdbd863efd0d30c8a1e
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.apache.commons:commons-lang3:3.8  Confidence:Highest

jackson-core-2.9.6.jar

Description:

 Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.9.6/jackson-core-2.9.6.jar
MD5: f3cf83b839fac92307cad542c2ded5c4
SHA1: 4e393793c37c77e042ccc7be5a914ae39251b365
Referenced In Project/Scope:rip:compile

Identifiers

  • cpe: cpe:/a:fasterxml:jackson:2.9.6  Confidence:Low  
  • maven: com.fasterxml.jackson.core:jackson-core:2.9.6  Confidence:Highest

jsr305-3.0.2.jar

Description:

 JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: com.google.code.findbugs:jsr305:3.0.2  Confidence:Highest

checker-qual-2.5.2.jar

Description:

 
        Checker Qual is the set of annotations (qualifiers) and supporting classes
        used by the Checker Framework to type check Java source code.  Please
        see artifact:
        org.checkerframework:checker
    

License:

The MIT License: http://opensource.org/licenses/MIT
File Path: /home/paulo/.m2/repository/org/checkerframework/checker-qual/2.5.2/checker-qual-2.5.2.jar
MD5: 04acc78b24bbd365423da357da003cf0
SHA1: cea74543d5904a30861a61b4643a5f2bb372efc4
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.checkerframework:checker-qual:2.5.2  Confidence:Highest

error_prone_annotations-2.1.3.jar

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/errorprone/error_prone_annotations/2.1.3/error_prone_annotations-2.1.3.jar
MD5: 97504b36cf871722d81a4b9e114f2a16
SHA1: 39b109f2cd352b2d71b52a3b5a1a9850e1dc304b
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: com.google.errorprone:error_prone_annotations:2.1.3  Confidence:Highest

j2objc-annotations-1.1.jar

Description:

 
    A set of annotations that provide additional information to the J2ObjC
    translator to modify the result of translation.
  

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/j2objc/j2objc-annotations/1.1/j2objc-annotations-1.1.jar
MD5: 49ae3204bb0bb9b2ac77062641f4a6d7
SHA1: ed28ded51a8b1c6b112568def5f4b455e6809019
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: com.google.j2objc:j2objc-annotations:1.1  Confidence:Highest

animal-sniffer-annotations-1.14.jar

File Path: /home/paulo/.m2/repository/org/codehaus/mojo/animal-sniffer-annotations/1.14/animal-sniffer-annotations-1.14.jar
MD5: 9d42e46845c874f1710a9f6a741f6c14
SHA1: 775b7e22fb10026eed3f86e8dc556dfafe35f2d5
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.codehaus.mojo:animal-sniffer-annotations:1.14  Confidence:Highest

guava-26.0-jre.jar

Description:

 
    Guava is a suite of core and expanded libraries that include
    utility classes, google's collections, io classes, and much
    much more.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/google/guava/guava/26.0-jre/guava-26.0-jre.jar
MD5: db2d6eae3ec08b0fd752ef0c5672aab7
SHA1: 6a806eff209f36f635f943e16d97491f00f6bfab
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: com.google.guava:guava:26.0-jre  Confidence:Highest

commons-codec-1.10.jar

Description:

 
     The Apache Commons Codec package contains simple encoder and decoders for
     various formats such as Base64 and Hexadecimal.  In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-codec/commons-codec/1.10/commons-codec-1.10.jar
MD5: 353cf6a2bdba09595ccfa073b78c7fcb
SHA1: 4b95f4897fa13f2cd904aee711aeafc0c5295cd8
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: commons-codec:commons-codec:1.10  Confidence:Highest

commons-collections4-4.1.jar

Description:

 The Apache Commons Collections package contains types that extend and augment the Java Collections Framework.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/commons/commons-collections4/4.1/commons-collections4-4.1.jar
MD5: 45af6a8e5b51d5945de6c7411e290bd1
SHA1: a4cf4688fe1c7e3a63aa636cc96d013af537768e
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.apache.commons:commons-collections4:4.1  Confidence:Highest
  • cpe: cpe:/a:apache:commons_collections:4.1  Confidence:Low  

poi-3.17.jar

Description:

 Apache POI - Java API To Access Microsoft Format Files

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/poi/poi/3.17/poi-3.17.jar
MD5: 243bc3d431e4fadb79738719504c64f7
SHA1: 0ae92292a2043888b40d418da97dc0b669fde326
Referenced In Project/Scope:rip:compile

Identifiers

  • cpe: cpe:/a:apache:poi:3.17  Confidence:Low  
  • maven: org.apache.poi:poi:3.17  Confidence:Highest

stax-api-1.0.1.jar

Description:

 StAX API is the standard java XML processing API defined by JSR-173

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/stax/stax-api/1.0.1/stax-api-1.0.1.jar
MD5: 7d436a53c64490bee564c576babb36b4
SHA1: 49c100caf72d658aca8e58bd74a4ba90fa2b0d70
Referenced In Project/Scope:rip:compile

Identifiers

  • cpe: cpe:/a:st_project:st:1.0.1  Confidence:Low  
  • maven: stax:stax-api:1.0.1  Confidence:Highest

CVE-2017-16224  

Severity:Medium
CVSS Score: 5.8 (AV:N/AC:M/Au:N/C:P/I:P/A:N)
CWE: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").

Vulnerable Software & Versions:

xmlbeans-2.6.0.jar

Description:

 XmlBeans main jar

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/apache/xmlbeans/xmlbeans/2.6.0/xmlbeans-2.6.0.jar
MD5: 6591c08682d613194dacb01e95c78c2c
SHA1: 29e80d2dd51f9dcdef8f9ffaee0d4dc1c9bbfc87
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.apache.xmlbeans:xmlbeans:2.6.0  Confidence:Highest

curvesapi-1.04.jar

Description:

 Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS.

License:

BSD License: http://opensource.org/licenses/BSD-3-Clause
File Path: /home/paulo/.m2/repository/com/github/virtuald/curvesapi/1.04/curvesapi-1.04.jar
MD5: 0dcbd9b7e498d1118c920d1d55046743
SHA1: 3386abf821719bc89c7685f9eaafaf4a842f0199
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: com.github.virtuald:curvesapi:1.04  Confidence:Highest

freemarker-2.3.26-incubating.jar

Description:

 
    FreeMarker is a "template engine"; a generic tool to generate text output based on templates.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/org/freemarker/freemarker/2.3.26-incubating/freemarker-2.3.26-incubating.jar
MD5: cbb030d58da59a3c597b65cec837c37e
SHA1: 713237e013f725b72f4f9ec931a49c14b1805359
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: org.freemarker:freemarker:2.3.26-incubating  Confidence:Highest

spark-template-freemarker-2.7.1.jar

Description:

 Freemarker Template Engine implementation for Spark

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/com/sparkjava/spark-template-freemarker/2.7.1/spark-template-freemarker-2.7.1.jar
MD5: 6e8db1ef3b369caa9bfd2bf9e9f7ba41
SHA1: 918e0063095a40a606dbf5f5c9917936b33b9686
Referenced In Project/Scope:rip:compile

Identifiers

  • cpe: cpe:/a:sparkjava:spark:2.7.1  Confidence:Low  
  • maven: com.sparkjava:spark-template-freemarker:2.7.1  Confidence:Highest

commons-logging-1.0.4.jar

Description:

 Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

The Apache Software License, Version 2.0: /LICENSE.txt
File Path: /home/paulo/.m2/repository/commons-logging/commons-logging/1.0.4/commons-logging-1.0.4.jar
MD5: 8a507817b28077e0478add944c64586a
SHA1: f029a2aefe2b3e1517573c580f948caac31b1056
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: commons-logging:commons-logging:1.0.4  Confidence:Highest

commons-io-2.1.jar

Description:

 
        The Commons IO library contains utility classes, stream implementations, file filters, file comparators and endian classes.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/commons-io/commons-io/2.1/commons-io-2.1.jar
MD5: 4854c2344aa182ad4f37976e83348aa0
SHA1: fd51f906669f49a4ffd06650666c3b8147a6106e
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: commons-io:commons-io:2.1  Confidence:Highest

jmimemagic-0.1.5.jar

Description:

 jMimeMagic is a Java library for determining the content type of files or streams.

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/paulo/.m2/repository/net/sf/jmimemagic/jmimemagic/0.1.5/jmimemagic-0.1.5.jar
MD5: 395348f324e112a92b1b3fe53f2f7bae
SHA1: 578173de87352d7b589fdb8f3648b5b8e112f7a0
Referenced In Project/Scope:rip:compile

Identifiers

  • maven: net.sf.jmimemagic:jmimemagic:0.1.5  Confidence:Highest

lombok-1.18.0.jar

Description:

 Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: /home/paulo/.m2/repository/org/projectlombok/lombok/1.18.0/lombok-1.18.0.jar
MD5: b9e6229086cbbb6ac6fc6ecbc62a6ef4
SHA1: c4647d46f0742746ac07ce4abeeee9b2fb18d147
Referenced In Project/Scope:rip:provided

Identifiers

  • maven: org.projectlombok:lombok:1.18.0  Confidence:Highest


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the Node Security Platform.